Effective 31 August 2026

Privacy Policy

How VisionX Studio handles the data you give us and the media you make. Written to be read, not skimmed past.

Who we are

VisionX Studio (“VisionX”, “we”) operates vxstudio.ai, a production platform where brand and agency teams generate, edit, and deliver AI video and imagery. This policy covers the website, the studio application, our API and MCP surfaces, and billing. Contact for anything in this document: shaurya@vxstudio.ai.

What we collect

  • Account and workspace data. Your email, name, workspace membership and role, and authentication records. Sign-in is handled by our auth provider; if you sign in with Google, we receive your email and basic profile from Google and no password is stored with us.
  • Content you upload. Reference images, clips, audio, brand assets, and Cast identity photos. You choose what to upload; uploads of identifiable real people are subject to the consent controls described below.
  • Content we generate for you. Prompts, generation settings, the resulting media, and per-job metadata such as engine, resolution, duration, and VX cost.
  • Billing data. Payments run through Stripe. We store your plan, invoices, and credit ledger; card numbers never touch our servers.
  • Usage and audit records. Application logs, and for API/agent access a per-call audit trail (which tool was called, by which credential, in which workspace, and what it cost). These exist so you can see exactly what an agent did with your credits.

Where it lives

Structured data (accounts, workspaces, jobs, ledgers) is stored with Supabase (PostgreSQL) in Singapore. Generated and uploaded media is stored on BytePlus TOS object storage in Jakarta, Indonesia. The application is served by Vercel behind Cloudflare.

Who processes it for us

We use a small set of providers to run the product, each receiving only what its job requires:

  • Generation model providers. Your prompt and any references you attach are sent to the model that renders the job — BytePlus (Seedance, Seedream) directly, and other engines (for example OpenAI, Google, Kling, FLUX, MiniMax) through the Anyfast aggregator. They receive the content of that job, not your account.
  • Supabase (database and authentication), Vercel (hosting and privacy-preserving analytics), Cloudflare (network and security), Stripe (payments), BytePlus TOS (media storage), ElevenLabs (voice and audio generation), Upstash (rate limiting), and Google (optional sign-in and site analytics).

We do not sell your data, and we do not use your content to advertise to anyone.

Real people in generated media

Identity is a first-class object here, so it gets first-class protection. Generating with a licensed persona requires a passing rights check and fails closed. Talent consent and license records are kept in append-only ledgers: corrections add new versions, and nothing is silently rewritten. Raw photos of real people used as references are subject to the model providers’ own person-content policies and may be refused by them.

How long we keep things

  • Generated media and library assets stay while your workspace is active, so your back catalogue keeps working.
  • Uploaded references follow a lifecycle of roughly 90 days unless they are in active use; download links themselves expire within minutes to days and are re-derived on demand.
  • Financial records (invoices, credit ledger) are retained as required for accounting.
  • Agent audit logs are retained so spend disputes can be answered; operational idempotency records are swept on a rolling window measured in days.

Cookies

We use cookies for one thing that matters: keeping you signed in. Analytics are Vercel’s cookieless Web Analytics plus Google Analytics for aggregate site traffic. We do not run third-party advertising trackers.

Your choices

  • Access and export. Your media is downloadable from the product at any time.
  • Deletion. Ask us to delete your account or workspace and we will remove your data from live systems, subject to the financial-record retention above.
  • Agent access. Every API key and connector grant can be revoked by you or by us, effective on its next call.

Changes

If this policy changes in a way that matters, we will update the effective date above and say so plainly rather than burying it. Questions, complaints, or requests: shaurya@vxstudio.ai.