Privacy policy

A plain-language outline of how the MVP handles account, order and private media data. Counsel should review it before public launch.

Information collected

We process account identity, project details, uploaded media, optional narration text, consent records, order selections, payment status, production communication and basic operational metadata.

How it is used

Information is used only to operate the service, produce and deliver ordered media, provide customer support, protect the platform and meet legal obligations.

Private media

Uploaded photographs, generated narration and videos are stored privately. Access requires ownership or authorized studio administration. Protected media routes do not expose storage keys or public bucket locations.

Video and voice generation

New projects use strict-fidelity assembly from authorized originals. Legacy projects may use Higgsfield for cinematic scene generation. When AI voice-over is ordered, the customer's narration text is transferred server-to-server to ElevenLabs for speech generation. Secret provider credentials and private storage locations are never placed in browser code.

Payments and delivery

When Stripe checkout is enabled, payment is collected on Stripe's hosted page. Vistalea records payment identifiers and status for the order but does not receive or store card details. When an order is ready, the customer's email address and files-ready message are sent server-to-server to SendGrid; private media is not attached.

Retention and deletion

Production retention periods and deletion procedures will be finalized before a public launch. Customers may contact the studio to request deletion subject to legal and accounting obligations. Each provider's applicable service terms govern its processing copies.

Subprocessors

The MVP uses OpenAI Sites and Cloudflare-backed storage and database services for hosting, Stripe when card checkout is enabled, Higgsfield for authorized legacy video generation, ElevenLabs for customer-selected AI voice-over, and SendGrid for transactional delivery email.