Privacy policy
Last updated 20 September 2026
1. Who We Are and Scope
CRALIO LLC, a single-member limited liability company formed in the State of Wyoming, United States, under filing ID 2026-002065886, of 5830 E 2nd St, Ste 7000 #38271, Casper, WY 82609, United States, is the controller of the personal data described here. Write to info@cralio.app.
This policy covers the Cralio website and application. It applies to you as our customer, to the people who appear or speak in what you upload — in a video, in a static creative, or in a picture you attach to a generation — whose faces and voices are personal data even though they are not our customers, and to anyone who has left an email address on the sign-up page while registration is closed.
Two roles, and which one we are depends on whose data it is. For your account, your billing, your job records, your ledger and anything you send us about yourself, we are the controller. For the people inside what you upload — the faces, the voices, the names printed on a static creative, the person in a picture you attach to a generation — you are the controller and we are your processor: we process their data only on your instruction, to run the job you submitted, under the data processing addendum, and we pass it to the companies on the subprocessors page as your sub-processors.
One consequence is worth stating rather than deducing: a question from one of those people about why their face was in a video goes to you. We did not decide to film them and we cannot answer for the decision. We will help you answer it, and the two acts that settle it are yours: Delete on a job removes what that job produced at once and takes the job off your dashboard, and it removes the file the job was made from as soon as no other job of the same submission still needs it — one upload can carry a job per language, and the master goes with the last of them; where we cannot tell whether a sibling still wants it, we keep it and let the retention rules in clause 7 collect it later, rather than break a job of yours that is still running. The job’s own record stays while your account does, as clause 7 says. Stop halts a job that is still running. Both are yours to press — there is no staff button that reaches into your account and does either one.
You are responsible for having the right to upload what you upload, including the right to have the people in it dubbed into another language or redrawn by a model.
2. Personal Information We Collect
| Account | Your email address and display name. If you sign in with Google, we receive your email address and your Google profile — the name, the picture and the identifier Google uses for that account — and nothing more. Only the address and the name are used. We ask for no other permission, so we cannot see your contacts, your calendar or your files. Google, for its part, learns that you signed in to Cralio. Signing in with an email address and a password tells them nothing. |
| Content | What you upload and everything derived from it: videos, and their extracted audio, transcripts, subtitle files and finished versions; static creatives, the wording read off them and the redrawn versions; generated tracks with their titles, lyrics and cover art; and the clips and stills Generate makes, with the images you hand it to steer them. A face or a voice in one of those files is, in some places, biometric data. What we do with it, what the provider may do with it, and what you must have obtained before uploading it are in the biometric notice. |
| What you write | The words you type into a job: a music prompt, a style note, lyrics you wrote yourself, and the prompt you write in Generate. These are sent to the provider that does the work, so treat them as you would the file itself — do not put anything in a prompt you would not upload. Your glossary is handled two ways. On a video it never leaves us: we apply it to the subtitle cues after the words come back. On a static creative the terms are also written into the instruction we send to the provider, because “this is a name, leave it alone” cannot be applied after the name has already been translated. Applying it costs nothing either way. |
| Generate | The words you type to describe a shot — up to four thousand characters — and the pictures you attach to steer it: PNG, JPEG or WebP files of up to five megabytes each, up to five of them, held under your own account’s prefix like any other upload. One of the four tools exists to hold a face or a product steady across a shot, so a picture you attach can be of a person, and the biometric notice covers that exactly as it covers a face in a video. |
| Your email address, if you asked to hear from us | While registration is closed the sign-up page offers a waiting list. If you use it we keep the address, a short label of our own recording which link brought you, and — if you arrived from a pricing tile — the plan and credit allowance you picked, so your choice is still there when it opens. Nothing else: no name and no company. It is stored lower-cased so that the one email we send cannot reach the same person twice. |
| Usage | Job records — file name, duration, languages, mode, what it cost and whether it succeeded — and the credit ledger behind them. |
| Payment | Handled by Stripe. We hold the identifiers needed to reconcile a payment; we never see or store your card number. |
| Fonts | Typefaces you upload, and the record of your confirmation that you have the right to use them. |
| Proof that you accepted these documents | Each time you accept the Terms or this policy we record which documents, their exact version and a hash of the text you were shown, when, and whether it was at sign-up, at upload, or because a document changed. Until 12 September 2026 three further confirmations were taken the same way — about the rights in what you send, the consent of the people in it, and where your files go — and those rows are kept exactly as they were recorded; what they said is now in Terms §3. With it we keep a shortened form of your IP address — the first three groups of it, never the whole address — and the identification string your browser sends with every request. That is the evidence the agreement happened and which words it was about. It is used for nothing else, and never to build a picture of you. Where that record is taken depends on how the account was made. The sign-up form shows both documents and its answer is carried to the link we e-mail you, so opening that link in the browser you filled the form in records both. Opened on another device there is nothing to carry, and an account made by signing in with Google was shown no form at all: both of those record these terms and this policy when the account is created. An invitation records them on the invitation screen. And the panel on the upload, statics, music and generation pages names whichever documents have changed since you last agreed, takes one tick for them, and writes a row for each, before the first thing you send from it. |
We do not run advertising trackers and we do not sell anything to anyone.
3. If You Only Left an Email Address
Registration is closed at the moment, so the sign-up page offers a waiting list instead of an account. If you used it, this clause is the whole of your relationship with us— there is no account and no file of yours anywhere. The row itself lives in the same database as everything else, which is Supabase in Ireland, and if you are still on the list when we open, the one launch message goes out through the mail provider named on the subprocessors page. Four entries on that page are involved in that and no others: the database that holds the row, the machine that received it, the storage the nightly copy of that database is written to — so a row you ask us to delete can still sit in one of those copies for about a month while that nightly copy is being taken, and for up to ninety days if it stops being taken, which is the rule the storage service puts on the backup files themselves — and the mail provider that would carry the one message.
We hold your email address, a short label of our own recording which link you arrived through, and — if you came from a pricing tile — which plan and credit bundle you pressed, so that choice is still there when you register. If the capitalisation you typed differs from the folded address, we keep that too. We asked for no name, no company and no “what are you interested in”, because none of those answers would change what we build and every one of them is a thing to look after.
We will write to you once, when it opens. That is the only use. It is not a mailing list, you will not be sent anything else, and the address is not used to work out who you are or matched against anything. If you would rather we did not keep it, write to us and we will delete the row by hand — there is no link to click, because there is no email yet to put one in, and nothing in the product removes it for you. Once the launch message has gone, the row is deleted automatically ninety days later, and that message carries an unsubscribe link of its own.
Two smaller things, because they are the kind that are better said than discovered. Submitting the same address twice is not an error and does not tell you whether it was already there — we answer the same way both times on purpose, so that this box cannot be used by a stranger to find out whether somebody uses Cralio. And the address is stored lower-cased, so that one person cannot end up on the list twice and receive the launch email twice.
4. How We Use Your Personal Information
To produce the outputs you asked for, to charge you correctly, to show you your own history, to email you about your jobs, your balance and your payments, to find out why something failed, to keep the service secure and stop abuse, to tell you what we have built — which you can switch off — and to be able to show which version of these documents you accepted. That is the complete list.
Cralio does not train models — it has none. Your content is processed to make your files and for nothing else, and it is not used as a demonstration or in marketing without asking you. How each provider may use what it receives, including whether its terms let it improve its own models with your content, is set out provider by provider on the subprocessors page with the date we last checked.
4a. Email We Send You
Two kinds, and only one of them can be turned off. Mail that is part of running the account — confirming it, inviting a colleague, a receipt, a failed payment, automatic top-up switching itself off, or a change to these documents — goes to the account contact and cannot be switched off while the account exists. Everything else — product news, and the notices about your work, your balance and your files — is on by default, and every one carries an unsubscribe link that works: it stops that one kind and leaves the rest, and your settings page lists every kind with a switch.
What is in each kind today. Cannot be turned off: confirming the account, an invitation to a workspace, a receipt, a failed payment, automatic top-up switching itself off — that one because it is the only warning before a batch runs out of credits mid-flight — and notice that one of these documents is changing. That last one cannot be optional: Terms §16 gives you thirty days to read a change and leave before it binds you, and an unsubscribe that could switch off the telling would bind somebody who was never given that chance. Carries an unsubscribe link: platform news, the one message a waiting-list address was left for, and the job notices — a video finishing, a batch finishing, a job failing, credits running low or out, and a retention window about to close.
Those job notices are on by default, because a thirty-minute job whose result nobody is told about is a product that requires you to sit and watch a tab. If you would rather not have them, the link at the bottom of any one of them stops that kind and leaves the rest.
5. Legal Bases for Processing
For nearly all of it, the job records included, because you asked us to do a job that cannot be done otherwise — a contract. For the error logs, the rate limiting and the audit log, because we need them to find out why something broke and to keep the service from being abused, which is a legitimate interest and the narrowest one we could pick. The ledger we keep because it is the record of money that moved, the balance of a workspace is the sum of it, and we have to be able to explain a charge — a legitimate interest, and the same reason clause 8 gives for keeping it through an erasure. The tax records are the invoices behind it; those are Stripe’s and are kept by them under their own duty. For an uploaded font, the confirmation you tick when you upload it. For an address on the waiting list, your consent — that one you can refuse and lose nothing, and you can withdraw it by asking us to delete the address. We do not rely on consent for anything else, because consent you cannot refuse without losing the product is not consent.
Nothing here makes an automated decision about you that has a legal effect. Credits are arithmetic, not profiling.
6. How We Share Your Personal Information
The work is done by providers we call on your behalf. Each one, what it receives and where it operates is listed on the subprocessors page, which is kept current with the code rather than reviewed annually.
Five of the eleven are in the United States — Google and HeyGen, which run models on your material; Luma, which recuts a video to another shape and has been announced but not yet called by anyone; OpenAI, which transcribes; and Slack, the alert channel we fall back to. Stripe is in both the United States and Ireland; the mail provider is Google Ireland, which passes those messages on to the United States under its own terms; and Telegram, where our own alerts go, is outside the EU altogether. The storage, the database and the machines that run the site are the remaining three, and they are in the EEA — Stockholm, Ireland and Munich. Which of your jobs reach the American ones is not the same across the products, and the difference is the point:
- Video. A dubbing or lip-sync mode transfers your video to the United States. A subtitles-only job in the video’s own language does not reach a dubbing provider at all — only the transcription one, which is in the United States as well. It is the mode that sends the least: the audio goes and the picture never does. A re-render of subtitles you have edited calls nobody.
- Statics. Every job goes to Google. There is no mode that does not: reading the wording off your creative, drawing the new one, and transcribing the drawn pixels so they can be checked against the line you sent are three calls, usually. Your creative itself goes with the first two; the check is sent the delivered picture only. When that check finds a line missing, the drawing and the checking run again — automatically, at no charge to you, and your creative goes with each new drawing — which takes it to five, and a second re-draw to seven. There is no fourth attempt: you are given the last one with the lines that did not survive named on it. Two further trips are possible and neither is automatic: buy a second opinion on a finished creative and it goes back once more with the copy you sent beside it, and edit a line on a creative you already have and the delivered image goes back to be redrawn and checked again, with the same free re-draws behind it — that edit is a purchase too, unless our own redraw dropped a line you had sent, in which case the first fix on that creative is ours. Either way it is the delivered picture rather than your master that travels. Your glossary goes with the first call: your terms are written into the instruction that reads your creative, because a rule like “this is a name, leave it” cannot be applied after the model has already translated the word. It is applied again by our own code when the words come back, which is why the same term is spelled identically in a dubbed video and in a banner.
- Music. Every job goes to Google — your prompt, your style note, and your own lyrics if you wrote them. There is nothing to upload to Music, so no file of yours makes that trip. One picture does, and it is not yours: where you asked for a cover, the cover Google drew goes back to Google once so its lettering can be read off the pixels, the way a static creative’s is. The one part that goes nowhere is the visualiser video: it is built from a finished track on our own machines and calls no provider.
- Generate. Every job goes to Google and there is no tool that does not: each still is one call to the same family of Google image models that redraws a static creative — so asking for four stills is four calls — and a clip is a long-running Google operation we start and then poll until the file comes back. What goes with it is the words you typed and any picture you attached to steer the shot — including, if you use the tool that holds a face or a product steady, a picture of a person. Asking us to rewrite a prompt sends that prompt and any image attached to it to Google as well, and costs nothing.
- Recutting a video. A finished cut sent to be recut for another shape goes whole to a company in the United States that is not the one that dubs, and to nobody else — with the sentence you typed describing the shot, the shape you asked for and the resolution you picked, and nothing else about your account. If there is a face in the picture, it is in what that company reads and in the wider frame it draws around it. Nothing is sent until you allow it: that provider was announced on 11 September 2026, and it receives nothing of yours until you have accepted our register of subprocessors with its row on it. The first recut you submit after that register has moved stops at the submit button: the screen names the documents that have changed, the register among them as a link to the page that says what each company receives, where it is and how long it keeps it — and nothing is priced, reserved or uploaded until you accept. It is one acceptance for the register, not one per company. Between 11 and 14 September 2026 this company had a tick of its own and you could decline it and go on using every tool that did not reach it; that was withdrawn, and a refusal now stops every submission rather than this one provider. What stands in its place is the notice, the refusal before anything moves, and the right in clause 6 of the addendum to object within the days it names and have back what you prepaid for the part of the service you end. Nothing has been sent to it by anyone.
Start with where we are. Cralio is a company in the United States, so if you are in the European Economic Area or the United Kingdom your personal data is in the hands of a company outside it the moment you create an account — not only when a job reaches one of the providers above. That is the transfer that matters most, and it is ours rather than a supplier’s.
Where it physically sits is a second question, and the answer is not the United States. Your uploaded and delivered files are in Amazon’s Stockholm region and are rendered there; your account, your job records and your credit ledger are in a database in Ireland; the machines that serve the site and the API are in Munich. What crosses the Atlantic is what a job sends to a provider, product by product as set out above — and no amount of European storage cures the paragraph above it, because a United States company decides what happens to all of it wherever it is kept.
The mechanism. Transfers of the material you upload are made under the European Commission’s Standard Contractual Clauses (Decision 2021/914). Module Two — controller to processor — governs the transfer from you to us, and Module Three — processor to processor — governs each onward transfer to a provider. Both are incorporated into our data processing addendum, which sets out every election they require: the governing law and forum, the sub-processor authorisation, the docking clause, and the annexes. That addendum forms part of the terms of service and takes effect when the agreement does, so the Clauses are in force for every customer from that moment rather than waiting on a signature. Where you are in the United Kingdom, the Information Commissioner’s International Data Transfer Addendum applies to them.
Three things are outstanding, and we would rather you learned them here than later. We are not certified under the EU–US Data Privacy Framework, so the Clauses stand alone rather than beside it. The transfer impact assessment those Clauses require — the written analysis of whether United States law undermines the protection they promise — has not been completed: the Clauses are in force; the assessment behind them is not. And the providers that receive your material process under their own published terms rather than under data protection terms we have imposed on them, which is what Module Three’s Clause 9 contemplates and we have not done; the data processing addendum says the same thing from the other side.
Our representative in the Union has not been appointed yet. A company outside the EU that offers a service to people inside it has to name someone there who can be written to and who answers for us to a regulator, and the same duty exists separately for the United Kingdom. It is an appointment, not a clause, and the moment it exists the name and address go here. We are recording its absence rather than leaving the question unasked — if you are about to rely on this service for EU personal data, this is the paragraph you should be asking about.
Our own staff. To answer a question about a job, our staff can see your account through our own administration screens: your jobs and their errors, your credit history, and the email addresses on your workspace. They cannot watch, download or play your videos from there.
We would rather state the limit than overstate the control: we log what staff change, not what they look at. Granting credits, retrying a job, changing someone’s role — every action of that kind is written to a record the application can add to but never edit or delete, naming the person, the account and the time. A read is not, and two platform-level switches are the exception: the face gate leaves only a server log line, and a safety hold is written to its own incident record instead. If you need to know who has looked at a particular workspace, ask us and we will tell you what we can reconstruct, which is less than an access log would give you.
If Cralio is ever sold or merged, your data moves with the part of the business it belongs to, under this policy. We would tell you before that happened, not after. There is no separate notice built for it: a change of who holds your data is a change to this page, and the one message that announces a change to this page is what would carry it — publishing it in advance is a person’s doing, not a scheduled job’s.
7. Retention
Uploads are deleted when the last job that used them stops being available to you, and within 30 days at the latest. A typeface you add is the exception, and it is not on that rule at all: it lives for your plan’s file-retention window counted from the last render that used it, every use restarts that count, no expiry rule on the bucket reaches typefaces, and a font whose last use we cannot establish is kept rather than deleted. For most work that is days rather than weeks: the sweep that removes a finished file removes the master it was made from in the same pass, and the 30-day rule on the bucket is only the backstop behind it. Finished work — a localized video, a redrawn creative, a generated clip or still, a generated track and its cover — stops being available to you at the end of your plan’s retention window and is deleted by the next sweep after that, and the working files of a job are deleted with it. Nothing is exempt from that window — there is no flag and no control of yours, and nothing you can ask us for, that takes one piece of finished work off it, so what you want after the window closes you download before it closes. One case set by law does override it, and it is not yours to invoke — it is the last paragraph of this section. One rule covers all four products: a campaign of localized images on a one-day plan is gone after a day, exactly as a video is. Extracted audio is never stored. The job record goes when its output does, on the same window; the ledger stays, because it is the record of what you were charged and it holds none of your content. The retention page has the exact figures and what enforces them.
A waiting-list address is deleted 90 days after we send the one email it was left for, or the moment you ask, whichever comes first. Ninety rather than immediately because the launch mail is when somebody is most likely to write back — the link did not work, I never got it, take me off — and answering that needs the row.
An address we have not yet mailed is kept, because the thing it was left for has not happened. That is deliberate, and the script that does the deleting names the day the oldest un-mailed address joined — a line an operator sees when they run it by hand. It counts only the rows it is about to delete, not the ones it is keeping, and the daily run reports only how many went.
Server logs. The machines that answer requests record the IP address, the URL and the time of each one, for security and for debugging. Those logs are rotated daily and kept 14 days. The request log names no account, though a URL in it can carry the id of a job that we could trace back to one; nothing in the product does that on its own. The application’s own log lines are a different thing: when something goes wrong they name the account or the workspace the request belonged to, because a failure we cannot attribute is one we cannot fix. On the machines that render your work those lines are kept 14 days; on the machine that answers requests they go to the system journal, which is trimmed by size rather than on a clock. We read either by hand, when we are investigating an attack or an error you reported.
Backups. The database — accounts, jobs, the ledger, and never your files — is copied once a day, and we keep the last 30 copies. So a deleted row survives in a backup for about a month while that daily copy is running, and for longer whenever it is not — up to ninety days, which is the rule the storage service puts on the backup files themselves and the outside edge of any of this. We count copies rather than days on purpose: an age rule alone leaves you with nothing if the job stops running, because the old copies expire on schedule and no new ones arrive.
Proof that you accepted these documents is kept while your account exists and is erased with it — the document, its version, the hash of the words you were shown, the time, the shortened IP address and the browser string, and nothing more. One part of it outlives the account: when the account is erased, the document, its version and the first part of that hash are copied into our own record of the erasure and stay there. The time, the shortened IP address and the browser string are not copied, and neither is anything that names you.
After an account is erased, two rows are written about the erasure itself and stay, and neither holds your address. They are not the whole of what survives an erasure — clause 8 lists the rest. The first is a one-way hash of the mailbox, the identifiers of the account and workspace that were erased, who ran the erasure, when, and any reason you typed when you asked. The hash cannot be turned back into an email address; the only question it can answer is whether the mailbox behind an address has been erased before, so that deleting an account and opening a new one on the same mailbox cannot collect the free starting credits a second time. The second is our own record that the erasure happened, and it is the fuller of the two: the same identifiers and reason, which documents the account had accepted, and — because it is written from the request itself — the whole IP address and browser string of the request that asked for the erasure, not the shortened form we keep elsewhere. Nothing removes either on a schedule.
And one thing is kept against every rule above. Where the law requires material to be preserved — a report of child sexual abuse material is the case that arises here — that material is copied somewhere no deletion sweep and no storage rule reaches. It survives your plan’s window, your own deletion of the job, and the account being closed, and a request to erase the account is refused rather than half-performed while it stands. The acceptable use policy sets out when that happens.
8. Your Rights and Choices
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete your account and its contents. Deleting a job from the dashboard removes what it produced immediately rather than waiting for the retention window, and the file it was made from with it once no other job of the same submission still needs that file. There is no export button: when you ask for a copy we put it together by hand from our own records. You can change your name yourself in Settings; changing the address on the account goes through us.
Deleting a whole account is done through the API, and there is no button for it in the dashboard yet. A DELETE request to /account, confirmed by typing the address on the account, erases your profile, your jobs, your uploads and your outputs and tells you what it had to keep — no person is involved. If you would rather not call an API, write to us at the address in section 15 and we will do it. The same is true of taking an address off the waiting list.
What an erasure removes. Your profile, your email settings and our record of the messages we sent you, your acceptances of these documents, invitations you sent, your uploads, your membership of every workspace, a waiting-list row in your name, and your sign-in. In the workspaces you OWN it also removes the jobs and everything in storage behind them — uploads and finished work alike — the typefaces you added, your glossary, your saved subtitle styles and the prompts you saved in Generate.
What it deliberately leaves, and why. Work you did inside a workspace somebody ELSE owns is theirs, not yours: a request from one member is not consent to destroy an organisation’s files, so those jobs and their delivered work stay. What comes off them is you — your identifier is removed from every one of them, so nothing there names you. If you want that work gone as well, the person who owns the workspace can delete it from their own dashboard.
What survives, and why. The credit ledger stays, because it is the record of money that moved and the balance of a workspace is the sum of it: those rows lose your name, your user id and any filename, and keep the amounts, the kinds and the dates. Nothing deletes them on a schedule. The record of what our own staff did stays, because it is append-only by design. Our pointer to your Stripe customer record stays, because Stripe holds its own payment record under its own duty and dropping our end would only make our half of a chargeback unanswerable — the invoices themselves live there rather than here. And the workspace itself is emptied and unnamed rather than deleted, for the same reason as the ledger. The prompts you saved in Generate used to be the one survivor: those rows hang on the workspace rather than on you, so an erasure that empties the workspace left them behind. Since 19 September 2026 the erasure deletes them outright, for every workspace you own, and there is nothing left to ask us to remove by hand.
Four things make us say not yet rather than no, and each refusal names which. A subscription still running — cancel it in Billing first, so nothing charges you afterwards. Jobs still running — wait for them, or stop them from the dashboard. Other people still in your workspace — remove them from the Team page first, because erasing you would take their work with it. And an account under review, where we will say only that. Where we cannot read enough to decide any of that safely, nothing is touched and a person finishes it by hand; and if part of an erasure cannot be completed we say which part rather than reporting a clean deletion.
What happens after you ask. We answer within one month. Where a request is complex we may take up to two months more, and we will tell you that inside the first month rather than at the end of it. We may ask you to confirm you are the account holder before we act. You can authorise someone to ask for you, and we will ask them for proof.
The other rights, named rather than left to be found. You can object to processing we do on a legitimate interest — the error logs, the rate limiting, the audit log and the credit ledger, which are the whole of that category. The ledger is the one we would refuse, for the reason clause 5 gives: it is our record of money that moved, and we have to be able to explain a charge. You can ask us to restrict processing while a correction or an objection is being sorted out. You can ask for a copy of what you gave us in a form another service can read. And where we rely on something you confirmed — the font-rights confirmation, and an address on the waiting list — you can withdraw it, which stops us from then on and does not undo a video we have already made. There is no button for any of these: they are requests, and section 15 is where they go.
If we refuse, we say why, and you can appeal by replying to the refusal — we will look at the decision again from the start and answer you in writing. Residents of Colorado, Connecticut, Virginia and states with similar laws have a statutory right to appeal a refusal: write to the address in section 15, and that is how you use it.
9. Security
Files are encrypted in transit and at rest and are reachable only through links that expire. What you upload is stored under a prefix belonging to your account and what we deliver under a prefix belonging to the job that produced it, with every request for an object checked against the account making it. What we have not done — audits and certifications — is stated plainly on the security page rather than left to be assumed.
If we learn of a breach affecting your data, we tell you without undue delay, and within 72 hours of learning of it where the data processing addendum applies — with what we know at the time and what we are doing about it. Where the picture is incomplete we send what we have and follow up, rather than delaying the first notice until it is tidy.
10. Cookies and Browser Storage
We set no cookies at all. What we keep is kept in your browser’s own storage instead, which is why none of it is sent to us with a request unless the page deliberately attaches it. There are thirteen things and this is all of them: the session that keeps you signed in, the light-or-dark theme you chose, which finished jobs you have already downloaded so the app can stop reminding you about a file you have, whether the dashboard was last left grouped or flat, which language groups you had opened in the picker, the documents you accepted on the sign-up form — kept only from the moment you fill that form in until you open the link we email you, because that is the first moment we can record your answer against the account it belongs to, and deleted as soon as it is read — a counter that tells a second music take apart from the first so that pressing Generate twice on the same words gives you a new one rather than handing back the one you already have, which tool each section of the generate workspace last opened on, what each generate tool was last set to — its model and its resolution, the shape, how a frame is fitted to it, the length, how many, and how much variation — the last twelve prompts you sent from that workspace with the pictures they pointed at, so that Reuse can put an order back in front of you, how large the gallery draws its tiles — one word out of three, about a grid on one screen: it names no result, carries no prompt and is never sent anywhere — the two initials drawn in your avatar, and whether your account is an admin one — the last two only so the sidebar does not flicker into shape on every page load. Both are read back from your account a moment later, both live only until the tab closes, and both are erased when you sign out. None of the other twelve is reported to us on its own; where one shapes a request you make — the model a tool was last set to, a prompt you put back in the box with Reuse, the counter that makes a second music take a second job, the acceptance that is posted when you open your confirmation link — it travels only as part of that request.
We run no advertising trackers, no cross-site pixels and no third-party analytics that follow you off this site, so there is no consent banner to click past — there is nothing to consent to.
Clearing this site’s data signs you out and forgets the other ten. Nothing else breaks.
11. Minors
Cralio is sold to businesses and is not for anyone under 18. We do not knowingly hold data about children. If you believe a child’s data has reached us — including as the person appearing in an uploaded video — tell us at the address in section 15 and we will delete it. The exception is material we are required to preserve for a report to the authorities: that is copied to a legal hold and cannot be erased on request. We will tell you only that the account is under review — the same words clause 8 gives — because saying more about a preservation order is how the material stops existing.
12. Notice to U.S. State Residents
We do not sell personal information, and we never have. We do not share it for cross-context behavioural advertising either. There is no opt-out link on this site because there is nothing to opt out of.
California, Colorado, Connecticut, Virginia and the other state laws that now look like them give you rights to know, delete, correct and port your data, and not to be discriminated against for asking. Those are the same rights section 8 (your rights) already gives everyone, and we do not ask where you live before honouring them.
13. Complaints
Tell us first — it is faster and we would rather know. If that does not settle it, you can complain to a data protection authority: in the EU, the one where you live or work; in the UK, the Information Commissioner’s Office. You do not need our permission and you do not have to come to us first.
14. Changes to This Privacy Policy
Every change to the words on this page changes the fingerprint at the foot of it, and the version it replaces stays readable at its own link. The date at the top is set when that fingerprint is re-pinned. If a change affects where your content goes or how long it is kept, we will tell you rather than only updating the date.
15. Contact Us
Questions about any of this, a request under section 8 (your rights), or a request to take an address off the waiting list: info@cralio.app.