Service terms
Last updated 12 September 2026
1. Video
What we take. A finished cut with audio on it — MP4, MOV, AVI, WebM or MKV — up to 500 MB and five minutes. Larger is refused before the transfer starts. Longer is refused at submit wherever your browser could read the file’s length, and after the upload on the containers it cannot decode — AVI, ProRes MOV and some MKV — where we measure it ourselves. Either way nothing is charged for a file we were never going to finish.
A dub is a machine translation spoken by a machine. The words are translated by a model and the voice is synthesised by one. It is an approximation of the original speaker, not a clone certified by them, and it is not a performance they gave. Where the original delivery carries the meaning — irony, timing, a joke that turns on a word — expect the dub to carry less of it than the person did.
Lip-sync depends on the face being visible. Quality follows from how much of the mouth is in frame, at what angle, and in what light. A speaker turned away, in shadow, behind a hand or moving quickly will sync worse, and there is no setting that fixes it. We do not guarantee a result, and a poor sync is not a failed job: the credits bought the attempt, and Terms §4 says when they come back.
Subtitles in the video’s own language call no dubbing provider at all. Nothing but the audio leaves for transcription, no picture is sent anywhere, and no voice is synthesised. It is the cheapest mode and it is also the one that transfers least — the DPA sets out which modes transfer what.
What is not translated. Background music, song lyrics, and any text burned into the picture — a caption in the footage, a product label, a sign behind the speaker — are left as they are. They are picture, and picture is not ours to rewrite. Subtitles we generate are ours to style; text somebody else baked into the frame is not.
Duration is measured by us and billed on the measurement. Not on what the container claims, and not on what you estimated when you submitted — a file’s declared length and its real one differ often enough that trusting the header would mean charging some people for seconds that are not there. The measured figure is on the job.
The glossary rewrites text we own, and only that. We apply it to the subtitle cues before they are burned and to the wording on a static creative — both are ours to rewrite. It is not applied to the dub. The provider translates the speech itself, and a brand name it decides to translate is translated; no glossary can reach that. Inside a video job a glossary term reaches the burned subtitles and nothing else — including the subtitles burned on a dubbed cut — and it reaches them by rewriting a cue we already hold: a rule fires on the whole word you configured wherever the model’s own translation writes it, whatever its capitalisation, so a word the translator respelled is a word no rule matches — and the same word inside a longer one is not a match at all, unless you switch whole-word matching off for that term, which today only the API can do. The glossary is included from the Pro plan upwards.
2. Static Creatives
What comes back is a reinterpretation of your artwork, not your file with the words swapped. The model is given your creative and asked to replace the strings you sent; every pixel of what it returns is something it drew. It usually looks like your creative because it was told to keep it. It is not the same file, and you should look at it before it runs.
We check the words for you, because the models silently correct copy they think is wrong. A third call transcribes the pixels that came back and our own code — not a model — compares them character by character against the line you sent. Where they differ you are told: the creative is still delivered and charged, and the lines that did not survive are named on its page. We had already drawn it up to three times before you were told, at our cost rather than yours, and you were charged once. After that, the first edit you make to that creative is free — the named lines or any other wording on it — and a second edit is a change of mind and a new purchase like any other.
We never invent a creative and we never enlarge one. Nothing is generated from nothing: your master is always in the request. And the size you receive is the smaller of what the model returned and what you asked for — choose the smaller delivery for a 1080×1920 master and you get 768×1376, said in those words beside the delivered-size option before you buy it, rather than a blurred file inflated to the number you hoped for.
Transparency does not survive. A master with a transparent background is accepted, and the transparency does not survive the repaint; where it is lost, the delivery says so. We do not promise a particular colour behind what used to be transparent. If the transparency is what you are buying, this is not the tool.
Wording is consistent between the formats of one creative, and not between creatives. One reading of a creative is reused across every shape of that same creative, so a square and a leaderboard of one asset say the same thing. Two different assets in one campaign are two readings and may phrase the same idea differently. We keep no translation memory, and we say so here rather than letting a thirty-creative campaign discover it.
A creative is read and repainted in one order. They are two jobs and two lines in your ledger, and both are reserved when you submit the campaign; a job that does not deliver is not charged for, and where the reading fails, the repaints waiting on it are failed and refunded with it.
The copy we read off your creative has the same shelf life as everything else on your plan, and on the shortest windows that is worth knowing before you submit. The wording is stored beside the job and deleted with it — so on a one-day plan, a campaign delivered on Friday has no readable copy on Saturday. Once it has gone we say so rather than quietly serving you a copy: opening it, editing a line on a delivered creative and redrawing from it are all refused, and the refusal names the window and the day it closed. The way back is submitting the creative again, at the price of a new creative — so download the copy sheet with the images.
A second opinion is a separate purchase, sold through the API rather than the app, and it is information rather than a remedy. The check above asks one question — are the approved characters on the image. You can also buy a review of a finished creative, which asks the three a human reviewer opens with: does the copy still mean what the master meant, would this market write it that way, and is any of the source language still visible. That sends your delivered creative to the provider once more. Two things follow. It never moves the money on the image, which was delivered and charged before the review existed — the model doing the reviewing is the same family that drew the picture, and a charge a model can reverse is a charge a prompt can reverse. And it changes nothing by itself: a finding is a suggestion you may paste into the wording, free, and then buy new pixels from.
3. Music
Music is included on every plan, Starter and the free tier included. A track is paid for out of the same credits as everything else, so what limits it is the balance rather than the plan.
Music takes nothing from you but words. A description, a style note, and your own lyrics if you write them. There is nothing to upload and nothing to attach — the option to supply your own photographs to steer the cover art was removed from the product, so no image of yours is involved at any point.
You cannot control the length. A clip is about thirty seconds. A full track is whatever it comes out as — the two we measured came back at 98.1 and 96.8 seconds, but the model takes no length parameter and neither do we. A track whose length you did not want is not a failure and is not refunded. The one exception is audio under five seconds, which is not a track at all: that fails the job and the whole hold is released. No track is priced by duration, so the length of one costs you nothing. The visualiser is priced differently — per second of the track it draws, so a longer track makes a longer video cost more.
Lyrics are delivered as plain text, with no timing in them. They are the words, not a subtitle file, and they will not line up with the audio. We used to promise timecodes and withdrew the promise rather than ship one that was sometimes met: the provider nowhere documents timed output, and we never counted how often it arrives — the model volunteers timing markers unevenly and we strip them.
The cover is optional and priced on its own. Clear the checkbox and no cover is generated and none is charged. Ask for one and it fails to arrive, and the track is still delivered and the cover is still not charged — you pay for what you received. Your choice is remembered for next time; it is your setting, not ours.
A track that comes back empty is refunded in full, including the parts that succeeded and including what we already paid for them.
Do not ask for a track in the voice or style of a named living artist. Nothing in the product reads your prompt for an artist’s name, so this is a rule you keep rather than a gate we run. It breaks these service terms, which section 7 of the terms of service makes part of your agreement, and asking for a named person’s voice is separately covered by the impersonation rule in the acceptable use policy. The provider blocks some prompts before it generates: a block returns no audio, which fails the job and releases the hold in full. We have no count of how often that particular ask is refused — and the provider also sometimes returns a finished track, which is delivered and charged like any other.
4. What Is Embedded in a Delivered Image
Every image Cralio generates for you — a localized creative, a cover for a track — was produced by a generative model. Two marks are involved, and only one of them can be seen. A poster frame is the one kind of image we cut rather than generate — on a localized video and on a clip you generate alike, ffmpeg takes a frame one second into the delivered cut. On the lip-sync modes the provider’s model has redrawn that picture along with the rest of the video; on subtitles and on the audio-only dub it is your own footage, untouched. Either way it is delivered like everything else and carries the same manifest, which says a generative model made the file. The signing rule does not vary by mode — so wherever the picture is your own, on either subtitle mode and on the audio-only dub, the poster frame carries a mark it did not earn. On the two subtitle modes, where no voice is synthesised either, so does the cut it was taken from. We would rather write that down than let one signature quietly overstate what is in a file.
An invisible watermark, in the pixels. Google embeds SynthID in everything its image models produce. Google designs it to survive resizing, re-encoding and cropping; that is their design rather than our measurement, because we have never tested it. There is no setting that turns it off, we cannot remove it, and we cannot read it — a detector we do not have will find it in your creative years from now. If what you need is an image carrying no machine-readable sign that a machine made it, this product cannot supply one, and no plan or price changes that.
A provenance manifest, in the file’s metadata. Anyone can read one; it is ordinary metadata, and it says the file was made by a generative model. Where we leave the pixels alone — cover art — the picture itself is the provider’s own, pixel for pixel: we neither redraw it nor re-encode it, so whatever it left Google with is still in it. The file is not byte for byte theirs, because ours is now on it: a manifest is metadata, written beside the picture rather than into it, which is why it can be added without touching what you see. That was not true until 9 September 2026, and the reason it was not was a mistake rather than a policy — the cover model returns a JPEG, our own code offered it for signing as a PNG, and the signature was refused before it began. A failed signature is never allowed to cost anyone a delivery, so the cover went out unsigned. What our code says about a file is now read from the file’s own first bytes and never from what a model claimed it sent. Bytes whose format we cannot name are still delivered, and still delivered unsigned: a name we cannot prove is worse than no mark at all, and that is the same reasoning as before, reaching the opposite answer because the facts changed. What stays either way is the SynthID in the pixels. Where we re-encode — a localized creative, which we re-encode to force the file type and to keep display banners under the ad networks’ byte limit — theirs cannot survive and ours takes its place. A C2PA signature covers a hash of the pixels, so changing one voids it; carrying it across anyway would be a claim we could not prove.
Ours is signed with our own certificate, and that certificate is in no trust list. A validator will show the manifest, read the assertion and the timestamp, name us as the issuer, and mark the issuer as unverified — because nobody has vouched for the name. That is what we have and we would rather write it down than let the word “signed” do work it has not earned. What it buys is a tamper-evident, machine-readable statement of origin. What it does not buy is a green tick.
A generated track carries one too, and every video we deliver: the clean cut, the subtitled one, each aspect variant, and the poster frame. So does the cover art, and so does a still you generate — both did not until 9 September 2026, and both for the one reason given above. Two files leave without a manifest, each for its own reason. Your own upload after we re-encode it to work on — nobody downloads that, and a mark saying a model made it would be false. The lyric sheet, which is plain text and has nowhere to put a manifest, so we do not try. There is a third case that is not a file but a condition: an image whose format our own code cannot identify from its bytes is delivered unsigned rather than signed under a guess. We have never seen one.
A generated still carries the SynthID and ours as well, and so does a generated clip. A still you generate comes from the same Google image models a localized creative does, so SynthID is in its pixels on the same terms — there is no setting that turns it off and we cannot remove it. A clip comes from a video model instead, and we have never tested one for an invisible watermark and make no claim either way about what is in its pixels. Both are signed like everything else here and carry our provenance manifest, signed by the same certificate and unverified in the same way. A still was not, until 9 September 2026, for the same reason the cover art was not: the image models return a JPEG and our own code offered the still for signing as a PNG. We still neither redraw a still nor re-encode it, so the picture is the model’s own and whatever it left Google with is still in it — what we have added sits in the file’s metadata beside it.
You will not remove, strip or obscure these marks. Where the law where you publish requires a visible label as well, adding it is yours — ours ends at what is machine-readable in the file.
5. Generated Clips and Stills
Four tools. A clip from a prompt, a clip from a frame you provide, a clip that holds a face or a product steady across the shot, and stills.
What we take. A prompt of up to four thousand characters, and in three of the four tools your own images: a still to be the first frame of a clip, and on the models that have a last-frame slot a second still to be its last; or reference images — up to five for a clip depending on the model, which your prompt names by alias, and up to three for a still, where the slots are unnamed and an alias in the prompt is refused. Anything you attach is a PNG, JPEG or WebP of up to 5 MB. Nothing else about your account goes with them.
We refuse rather than adjust. A length, a resolution, a frame count or a number of references the model you chose cannot run is refused before anything is sent and before anything is charged: the estimate runs the same checks the submission does, so a price is only ever quoted for a request that can run. Nothing is quietly moved to a combination that works — a clip quoted at ten seconds is never delivered as six, a second frame you paid for is never dropped, a fifth reference is never discarded in silence, and a job priced against one model is never run on another.
One image is one purchase. Ask for two or four stills in a single press and each is a separate generation, separately reserved and separately settled. If half of them arrive you have bought half of them, and the rest returns to your balance.
Rewriting your prompt costs nothing. The rewrite button sends what you have typed, and any image you attached to it, to a Google model and hands back a rewrite. It spends no credits, it generates nothing, and it is limited to twenty rewrites a minute.