Legal
Privacy Policy
Version 1.1 · Updated and effective 9 October 2026
This Privacy Policy explains how Li Dong, an individual operator of Ovanto (“Ovanto”, “we”, “us”, or “our”), handles information when you use https://www.ovanto.ai/, including its AI image generation, short video generation, and image editing tools (the “Service”). It should be read together with our Terms of Service.
We do not sell personal information and do not share it for cross-context behavioral advertising. We collect and use information only for the purposes described below, or as otherwise permitted or required by applicable law.
1. Who is responsible for your information
The operator responsible for the Service is Li Dong. For privacy questions, access or deletion requests, complaints, and other data requests, contact hello@ovanto.ai. Li Dong handles privacy requests through this email address.
2. Information we collect
2.1 Information you submit
- Prompts, instructions, and settings used to request an image, video, or edit.
- Photos or other image files you choose to upload for an editing request, together with their upload metadata.
- Your email address and account or login information when you use paid account features.
- Order identifiers, product, quantity, price, currency, payment status, and credit ledger information. We do not receive or store full payment card numbers on our servers.
- Messages and other information you include when you contact support.
- Content safety reports sent by email, such as a job or report ID, category, brief description, and related correspondence. Please do not send CSAM attachments, secrets, or another person’s sensitive personal information.
2.2 Information generated or collected automatically
- Generation identifiers, provider and model identifiers, processing status, output URLs, and error or audit records needed to operate a request.
- A keyed hash of the trusted network IP address used for anonymous quotas, rate limiting, abuse prevention, request ownership, and security. We do not use this hash to identify you by name.
- The country signal supplied by the hosting infrastructure for regional availability and abuse controls. We do not intentionally collect precise location through the Service.
- Necessary cookies and opaque identifiers, such as the anonymous owner cookie, account session cookie, and checkout claim cookie.
- Request, security, and diagnostic information such as timestamps, response status, browser and device details made available to our hosting infrastructure, and failure information.
- The result of Cloudflare Turnstile verification. We do not retain the Turnstile token as a user profile.
2.3 Information from payment and email providers
Stripe, Waffo Pancake, and other checkout partners may provide payment status, transaction identifiers, email, and related fraud or reconciliation information. Resend may provide delivery and failure information for activation, login, and other transactional email. We do not ask you to send card details by email.
3. How we use information
We use the information above to:
- provide, process, display, and deliver requested generations and edits;
- send prompts and, when needed, uploaded images to the provider that performs the requested operation;
- maintain quotas, credits, reservations, job status, downloads, and account access;
- process checkout, reconcile payments, issue credits, investigate refunds, and answer billing questions;
- authenticate users, send login or account emails, and provide support;
- review content safety reports, coordinate with a provider where possible, and take actions within our capability and the law;
- protect the Service against fraud, abuse, automated attacks, unauthorized access, and unsafe use;
- diagnose errors, maintain reliability, and improve the Service without using your inputs to train a general AI model without separate permission; and
- comply with legal obligations, enforce our Terms, and respond to valid legal requests.
The legal basis depends on the purpose and applicable law: contract performance for requested generations, edits, payment and credit fulfillment, and account or login service; legitimate interests for security, abuse prevention, diagnostics, and support; legal obligations for payment records, compliance, and valid legal requests; and consent where the law requires consent for a particular optional processing activity. We may create aggregated or de-identified information for reliability and service analysis when it no longer reasonably identifies you.
4. Cookies and tracking
The Service uses necessary cookies for anonymous quota ownership, account sessions, checkout continuity, security, and request operation. The anonymous owner cookie and checkout claim cookie are currently configured to last up to 2 days; a paid account session is currently configured to last up to 30 days. Login codes and activation links have separate short validity periods.
We do not currently use analytics tools, advertising pixels, ad-tech identifiers, or cross-site behavioral tracking. Cloudflare Turnstile and our infrastructure may use their own security mechanisms subject to their policies. You can control cookies through your browser, but disabling necessary cookies may prevent the Service from working.
5. When we share information
We share only the information reasonably needed for the purpose and service involved. Depending on the request, recipients may include:
- Hosting and storage: Vercel hosts the application and Upstash stores operational records such as jobs, quotas, reservations, and security hashes.
- Safety and verification: Cloudflare Turnstile verifies that a request is not automated abuse.
- AI providers: Replicate and fal receive prompts, settings, and an uploaded image where needed to provide the requested generation or edit. Their processing is also subject to their own terms and privacy policies.
- Payment: Stripe processes the current checkout where Stripe checkout is used. Waffo Pancake may act as the merchant of record or reseller for a checkout presented through Waffo.
- Email: Resend sends login, activation, and other transactional email.
- Legal and safety recipients: We may disclose information when required by law, court order, valid governmental request, or to protect users, the Service, or our rights.
We do not sell your information. We do not share it with another party for cross-context behavioral advertising. If the Service or its assets are involved in a merger, acquisition, financing, or sale, information may be transferred as part of that transaction subject to continued protection and any notice required by law.
6. Third-party services
The following links identify principal third-party services used by the Service or identified in a checkout we offer. Their policies govern their own processing:
- Vercel Privacy Notice
- Upstash Privacy Policy
- Cloudflare Privacy Policy
- Replicate Privacy Policy
- fal Privacy Policy
- Stripe Privacy Center
- Waffo Pancake Privacy Policy
- Resend Privacy Policy
7. Security
We use HTTPS/TLS for transmission, signed secure cookies, keyed hashes for anonymous network controls, hashed credentials and tokens where stored, access controls, and bounded provider requests. We limit provider URLs and inputs to the formats needed by the Service. Where required by applicable law, we will notify the relevant regulator within 72 hours after becoming aware of a personal data breach and notify affected users without undue delay when the law requires it. No internet service can guarantee absolute security, so please protect your account and tell us promptly about suspected misuse or a security issue.
8. How long we keep information
We keep information only for as long as it is needed for the purpose collected, service operation, security, dispute handling, or legal obligations. Current operational retention settings are:
- Free generation job records: up to 24 hours from the last write.
- Generation audit records: up to 30 days.
- Anonymous daily quota records: up to 2 days.
- Uploaded asset metadata and validated upload records: up to 1 hour; provider upload objects may have the same one-hour lifecycle where configured.
- Anonymous owner and checkout claim cookies: up to 2 days; account session cookies: up to 30 days. Login codes are valid for 10 minutes and activation links for 7 days; those validity periods control use of the credential, while related records may be retained longer where needed for security or legal purposes.
- Provider output URLs: according to the relevant provider’s availability and expiration behavior. We do not promise that a provider URL will remain available indefinitely.
- Paid account, credit, order, and transaction records: no scheduled automatic expiry is currently applied. We keep them while needed to provide the account or credits, complete refunds and disputes, and meet applicable legal obligations. We will consider deletion requests subject to those requirements.
- Support and content-safety correspondence: ordinarily up to 12 months, or longer where needed for a dispute, security investigation, or legal obligation.
Third-party providers may keep prompts, uploads, outputs, or logs under their own policies and contractual settings. Their retention is outside our control.
9. Your rights and choices
Subject to applicable law, you may ask us to confirm whether we process your information and request access, correction, deletion, restriction, portability, or information about our processing. You may object to processing based on legitimate interests and withdraw consent where our processing relies on consent. Withdrawal affects future consent-based processing and does not affect processing already carried out lawfully.
To make a request, email hello@ovanto.ai from the relevant account email where possible, include enough information for us to locate the request, and do not send card details, passwords, API keys, or Turnstile tokens. We aim to respond within 30 calendar days or the shorter or longer deadline required by applicable law; we may extend or refuse a request where the law permits after explaining why. We may need to verify identity before disclosing or deleting information.
If you believe we have not handled a request properly, you may contact the data protection authority or other regulator in the place where you live or work. Simply continuing to use the Service is not intended to be affirmative consent where applicable law requires a separate consent choice.
10. International processing
Ovanto and its providers may process information in the United States and other regions where those providers operate. When applicable law requires safeguards for an international transfer, we use the contractual, organizational, or other lawful mechanism available for that transfer. The relevant provider may also process information under its own cross-border terms.
11. Children
The Service is for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided information, contact hello@ovanto.ai and we will review and delete it where required.
12. Changes to this Policy
We may update this Policy when the Service, providers, or legal requirements change. For a material change, we aim to give at least 15 days’ notice through the Service or another appropriate channel before it takes effect, unless a shorter period is required for law, security, or an urgent operational reason. We will update the effective date at the top of this page. Where applicable law requires consent for a change, we will ask for it separately.
13. Contact
For privacy requests, support, billing questions, security reports, or content-safety reports, contact hello@ovanto.ai. The operator is Li Dong. Please do not include payment card details or other secrets in email.
Li Dong · https://www.ovanto.ai/ · Version 1.1