Privacy Policy
About this notice
This notice describes the current Carivio AI preview. Contact support@carivioai.com with privacy questions or requests. Updated September 16, 2026.
Information we use
We use your name, email address and account identifiers to provide account access. Supabase manages sign-in and email verification; verification emails are delivered through Resend. We store account records, creation descriptions, generated media, credit activity and content reports on our service.
Web payments
Stripe processes payments on its hosted checkout page. Payment-card details are entered directly with Stripe; Carivio AI does not store full card numbers. We keep purchase identifiers, pack amounts, payment status and credit adjustments to deliver purchases and prevent duplicate credits. Account deletion removes the account link from our purchase records; minimal payment records remain for reconciliation, refunds and dispute handling. Stripe retains its own payment records under its privacy policy.
Account activity
We record studio session openings, logouts and recent authenticated activity to operate the service and provide owner-only support and usage reporting. Session activity is retained for up to 90 days, capped at 5,000 events, and removed when account deletion finishes. The owner can view registration and confirmation status, account email, credit balance, generation status and payment status. Dashboard activity does not record passwords, access tokens, payment card details or browsing outside Carivio AI.
AI providers
Photo and video descriptions are sent to Runway to generate your creations. If you attach a photo or product image, that image is sent to Runway only after you confirm image-guided photo or video generation. The source image is processed transiently by our server; a fingerprint is retained to prevent duplicate charges, but the source image is not stored in the server gallery. Voice-over scripts are sent through Runway to its ElevenLabs speech model. You are asked for permission before sending descriptions, and separately before creating a voice-over. Do not include sensitive information or other people’s private information without permission.
On your device
The native app stores sign-in information using secure device storage. The website keeps sign-in information in browser session storage for the current tab. Closing the tab normally ends that local browser session; browser session restoration may retain it. Log out when using a shared device. Drafts, your selected profile photo and your AI consent preference are stored on your device. Selected generation images may remain in the device picker cache; attachments are kept in the current session and are not included in text drafts. The native app saves downloads to your photo library when you allow it. The website downloads files through your browser. Browser drafts and profile photos use local storage on this device. Reset AI consent from the account menu to be asked again before generating. Resetting consent does not delete existing data.
Use and access
We use this information to authenticate accounts, create and deliver media, manage credits, investigate reports and respond to support requests. Gallery access is restricted by account. Service operators and providers may process information to operate and support the service. The current app does not include advertising or advertising-tracking features.
Storage and retention
This preview stores account records, credit history and generated media on a Render-hosted server in Oregon, United States. Encrypted daily backups are scheduled to the operator’s computer when it is available. Daily copies older than seven days are removed after a new verified backup succeeds. Separate historical migration copies remain pending retention review. Backups are not deleted immediately when an account is deleted; contact support with retention questions. There is no independent cloud backup yet. Account and creation records remain until removed or handled through support. Providers may retain information under their own terms and policies. Do not use the preview for information that requires guaranteed confidentiality or permanent storage.
Deletion and requests
Delete creation removes that creation’s media and description from the active service. Minimal job identifiers and credit records remain to prevent duplicate charges; content-report records may remain for review. Copies already downloaded to your phone are not removed. Drafts and profile photos remain local. Open the account menu and choose Delete account to request permanent deletion. This requires the server deletion service to be configured; if the app reports that it is unavailable, contact support. An accepted request immediately locks account access while the service removes active account records, creations and credit history. Private backups and AI-provider records follow their separate retention policies. Email support@carivioai.com to request access, correction or account/data deletion; identity verification may be needed. We do not promise immediate or automatic deletion from every provider.
Changes
We will update this notice as the service changes. Review the updated notice before using new features.