Privacy Policy
Last updated 19 August 2026
Who is responsible
GenViz AI LLC operates SY Visuals and decides what happens to the data described below — in data-protection terms, we are the controller. Write to support@genviz.app about anything on this page, or by post at GenViz AI LLC, Dubai, United Arab Emirates.
The short version
We store the account you create, the films you make, and a ledger of your credits. We send your premise text to an AI provider when you ask for an analysis, and your prompts to an image provider when you ask for a render. We do not sell anything about you, and there is no advertising or cross-site tracking in this product.
What we store
- Account — your name, email address, and a scrypt derivation of your password. We never store the password itself and cannot recover it.
- Projects — everything you put into a film: title, premise, breakdown, characters, locations, shots and generated frames.
- Credits — your balance and every movement in or out of it, with a label describing what it paid for.
- Sessions — a hash of your session token, its expiry, and the browser user-agent string that created it.
- Abuse controls — short-lived counters keyed by IP address, used to rate-limit sign-ins and generation. They are swept away once they are more than a day old.
- Payments — if you buy credits, a Stripe customer id. Card details go to Stripe directly and never reach our servers.
Cookies
One cookie: sy_session, which keeps you signed in. It is http-only, same-site, and holds an opaque token — no personal data is in it. There are no advertising or cross-site tracking cookies.
Who else processes it
- Anthropic — receives your title, genre, runtime and premise when you run an AI analysis, and returns the breakdown.
- fal.ai — receives the image prompt and seed for each render, and returns the image.
- Stripe — handles payment for credit packs and holds the payment details we never see.
- Our hosting and database providers — store and serve the data described above on our behalf.
- Vercel Analytics and Speed Insights — collect aggregate page-view and performance measurements. They are cookie-less and do not build a profile of you.
That is the complete list. We do not share your projects with anyone else, and nothing you write is used to train our own models.
Sharing a film
A film is private until you publish it. Publishing creates an unguessable link; anyone who has that link can watch the film, and search engines are asked not to index it. Revoking the link removes the page immediately.
How long we keep it
Projects stay until you delete them. Deleting a project removes it and its frames. Closing your account removes the account, its projects, its sessions and its ledger.
Sessions expire thirty days after their last use. Rate-limit counters are swept away a day after they are last touched. Payment records are kept as long as tax and accounting law requires.
Your choices
You can see and edit everything in your account from the studio, delete any project from the dashboard, export a film as HTML, JSON or video at any time, and delete your account outright from the billing page — which removes your films, their frames and your ledger immediately.
To get a copy of your data or have your account deleted, email support@genviz.app. Depending on where you live you may also have the right to correct your data, object to processing, or complain to a data protection authority.
Security
Passwords are stored as scrypt derivations with a per-account salt. Session tokens are stored only as hashes, so a copy of the database does not hand anyone a live session. Traffic is served over HTTPS. No system is perfect, and we will tell affected users promptly if we ever discover a breach that puts their data at risk.
Changes
If this policy changes materially we will say so in the studio before the change takes effect. The date at the top of this page always reflects the current version.