Fiava legal
Privacy Policy
Effective and last updated September 6, 2026
This Policy explains what personal data Fiava handles, why, where it goes, how long it is kept, and how to exercise your privacy rights.
1. Who controls your data
Fiava, Inc. is the controller of personal data covered by this Policy. Our mailing address is 1209 Mountain Road Place NE, Suite R, Albuquerque, NM 87110, USA. Privacy questions and requests may be sent to legal@fiava.ai.
This Policy covers Fiava’s website, authenticated application, generation service, billing features, and support interactions. It does not govern a third party’s service when you use it independently of Fiava.
2. Personal data we collect
| Category | Examples and source |
|---|---|
| Account identifiers | WorkOS user ID, normalized email, email-verification status, name, and avatar URL supplied by WorkOS when you authenticate. Fiava does not receive your password. |
| Workspace and preferences | Internal user and workspace IDs, workspace name, membership and capability records, account status, and creation and language preferences generated by Fiava or chosen by you. |
| Creative Input | The idea or other text you submit and, when an upload feature is offered, an image you choose to upload. Do not submit sensitive personal data you do not need Fiava to process. |
| Derived creative information | An automated restatement, structured creative brief, provider prompt, safety or clarification result, and technical generation settings derived from your Input. |
| Output and media metadata | Generated videos and file details such as type, byte size, checksum, dimensions, duration, frame rate, codec, and audio presence. |
| Generation and usage records | Creation mode, model and operation, timestamps, status changes, request fingerprints, provider-job references, allowance set aside and used, and records of private download-link requests. |
| Commercial and billing information | Stripe customer, checkout, payment, invoice, price, subscription, and order identifiers; plan, amount, currency, status, renewal or cancellation state, allowance granted, refunds, and disputes. Card details are collected by Stripe and are not stored by Fiava. |
| Network, security, and diagnostics | IP address and browser/network data necessarily processed by Cloudflare; sign-in and security events; rate-limit counters; request IDs; route names; internal resource identifiers; timings; and safe error codes. Fiava is designed not to place prompts, media, passwords, cookies, payment details, or raw provider responses in application logs. |
| Communications | Messages and attachments you send to support or legal, the request you make, identity-verification information where necessary, and Fiava’s response and resolution record. |
Fiava does not intentionally collect a date of birth, government identifier, precise location, contact list, or full payment-card credentials. Creative Input can nevertheless contain personal or sensitive information if you put it there. Please do not provide another person’s sensitive information without a lawful reason and any required permission.
3. Why we use data and our legal bases
| Purpose | Data | Legal basis where required |
|---|---|---|
| Authenticate you and operate your account | Account, workspace, cookie, and preference data | Performing our contract with you |
| Interpret requests, generate, store, and deliver videos | Input, derived creative information, Output, metadata, and usage records | Performing our contract with you |
| Process payment, grant plan allowance, administer renewal and cancellation | Account, commercial, billing, and usage information | Contract; legal obligations for tax and accounting |
| Prevent fraud, abuse, unsafe use, and unauthorized access | Account, Input, automated safety results, network and security data | Legitimate interests in protecting users, Fiava, providers, and others; legal obligations where applicable |
| Diagnose failures, reconcile provider and billing outcomes, and support you | Diagnostics, minimized identifiers, generation, billing, and communications | Contract and legitimate interests in a reliable, accountable service |
| Respond to rights requests, legal claims, and official demands | Relevant account, request, billing, security, and communications records | Legal obligation and legitimate interests in legal compliance and claims |
Fiava does not currently use consent as the basis for advertising, analytics, or marketing because the product does not use those features. If Fiava later offers an optional use that requires consent, it will ask separately and you may withdraw that consent without affecting earlier lawful processing.
4. AI processing and automated checks
Fiava sends the exact idea you submit to Anthropic’s commercial API for automated interpretation and safety classification. The request body is designed not to include your name, email, Fiava user ID, workspace ID, or session. An idea can itself identify you or someone else, so avoid unnecessary personal data.
If accepted, Fiava creates prompts from your idea, selected format, and character information. Names, quotations, or other exact elements can remain in those prompts. The generation path determines which providers receive this creative information.
On Fiava’s primary portrait-video path, Google receives an image-preparation prompt and reference images to create an opening-scene image. Fiava then sends Kie a video prompt, generation settings, a temporary access URL for that image, and a callback address containing an opaque job-correlation token. Kie provides the Grok Imagine video service, which Kie identifies as using xAI’s model. Fiava’s request goes to Kie; the exact downstream processing arrangements depend on Kie’s service.
Other supported video configurations use Google Vertex AI/Veo: Google receives the derived prompt, settings, and any input media required by that path. Google stages those video results in Google Cloud Storage. Fiava copies delivered video from the selected provider into private Cloudflare R2 storage. Creative content and reference images can contain personal data even when the request omits account identifiers.
These systems decide whether to clarify, refuse, or process a creative request. They do not make a decision about your employment, creditworthiness, housing, education, insurance, legal rights, or another similarly significant matter. If you believe an automated refusal is mistaken, contact us for support.
Fiava labels completed video as AI-generated in the product. Google states that videos created by Veo are marked with its invisible SynthID watermark. That statement concerns Veo output; it is not a claim that every provider’s video carries the same marking. Fiava copies provider output without intentionally removing its markings.
Fiava does not use Input or Output to train its own general-purpose AI models. Under the standard commercial/API terms, Anthropic does not use API Input or Output to train its models by default, and Google does not train or fine-tune managed models on customer data without permission or instruction. These provider-specific terms do not establish Kie’s or its downstream providers’ practices. Fiava has not verified a no-training commitment for Kie’s processing of this route. Provider processing for abuse prevention, security, legal compliance, and service operation is subject to each applicable service’s terms and settings.
5. Service providers and disclosures
Fiava discloses data only as needed to operate the service, process a transaction, protect rights and safety, complete a corporate transaction, or comply with law. The principal service providers are:
| Provider | Role and data |
|---|---|
| WorkOS | Hosted authentication and account recovery; returns identity attributes to Fiava and handles credentials directly. |
| Anthropic | Commercial AI intake and safety processing; receives the submitted idea and Fiava’s system and tool instructions, without Fiava account identifiers in the request body. |
| Google Cloud | Image preparation with Gemini and video generation with Vertex AI/Veo; receives derived prompts, settings, and reference images or other required input media. Google Cloud Storage stages Google video results. |
| Kie | Grok Imagine video generation, described by Kie as using xAI’s model; receives the video prompt, settings, temporary image-access URL and image, and callback correlation information. Kie and its applicable downstream providers process this request and generated result. |
| Cloudflare | Website and API delivery, network security, Workers logs, and private R2 storage; processes network data, diagnostics, Input media, and Output. |
| Neon | Managed PostgreSQL database and backups; stores account, workspace, generation, encrypted Input, derived creative, usage, and billing records. |
| Stripe | Checkout, payment, invoicing, subscriptions, billing portal, refunds, and disputes; receives Fiava order/workspace metadata and data you enter directly on Stripe-hosted pages. |
| Postmark | Transactional email delivery for account messages Fiava sends you; receives your email address and the message itself, and reports whether it was delivered. Fiava does not use open or click tracking, so no pixel is embedded and no link is rewritten. Postmark does not receive your Fiava account identifiers, ideas, or generated videos. |
Fiava may disclose information to professional advisers, insurers, authorities, or counterparties when reasonably necessary for a legal obligation, claim, safety issue, financing, merger, acquisition, or sale. A successor must handle personal data under this Policy or give legally required notice of a new policy.
Fiava does not sell personal data, share it for cross-context behavioral advertising, use it for targeted advertising, or disclose it to a data broker. Fiava does not offer a financial incentive in exchange for personal data.
7. Where data is processed and international transfers
Fiava is a United States company. Google video requests use the us-central1 regional endpoint; Google image preparation uses its global endpoint. Fiava has not verified a fixed processing region for Kie and its downstream providers. These paths are not all restricted to one United States region. Anthropic, WorkOS, Stripe, Cloudflare, Neon, Postmark, and their subprocessors may process data in the United States and other countries where they operate. Cloudflare’s network may handle requests near the place from which you connect; Fiava’s R2 configuration does not promise storage in a particular country unless Fiava expressly agrees otherwise.
Transfer safeguards depend on the processor and the applicable contract. Fiava has not yet verified Kie’s account-specific transfer terms or downstream safeguards. A provider’s public description of its service does not establish those contractual protections. Contact us for information about the terms and safeguards verified for a particular transfer.
8. Retention and deletion periods
Fiava keeps personal data only for the service purpose, the period described below, or longer where a legal obligation, fraud investigation, dispute, or narrowly scoped preservation duty requires it. Retention is measured from the relevant event; deletion jobs can run on a schedule rather than at the exact second a period ends.
| Data | Retention |
|---|---|
| Account profile, workspace, preferences, and active membership | While the account is active. After Fiava verifies and approves a deletion request, active profile and workspace data is deleted or de-identified, subject to the limited records and provider-retention periods below. |
| Raw idea, normalized intent, and structured creative brief | Kept with the generation so you can identify and use your work, until that generation or account is deleted. The raw idea is encrypted at application level; derived intent and brief fields are stored in plaintext in the private database. |
| Detailed prompt sent to the video provider | Encrypted and retained only while submission, retry, or authoritative recovery can require it. Once the creation has finished and its allowance has been finally accounted for, it becomes cleanup-eligible, with a target of deletion within 24 hours. A genuinely unresolved provider outcome remains retained until resolution. |
| Accepted Input media and generated Output in Fiava storage | While the account or generation remains available. An approved deletion request first makes the relevant object unavailable and then places it into Fiava’s storage-cleanup process. Physical-object cleanup can follow a 30-day deletion grace period. |
| Temporary, abandoned, or refused uploads | Accepted temporary copies are targeted for deletion within 24 hours of promotion. Abandoned upload intents expire after 24 hours and the object is targeted within the following 24 hours. Quarantined or invalid objects are cleanup-eligible within 72 hours and are removed by the next daily cleanup cycle; minimized validation results remain 30 days. Terminal upload-intent rows remain 30 days. |
| Creative-intake replay cache and short request fingerprints | Up to 24 hours. |
| Private media-access events | 180 rolling days. |
| Application logs in Cloudflare Workers Logs | Up to 7 days under Cloudflare’s current product limits. |
| Billing, tax, accounting, refund, dispute, and anti-fraud records | For the period required by applicable accounting, tax, payments, fraud, and claims law. Identity is minimized or pseudonymized when full identification is no longer needed; append-only economic records may remain linked to a random internal tombstone. |
| Support, legal, and privacy-request records | Until the matter is resolved, then for the applicable claims or compliance period, normally no more than 3 years unless law or an active dispute requires longer. |
Provider copies follow the provider’s terms and technical controls. Under Anthropic’s standard commercial API terms, API Input and Output may be retained for up to 30 days unless Fiava has an applicable zero-data-retention arrangement; limited security or legal exceptions can apply. Google and other processors may retain temporary service, security, audit, or backup records under their applicable terms and configured controls. Kie’s API documentation states that generated media is retained for 14 days and text or metadata logs for 2 months. Fiava has not verified the retention of every submitted image, prompt, or downstream copy, account-specific exceptions, or a request-level deletion mechanism. Expiry of a temporary access URL does not prove deletion of copies already retrieved by a provider. Fiava will delete or request deletion of provider-side copies when the provider and Fiava’s available tools permit it, and identify known remaining retention in the response to a rights request. A rights request remains open while a provider step that Fiava controls is still pending.
Deleted data can remain in encrypted disaster-recovery backups until the provider’s ordinary rotation completes. Backups are isolated from ordinary service and are not used to restore deleted data for routine product use. If Fiava restores an earlier backup, the restored data remains subject to the original deletion request and must be erased again before ordinary processing resumes.
9. Your privacy rights
Depending on where you live, you may have rights to know or access personal data, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, and appeal a denied request. You may also have the right not to be discriminated against for exercising a privacy right. Fiava offers the core access, correction, deletion, and portability request process regardless of location, subject to lawful exceptions.
Send a request from the email associated with your account to legal@fiava.ai and state the right you wish to exercise. You may also write to the postal address in section 1. Fiava will acknowledge the request, verify identity proportionately, and normally respond within 30 days. If applicable law permits more time for a complex request, Fiava will explain the extension. Authorized agents should identify the person and provide proof of authority; Fiava may still verify the request directly with the person.
You can correct identity details through your WorkOS-hosted sign-in account, download individual delivered videos, review usage in Fiava, and review invoices and payment details in Stripe’s portal. To request a copy in a commonly used format, account or content deletion, restriction, objection, or an appeal, use the request channel above.
After Fiava verifies and approves an account-deletion request, Fiava disables access to the affected workspace; deletes or de-identifies active profile and retained creative data; and arranges deletion of associated Input and Output objects that Fiava controls. Provider and backup copies may remain temporarily as described in section 8. Fiava retains only information reasonably required for billing, fraud, security, legal claims, complying with law, and documenting the request. Fiava will tell you when active-system steps are complete and identify any known retention that remains. A later sign-in does not restore content erased in response to the request.
A request can be limited where an exception applies, including another person’s rights, security, fraud prevention, legal claims, tax/accounting duties, or data Fiava cannot reasonably verify as relating to you. Fiava will explain a denial and any available appeal. You may complain to your local privacy or data-protection authority; EEA and UK residents may complain in the country where they live or work or where an alleged infringement occurred.
10. United States state privacy notice
In the preceding 12 months, Fiava may have collected the categories described in section 2: identifiers; commercial information; internet or electronic activity; audio-visual content; and inferences in the form of derived creative information. The sources are you, WorkOS, Stripe, Fiava’s systems, and service providers. Fiava uses and discloses them for the purposes and to the provider categories described in sections 3 and 5. Fiava does not sell these categories or share them for cross-context behavioral advertising.
Fiava does not use sensitive personal information to infer characteristics about you. If your creative Input contains sensitive information, Fiava processes it only for the service, security, legal, and support purposes described here. Where state law applies, you may exercise access, correction, deletion, portability, opt-out, and appeal rights through section 9. Because Fiava does not sell data, use targeted advertising, or perform covered profiling with legal or similarly significant effects, there is currently no sale, targeted-advertising, or covered-profiling opt-out to apply.
11. Security and incident response
Fiava uses HTTPS, secure and host-scoped sessions, private object storage, short-lived signed download URLs, application-level AES-GCM encryption for raw ideas and provider prompts, versioned keys, tenant-scoped queries, capability checks, PostgreSQL row-level security, restricted runtime credentials, structured-log redaction, and bounded retention jobs. Providers encrypt data in transit and at rest under their controls.
No system is perfectly secure. If Fiava confirms a breach requiring notice, Fiava will notify affected people and authorities in the manner and time required by applicable law. Report a suspected security issue to legal@fiava.ai and do not include exploit details in a public report.
12. Children
Fiava is for adults aged 18 or older and is not directed to children. Fiava does not knowingly collect personal data from a child. If you believe a child has provided data to Fiava, contact us so we can investigate and delete it where required.
13. Changes to this Policy
Fiava may update this Policy as the service or law changes. The date at the top identifies the current version. Fiava will post the new Policy here and, for a material change, provide any additional notice or consent required by law before the new use begins. Earlier versions and their effective dates are retained in Fiava’s release history.
14. Contact
Fiava, Inc.
1209 Mountain Road Place NE, Suite R, Albuquerque, NM 87110, USA
legal@fiava.ai