← back to homepage
🛡 OWNED IN INDIA · MMXXVI
Privacy policy.
We keep the data we need to mint your reels and ship your account — nothing more. We never sell your data. Indian creators, Indian laws (DPDP Act 2023).
1. What we collect
- Account info: email, phone (for OTP login), name (optional). Pretty much it.
- Generated content: the topics you type, the reels we render for you. Stored on your account so you can re-render or download for 7 days.
- Payment metadata: our PCI-DSS-compliant payment partner handles your card. We never see the card number — just order ID + amount + status.
- Usage logs: anonymised counts of API calls (for rate limiting + cost forecasting). No content.
2. What we don't collect
- No cross-site trackers. No Facebook pixel. No Google Analytics — we use a self-hosted minimal counter.
- No third-party ads. No data brokers. No "anonymized" data resold.
- No mic / camera / location access. We never ask.
3. Where data lives
All user data + generated reels are stored on a dedicated server operated by Ravyo Labs. Rendered MP4s are deletable on request and auto-purged after 7 days from generation.
4. Third-party services we use
To deliver Ravyo AI Video Pro we use a small number of trusted third-party providers. Each one only receives the minimum data needed to do its job. Specific vendors:
- OpenAI (GPT-4o / GPT-4o-mini): your typed topic is sent to OpenAI's API to generate the script. OpenAI does not retain API inputs for model training per their API data policy.
- Pexels (videos.pexels.com): we send AI-generated search keywords (not your topic verbatim) to Pexels' API to fetch matching b-roll clips. The video bytes stream directly from Pexels' CDN to your browser — we never proxy them.
- Voice synthesis (Supertonic 3): performed on our own infrastructure using a self-hosted ONNX model. Your script text never leaves Ravyo's servers.
- Razorpay: payment processing. PCI-DSS-compliant. We receive order ID + amount + status; we never see card/UPI details. Razorpay's privacy policy.
- Post for Me (PFM): auto-posting to Facebook, Instagram, YouTube. PFM receives the rendered MP4 + your social tokens (encrypted) only when you trigger an auto-post.
- Cloudflare: we use Cloudflare as a CDN + DDoS protection in front of our server. Cloudflare sets one session cookie (`__cf_bm`) to distinguish humans from bots — required for site security. See Cloudflare's privacy policy.
- SMS provider: sends OTP for login. The provider receives your phone number + the OTP code, used only for that single authentication.
5. Your rights (DPDP-compliant)
- Right to access: email us, we'll export your data within 30 days.
- Right to delete: email us, we delete your account + every reel within 7 days.
- Right to correct: update your profile from /account, or email us.
- Right to portability: we provide a JSON dump of your account history on request.
6. Cookies
- Session cookie (set by Ravyo): HTTP-only, secure, SameSite=Lax, JWT-signed. Used only to keep you logged in. Expires when you log out.
- __cf_bm (set by Cloudflare): distinguishes humans from bots. Required for site security. ~30 minute lifespan.
- No advertising cookies. No tracking cookies. No third-party analytics.
7. Children
Ravyo isn't designed for users under 18. If we learn we've collected data on a minor, we delete it immediately.
8. Changes to this policy
If we update this policy materially, we email every account and post a notice on the homepage 30 days before the change kicks in.
9. Contact
Ravyo Labs · Jagadhri, Haryana, India · GSTIN 06BPSPG4969L2Z1
Privacy questions: [email protected] · Real human responds within 48 hours · Phone/WhatsApp: +91 9812 22 2564