🛡 Owned in India · DPDP 2023
Privacy policy.
We keep the data we need to run your agents and ship your account — nothing more. We never sell your data. Indian businesses, Indian laws (DPDP Act 2023).
01 What we collect
- Account info: email, phone (for OTP login), name (optional). Pretty much it.
- Generated content: the topics you type, the reels we render, and call transcripts your agent produces — stored on your account so you can re-use or download them.
- Payment metadata: our PCI-DSS-compliant payment partner handles your card. We never see the card number — just order ID + amount + status.
- Usage logs: anonymised counts of API calls (for rate limiting + cost forecasting). No content.
02 What we don't collect
- No cross-site trackers. No Facebook pixel. No Google Analytics — we use a self-hosted minimal counter.
- No third-party ads. No data brokers. No "anonymised" data resold.
- No mic / camera / location access beyond what a live call you initiate requires. We never ask otherwise.
03 Where data lives
All user data and generated content are stored on dedicated servers operated by Ravyo Labs. Rendered MP4s are deletable on request and auto-purged after 7 days from generation.
04 Third-party services we use
To deliver our products we use a small number of trusted providers. Each receives only the minimum data needed to do its job.
- Language models: typed topics and call context are sent to our model providers' APIs to generate scripts and replies. They do not retain API inputs for model training per their API data policies.
- Pexels: AI-generated search keywords (not your topic verbatim) are sent to fetch matching b-roll. Video bytes stream directly from Pexels' CDN to your browser — we never proxy them.
- Voice synthesis: performed on our own infrastructure using self-hosted models. Your script text never leaves Ravyo's servers.
- Razorpay: payment processing, PCI-DSS-compliant. We receive order ID + amount + status; never card/UPI details. See Razorpay's privacy policy.
- Cloudflare: CDN + DDoS protection. Sets one session cookie (
__cf_bm) to tell humans from bots — required for security. See Cloudflare's privacy policy. - SMS provider: sends OTP for login. Receives your phone number + the OTP code, used only for that single authentication.
05 Your rights (DPDP-compliant)
- Right to access: email us, we'll export your data within 30 days.
- Right to delete: email us, we delete your account + every reel within 7 days.
- Right to correct: update your profile, or email us.
- Right to portability: we provide a JSON dump of your account history on request.
06 Cookies & contact
We set one HTTP-only, secure, SameSite=Lax, JWT-signed session cookie — used only to keep you logged in. For any privacy or data request, email [email protected].