Privacy Policy
Effective date set at launch.
1. Who this covers
AvatarStudio lets you pick a character (a “Sidekick”), pick a dance (a “Move”), and record yourself dancing beside it to make a short composited video. This policy explains what personal information we collect when you use the AvatarStudio app and website at avatarstudio.cloud, how we use it, who we share it with, how long we keep it, and the choices you have. It applies to everyone who uses AvatarStudio. Browsing the public Sidekick and Moves libraries does not require an account; creating, saving, buying credits, and publishing do.
2. What we collect
- Account information. When you create an account, sign-in is handled by Amazon Cognito. We collect the email address you register and an opaque account identifier (your Cognito subject id). We do not store your password; Cognito does.
- Device identifier. An opaque device/session identifier used to keep your creations, wallet, and settings tied to you and to detect abuse. It is not your phone's hardware serial number.
- Age range and consent records. Your age range (a bracket, not your exact birthday) and the safety acknowledgements and consents you accept — including, where applicable, verifiable parental consent — so we can apply the right protections and keep a record that consent was given.
- Creation inputs. When you make your own Sidekick or Move, we process the generation prompt you type and any images or videos you upload (for example, a dance clip used to extract motion, or a photo used to derive a character). A finished duet may use a video you record as the backdrop. See section 6 for image-derived characters and biometric considerations.
- Product-analytics events. A small set of opaque usage events (for example: you started a creation, reached the preview, saved a video, opened the buy-credits sheet). These carry the opaque account/device id and a few non-identifying tags only — no free text, no prompt content, no uploaded media, and no contact details.
- Payment metadata. When you buy credits, our payment processor (Stripe) handles your card and returns only metadata to us (for example: that a charge succeeded, the amount, currency, the credit pack purchased, and a Stripe customer/charge token). We never receive or store full payment card numbers.
- Credits ledger. We keep an append-only ledger of your credit balance and transactions (grants from pack purchases or promos, and debits when you generate a custom Sidekick or Move, or remove a watermark). This is needed to run the wallet, prevent double-spend, and provide an audit trail.
3. Where your duet is made
On supported phones, your finished duet video is created and saved to your camera roll on your device, so the recorded footage does not need to leave your phone to produce the file. When your device cannot do this (older hardware, missing video support, or an interruption), we fall back to building the video in the cloud on Amazon Web Services so the save still works. This cloud fallback is a mandatory, budgeted part of the service, not an optional extra; when it runs, the footage and assets needed to build your video are processed on our servers and the result is returned to you. We indicate which path is in use.
Your camera turns on only while you are recording, and we stop it the moment you finish. We do not stream or upload your live camera feed.
4. How we use what we collect
- To create and operate your account and keep your creations and wallet tied to you.
- To generate the custom Sidekicks and Moves you ask for, and to build your duets.
- To process credit purchases and maintain your credits ledger.
- To apply age-appropriate protections and to record the consents and acknowledgements the law and our policies require.
- To run safety, moderation, and notice-and-takedown processes (see the Acceptable-Use Policy and Notice & Takedown Policy).
- To understand and improve the product using opaque analytics events, to prevent fraud and abuse, and to meet legal obligations.
5. Third-party processors
We rely on a small set of vendors to run the service. Each receives only what it needs for its purpose:
- Meshy — generates a 3D character (Sidekick) from your prompt or image when you make your own. Receives your generation prompt and any image you supply.
- Move.ai (Move) — extracts motion from a dance video you supply so it can drive a character. Receives the video clip you upload for motion capture.
- Stripe — processes credit-pack payments and handles your card details so we do not have to. Receives the payment information you enter at checkout.
- Amazon Web Services (AWS) — runs the underlying platform: Cognito (sign-in and account identity), DynamoDB (your profile, library entries, wallet, and credits ledger), S3 (stored assets: character and motion files, posters, idle and demo loop videos), and CloudFront (hosting and content delivery), plus the cloud fallback for building your video, described above.
Each processor handles your data under its own terms and our agreement with it. The final list, sub-processor links, and any data-transfer mechanisms are confirmed with counsel before launch.
6. Children, minors, and biometric considerations
A character built from a photo of a real person can act as biometric personal information, so we treat any image-derived character with extra care. For people under 13 we follow children's-privacy rules (including the U.S. Children's Online Privacy Protection Act, COPPA): we require verifiable parental consent before any image-derived character is created, we limit what we collect, and we apply children's-privacy retention limits. People under 16 cannot publish to the public library at all. We collect an age range at a gate so we can apply these protections, and we keep a record of the consents obtained. If you believe a child has given us personal information without the required consent, contact us and we will act.
7. Likeness and right of publicity
You may only create or upload likenesses you have the right to use. A person's appearance is protected by right-of-publicity and similar laws, and there is no automatic safe harbor for those claims. Before custom creation and again before anything is made public, we ask you to confirm you hold the necessary rights, and we run checks on submissions headed for the public library. See the Acceptable-Use Policy for what is and is not allowed.
8. Private by default; public only after a gate
Anything you create is private by default and visible only to you. Content becomes public only if you opt in to publish it, it passes our moderation and human-review gate, and you complete the required safety acknowledgements. We never make your content public automatically. Public library entries (and any attribution shown with them) are visible to anyone browsing the libraries, which do not require an account.
9. Cookies and analytics consent
We use a small number of cookies and similar storage that are strictly necessary to run the service (for example, to keep you signed in via a session cookie). For analytics and any non-essential storage, we ask for your consent where the law requires it, and you can change your choice. We do not sell your personal information. The specific cookie list and the consent mechanism are finalized with counsel before launch.
10. Your rights and choices
You can access, export, and delete your account and the data tied to it from your account settings. Export gives you a copy of the data tied to your account; delete removes or anonymizes that data, subject to the retention limits below. Depending on where you live, you may have additional rights to your personal information (such as to correct it or object to certain processing); contact us to exercise them, and we will not discriminate against you for doing so.
11. Retention and deletion
We keep what we need to run the service and meet legal obligations, and remove the rest. When you delete your account we remove your creations from the libraries and clear the prompts and free text you typed, except where we must retain limited records — for example, billing and credits-ledger records for tax and fraud purposes (with personal details unlinked), the consent records we are required to keep, and items under a legal hold. We do not retain full card numbers. For people under 13 we apply children's-privacy retention limits. The detailed, COPPA-compliant retention and deletion schedule is finalized with counsel before launch.
12. Governing law, changes, and contact
This policy is governed by the laws of [governing-law placeholder — pending counsel]. We may update it; we will mark the new effective date and, where required, notify you. Questions about your privacy can be sent to legal@avatarstudio.cloud (placeholder pending counsel).