Privacy Policy for img2.video
Last updated: October 2026 · Operated by img2.video
This policy explains what data img2.video ("we", "the app") collects, how we use it, and the choices you have. The app uses Google OAuth Sign-In (scope: openid, email, profile).
1. Data we collect
- Account data (via Google Sign-In): your Google account email address, display name, and Google user ID. We receive these when you choose to sign in. We do not receive your Google password, and we cannot read your email, files, or any other Google account data.
- Content you submit: images you upload and text prompts you type, for the purpose of generating videos for you.
- Usage and billing data: credit balances, purchase records, and generation logs (timestamps, model used, success/failure).
- Technical data: IP address and request metadata used for rate limiting and abuse prevention.
2. How we use data
- Create and secure your account (email + user ID).
- Process your image-to-video generation requests.
- Maintain credit balances and process payments.
- Prevent abuse (rate limits, fraud detection).
We do not use your data for advertising profiling, and we do not sell or rent personal data to anyone.
3. Google API Services disclosure
img2.video's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request the openid, email and profile scopes, and use the data solely to operate sign-in.
4. Service providers (processors)
- Cloudflare — hosting, storage (uploads and results), database.
- Google — OAuth sign-in only.
- AI model providers (e.g. fal.ai) — receive the image + prompt you submit, solely to generate your video.
- Our payment provider (Waffo) — checkout and billing; they receive your email and payment details for the transaction.
5. Retention & deletion
Uploaded images and generated videos are automatically deleted after 7 days. Account records are kept while your account is active. You may request deletion of your account and all associated data at any time by contacting us; deletion completes within 30 days.
6. Your rights
Depending on your jurisdiction (e.g. GDPR/CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to processing. Exercise any of these by contacting us; we respond within 30 days.
7. Cookies & local storage
We use only an essential session token stored in your browser's local storage to keep you signed in. No third-party advertising or tracking cookies.
8. Children
The service is not directed to children under 13 (or equivalent age in your jurisdiction), and we do not knowingly collect their data.
9. Abuse prohibition
The app must not be used to create non-consensual intimate imagery of real people, deepfakes intended to deceive, or any unlawful content. Violations result in account termination. See our Terms.
10. Changes & contact
We may update this policy; material changes will be reflected on this page. Questions: contact us or [email protected].