Privacy Policy
Last Updated: October 18, 2025 Effective Date: October 18, 2025
Introduction
Welcome to Right AI ("we," "our," or "us"). We operate the website https://rightai.io/ and provide AI-powered video and image generation services (collectively, the "Service").
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the Service.
We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.
1. Information We Collect
1.1 Personal Information You Provide
We collect information that you voluntarily provide to us when you:
- Register for an account: Email address, name, password
- Authenticate via OAuth: Google account information (email, name, profile picture)
- Make a payment: Payment information processed by our payment provider Creem (we do not store complete credit card details)
- Contact us: Email address and any information you choose to provide in your communications
1.2 Automatically Collected Information
When you access our Service, we automatically collect certain information, including:
- Log Data: IP address, browser type, operating system, referring URLs, access times
- Device Information: Device type, unique device identifiers
- Usage Data: Pages viewed, features used, time spent on pages, navigation paths
- Analytics Data: Collected via Vercel Analytics and Google Analytics to understand user behavior and improve our Service
1.3 Content You Create
When you use our AI generation services, we collect and process:
- Text Prompts: Instructions you provide to generate videos or images
- Uploaded Images: Images you upload for AI processing (e.g., image-to-video generation)
- Generated Content: Videos and images created by our AI models
- Generation History: Records of your generation requests, credits used, and timestamps
1.4 Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our Service and store certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Provision and Improvement
- Account Management: Create and manage your user account
- Service Delivery: Process your AI generation requests and deliver generated content
- Feature Development: Analyze usage patterns to improve existing features and develop new ones
- Performance Optimization: Monitor and optimize Service performance and reliability
2.2 AI Processing
- Temporary Processing: Your text prompts and uploaded images are temporarily sent to our AI service providers (Google AI, OpenAI, Volcano Engine) to generate your requested content
- No Training Use: We do not use your prompts, uploaded images, or generated content to train AI models
- Processing Completion: AI service providers process your requests and do not retain your data after processing is complete
2.3 Communication
- Transactional Emails: Send verification emails, password reset links, and payment confirmations via Resend
- Service Updates: Notify you about changes to our Service, new features, or important announcements
- Customer Support: Respond to your inquiries and provide technical support
2.4 Payment Processing
- Transaction Processing: Process payments and manage subscriptions through Creem
- Credit Management: Track credit purchases, grants, and usage in our credit ledger system
- Billing Records: Maintain payment records for tax compliance and dispute resolution
2.5 Legal Compliance and Security
- Fraud Prevention: Detect and prevent fraudulent transactions and unauthorized access
- Legal Obligations: Comply with applicable laws, regulations, and legal processes
- Terms Enforcement: Enforce our Terms of Service and protect our rights
3. Data Sharing and Disclosure
We may share your information in the following circumstances:
3.1 Service Providers
We share your information with third-party service providers who perform services on our behalf:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Google AI | AI video/image generation | Text prompts, uploaded images (temporary) |
| OpenAI | AI processing capabilities | Text prompts, uploaded images (temporary) |
| Volcano Engine | AI video/image generation | Text prompts, uploaded images (temporary) |
| Creem | Payment processing | Email, payment details, transaction amounts |
| Resend | Email delivery | Email address, transactional content |
| Vercel Analytics | Performance analytics | Usage data, anonymized metrics |
| Google Analytics | User behavior analytics | Anonymized usage patterns |
Important: AI service providers process your data temporarily to fulfill your generation requests and do not retain your data after processing.
3.2 Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal processes (subpoenas, court orders, government requests)
- Enforcement of our Terms of Service or policies
- Protection of our rights, property, or safety, or that of others
- Detection and prevention of fraud, security, or technical issues
3.3 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
3.4 With Your Consent
We may share your information for other purposes with your explicit consent.
4. International Data Transfers
Right AI operates from China (Sichuan Province), but our Service utilizes infrastructure and service providers located in various countries, including:
- China: Primary operations and database hosting
- United States: AI processing (Google AI, OpenAI), analytics services
- Global: Content delivery networks and cloud infrastructure
By using our Service, you acknowledge and consent to the transfer of your information to countries outside your country of residence, which may have different data protection laws.
For European Users (GDPR): When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
For California Users (CCPA): We disclose your data internationally as described above to provide our Service.
5. Data Retention
We retain your information for different periods based on the type of data and your account status:
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of account existence |
| Generated Content (Free Users) | 7 days after generation |
| Generated Content (Basic/Pro/Premium Users) | 30 days after generation |
| Generation History | Duration of account existence |
| Payment Records | 7 years (tax compliance) |
| Credit Ledger | Duration of account existence |
| Email Logs | 90 days |
| Analytics Data | 26 months (Google Analytics default) |
After the applicable retention period, we will delete or anonymize your information. You may request earlier deletion by contacting us (see Section 9).
6. Data Security
We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction:
- Encryption: Data in transit is encrypted using SSL/TLS protocols
- Access Controls: Restricted access to personal information on a need-to-know basis
- Database Security: PostgreSQL database with authentication and access controls
- Password Protection: Passwords are hashed using industry-standard algorithms
- Regular Monitoring: Continuous monitoring for security vulnerabilities
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
7.1 General Rights (All Users)
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal obligations)
- Data Portability: Request an export of your data in a machine-readable format
7.2 GDPR Rights (European Users)
If you are located in the European Economic Area (EEA), you have additional rights:
- Right to Object: Object to processing of your personal data for certain purposes
- Right to Restriction: Request restriction of processing in certain circumstances
- Right to Withdraw Consent: Withdraw consent where processing is based on consent
- Right to Lodge a Complaint: File a complaint with your local data protection authority
Legal Basis for Processing (GDPR):
- Contract Performance: To provide our Service as agreed in our Terms of Service
- Legitimate Interests: To improve our Service, prevent fraud, and ensure security
- Consent: For marketing communications (where required by law)
- Legal Obligations: To comply with legal and regulatory requirements
7.3 CCPA Rights (California Users)
If you are a California resident, you have the right to:
- Know: Request disclosure of categories and specific pieces of personal information collected
- Delete: Request deletion of your personal information
- Opt-Out: Opt-out of the "sale" of personal information (we do not sell personal information)
- Non-Discrimination: Exercise your rights without discriminatory treatment
CCPA Categories of Information We Collect:
- Identifiers (email, name, IP address)
- Commercial information (payment records, generation history)
- Internet activity (usage data, analytics)
- Inferences (user preferences, behavior patterns)
7.4 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: contact@rightai.io Subject Line: "Privacy Rights Request"
Please include:
- Your full name and email address associated with your account
- The specific right you wish to exercise
- Sufficient detail to allow us to locate your information
We will respond to your request within:
- 30 days (general requests)
- 1 month (GDPR requests, extendable by 2 months for complex requests)
- 45 days (CCPA requests, extendable by 45 days with notice)
8. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at contact@rightai.io. If we become aware that we have collected personal information from children under 18 without verification of parental consent, we will take steps to remove that information from our servers.
9. Third-Party Links and Services
Our Service may contain links to third-party websites, applications, or services that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
9.1 OAuth Authentication
When you authenticate using Google OAuth, you are subject to Google's privacy policy. We only receive the information you authorize Google to share with us (email, name, profile picture).
9.2 Payment Processing
Payment information is processed by Creem. We do not store your complete credit card details. Please review Creem's privacy policy for information on how they handle your payment data.
10. Do Not Track Signals
Some web browsers incorporate a "Do Not Track" (DNT) feature that signals to websites you visit that you do not want to have your online activity tracked. Our Service does not currently respond to DNT signals due to lack of industry standards.
11. Your Choices and Controls
You have several choices regarding your information:
11.1 Account Information
- Update: Modify your account information through your account settings
- Delete Account: Request account deletion by contacting contact@rightai.io
11.2 Communications
- Transactional Emails: You cannot opt-out of transactional emails (verification, password resets, payment confirmations) as they are necessary for the Service
- Marketing Communications: If we send marketing emails in the future, you can opt-out via unsubscribe links
11.3 Cookies
- Browser Settings: Configure your browser to refuse cookies or alert you when cookies are being sent
- Analytics Opt-Out: Opt-out of Google Analytics via the Google Analytics Opt-out Browser Add-on
11.4 Generated Content
- Delete Content: You can delete your generated content at any time through your account
- Automatic Deletion: Content is automatically deleted based on your plan (7 days for Free users, 30 days for paid users)
12. Data Processing Transparency
We are committed to transparency in how AI processes your data:
12.1 AI Processing Flow
- Input: You provide a text prompt and/or upload an image
- Temporary Transfer: Your input is securely transmitted to our AI service provider (Google AI, OpenAI, or Volcano Engine)
- Processing: The AI model generates your requested video or image
- Delivery: Generated content is returned to our servers and displayed to you
- No Retention by AI Providers: AI service providers do not retain your prompts or uploaded images after processing
12.2 What We Do NOT Do
- ❌ We do NOT use your prompts to train AI models
- ❌ We do NOT use your uploaded images to train AI models
- ❌ We do NOT use your generated content to train AI models
- ❌ We do NOT share your content with third parties for marketing purposes
- ❌ We do NOT sell your personal information
12.3 What Happens to Your Content
- Your Ownership: You retain all rights to your prompts and generated content
- Our License: You grant us a limited license to process and display your content as necessary to provide the Service
- Deletion: You can delete your content at any time, subject to our retention policies
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Right AI Email: contact@rightai.io Website: https://rightai.io/ Address: Sichuan Province, China
For privacy-specific inquiries, please use the subject line: "Privacy Inquiry"
We will respond to your inquiry within 5 business days.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our data practices
- New features or services
- Legal or regulatory requirements
- Feedback from users
Notification of Changes:
- We will update the "Last Updated" date at the top of this policy
- For material changes, we will notify you via email or a prominent notice on our Service
- Continued use of the Service after changes constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
15. Legal Disclaimer
This Privacy Policy is provided for informational purposes and represents our current data practices. While we strive for accuracy and compliance with applicable laws, this document does not constitute legal advice.
For jurisdiction-specific legal requirements or if you have concerns about our data practices, please consult with a qualified attorney in your location.
Summary of Key Points
For your convenience, here's a quick summary of our privacy practices:
| What We Collect | Why We Collect It | How Long We Keep It |
|---|---|---|
| Email, name, password | Account management | Account duration |
| Text prompts, uploaded images | AI generation (temporary) | AI providers: not retained<br>Our servers: 7-30 days |
| Generated videos/images | Service delivery | Free: 7 days<br>Paid: 30 days |
| Payment information | Transaction processing | 7 years (via Creem) |
| Usage analytics | Service improvement | 26 months |
Your Rights: Access, correct, delete, and export your data Our Commitment: Transparency, security, and respect for your privacy No AI Training: We do not use your content to train AI models Contact: contact@rightai.io for any privacy questions
Thank you for trusting Right AI with your information. Your privacy is important to us.
RIGHTAI