1. Controller and scope
The controller for Visutta account, website, billing, security, and product-operation data is Niklas Koeder, operating Visutta in Germany. Privacy requests can be sent to support@visutta.com.
The complete service address and the competent German supervisory authority will be added before public launch after the operator's legal form and registered or business address are confirmed.
This Policy covers the Visutta website, Studio and Pro interfaces, desktop application, accounts, billing, collaboration, generation, support, and related services. A business customer may be a separate controller for personal data it uploads to a workspace. In that case, Visutta processes that data on the customer's instructions where a processor relationship applies.
2. Personal data we process
Account and authentication data
Name or display name, email address, password hash, account identifier, Google sign-in identifier if used, authentication method, session token, session timestamps, IP address, user agent, and security events.
Project and Customer Content
Scripts, prompts, production notes, project memory, reference images, video and audio, generated output, edits, timelines, comments, model settings, file metadata, workspace membership, and collaboration history. This material can contain personal data about you or other people.
AI job and usage data
Selected models and providers, request settings, references, job and prediction identifiers, queue state, timestamps, status and error events, output metadata, credit estimates, reservations, settlements, refunds, provider cost, and technical traces needed to operate and debug a job.
Billing and plan data
Plan, billing interval, credit balance and events, team pool and limits, Stripe customer, checkout, subscription, and transaction identifiers, invoice status and PDF links, invoice-email delivery records, tax and billing information returned by the payment provider, and fraud or chargeback information. Visutta does not normally receive full card numbers or card security codes.
Communications and support
Emails, support requests, feedback, legal or rights requests, attached material, and the records needed to investigate and respond.
Website and device data
Requested path, request ID, IP address, user agent, response status and timing, rate-limit events, site-gate status, interface preferences, locally cached drafts, and other data stored on your device as described below.
3. Sources of data
- directly from you when you register, upload, prompt, edit, pay, or contact us;
- from team owners, administrators, and collaborators who invite or mention you;
- from Google when you choose Google sign-in;
- from Stripe when you start, change, or cancel a paid plan or purchase credits;
- from AI providers when they return job status, output, moderation, or error data;
- automatically from browsers, applications, servers, security controls, and infrastructure.
4. Purposes and legal bases
| Purpose | Typical data | Legal basis under GDPR |
|---|---|---|
| Provide accounts, workspaces, generation, storage, collaboration, export, and support | Account, Customer Content, project, job, and communication data | Contract performance and steps requested before contract, Art. 6(1)(b) |
| Process plans, credits, invoices, refunds, and accounting | Billing, plan, wallet, and transaction data | Contract, Art. 6(1)(b), and legal obligations, Art. 6(1)(c) |
| Protect users, tenants, media, providers, and infrastructure | Sessions, IP, device, logs, abuse and security events | Legitimate interests in secure and reliable operation, Art. 6(1)(f), and legal obligations where applicable |
| Debug failures, improve reliability, measure usage and unit economics | Job status, errors, model settings, cost and performance metrics | Contract and legitimate interests in operating and improving the Service, Art. 6(1)(b) and (f) |
| Handle legal claims, rights requests, takedowns, and compliance | Account, content, communications, logs, and claim records | Legal obligations and legitimate interests, Art. 6(1)(c) and (f) |
| Optional marketing or non-essential device access, if introduced | Only the data described at the point of choice | Consent, Art. 6(1)(a), which can be withdrawn prospectively |
Where we rely on legitimate interests, we consider necessity, your reasonable expectations, impact, and available safeguards. You may object as described in the rights section.
5. AI and provider processing
To perform a requested generation or director task, Visutta sends the prompt, selected references, requested settings, and necessary technical metadata to the provider used by that model. A linear or director pipeline may send different stages to different providers. The selected model and used references are recorded with the job so you can inspect what was sent.
Visutta does not use Customer Content to train a Visutta-owned general-purpose model. External providers process submitted material under their API or business terms and configured data controls. Their retention and use can differ, so do not submit secrets or personal data that are not necessary for the requested output.
| Provider or category | Use in Visutta | Data typically sent |
|---|---|---|
| OpenAI | Director language processing and image generation | Prompts, scripts, references, settings, and request metadata |
| Optional sign-in and selected image models | Sign-in credential, or prompts, references, and model settings | |
| ByteDance / BytePlus ARK | Seedream image and Seedance video generation | Prompts, image or video references, media settings, and task metadata |
| Kling AI | Selected video generation models | Prompts, frames, settings, and task metadata |
| ElevenLabs | Speech, voice design, and consented voice cloning | Text, voice settings, language, and voice samples where requested |
| Configured music provider | Music generation | Lyrics or prompt, style, title, settings, and task metadata |
6. Recipients and disclosure
We disclose personal data only where needed to:
- use the AI and authentication providers described above;
- process payment through Stripe;
- host compute, databases, backups, email, and object storage;
- deliver protected media through Cloudflare;
- make team or collaboration content visible to authorized workspace members;
- obtain professional legal, accounting, security, or technical support under confidentiality;
- comply with law, protect rights and safety, or establish and defend legal claims;
- complete a corporate transaction subject to appropriate safeguards.
We do not sell personal data and do not use third-party behavioral advertising analytics in the current pre-release website.
7. International transfers
Some providers may process data outside Germany or the European Economic Area. Depending on the provider and destination, transfers may rely on an adequacy decision, the European Commission's Standard Contractual Clauses, and supplementary contractual, organizational, or technical measures. Provider location can also depend on the selected model or API region.
The final production subprocessor register must identify the contracted entity, processing country, and transfer mechanism for each enabled provider before public launch. You can request the current register and available safeguards through support.
8. Retention
We retain personal data only for as long as needed for the purpose, contract, security, legal obligation, or claim. We use the following criteria and current operational defaults:
- Account and workspace data: while the account or workspace is active and afterward only as needed to complete deletion, resolve disputes, prevent fraud, or meet legal obligations.
- Projects and media: until deleted through available controls or an account-deletion request is completed, subject to shared workspace rights, legal holds, and rolling backups.
- Sessions: the account session cookie currently has a maximum age of 30 days and may be revoked earlier. Server-side security records can remain longer where needed to investigate abuse.
- Generation and pipeline records: retained to show job state, references, output, billing, and trace history. Terminal pipeline rows may be pruned after 90 days; related accounting or dispute records can remain longer.
- Temporary voice-clone uploads: removed from the private temporary job directory after the job succeeds or fails. A saved voice identity or output remains until deleted or otherwise no longer needed.
- Billing and tax records: retained for the periods required by applicable commercial and tax law.
- Backups: overwritten on a rolling operational schedule. Deletion from backups can therefore occur later than deletion from active systems.
10. Security
Visutta uses layered controls including TLS at the edge, protected origin services, account and tenant authorization, rate limits, durable job state, server-side provider credentials, signed media URLs, private object storage, database transaction controls, backups, and operational monitoring.
No system is completely secure. Protect your credentials, use only trusted devices, remove former collaborators promptly, and report suspected account compromise or a vulnerability to support. Do not send provider keys or passwords in prompts or support screenshots.
11. Your data-protection rights
Subject to the legal requirements and exceptions, you may have the right to:
- access personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- receive certain data in a portable format;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent prospectively where processing relies on consent;
- complain to a competent data-protection supervisory authority.
Send a request to support@visutta.com. We may ask for information needed to verify identity, protect other users, and locate the relevant account or workspace. A team member may also need to contact the team or business controller for data that organization controls.
12. Automated decisions and moderation
AI generation and creative recommendations do not make decisions that produce legal or similarly significant effects about you. Automated abuse, rate-limit, billing-reservation, and security controls may reject or pause a request or account to protect the Service. You can ask support for human review of a material account or content decision.
13. Children and sensitive data
The Service is not intended for people under 18. If you believe a minor created an account or submitted personal data, contact support.
Prompts, reference media, or voice samples may reveal sensitive or special category data. Submit such data only where necessary, lawful, and supported by an appropriate legal basis. Visutta does not use voice samples for biometric authentication; a voice-cloning feature still requires authority and consent for the voice being cloned.
14. Personal data about other people
If you upload or generate material about another person, you are responsible for having a lawful basis and providing any required notice. This includes actors, employees, customers, collaborators, voice talent, depicted persons, and people appearing incidentally in source footage.
Do not use Visutta to clone a voice, imitate a likeness, create intimate content, or make a consequential decision about a person without the rights, consent, and legal authority required for that use.
15. Changes and contact
We may update this Policy when the Service, providers, laws, or processing practices change. We will post the updated date and provide additional notice for material changes where required. A privacy notice describes processing; continued use is not treated as consent where the law requires a separate affirmative choice.
Privacy and data-protection requests: support@visutta.com.