Skip to content

Privacy Policy

Last updated: 2026-07-27

This policy describes what data we collect, why, and your rights. We try to collect as little as possible.

1. Data we collect

Account data. When you create an account, we store your email address and a password hash. Email verification and password reset tokens are single-use and expire. We never store your raw password.

Activity data. We log request IP, timestamp, path, and HTTP status for operational debugging and abuse detection. Access logs are retained for 30 days.

Cookies. See section 4.

Face-swap inputs and outputs. When you submit a face image for the face-swap service, we store it in encrypted storage. The face image and master clip are sent to our GPU processor only to run the job you requested. Face data is private to your account. You can ask us to delete it at any time, and if you delete your account we erase uploaded faces and generated outputs from storage as part of the account-purge flow. The generated output is retained on your account until you delete it.

Payment data. USDT payments are settled on-chain. We store the sending wallet address, transaction hash, amount, and chain. We do not collect credit-card data.

Waitlist data. If you submit your email to the launch/studio waitlist, we record that email address so we can notify you when the feature you asked about becomes available. This is a deliberate opt-in lead submission you make by entering your email and pressing join.

2. Why we collect it

  • to operate the service (authentication, playback, credits)
  • to prevent and investigate abuse (CSAM, non-consensual deepfakes, payment fraud)
  • to comply with legal obligations (DMCA, lawful access requests)
  • to debug operational issues

3. Third parties

We share the minimum data necessary with the following processors:

  • Cloudflare — edge proxy, DDoS protection, CDN, encrypted object storage (R2)
  • AWS — application hosting, database (Seoul region), and transactional email (SES)
  • RunPod — GPU inference for the face-swap service (master clip + face image sent to the GPU node for the duration of the job)
  • PostHog — product analytics and browser error tracking; also receives waitlist lead submissions (the email you submit and that you joined the waitlist). Hosted by PostHog Cloud (US region for this project). Session Replay is enabled only within the anonymous signup and email-verification funnel on myav.ai; it is off everywhere else, including myav.app. All form-input values are masked. Replay does not capture console logs, network request or response headers or bodies, or URL query strings; the authenticated header's account email and credit balance are excluded. We keep PostHog's hosted Replay network-payload setting off as a mandatory release-acceptance condition, with local browser settings as additional protection.
  • TronGrid / BscScan — public-chain indexers for payment verification on the TRC20 (Tron) and BEP20 (BSC) networks (sending wallet address + transaction hash only)

We do not sell personal data.

4. Cookies

  • better-auth.session_token — your sign-in session; cleared on sign-out
  • locale — your locale preference, when set explicitly
  • ph_anon_distinct_id — a first-party anonymous analytics identity cookie. It has SameSite=Lax, lasts one year, and identifies browser analytics events sent through our first-party /ingest path. It can also be the fallback ID for server-side named analytics events, which we forward directly to PostHog.

PostHog also uses first-party browser storage on our domain — local storage and a project-keyed first-party cookie — to retain analytics identity and session/event state. We do not use third-party advertising cookies. Passive product analytics (page views and feature usage) and browser error reports are sent to PostHog through our first-party /ingest path. By visiting or using myav, you accept these cookies and this privacy policy. This does not apply to the waitlist form: submitting your email is a deliberate lead submission we process at your request.

5. Your rights

Depending on your jurisdiction (GDPR — EU/UK, CCPA — California, and similar laws elsewhere), you may have the right to:

  • request a copy of the personal data we hold about you
  • request correction or deletion
  • object to processing or withdraw consent
  • lodge a complaint with your data-protection authority

To exercise these rights, email [email protected] or use the /legal/contact form. We will respond within 30 days.

6. Children

The service is for adults only (18+). We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, please email [email protected] and we will delete it.

7. International transfers

Data is stored in the AWS Asia-Pacific (Seoul) region. If you access the service from outside that region your data is transferred to Seoul to be processed.

8. Changes

We may update this policy. Material changes will be reflected on this page before they take effect.

9. Contact

Privacy questions: [email protected] or /legal/contact.