Privacy Policy

Last updated: July 29, 2026

Application and Developer Information

This document outlines the privacy practices for VeilVid, a mobile application available through Google Play. The app is managed solely by Mr TPM, who acts as the data controller for all user-related information. Any mention of "we" within this policy refers to this developer entity. For users who obtain VeilVid via Google Play, this policy describes how personal data is handled during app usage, including collection, retention, and sharing procedures.

Workflow Overview

  1. Users submit images and select a preferred style option.
  2. A dedicated instance of the stable diffusion framework is fine-tuned with the submitted data to deliver customized results.
  3. Following fine-tuning, the system produces a personalized avatar based on the adjusted model.
  4. Upon avatar generation, both the original images and the fine-tuned model instance are permanently deleted from our infrastructure. Please be aware that avatar outputs must comply with content policies—for instance, generating explicit material or using third-party imagery without authorization is strictly forbidden.
  5. Your submitted information will not be incorporated into any general-purpose training datasets or leveraged for building additional independent AI services.

Cloud-Based Processing Triggered by Users

VeilVid offers a range of AI-driven capabilities—including editing, enhancement, and rendering—via protected cloud infrastructure. These operations are carried out remotely only when you actively engage a function that depends on server-side resources. Processing does not occur automatically or in the background; it is initiated solely by your direct actions.

Upload Conditions

Media files—such as images, video clips, or other formats—are transmitted to our protected servers solely when you manually choose a cloud-dependent tool and deliberately start the operation. The application does not transmit your content passively, while running in the background, or in the absence of your explicit action. Prior to transmission, the interface provides a visible notice that remote processing will be engaged.

Storage Duration and Removal

Any media you submit is kept solely for the duration required to fulfill your requested operation. Once processing finishes, both the source files and the output content are permanently purged from our systems within 72 hours. The developer does not maintain any copies or backups of your materials, nor does it employ your data for promotional activities, algorithm refinement, user analytics, or any other extraneous objectives.

Protection Measures

All incoming and outgoing file transfers are secured with TLS encryption, which is the prevailing industry practice. Only the automated operational systems and essential backend components needed to fulfill your request are permitted to access submitted materials. No other parties or systems have visibility into your content during or after processing.

Content Advisory

We make every reasonable effort to ensure the AI model operates within suitable parameters. Nevertheless, you might come across material that does not align with your personal preferences. Should you encounter anything that seems objectionable or out of place, kindly reach out to us via tarineeprasadmallick@gmail.com. We will address your concern without delay, and your input also contributes to refining our system's performance over the long term.

Categories of Collected Information

1. Interaction Records

We track your activity across the service—including navigation choices, download events, content forwarding, modification actions, and any other material you enter. This enables us to operate the functions you access.

2. Terminal and Session Metadata

For operational stability, risk prevention, interface optimization, promotional delivery, and account protection, we record device-level and session-level details whenever you connect through our platforms. Examples are hardware fingerprints, GAID, handset type, locale and country settings, ad ID, operating environment, numeric address, release iteration, access medium and signal strength, along with usage timelines.

3. User-Submitted Inquiries

Whenever you approach us with questions or suggestions, we archive your message content, attached items, and reachable addresses (such as telephone or email) to facilitate our responses and ongoing assistance.

4. Facial Landmark Analysis

Where you activate editing or merging tools that involve faces, we extract positional and contour data from facial features to drive the processing logic. The resulting visual outputs are then served to you. No original imagery, footage, landmark sets, or final compositions are stored by us or passed to any recipient. This procedure is limited to enabling the capability and elevating final quality. Should your work include someone else's appearance, it is your duty to advise them and obtain prior clearance.

5. Temporary Off-Device Execution

To achieve rapid and precise transformations, we may forward your media or associated descriptors to a remote computing resource exclusively for that job. These transfers are confined to the instant operation you order. We neither hold onto the forwarded items, descriptors, or ancillary records beyond the necessary interval, nor apply them in any other context or distribute them to third entities.

Device Access Rights

To deliver enhanced functionality, efficient operations, and a smoother experience, we may request specific system permissions on your device when offering supplementary services. With your explicit agreement and adhering to a minimal-data principle, we may utilize the following access rights and their associated information:

  1. External Storage Access -- Enables reading from and writing to your device's memory card to support video editing tasks.
  2. Camera Access -- Permits capturing photos and recording video directly within the application.
  3. Network Access -- Facilitates online capabilities, including retrieving and downloading available materials.

Information linked to these permissions is treated as sensitive. Refusing any permission simply limits your use of the particular feature that depends on it—other app functions remain fully accessible. You may review your permission status at any moment via your device's system configuration panel and are free to grant or withdraw any of these rights as you see fit.

Please note that granting a permission constitutes your authorization for us to collect and process the relevant personal data solely for delivering the associated service. Should you later revoke a permission, this terminates your prior consent, and we will cease all collection and processing activities tied to that permission going forward. However, such revocation does not affect any data handling that took place while the permission was active.

External SDKs and Service Partners

To enable essential functionality, perform usage analysis, and handle in-app transactions, VeilVid incorporates several third-party software development kits (SDKs). Each SDK may access certain device-level and behavioral information as outlined below. All such data handling occurs only after you have accepted this Privacy Policy.

1. AppsFlyer (provided by AppsFlyer Ltd.)

Role: Attribution tracking, marketing insight, and campaign evaluation.
Data accessed: Hardware IDs (Android ID, Google Advertising ID), IP address, installation source, conversion milestones, and in-app activity. This supports our understanding of acquisition channels and promotional effectiveness.

2. Google Play Billing (provided by Google LLC)

Role: Facilitating purchases and subscription management.
Data accessed: Order specifics, transaction records, and purchase references. Full payment credentials are never stored or visible to us; all financial handling occurs through Google Play's infrastructure.

3. Google Install Referrer (provided by Google LLC)

Role: Pinpointing the origin that brought you to install the app.
Data accessed: Referral source (e.g., campaign or ad identifier) and installation time. This is applied exclusively for attribution purposes.

4. Google Ads Identifier & AppSet ID (provided by Google LLC)

Role: Supplying de-identified markers for analytical and advertising performance purposes.
Data accessed: Google Advertising ID (AAID) and AppSet ID. You have the ability to reset or restrict these markers through your device's settings at any time.

5. Google Sign-In (provided by Google LLC)

Role: Allowing authentication via Google account credentials.
Data accessed: Only when you voluntarily opt to log in, we obtain basic profile fields (display name and email address) from your Google account. No passive collection occurs.

6. Functional Libraries (No Data Collection)

The following components are employed purely for technical execution—including networking, graphic rendering, media handling, local preference storage, and job scheduling. They do not gather, forward, or process any personally identifiable information: Retrofit & OkHttp (HTTP communication), Glide (image display), ExoPlayer (audio/video playback), DataStore (settings persistence), WorkManager (background orchestration), and Hilt (dependency management).

Usage Analytics

We gather and analyze information to persistently enhance our service and overall user satisfaction. This data is handled in a consolidated, non-individualized format, enabling us to identify trends in usage and guide product refinement. These compiled observations may be disclosed to our affiliated entities, representatives, and commercial collaborators for purposes such as research, ongoing development, and strategic planning. Rest assured, all such information is stripped of personal identifiers and does not reveal your identity or that of any individual user.

How We Use Your Personal Information

We may use the information you provide, consistent with this policy, to deliver our services or to communicate with you. Specific use cases include the following:

1. Product Improvement

Your data supports the creation, evolution, operation, and delivery of our services, as well as ongoing refinement. By examining user engagement patterns, we can keep the platform straightforward and user-friendly.

2. Safety Measures

We leverage your information to uphold account integrity and network protection, safeguarding the service for everyone. This may involve automated review of submitted content to detect potentially prohibited material. Your data also contributes to fraud prevention, user support, and related protective actions.

3. Essential Notifications

We rely on your information to send you important updates—for instance, account status alerts or modifications to our terms, policies, or other governing documents.

4. Legal Adherence

We hold and handle your information as needed to fulfill our statutory duties. This can include recording, reviewing, analyzing, or otherwise processing your data in accordance with relevant regulations, including urgent circumstances.

Your Control Options

You can reduce data collection through the following measures:

Data Deletion Rights

When using our application, you maintain full authority over your personal information and may remove stored records whenever you wish. We are dedicated to safeguarding your privacy and facilitating straightforward data removal. You can clear your activity history and other saved content via the settings section within the app. Furthermore, removing the application from your device will automatically wipe any locally persisted data. Please note that once information is erased, it cannot be retrieved. Should you have any inquiries about your deletion entitlements, do not hesitate to contact our support team for assistance.

Cookies and Comparable Technologies

As is customary for most online platforms, we utilize cookies, web beacons, and related mechanisms. Cookies are compact data files placed on your storage drive or device memory. They hold details about your usage behavior—enabling functions like identity verification, preference retention, activity pattern analysis, campaign outcome measurement, and social feature support. Web beacons are small embedded scripts on webpages or within emails that allow us to observe your interactions with that content.

By default, most browsers are configured to accept cookies. You have the option to adjust your browser settings to reject or remove them if desired. However, this may impact the availability and performance of certain features.

We rely on third-party analytics solutions to monitor traffic and usage trends across our services. These tools receive information from your device or our systems—including pages visited, features accessed, and other behavioral signals—to help us refine our offerings. Such data is combined with similar information from other users in an aggregated form that does not reasonably identify any specific individual.

We collaborate with external advertising partners to display ads across the internet and other media. To evaluate campaign effectiveness and determine compensation to these partners, we embed third-party components within our applications. These modules may also be included to gain insights into how users engage with our services.

Data Retention Period

We hold onto your personal information for a term of 48 months. We may continue to store and utilize your data as required to satisfy legal duties (such as adhering to relevant regulations), settle disagreements, and uphold our contractual terms and operational guidelines.

Additionally, we maintain Usage Data for internal analytical purposes. This category of information is typically kept for a briefer interval, unless it is required to maintain system security, boost service performance, or we are obligated by law to preserve it for an extended duration.

Data Sharing

We do not sell or rent your personal data to third parties. The SDKs listed above share data only with their respective providers for the purposes stated, and we contractually require them to process data in accordance with applicable privacy laws.

Information Disclosure Practices

Mr TPM does not engage in the sale, lease, or exchange of your personal data with any external parties. We disclose personal information solely under circumstances where it is required to deliver your requested services, manage and sustain VeilVid, complete financial transactions, adhere to relevant legal requirements, or safeguard our legitimate interests and the overall security of our platform.

External Service Partners

To enable the essential operations of VeilVid, we collaborate with carefully vetted external service providers. These partners assist with functions including identity verification, payment settlement, usage measurement, install source tracking, backend hosting, abuse prevention, and system oversight.

Depending on which features you access, these partners may process certain limited data categories, such as:

Each external partner handles personal information exclusively for the purpose of fulfilling the services they perform on our behalf, in line with their respective privacy policies and relevant legal frameworks. We do not permit our service providers to repurpose your personal information for their own promotional or marketing initiatives.

AI Content Processing

When you voluntarily upload photos, videos, or other media for AI-powered processing, your content is used solely to generate the results you request.

Your uploaded content is never sold, licensed, or shared with third parties for advertising, profiling, or training general artificial intelligence models. Media files are processed only for the requested service and are automatically deleted according to the retention period described in this Privacy Policy.

Mandatory Information Release

We may share your personal data only when we determine that doing so is required for the following purposes:

Corporate Changes and Data Transfer

Should VeilVid or Mr TPM become party to a merger, acquisition, structural reorganization, investment round, asset divestiture, or analogous business event, your personal information may be included among the assets transferred.

Under such circumstances, the acquiring organization will be obligated to safeguard your data under privacy standards that are materially comparable to those outlined in this Privacy Policy, and in compliance with relevant data protection regulations.

Security Safeguards

We take the protection of your personal information very seriously. To prevent unauthorized access, exposure, or other threats, we have deployed sensible physical, technical, and administrative controls over data collected through your use of our Platform. We are committed to making every reasonable effort to secure your information.

Our security protocols are periodically examined and updated in response to operational changes, emerging technologies, and regulatory developments. These safeguards encompass technical and policy-based controls, access restrictions, and employee awareness initiatives.

While we are deeply dedicated to data protection, please recognize that no transmission method over the internet or electronic storage system is completely immune to risk. Although we apply industry-standard measures to safeguard your personal information, absolute security cannot be assured.

Should we become aware of a security incident affecting your personal data, we will provide notice to you as mandated by applicable regulations. By continuing to use the Platform, you consent to receive such notifications via electronic means.

Your Privacy Rights

If you would like to understand more about your legal entitlements under applicable regulations or wish to exercise any of them, please do not hesitate to contact us through the details provided in the "How to Contact Us" section below. Depending on your jurisdiction, you may have the right to request that we:

  1. Grant you access to or provide a copy of certain personal data we hold about you.
  2. Cease using your information for direct promotional purposes, including any marketing efforts based on behavioral profiling.
  3. Update any outdated or inaccurate information we maintain on you.
  4. Delete specific data we hold about you.
  5. Restrict how we process or disclose certain information relating to you.
  6. Transfer your data to another external service provider.
  7. Revoke any consent you previously provided regarding the handling of your information.

We will assess all requests and respond within the timeframe stipulated by relevant law. Please note that in certain cases, some information may not be subject to these requests—for example, if we are obligated to continue processing your data to protect our legitimate interests or to meet legal requirements. Prior to acting on your request, we may ask you to provide reasonable identification details to verify your identity.

Privacy Protections for Minors

Our services are not designed for users under 18 years of age (referred to as "minors"). We do not knowingly collect personally identifiable information from anyone below this age. If you are a parent or legal guardian and become aware that your child has provided us with Personal Data, please get in touch with us. Upon discovering that such information has been collected without verified parental consent, we will take appropriate steps to delete it from our records.

Rights Under CCPA, VCDPA, GDPR, and LGPD

We comply with the data protection standards established by California (CCPA), Virginia (VCDPA), the European Union (GDPR), and Brazil (LGPD). If you are a resident of any of these regions, the relevant privacy laws grant you entitlements including the ability to access, amend, remove, or challenge the handling of your personal information. To exercise any such entitlements, please contact our support team for assistance.

Bases for Processing Your Data

We handle your personal information in accordance with relevant privacy regulations, including the General Data Protection Regulation (GDPR). Depending on the context of processing, we rely on one or more of the following justifications:

1. Legitimate Interests

We may process certain non-sensitive information to advance our legitimate purposes, which include:

2. Legal Requirements

In some cases, we must process your data to satisfy statutory duties—such as meeting financial, taxation, or regulatory reporting standards.

3. Critical Circumstances

Under rare conditions, we may process your data to safeguard your own or another individual's essential welfare—for instance, when addressing a safety incident linked to one of our applications.

Right to Submit a Complaint

If you believe that our handling of your personal data contravenes applicable privacy legislation or infringes upon your entitlements under such laws, you are entitled to lodge a grievance with the relevant oversight body. This right is available, for instance, to residents of the EU under the General Data Protection Regulation (GDPR), as well as under other local data protection frameworks that may be applicable in your jurisdiction.

How to File a Complaint

If you decide to lodge a formal complaint, you may do so with the appropriate data protection authority in your jurisdiction. Their contact details are generally accessible through their official websites. You may also contact us directly for additional assistance or direction.

Prior Internal Review

Before proceeding with a formal complaint, we kindly ask that you first reach out to us so we can make every reasonable attempt to resolve your issue. You may contact our Data Protection Officer (DPO) or email us at tarineeprasadmallick@gmail.com.

Data Controller Details

Under relevant data protection regulations, the data controller accountable for handling personal information gathered via VeilVid is Mr TPM. This entity establishes the objectives and methods of data processing and bears responsibility for upholding compliance with all applicable privacy laws. For any inquiries concerning privacy matters, please reach out to us at tarineeprasadmallick@gmail.com.

Privacy Officer Appointment

We have designated a Data Protection Officer to supervise our privacy operations. You may reach the DPO through the following channels:

Policy Revisions

We may update this Privacy Policy as needed from time to time. We recommend that you check this page regularly to stay informed of any changes. Whenever modifications are made, we will publish the updated version on this page. All revisions become effective immediately upon publication.

Contact Us

Should you have any inquiries, issues, or feedback concerning our Privacy Policy, please feel free to reach out to us at tarineeprasadmallick@gmail.com.