Legal
Privacy Policy
Last updated July 17, 2026
You're pasting an API key tied to your own paid account into our product. We think that deserves an unusually clear explanation of what we do with your data — so here it is, without the vague language most privacy policies hide behind.
01What We Collect
- Your email address — used for sign-in (one-time codes) and account notices.
- Your provider API keys, encrypted — stored as ciphertext (AES-256-GCM) plus the last 4 characters of the key, so you can recognize which key is which in Settings.
- Your jobs — the prompts, parameters, and settings you use each time you generate something, so your history and asset library work.
- Your generated assets — the images, video, and lipsync output your jobs produce, mirrored into our storage so they don't disappear when a provider's temporary hosting expires.
- Your subscription state — plan status (trialing, active, canceled, etc.) and billing metadata from Stripe. We don't store your full card number; Stripe does.
02What We Don't Do
- We don't keep your API key in plain text. It's encrypted the moment it's saved. Our server decrypts it only in memory, only to make the specific API call your action triggered, and never logs or returns the plaintext, the ciphertext, or the encryption values used to protect it.
- We don't sell your data. Not your email, not your prompts, not your usage patterns. No exceptions, no "in aggregate" carve-out.
- We don't train models on your content. Your prompts and generated assets aren't used to train or fine-tune anything — by us or, to the best of our knowledge and per their own terms, by the providers you connect for generation itself.
03How We Use What We Collect
Strictly to run the product: authenticate you, decrypt your key just long enough to place the API call you asked for, show your job history and asset library, calculate your running spend, process your subscription, and respond if you contact support.
04Who We Share It With
We use a small number of processors to run KEYFRAME. Each one only sees the data it needs to do its job:
- Convex — our database, backend functions, and file storage. Holds your account data, encrypted keys, job records, and stored assets.
- Stripe — payment processing and subscription billing. Holds your card details and billing history; we never see or store your raw card number.
- Vercel — hosts and serves the KEYFRAME application.
- The model provider(s) you connect (for example fal.ai or Replicate) — receive the prompt, parameters, and your decrypted API key for each generation you run, because that's what actually produces your output. That provider's own privacy policy governs what they do with it on their side.
We don't share your data with anyone else, and we don't share it for advertising.
05Data Retention & Deletion
Deleting a key is immediate and permanent. When you delete a provider key from Settings, the ciphertext is hard-deleted from our database right away — not soft-deleted, not held in a backup queue for later purging. There's nothing left to restore.
You can delete individual generated assets from your library at any time; deleted assets are removed from our storage. Closing your account deletes your stored keys and stops future billing; we retain the minimum account and billing records we're legally required to keep (for example, for tax and fraud-prevention purposes).
06Your Rights & Data Export
You can request a copy of the personal data we hold about you, or ask us to delete it (subject to the legal retention exceptions above), by contacting us at the email below. We'll respond and fulfill valid requests promptly.
07Security
Provider API keys are encrypted at rest with AES-256-GCM, with a fresh encryption value generated for every key. We only ever log non-sensitive metadata about a key — its last 4 characters, validation status, and when it was last checked — never the key itself. No system is unbreakable, but a stolen database backup on its own is not enough to recover your key.
08Changes to This Policy
If we materially change what we collect or how we use it, we'll update the date at the top of this page and, where required, email you before the change takes effect.
Questions?
Email privacy@keyframe.app and a real person will answer. (Placeholder inbox — swap for the real support address before this page goes live for paying customers.)