Vigen Vigen

Privacy Policy

Updated: 2 August 2026, Subject to Indonesia's Personal Data Protection Law No. 27 of 2022

1. Data We Collect

Email & password hash (for login). Credentials (cURL / tokens) you paste to connect third-party AI provider accounts. Midtrans payment transactions (for verification). Prompts you submit and the content generated from them (image/video URLs). If you link Telegram for our community group: your Telegram user ID & username. Basic analytics & advertising signals (page events, device/browser, IP) collected via Meta Pixel & Microsoft Clarity.

Anti-fraud data. We record the IP address and a device/browser fingerprint at signup and at login, and we keep a record of which account referred which. This is used only to detect duplicate accounts and affiliate abuse: for example, a referral made from the same IP address as the referrer is automatically marked invalid and earns no commission. We do not use this data for advertising or profiling.

Temp Email. If you use the Temp Email tool, messages delivered to the disposable address are stored on our infrastructure for a short period so you can read them. Operators may access them for abuse prevention. Do not use this tool for sensitive or private correspondence.

Session. Only one device can be signed in to an account at a time, so we store a session identifier against your account and invalidate the previous one when you sign in elsewhere.

2. Storage

Passwords are hashed with bcrypt (irreversible). Connected-account credentials are encrypted with Fernet AES-128 in the database. Generated files are stored on our server (Indonesian VPS).

3. Usage

Used to run the AI generation service, process payments, provide support, and prevent fraud and abuse. We use aggregated analytics & advertising-measurement signals (Meta Pixel, Microsoft Clarity) to improve the service and measure our ads. We do not sell your personal data.

Prompts and generated media are processed by the third-party AI providers behind each mode, and are subject to that provider's own handling of the data. Where a mode runs on a credential you connected yourself, the request is made against your own provider account.

4. Your Rights

Per the PDP Law: access, correct, delete your data anytime, and withdraw consent. Contact [email protected] to request. Note that anti-fraud records may be retained after account deletion where we need them to prevent repeat abuse, and that payment records are kept as long as required by tax and accounting rules.

5. Cookies

We use a session cookie for login (Flask-Login), a first-party attribution cookie that records where you first arrived from (campaign / referral source, captured once and not overwritten), plus third-party cookies from Meta Pixel & Microsoft Clarity for analytics & advertising measurement. You can block these via your browser settings.

6. Retention

Account & history data are kept while the account is active + up to 90 days after expiry. Generated assets: up to 100 videos + 100 images per user, kept up to 30 days: older or excess assets are auto-removed for storage efficiency (see Terms & Conditions §5b).

7. Contact

Privacy questions: [email protected]

← Back