Privacy Policy
Last updated: 2 August 2026 · Chitrio ("we", "us") · Contact: [email protected]
This policy explains what data Chitrio collects, why, and your choices. It applies to chitrio.com and the Chitrio application.
1. Data we collect
Account data: name, email, password hash, workspace/company name, plan and billing status. Content you provide: topics, scripts, uploaded footage, images, documents, brand assets, voice samples you explicitly provide for cloning, and the videos you generate. Usage data: renders, credit transactions, feature usage, device/browser type, IP address and logs (including security logs such as failed sign-in attempts). Payment data: handled by our payment providers (Razorpay/Stripe) - we never store your card number.
2. How we use it
To operate the service (generate scripts, voices, visuals and videos you request), bill you, secure the platform (fraud and abuse prevention), provide support, send transactional email (verification, render notifications), and - only with the ability to opt out - occasional product updates. We do not sell your personal data.
3. AI processing and sub-processors
Creating your videos requires sending relevant content to specialised providers under their API terms: OpenAI (script and speech generation, transcription), ElevenLabs (premium voices and voice cloning), image and video generation providers (e.g. Leonardo/Flux, fal.ai, Google), Cloudinary (temporary media hosting so generation APIs can fetch your scene assets), Pexels (stock search), Brevo (transactional email), Razorpay/Stripe (payments), Microsoft Azure (hosting and storage) and GitHub (only for platform error diagnostics - never your content). We send each provider only what the requested feature needs.
4. Google user data (YouTube connection)
If you connect a YouTube channel, we receive OAuth tokens and basic channel information, and - if you use analytics - aggregate channel statistics. We use this data only to upload the videos you ask us to upload, set their metadata/thumbnails, and show you your channel's performance. Chitrio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and no humans read it except for support (with your permission), security, or legal compliance. You can revoke access at any time at myaccount.google.com/permissions or by disconnecting the channel in Settings.
5. Meta platform data (Facebook Page and Instagram connection)
If you connect a Facebook Page or an Instagram professional account, we receive an access token, the list of Pages you chose to grant, those Pages' names and IDs, and the ID of any linked Instagram business account. We use this data for one purpose: publishing the videos you explicitly ask us to publish, and showing you which account is connected. Chitrio's use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies. We do not use it for advertising, we do not sell it, we do not read your messages or your audience's personal data, and we never post anything you did not ask us to post. Tokens are encrypted at rest. You can revoke access at any time from Facebook Settings - Business Integrations, or by disconnecting the account in Chitrio; either action stops all publishing immediately. Disconnecting, or deleting your Chitrio account, deletes the stored token and account details.
6. Cookies and local storage
We use strictly necessary storage: your sign-in token, workspace preferences (theme, active renders) and similar. The marketing site does not run third-party advertising trackers. If our marketing team adds analytics or ad pixels, this policy and a consent banner will be updated first.
7. Retention
Account data is kept while your account is active. Generated videos and uploads are kept so you can access them, and may be removed after account termination or extended inactivity following notice. Security and billing logs are kept as required for fraud prevention and legal obligations. You can request deletion (below) at any time.
8. Security
Data is encrypted in transit (HTTPS) and platform secrets are encrypted at rest. Access to production systems is restricted and logged; administrative actions are recorded in an audit trail; accounts are protected by rate limiting and automatic lockout on repeated failed sign-ins. No system is perfectly secure - if we learn of a breach affecting your data we will notify you as required by law.
9. Your rights
You may access, correct, export or delete your personal data, object to processing, or withdraw consent, subject to applicable law (including India's DPDP Act and, where applicable, the GDPR). Email [email protected] - we respond within 30 days. Deleting your account removes your workspace data except records we must keep (e.g. invoices).
10. Children
Chitrio is not directed at children under 18 and we do not knowingly collect their data.
11. Changes and contact
We will notify material changes in-app or by email. Data controller: Chitrio, contact [email protected].
Questions about this policy? Email [email protected].