Privacy Policy
Effective Date: July 13, 2026
Welcome to Vatt (the “Platform”), provided and controlled by VATTENTION PRIVATE LIMITED, a company incorporated in Singapore with its registered office at 91 Bencoolen Street #12-03 Sunshine Plaza Singapore 189652 (“we,” “us,” or “our”).
This Privacy Policy (the “Policy”) explains what personal information we collect, how we use it, and your rights in relation to it. Please read it carefully. By accessing or using the Platform and related websites, desktop applications, products, and services (collectively, the “Services”), you acknowledge the practices described in this Policy.
IF YOU DO NOT AGREE WITH ANY TERM IN THIS POLICY, PLEASE DO NOT USE OUR SERVICES.
Creator Quick Answers
- Are my original videos uploaded? Not merely because you import them. Vatt is local-first. When you deliberately use a cloud AI feature, we upload only the media or derived material needed to perform that feature.
- Do you train AI models on my content? Not for general-purpose models used by other users unless you separately opt in through a clear affirmative control. Acceptance of this Policy, ordinary use of Vatt, or failure to opt out is not consent to training.
- How long is my data kept? Local files remain on your device until you delete them. Local temporary AI workspace files are eligible for cleanup after 30 days. Cloud files, analysis results, account records, and logs follow the category-specific schedule in Section 7.2, including the biometric-data rules in Section 5.
- How do I delete it? Delete the relevant asset or analysis through available controls, close your account, or contact official@vatt.ai. Copies subject to backups, security records, legal holds, or mandatory recordkeeping may follow a different schedule.
- How are faces, voices, and emotions handled? Vatt may detect faces, face locations, voices, and emotion signals to provide editing features. These signals are not intended for identifying who a person is. Some processing is local; a cloud feature may upload audio, frames, clips, or derived results as disclosed when the feature is used. See Section 5.
This Policy is structured as follows:
- What Information We Collect
- How We Collect Your Information
- How We Use Your Personal Information
- Legal Bases for Processing (EEA and UK Users)
- Media, Face, Voice, and Emotion Processing
- Use of Cookies and Similar Technologies
- Storage and Retention of Your Information
- International Data Transfers
- How We Share Your Information
- How We Protect Your Information
- Your Rights
- Children's Privacy
- Changes to This Policy
- How to Contact Us
Supplemental Terms – Jurisdiction Specific
1. What Information We Collect
1.1 Account and Login Information
When you create an account or log in, we collect your account identifier and, where applicable, your name, email address, and profile image as provided by Google or another login method made available by us. We may also collect an invitation code and its redemption status.
1.2 Device and Technical Information
To operate the Services, maintain compatibility, and protect account security, we may collect:
- device model, operating system, version, and CPU architecture;
- application, Electron, browser, and runtime versions;
- system language and country or region setting;
- browser type and User-Agent string;
- network status, IP address, and approximate location derived from IP address; and
- device or installation identifiers used for authentication, security, and analytics.
1.3 Media and Project Content — Local and Cloud Processing
Vatt project files, source videos, audio, images, and exports are stored locally on your device by default. Importing media into a local project does not by itself upload the original media to us.
When you request a cloud AI feature, such as transcription, shot analysis, emotion analysis, semantic understanding, AI chat, or another assisted editing feature, Vatt may compress, extract, or upload media and derived files to our cloud infrastructure for processing.
We may retain the minimum data necessary to provide the requested feature, including uploaded or derived files during processing and results such as transcripts, shot boundaries, descriptions, embeddings, metadata, emotion signals, and editing suggestions. You may delete related analysis data by deleting the asset or using available cache and analysis controls.
1.4 Input and Output Content
We collect prompts, chat messages, parameters, editing instructions, and other inputs you provide, together with generated responses, suggestions, edits, and other outputs. We use them to provide, maintain, secure, support, and improve the Services you use.
We do not use your User Content to train general-purpose AI models for other users unless we first obtain your separate, express consent through a clear affirmative opt-in. Any such programme will be off by default, describe the content and purpose involved, record the consent, and provide a way to withdraw from future use. Acceptance of this Policy, ordinary use of the Services, or failure to opt out does not constitute consent to training.
1.5 Face, Voice, and Emotion Signals
Features such as face detection, face-focused framing, reaction analysis, emotion analysis, transcription, and audio analysis may process facial images, face locations or bounding boxes, voice or speech features, inferred emotion labels, timestamps, confidence scores, and related evidence. These inferences can be inaccurate and are used to assist editing, not to determine a person's identity, health, character, eligibility, or legal status.
Vatt is not designed to create or use faceprints, voiceprints, or other biometric templates to uniquely identify or authenticate a person. If a future feature would collect or use a biometric identifier or biometric information as defined by applicable law, we will provide any required separate notice, obtain any required express or written consent before collection, and apply the retention and deletion rules described in Section 5.
1.6 Payment and Subscription Data
To process transactions and manage subscriptions, Stripe and other payment providers may collect payment-card or bank-account information and transaction history on our behalf. We do not directly store full payment-card details. We may retain plan, subscription status, billing cycle, Credits history, payment-method type, card brand, last four digits, expiration date, billing country, and transaction records.
1.7 Usage and Activity Logs
We collect logs about how the Platform is used, including project creation and reopening, media imports, editing actions, AI feature usage, exports, feature adoption, task outcomes, performance timing, error categories, crashes, and security events.
We use Mixpanel and related analytics services. When you are signed in, product and performance events may be associated with your Vatt account identifier and profile information such as your email address or name. Analytics providers may also receive device, browser, referring-page, IP-address, and approximate-location information. We do not describe these account-linked events as anonymous. Our analytics instrumentation is designed not to include local file paths, media content, full prompts or messages, request bodies, or other large content objects.
1.8 Customer Support and Diagnostic Information
When you contact us for support or submit feedback, we collect your contact details and the content of your communication.
The Platform may attach a diagnostic package to feedback to help us investigate a problem. Depending on the issue, it may contain application logs, crash dumps, selected AI workspace data, the current project file, local editor-state databases, app and build information, and file metadata. Because these materials may contain project details or personal information, the feedback interface will identify the categories attached before submission.
1.9 Information from Third-Party Sources
We may receive information from login integration partners such as Google, payment providers such as Stripe, cloud and AI-processing providers, marketing or event partners, and business customers or teammates who invite you to the Services.
2. How We Collect Your Information
We collect information in three ways:
- Directly from you — when you create an account, redeem an invitation, import or upload files, submit prompts, make a purchase, or contact support.
- Passively — through cookies, local storage, application storage, event logging, crash reporting, and similar technologies as you use the Services.
- From third parties — as described in Section 1.9.
Website and Desktop Data Access
When you use our website or desktop application:
- Account login: we receive an identifier and information you choose to share from Google or another login provider.
- Session management: we use secure tokens, cookies, or local application storage to maintain your authenticated state.
- Local files: Vatt accesses files only when you select, import, create, or otherwise authorise access through the operating system or the Platform.
- Cloud processing: media is uploaded only when needed for a cloud feature you request or when you intentionally submit it.
- Local preferences: the Platform uses local storage and application databases for project state, caches, settings, and interface preferences.
- Website information: we may collect browser and User-Agent information to maintain compatibility and security.
You can manage website cookies through your browser. Disabling essential cookies or local storage may affect core functionality.
3. How We Use Your Personal Information
We use information for the following purposes:
- To provide and maintain the Services: to operate the Platform, authenticate accounts, process media, fulfil editing and AI requests, complete exports, manage subscriptions, and process transactions.
- For customer support: to respond to enquiries, investigate diagnostic packages, and maintain records of communications.
- For security and integrity: to protect the Services and users, prevent fraud, abuse, and illegal activity, and ensure platform stability.
- To improve the Services: to analyse feature adoption, performance, reliability, and aggregated or de-identified usage trends.
- For legal compliance: to comply with laws, regulations, legal processes, and enforceable government requests.
- To send important notices: such as account, transaction, security, Terms, and policy updates.
- With your consent: for another purpose clearly disclosed when consent is requested.
4. Legal Bases for Processing (EEA and UK Users)
If you are in the European Economic Area (EEA) or United Kingdom, we process personal data only where we have a valid legal basis:
- Performance of a contract: processing needed to provide requested Services, including account management, media processing, AI features, exports, subscriptions, and transactions.
- Legitimate interests: processing for security, support, service improvement, and analytics where our interests are not overridden by your rights.
- Legal obligation: processing required to comply with applicable law.
- Consent: where we rely on consent, which you may withdraw at any time without affecting prior lawful processing.
Where we rely on legitimate interests, you have the right to object. See Section 11.
Facial images, voice data, and emotion signals may be personal data when they relate to an identifiable person. Under EEA and UK law, biometric data processed for the purpose of uniquely identifying a person is special-category data. Current Vatt editing features are not intended to uniquely identify or authenticate people. If we introduce such processing, we will identify an Article 9 or equivalent condition, provide a separate notice, and obtain explicit consent where required before the feature is enabled.
5. Media, Face, Voice, and Emotion Processing
Local-First by Default
Your project files, source media, and exports are stored locally on your device by default. We do not upload or retain original media merely because you import it into a Vatt project.
Cloud Processing
When you request cloud AI features, Vatt may upload media, compressed copies, audio, frames, thumbnails, or other derived files to our cloud infrastructure. Transmission is encrypted in transit. The files are processed to perform the feature you requested.
Face, Voice, Emotion, and Biometric Data
Vatt may detect whether and where a face appears, analyse audio or visible reactions, and create editing signals such as face bounding boxes, emotion labels, timestamps, confidence scores, and suggested crop or emphasis points. Depending on the feature, face detection and related enrichment may occur locally, while audio, frames, clips, or derived results may be sent to our cloud infrastructure or processors for a requested cloud feature.
These features are intended to locate or describe moments for video editing. We do not use their results to identify a person, authenticate an account, make decisions about employment, education, credit, insurance, housing, healthcare, or another person's legal rights, or build a cross-project identity database.
We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. Where applicable law treats processing by a Vatt feature as collection of a biometric identifier or biometric information, we will, before collection, provide the legally required written notice describing the purpose and duration and obtain the legally required consent or written release. This Policy does not replace a separate feature notice or written release where one is required. We will store and transmit such information using reasonable care and protections at least as protective as those used for other confidential information.
For biometric identifiers or biometric information subject to the Illinois Biometric Information Privacy Act, our retention schedule is permanent destruction when the initial purpose for collection has been satisfied or within three years after the person's last interaction with us, whichever occurs first, unless a valid legal requirement requires otherwise. We apply any shorter destruction period required by another applicable law. A feature-specific notice may establish a shorter period.
Vatt cannot determine whether every person appearing in User Content has consented. You must have the rights and permissions required to upload and process another person's face, voice, likeness, or personal information.
Model Training Choice
Providing User Content for editing or cloud processing does not opt it into general-purpose model training. Any future training programme involving User Content will require a separate, affirmative, off-by-default choice that identifies the purpose and content involved. We will maintain a record of that choice and provide a method to withdraw from future use. Withdrawal does not require us to retrain or delete a model already lawfully trained before withdrawal where deletion is not technically feasible or legally required, and any such limitation will be disclosed when consent is requested.
What We Retain
We retain only what is reasonably necessary to provide and support the feature, which may include cloud-processing files during a requested task and analysis results such as transcripts, shot boundaries, descriptions, embeddings, metadata, emotion signals, and editing suggestions. The objective end points for each category are set out in Section 7.2; we do not keep a result merely because it might be useful in the future.
Deleting Your Data
You may delete analysis data by deleting the corresponding asset or using available analysis and cache controls. We will remove associated active records in accordance with our retention processes. Deletion is irreversible and may not immediately remove information from encrypted backups, legal holds, fraud-prevention records, or security logs.
6. Use of Cookies and Similar Technologies
6.1 Essential Cookies and Tokens
We use session cookies, authentication tokens, and similar technologies to maintain login state, protect accounts, and provide the Services. These are necessary for core functionality.
6.2 Local Storage
The website and desktop application use browser local storage, application storage, caches, and local databases to store drafts, project state, settings, and preferences on your device.
6.3 Analytics
We use Mixpanel and may use other analytics providers to understand product usage, feature adoption, performance, and reliability. Depending on your login state, analytics events may use an account or installation identifier and profile information such as email address or name. Providers may process IP address and derive approximate location. These events may therefore be personal data and are not necessarily anonymous. We configure event payloads not to include media content, full prompts, full messages, request bodies, or local file paths.
We use analytics for our legitimate interests where permitted. Where applicable law requires consent for non-essential analytics, this Policy is not consent and such analytics must not be enabled before valid consent is obtained. You may object to account-linked analytics or withdraw consent by contacting us. We contractually limit analytics providers to processing for the services they provide and use applicable transfer safeguards described in Section 8.
You can manage browser cookies through browser settings. Disabling essential cookies or local storage may prevent full use of the Services.
7. Storage and Retention of Your Information
7.1 Storage
Information may be stored on servers in Singapore, the United States, and cloud infrastructure regions used by our providers. We take reasonable technical and organisational measures to protect information wherever it is stored.
7.2 Retention Periods
We retain personal information for as long as necessary for the purposes for which it was collected or as required by law. In general:
- Local project files and source media: retained on your device until you delete them. We cannot delete copies on devices we do not control.
- Local temporary AI workspace data: periodically cleaned by the desktop application; current temporary-workspace files are eligible for cleanup after 30 days.
- Cloud-processing files: retained only for the requested task and any directly related verification, security, or support need. When those purposes end, the files are deleted or de-identified under our operational deletion cycle. A feature that needs a longer fixed period will disclose it before upload.
- AI analysis results: retained until the earliest of (a) your deletion of the related asset or analysis, (b) closure of the account to which a cloud result is linked, or (c) discontinuation of the feature where the result is no longer needed, subject to backups and legal exceptions.
- Face, voice, emotion, and regulated biometric data: follows the same task- or asset-based rule above. If information is a biometric identifier or biometric information under applicable law, the specific schedule in Section 5 and any shorter feature notice apply.
- Account information: retained while the account is open. After closure, information needed for account recovery is kept only during the disclosed recovery window, and information needed for security, disputes, billing, or law is kept only for that purpose before deletion or anonymisation.
- Transaction and Credits records: retained as required by applicable financial, tax, fraud-prevention, and accounting laws, which may require retention for up to seven years.
- Support correspondence and diagnostic packages: retained until the support matter is closed and no longer reasonably needed for follow-up, dispute, legal, or security purposes. Diagnostic attachments are not retained merely as a general product archive.
- Analytics logs: retained only while needed for the disclosed product-analysis and reliability purposes, after which they are deleted or aggregated so they no longer reasonably identify a person.
- Error and security logs: retained while needed to investigate reliability, fraud, abuse, or security incidents and to meet legal obligations, then deleted or de-identified.
We periodically review retained cloud data against these end points. When information is no longer needed, we securely delete or anonymise it. Encrypted backups are isolated from ordinary use and removed through the applicable backup-rotation cycle unless a legal hold applies.
8. International Data Transfers
As a Singapore-incorporated company using global cloud infrastructure, personal data may be transferred to and processed outside your country of residence, including outside the EEA or UK.
For transfers from the EEA or UK to countries not recognised as providing adequate protection, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or the UK International Data Transfer Agreement, as applicable. You may request details by contacting us.
9. How We Share Your Information
We do not sell personal information to third parties and do not share it for cross-context behavioural advertising.
We may share information in the following circumstances:
- Service providers: providers of cloud infrastructure, storage, media processing, AI inference, authentication, analytics, payment processing, email, customer support, and security, contractually restricted to processing for the services they provide to us.
- Google and other login providers: when you choose to authenticate or connect an account.
- Stripe and other payment providers: for purchases, subscriptions, refunds, fraud prevention, and billing support.
- Mixpanel and analytics providers: for product usage, feature adoption, performance, and reliability analysis.
- Legal requirements: where required by law, court order, or enforceable government request.
- Protection of rights: where necessary to protect the rights, property, or safety of Vatt, the Company, users, or the public.
- Business transfers: in a merger, acquisition, financing, reorganisation, bankruptcy, or asset sale, subject to equivalent protections.
- At your direction: when you export, publish, or share through a connected service or otherwise consent.
We may share aggregated or de-identified information that cannot reasonably identify you.
10. How We Protect Your Information
We implement reasonable technical and organisational safeguards, including:
- encryption of data in transit using SSL/TLS;
- access controls limiting internal and provider access;
- secure authentication and credential handling;
- monitoring and security-event logging;
- data-minimisation rules for analytics; and
- review and updating of security policies and procedures.
Where required by law, we will notify affected users and supervisory authorities of a qualifying personal-data breach within the applicable timeframe.
No internet transmission or storage system is completely secure. We cannot guarantee absolute security.
11. Your Rights
Depending on your location, you may have the following rights:
- Access: request confirmation of processing and a copy of your personal data.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion in certain circumstances.
- Restriction: request that we limit processing.
- Data portability: receive data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests or direct marketing.
- Withdrawal of consent: withdraw consent at any time where processing is based on consent.
- Appeal: appeal a decision about a privacy request where applicable law provides that right.
How to Exercise Your Rights
You can update certain information through account settings. To delete local media or project data, use your device or the Platform's controls. To delete associated cloud analysis data, delete the relevant asset or use available analysis controls.
For other requests, contact official@vatt.ai. We aim to respond to verified requests within 30 days or the period required by law. We may verify your identity before acting.
Account Closure
You may close your account through available account settings or by contacting us. We will delete or anonymise personal information under Section 7.2, except where retention is required for legal, security, billing, or dispute purposes. Account closure is irreversible and may cause loss of access to projects, Credits, subscriptions, and cloud analysis data.
12. Children's Privacy
The minimum age to use Vatt is:
- 13 years in the United States and United Kingdom;
- 16 years in the EEA, or the lower age permitted by the relevant Member State, with a minimum of 13 years; and
- 13 years elsewhere, unless local law requires a higher age.
We do not knowingly collect information from users below the applicable minimum age. If a parent or guardian believes a child has provided information without required consent, contact official@vatt.ai, and we will investigate and delete the relevant data and account where required.
13. Changes to This Policy
We may update this Policy from time to time. We will notify you of material changes through a prominent website or in-app notice at least 15 days before they take effect, unless a shorter period is needed for legal, security, or urgent operational reasons. The revised Policy will display a new Effective Date.
If you do not agree with an updated Policy, you must stop using the Services.
14. How to Contact Us
For questions, complaints, or requests about this Policy or personal information, contact our privacy contact:
VATTENTION PRIVATE LIMITED, 91 Bencoolen Street #12-03 Sunshine Plaza Singapore 189652. Email: official@vatt.ai
If you are in the EEA or UK and are not satisfied with our response, you may complain to your local data-protection supervisory authority.
Supplemental Terms – Jurisdiction Specific
If supplemental terms conflict with the rest of this Policy, the relevant supplemental terms control.
Addendum for EEA, UK and Switzerland Residents
If you use the Services from the EEA, UK, or Switzerland, the following terms apply.
Data Controller
The controller responsible for your personal data is VATTENTION PRIVATE LIMITED, 91 Bencoolen Street #12-03 Sunshine Plaza Singapore 189652.
Your Rights under GDPR / UK GDPR
In addition to Section 11, you may have:
- the right to confirmation of processing and a free copy of personal data;
- the right to data portability and, where technically feasible, direct transmission to another controller;
- the right not to be subject to solely automated decisions that produce legal or similarly significant effects, except where authorised by law;
- the right to object to processing based on legitimate interests, including profiling;
- the right to object to direct marketing at any time; and
- the right to complain to a local supervisory authority.
International Transfers (EEA / UK)
Transfers outside the EEA or UK rely on safeguards described in Section 8. You may request details by contacting official@vatt.ai.
Dispute Resolution (EEA)
If you are a consumer under applicable EU law, disputes relating to this Policy may be referred to a court in your place of residence or domicile.
Addendum for United States Residents — Biometric Information
If a Vatt feature collects a biometric identifier or biometric information as defined by applicable United States law, the notice, consent, use, disclosure, security, retention, and destruction commitments in Section 5 apply. We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. Illinois residents receive the retention schedule stated in Section 5. For biometric identifiers subject to Texas law, we destroy the identifier within a reasonable time and no later than one year after the purpose for collecting it expires, unless law permits or requires longer retention.
Addendum for California Residents
This Addendum applies to California residents under the California Consumer Privacy Act (CCPA) and other applicable California law.
Personal Information We Collect
We collect, use, retain, and share the categories described in this Policy, including identifiers; customer records; commercial information; internet or electronic activity; approximate geolocation; audio, visual, and other media; biometric information where a feature's processing falls within the statutory definition; and inferences or AI-derived information such as emotion signals. Processing biometric information to uniquely identify a consumer is sensitive personal information under California law; current Vatt editing features are not intended for that purpose.
In the past 12 months, we have not sold California residents' personal information or shared it for cross-context behavioural advertising.
Your Rights under the CCPA
Subject to applicable exceptions, California residents may request that we:
- disclose the categories and specific pieces of personal information collected, sources, purposes, and categories of recipients;
- correct inaccurate personal information;
- delete personal information collected from them; and
- provide a portable copy of covered personal information; and
- limit the use or disclosure of sensitive personal information where that right applies.
You have the right not to be unlawfully discriminated against for exercising CCPA rights.
How to Submit a CCPA Request
Submit a request to official@vatt.ai. We aim to fulfil verified requests within 45 days. If an extension is permitted and required, we will notify you of the reason and expected timing.