Back to HomeTIO

Version 29 September 2026

TIO — Privacy Policy


1. Who we are

VisionData Corp, LLC ("TIO," "we," "us") operates the TIO application at app.usetio.com, the usetio.com site, and the API at api.usetio.com. This policy explains what personal information we collect, why, who we share it with, how long we keep it, and what control you have. We are the controller of the information described here.

This policy sits alongside our Terms of Service.


2. Your project material

TIO is a filmmaking tool. What you bring to it — unproduced scripts, treatments, recordings, casting references — is usually the most commercially sensitive thing you own. Three commitments:

  • We do not use your project material to train AI models, ours or anyone else's.
  • We do not sell it, publish it, or show it to other users.
  • Our own people see it only in the narrow cases in Section 7, and every such access is logged.

3. What we collect

3.1 From you

CategoryDetail
AccountName, email address, and authentication credentials, handled by Clerk. If you sign in through a third-party provider, we receive the identity fields that provider shares.
Project materialAudio and video you upload; scripts and shotlists you upload or edit; reference images for style, characters, wardrobe, and sets; prompts, notes, character and set descriptions, timelines, and project settings.
Voice samplesAudio clips used to build a character voice profile, stored under your account.
Generated materialTranscripts, style analyses, shotlists, element/character/set imagery, shot images, video clips, converted dialogue, merged cuts, and export packages.
Your provider API keysIf you supply your own OpenAI, KIE, or other provider keys. Stored encrypted (AES-256-GCM); used only to run generations you request.
BillingName, billing details, and subscription and credit history. Card details go directly to Stripe — we never receive or store them.
Support and reportsBug and feature reports you file, including anything you write and any screenshots you attach; messages to the in-app assistant; direct messages to our team.
Waiting-list signupEmail address and whatever you tell us when requesting access.
PreferencesEmail preferences, dismissed tips, notification state.

3.2 Automatically

  • Usage and job records — which projects and stages you run, every generation submitted and its outcome, which model handled it, credits consumed, timings, and error detail. This is how billing, retries, and failure diagnosis work.
  • Storage accounting — how much space your files occupy.
  • Watch-link plays — when a shared cut is played, we count it. We do not identify the viewer.
  • Technical logs — request and error logs from the application and the job workers, which include IP address and standard connection metadata.

3.3 What we do not collect

TIO carries no analytics, advertising, or tracking software. There is no Google Analytics, no advertising pixel, no session-replay tool, no product-analytics SDK, and no error-reporting service that receives your data. We do not track you across other sites, and we do not build a marketing profile of you.

3.4 What we ask you not to upload

Please do not upload another person's health information, biometric data, government identifiers, or financial account numbers. TIO is not built to handle that material and our Terms prohibit it.


4. How we use information

PurposeLegal basis (EEA/UK)
Create and authenticate your accountContract
Run the pipeline you ask for, including sending the necessary material to the providers in Section 6Contract
Store your projects so you can return to themContract
Meter credits, process payments, manage subscriptions, and issue invoicesContract; legal obligation
Enforce storage allowancesContract
Answer support requests and investigate reported faultsContract; legitimate interests
Send service messages about your account, a job, or a change to these documentsContract; legal obligation
Keep the service running — monitoring, debugging, capacity, and provider failoverLegitimate interests
Detect and prevent fraud, abuse, and breaches of the TermsLegitimate interests; legal obligation
Comply with law, including sanctions screening and taxLegal obligation
Send product updates and changelog emails, where you have not opted outLegitimate interests; consent where required

On "improving the service." We use usage and job records — which stage ran, which model, how long it took, whether it failed and why — to fix faults, choose between providers, and set prices. We do not use your project material for this, and we do not use either to train models.


5. Where your data lives

ComponentProviderHolds
Application hostingVercelThe web application
API and job workersFly.ioPipeline processing; temporary scratch space during video assembly
FilesCloudflare R2All uploads and generated output, under a key prefix unique to you
DatabaseNeon (Postgres)Projects, shots, characters, sets, jobs, credits, settings
Queue and progressUpstash (Redis)Job queue and progress events
AuthenticationClerkAccount identity and credentials
PaymentsStripePayment methods, subscriptions, transactions
EmailResendTransactional and changelog email
Issue trackingGitHubBug and feature reports you file

6. AI providers

Every generation is run by a third-party provider. This is the most important disclosure here, so it is set out plainly.

What is sent: the prompt or scene text, the reference or source images the request needs, the audio or video file for transcription, and audio samples for voice work.

What is not sent: your name, email address, account identifier, billing information, or location. Requests carry a technical identifier, not your identity.

Providers:

ProviderUsed for
OpenAITranscription (Whisper); text generation
AnthropicShotlist and prompt generation; the in-app assistant
KIE.aiImage and video generation; text endpoint
— routing toGoogle, ByteDance, Kling, MiniMax, OpenAI, xAI models
PoYoImage generation (alternative route)
Pollo.aiVideo generation (alternative route)
fal.aiVideo generation (failover route)
ElevenLabsVoice profile creation and dialogue conversion

Each provider receives only the material needed for the request you made and processes it under its own privacy terms. Most process in the United States; some may process in other regions. We do not license your content to any provider for model training.

Provider completion callbacks. Some providers notify us over a signed webhook when a job finishes. Those callbacks carry job identifiers, not your project material.

Your own keys. If you supply your own provider key, generations run against your account with that provider under their privacy policy, not ours.


7. Who else sees your data

Our team, to investigate a fault you report. When you file a bug report, a member of our team may be granted read access to that project so they can reproduce the problem. Access is tied to that one report, ends when the report is closed or you revoke it, and every access is recorded: who looked, at which project, and when.

Service providers. The companies in Section 5, each under contract and only to provide their part of the service.

AI providers. As described in Section 6.

Anyone holding a watch link you created. A shared cut can be viewed by anyone with the link, without an account, until you revoke it.

Our issue tracker. Reports you file are recorded as issues, including what you wrote and any screenshots you attached.

Professional advisers, authorities, and legal process — where needed to obtain advice, where the law requires disclosure, where necessary to establish or defend legal claims, or to protect someone's safety.

A successor — in a merger, acquisition, financing, or sale of assets, with this policy continuing to apply.

Anyone you direct us to.

We do not sell your personal information and we do not share it for cross-context behavioural advertising. As set out in Section 3.3, TIO runs no advertising or analytics technology of any kind.


8. How long we keep it

DataRetention
Account recordWhile your account is open
Project material and generated outputWhile the project exists and your account is open
Deleted projectsDatabase rows removed on deletion; files removed by an automated sweep that confirms an object is unreferenced across more than one run before deleting it
Voice profiles and samplesUntil you delete the profile, which also instructs the provider to delete the cloned voice
Material sent to AI providersPer the table in Section 6
Billing and transaction recordsAs tax and accounting law requires — typically two (2) years
Job, credit, and usage recordsTwo (2) years — these underpin billing and dispute resolution
Support-access audit logAppend-only, retained indefinitely as a forensic record
In-app assistant conversations and direct messagesUp to two (2) years
Reports filed in the issue trackerFor the life of the issue tracker
Waiting-list signupsTwo (2) years
Application and platform logsTwo (2) years
After you delete your accountSee Section 9

We keep information longer where the law requires it, or to resolve a dispute or enforce our agreements.


9. Deleting your account

You can delete individual projects at any time from your dashboard.

You can delete your entire account at any time from your profile (“Delete my account”), or by emailing contact@visiondata.com from the email address on your account. When you do, we delete your account record, your projects, your files, your voice profiles (including the cloned voices held by our voice provider), your assistant conversations, and your settings within 30 days, and purge them from backups on the ordinary backup rotation, which completes within a further 30 days.

Some records survive deletion because we are required to keep them: billing and transaction records for the statutory period, your record of accepting these documents, and the support-access audit log, which records that a project was accessed and by whom but not what it contained.


10. Security

Files are stored under a key prefix unique to your account, and every request is checked against the authenticated user before it can touch a key — that check is the boundary between your material and everyone else's. Access to the application requires authentication through Clerk. Provider API keys you supply are encrypted at rest with authenticated encryption. Data is encrypted in transit. Staff access to project content is possible only through the logged, per-report grant described in Section 7.

No system is completely secure and we cannot guarantee absolute security. Keep your credentials safe. If a breach affects your personal information we will notify you and the relevant authorities where the law requires.

Report a suspected vulnerability to contact@visiondata.com.


11. International transfers

We are based in the United States. Our providers operate in the United States and, for some third-party services and cloud infrastructure, other countries or regions. Your information may be processed in countries whose data protection law differs from where you live.

Where we transfer personal data out of the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where applicable, with a transfer risk assessment. Write to contact@visiondata.com for a copy of the safeguards.


12. Cookies

TIO sets only the cookies it needs to work: authentication and session cookies set by Clerk, and security cookies that protect against cross-site request forgery. There are no analytics cookies, no advertising cookies, and no third-party trackers.

You can block cookies in your browser, but you will not be able to sign in.

Global Privacy Control. We honour it, though as we neither sell nor share personal information there is nothing for it to switch off.


13. Your rights

Everyone. Update your account details in settings, delete individual projects, revoke a watch link, revoke a support-access grant, delete a voice profile, delete your account (Section 9), and unsubscribe from product email using the link in it. Unsubscribing does not stop service messages about your account or your jobs.

EEA, UK, and Switzerland. You have the right to access your personal data and receive a portable copy, to correct it, to have it erased, to restrict or object to processing — including processing based on legitimate interests and direct marketing — and to withdraw consent where consent is the basis, without affecting what was done before.

Email contact@visiondata.com. We respond within one month, extendable by two months for complex requests, and may ask for information to verify your identity.

You may complain to your local data protection authority.

US state privacy laws. If you live in a state with a comprehensive privacy law — California, Colorado, Connecticut, Texas, Virginia and others — you have the right to know what we hold and how we use it, to obtain a copy, to correct it, to delete it, and to opt out of any sale, sharing, targeted advertising, or profiling with legal or similarly significant effects. We do none of the latter. We will not discriminate against you for exercising these rights.

Email contact@visiondata.com. If we deny a request you may appeal by replying to our decision; if the appeal outcome does not satisfy you, you may contact your state attorney general.

Biometric information. Where a voice profile you create is treated as biometric information under the law of your state, you have the rights that law gives you, including deletion.

Authorized agents. An agent may act for you with proof of authority. We may contact you to confirm.


14. Children

TIO is for adults. It is not directed to anyone under 18 and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to contact@visiondata.com and we will delete it.

If your project material includes images or recordings of a child — a child actor, for instance — you must have parental or guardian consent and must comply with the child-performer rules governing your production.


15. Changes

We may update this policy. When we do we bump its version, and because acceptance is recorded against a specific version, a material change will ask you to accept the new one before you continue. Earlier versions of what you accepted are preserved.


16. Contact

VisionData Corp, LLC · 5700 Wilshire Blvd., Suite 650, Los Angeles, CA 90036

  • Privacy and rights requests: contact@visiondata.com
  • Security: contact@visiondata.com
  • Support: contact@visiondata.com