Privacy Policy
How Kavello collects, uses, shares, and protects personal information
Last updated: 2026-09-15
Last updated: September 15, 2026
This Privacy Policy explains how Kavello collects, uses, discloses, and protects personal information when you use kavello.app, our AI image generation and editing, video generation, prompt templates, and image showcases, accounts, support, and related services (the “Service”).
Kavello is operated by Hong Li, an individual operator based in China (“Kavello,” “we,” “us,” or “our”). Questions and privacy requests may be sent to support@kavello.app.
1. Scope and age requirement
This Policy applies to the Service and communications with us. It does not govern third-party sites or services that have their own privacy notices.
The Service is intended only for people aged 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us so we can investigate and delete it where required.
2. Information we collect
Depending on how you use Kavello, we may collect:
- Account and authentication information: name, email address, profile image, language, authentication provider identifiers, session information, and account status. When you use Google sign-in or Google One Tap, Google provides information according to your Google settings and consent.
- User content and generation history: prompts, images, videos, audio or other files you submit; model and generation parameters; task status; output URLs; generated files; and related timestamps.
- Transaction information: order and subscription identifiers, plan or credit-pack details, price, currency, tax, payment status, renewal and cancellation status, and limited processor-provided billing details. We do not receive or store complete payment-card numbers.
- Usage and device information: pages and features used, approximate location derived from IP address, browser and device type, operating system, referring source, timestamps, diagnostic events, and standardized error information.
- Security and anti-abuse information: IP address, a keyed one-way representation of a normalized IP address, session and authentication data, rate-limit signals, and records needed to detect fraud, abuse, unauthorized access, or policy violations.
- Support information: your messages, attachments, contact details, and records of how we handled a request.
- Cookie and analytics information: information described in our Cookie Policy, including browser preferences and data collected by enabled analytics services.
Please do not submit sensitive personal information unless it is necessary for the generation you expressly request. If you submit face or voice material, we process it to provide the requested AI function, not to identify you biometrically or build an advertising profile.
3. How and why we use information
We use information to:
- create and secure accounts, authenticate users, and provide requested features;
- process prompts and files, generate outputs, and show account generation history;
- process purchases, subscriptions, renewals, cancellations, refunds, invoices, credits, and payment disputes;
- provide support and respond to privacy, copyright, safety, and other requests;
- operate, troubleshoot, measure, and improve the Service;
- prevent fraud, repeated promotional-credit abuse, security incidents, unlawful activity, and violations of our Terms;
- comply with accounting, tax, consumer-protection, sanctions, court-order, and other legal obligations; and
- send transactional notices about accounts, generations, payments, renewals, security, and material policy changes.
Where applicable law requires a legal basis, we rely on:
- performance of a contract for accounts, generation, payments, subscriptions, and support;
- consent for Google Analytics, Microsoft Clarity, and optional first-party event analytics where consent is required;
- legitimate interests in security, fraud and abuse prevention, troubleshooting, service improvement, and cookie-free aggregate Plausible analytics, balanced against your rights; and
- legal obligations for tax, accounting, lawful requests, and dispute records.
We do not use AI safety filtering to make decisions that produce legal or similarly significant effects about you. Safety systems may block or restrict content or accounts under our Terms.
4. AI processing
To perform a generation request, we may send the content and parameters necessary for that request to Kie.ai or Replicate, depending on the model selected, technical availability, and production configuration. These providers may use underlying infrastructure or model providers and may process data in other countries.
When content safety screening is enabled, we also send the text of your prompt to Creem to check for content that may violate our Terms before generation. This is separate from payment processing and does not require a Creem payment. Screening may prevent a request from proceeding. This prompt-screening integration sends prompt text, not your uploaded image or video files.
We require providers to be used only for legitimate Service purposes, but their independent retention and security practices are governed by their own terms and privacy notices. We cannot guarantee that a third-party AI provider will follow Kavello's own file-retention periods.
Do not upload content you lack the right or authority to process. For more information about content rights and restrictions, see our Terms and Conditions.
For GPT Image 2.5, requests are routed through the configured AI service (currently Kie.ai), which may use OpenAI models and other infrastructure. Reference photos and prompts are processed to perform the requested task. Private visibility does not mean local-only processing or a provider zero-retention or no-training commitment. Applicable API provider retention and use terms may differ from this policy.
Image visibility and withdrawal
Image generation defaults to Private. If you select Public, the output image, prompt, derived title, tags, and publication information may be made accessible in Image Showcases. Reference uploads are not included in the public showcase merely because an output is public. Do not put personal or confidential information in a prompt you choose to publish. Private results are not publicly listed; necessary provider processing still occurs.
Deleting an image-history record removes it from your history and withdraws its associated public showcase from our listing and access routes. This is a visibility change, not immediate erasure of retained files or backups. Previously downloaded or cached copies cannot be recalled, and already issued short-lived links may remain usable until they expire. Contact support to request deletion of retained inputs, outputs and showcase copies; eligible requests are normally processed within 30 days, subject to the exceptions below.
5. Service providers and disclosures
We disclose information only as reasonably necessary for the purposes described above, including to:
- Cloudflare for content delivery, network security, Workers hosting, D1 database services, and R2 file storage;
- Google for OAuth, One Tap, and, when enabled under the Cookie Policy, Google Analytics 4;
- Microsoft for Clarity analytics when enabled under the Cookie Policy;
- Plausible Analytics Cloud for cookie-free aggregate site analytics;
- Kie.ai and Replicate for AI generation;
- Creem for prompt-based content safety screening when enabled, separately from its payment-processing role;
- Feishu (Lark) for internal payment notifications when enabled. These messages may include an internal order reference, product or plan, payment type, amount and currency, payment processor, payer or account email, acquisition source, approximate country derived from IP, and payment time. They are used for payment reconciliation, support, and transaction troubleshooting, not advertising;
- Resend for transactional email;
- Stripe, PayPal, Waffo, or Creem for payments, depending on the method actually offered at checkout; and
- professional advisers, authorities, counterparties, or other recipients when reasonably necessary to comply with law, protect rights and safety, investigate fraud or disputes, or complete a business reorganization subject to appropriate safeguards.
Providers may change as the Service evolves. We will update this Policy and, where required, request new consent before materially changing an optional analytics purpose or provider.
6. Cookies, analytics, and privacy signals
Our Cookie Policy explains the cookies and similar technologies used by Kavello and how regional choices work.
Plausible is used in a cookie-free, aggregate configuration. Google Analytics 4 and Microsoft Clarity are optional analytics: in regions requiring prior consent, they should load only after consent; they remain disabled after rejection and when a supported Global Privacy Control (GPC) signal is active. Clarity is intended only for public pages, with inputs masked and authenticated generation, dashboard, history, settings, and checkout pages excluded.
Kavello first-party event analytics also follows the optional Analytics choice above. It links a random browser visitor identifier to the internal account ID after sign-in, within the local database, to measure step-by-step click, signup, generation and payment conversion. These identifiers are not sent to Plausible or used for cross-site tracking or advertising. Cookie and pending-queue duration and withdrawal controls are described in our Cookie Policy.
We keep account, order, subscription, credit and generation records to deliver and support the Service, independently of optional Analytics. Internal operational summaries are derived from these business records and kept separate from optional journey analysis. Rejecting Analytics does not stop purchases, credit processing or generation history. Optional server-side copies of signup, generation and payment outcomes require a valid browser permission context, checked again when an asynchronous operation finishes. When we receive a withdrawal or GPC signal, we revoke that context and stop subsequent optional recording and pending delivery; previously collected details follow the retention and rights-request rules below.
For registration anti-abuse deduplication, we normalize the network IP and store a keyed HMAC representation rather than a raw registration IP. This representation is restricted to anti-abuse purposes and is not an analytics identifier. It is pseudonymized, not anonymous; separate authentication, network-security or dispute records may still process IP addresses as described in this Policy.
We do not sell personal information for money and do not currently operate behavioural advertising. If an applicable law treats optional analytics as a “sale,” “sharing,” or targeted advertising, you may opt out using Cookie Preferences or GPC.
7. Retention
We retain information only for as long as reasonably necessary for the purposes described here:
- temporary uploads not attached to a generation-history record: no more than 3 days;
- history-linked input images and videos: retained with the corresponding generation record, including failed, timed-out, or safety-rejected attempts, subject to eligible deletion requests and the processing period below;
- generated images and videos, and showcase copies: retained for generation history and service support; eligible file or account deletion requests are normally processed within 30 days, subject to the exceptions below. Removing image history withdraws visibility but does not itself erase every stored copy;
- account and generation-history records: while your account is active and then normally deleted within 30 days after an eligible deletion request;
- orders, subscriptions, tax, refunds, and disputes: for the period required by applicable accounting, tax, payment, fraud-prevention, or legal rules;
- internal payment-notification copies: only as long as needed for reconciliation, support, transaction troubleshooting, or applicable legal and dispute obligations. Eligible privacy requests also cover notification copies under our control;
- ordinary operational logs: no more than 30 days; longer-lived security, fraud, or dispute evidence is isolated and kept only while necessary;
- optional first-party event details: 90 days, followed by scheduled deletion. Expired visitor associations are removed once no retained events need them; withdrawing Analytics does not by itself delete earlier lawful records. Eligible access and deletion requests cover these records and associations;
- third-party analytics: GA4 user/event data for 14 months without resetting the period on new activity; ordinary Clarity retention without favouriting sessions; Plausible data while the site account remains active, subject to deletion through Plausible; and
- keyed IP anti-abuse records: while the relevant promotion operates and the record remains necessary to prevent abuse or resolve disputes, reviewed at least annually and deleted when the programme or Service ends and related disputes are resolved.
Deletion may take up to 30 days and may not immediately remove encrypted backups or information that we must retain for security, fraud, accounting, legal claims, or payment disputes. Third-party providers, including Creem for prompt screening and Feishu/Lark for notifications, may have separate retention periods under their applicable terms and settings; we do not promise that these match Kavello's R2 file-retention periods.
8. International processing
Kavello and its providers may process information in countries other than yours. Privacy laws and government-access rules may differ. Where applicable law requires it, we use appropriate contractual or other safeguards for cross-border transfers. We do not promise that all information is stored in a particular country.
9. Security and incident response
We use reasonable technical and organizational measures designed to protect information, including access controls, secrets management, and service-provider safeguards. No online service is completely secure, and we cannot guarantee absolute security.
If a security incident creates a notification duty under applicable law, we will notify affected users and authorities as required.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, receive portable data, or complain to a regulator. Withdrawing consent does not affect earlier lawful processing.
To make a request, email support@kavello.app from the email associated with your account. We may ask you to verify that address and provide information reasonably necessary to locate the records. We normally respond to eligible requests within 30 days, subject to lawful extensions and exceptions.
Portable exports are generally provided in JSON or CSV and may include account, order, subscription, credit, task, prompt, and retained-file records. We may exclude internal security and risk signals, keyed IP values, provider secrets, information about others, and material protected or retained by law.
Self-service account deletion is not currently available. Until it is introduced, verified deletion requests are handled through the support process above.
11. Changes to this Policy
We may update this Policy as the Service changes. We will post the updated version and date here. For material changes to data uses, content licensing, user rights, price, or renewal practices, we will provide at least 30 days' email or in-app notice where practicable and legally required. Urgent legal or security changes may take effect sooner.
12. Contact
Operator: Hong Li
Location: China
Website: https://kavello.app
Email: support@kavello.app
If the English Policy conflicts with a translation, the English version controls to the extent permitted by law. Mandatory rights under applicable law remain unaffected.