VividSpark logo
FeaturesPricingBlog
Legal

Privacy Policy

Last updated: October 2026
中文版

Welcome to VividSpark, operated by VIVIDTECH PTE. LTD., a company incorporated in Singapore ("VividSpark," "we," "our," or "us").

At VividSpark, we believe that creators should have confidence not only in the tools they use, but also in how their information is handled. This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices available to you when using www.vividspark.ai and our related products and services (collectively, the "Services").

By creating an account, accessing, or using our Services, you acknowledge that you have read and understood this Privacy Policy.

1. Who We Are

VividSpark is an AI-native creator growth platform that helps creators streamline their content publishing workflow through AI-powered music matching, music licensing, publishing, analytics, and related creative tools.

  • Company: VIVIDTECH PTE. LTD.
  • Singapore
  • Website: https://www.vividspark.ai
  • General Support: support@vividspark.ai
  • Music Licensing: licensing@vividsoundlibrary.com

2. Scope of This Privacy Policy

This Privacy Policy applies to:

  • Our website
  • VividSpark web application
  • AI-powered creator tools
  • Music licensing services
  • Customer support
  • Marketing communications
  • Related online services operated by VIVIDTECH PTE. LTD.

It does not apply to third-party services, websites, or platforms that we do not own or control.

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

  • Email address
  • Username or display name
  • Encrypted password credentials

Passwords are securely hashed before storage. We do not have access to your plaintext password.

3.2 Content You Upload

To provide our Services, you may upload:

  • Videos, including their audio
  • Images, such as reference images, logos and other brand assets

These files are processed solely for providing requested features such as: AI Soundtrack, background music matching, cover generation, publishing workflow, AI video production, and performance analysis. To provide these features, some of this content is sent to the AI service providers listed in Section 6.1.

Ownership of uploaded content remains with you.

3.3 Payment Information

Payments are processed securely by Stripe.

We do not collect or store full credit card numbers, security codes (CVV), or complete payment credentials.

We may receive limited payment-related information from Stripe, including payment status, subscription status, transaction identifiers, billing country, and partial payment method information (such as card brand and last four digits).

Stripe processes payment information in accordance with its own Privacy Policy.

3.4 Usage Information

We automatically collect certain information regarding how our Services are used, including browser type, device type, operating system, IP address, approximate geographic region, pages visited, session duration, feature usage, click interactions, referral sources, and error logs.

3.5 AI Video Analysis Data

Certain AI-powered features require permission to analyze uploaded content.

When you use these features, we may process information extracted from uploaded videos, including scene segmentation, motion analysis, visual characteristics, timing information, music matching metadata, and AI-generated recommendations.

To produce this analysis, we may send the following to our AI service providers:

  • the full uploaded video, including its picture, audio and speech, for video understanding;
  • still frames taken from the video, and text that appears on screen;
  • the audio track, or the voice part separated from it, for transcription and audio separation;
  • transcripts and summaries derived from the video.

Which provider receives what, and for which feature, is listed in Section 6.1. This analysis is performed solely to deliver requested functionality.

3.6 Performance Data

If you authorize VividSpark to access supported social media accounts, we may collect performance information including views, engagement metrics, reach, audience interactions, and publishing performance.

This information is collected only after you grant the required permissions.

3.7 AI Soundtrack Conversations

When you use the AI Soundtrack assistant, we keep a record of the conversation to provide the feature, investigate problems, and improve our products. This record includes:

  • the messages you type and the buttons you press in the conversation;
  • the replies shown to you, and the intermediate steps used to produce them;
  • how our system interpreted your messages, such as the intended use you described for your video;
  • identifiers of the related video analysis and music tracks;
  • technical details such as timestamps, the software version, and whether a reply was displayed.

These records are stored in our primary database. Access is limited to authorized VividSpark staff who need it to operate and support the Services. To generate replies and search the music catalog, your messages, or text derived from them, are processed by our AI service providers: Anthropic, to understand your messages and write replies, and OpenAI, to interpret music search requests (see Section 6.1).

The text of your messages and of the replies is deleted after 180 days. We keep non-content information, such as timestamps and which part of the feature responded, for longer to measure and improve the Services. Text you can see as the title of a saved soundtrack version stays in your version history and is deleted at your request (see Section 11). Your browser also keeps a copy of the conversation on your device for up to 24 hours.

3.8 Growth Agent: Leads

When you use the Growth Agent's Leads feature, we collect and organize information about people and businesses who may be interested in what you offer (“leads”). Leads come from three places:

  • Comments and direct messages on your connected accounts. For campaigns you run with the Growth Agent, we read new comments on the posts that campaign published and new direct messages sent to the accounts it published from during the campaign, through our social media provider. Comments you or your own account wrote are skipped.
  • Public posts found by lead search. When you run a lead search, we look for publicly available posts — for example on Reddit, Bluesky, Hacker News and other public websites — using third-party search services. We only use search results and public posting interfaces; we do not log in to any service to read posts and we do not access private content.
  • Leads you add yourself.

For each lead we store a short excerpt of the post or message (up to 300 characters), the name or handle the author shows publicly, a link to the original, when it was posted if known, and our assessment of it: what the person appears to need, a score, a one-sentence reason and, for lead search, whether their location appears to match the area your campaign serves. Notes you add are stored with the lead.

To make that assessment, the text of the posts and messages, together with your campaign's description, is processed by our AI service provider, Anthropic. We do not contact anyone on your behalf: whether and how to reach out to a lead is your decision.

Leads are visible only to you. A lead nobody has contacted is deleted automatically 90 days after it was last updated; a lead you have marked as contacted, replied or won is kept with your account. To avoid reading or paying for the same post twice, we keep a list of the items already assessed for each campaign; it contains identifiers only (such as a link or a fingerprint of the text), not the text itself, and is deleted after 90 days. Records of notifications received from our social media provider contain only an event identifier and type, and are deleted after 30 days.

If you believe a post of yours appears as a lead in someone's VividSpark account and you want it removed, contact us (see Section 17) and we will delete it.

3.9 AI Video Production

Where this feature is available to your account, you can ask VividSpark to produce a finished video for you — editing your footage, adding music from our catalog, sound effects, on-screen text and, if you choose, an AI voice-over. To do this we process:

  • the videos, images, logos and other brand assets you upload;
  • your description of what you want, your answers to our questions, and your requests for changes;
  • the production brief we prepare from them, the drafts we produce, and the finished video;
  • if you choose a voice-over, the script, which you approve before it is recorded.

The work is carried out by an AI agent running in an isolated computing environment provided by Modal. The agent uses Anthropic's AI models, which receive your request, your answers, still frames and transcripts of your footage, and the brief. Voice-overs are generated by OpenAI, which receives the approved script. Your footage is also analyzed as described in Section 3.5.

The working files for a video, including the agent's session, are kept for about 24 hours so that you can ask for changes, and are then deleted. The text of the conversation is kept as described in Section 3.7. Finished videos are kept so that you can download them. Purchasing a music licence always requires your confirmation; the agent cannot buy one for you.

3.10 AI-Generated Content and Labels

Some of what our Services produce is generated or substantially edited by AI, including cover images, captions and titles, music matching decisions, voice-overs and produced videos.

Where the law or a publishing platform requires it, we may add a visible label to AI-generated content, such as a notice at the start of a video or in a voice-over, and we may record in the file's metadata that it was AI-generated, together with our name and a content identifier. Platforms such as YouTube, TikTok, Facebook and Instagram ask creators to disclose realistic AI-generated or AI-altered content when they post it; when you publish content made with VividSpark, you are responsible for making the disclosures those platforms and the law require. We do not offer voice cloning.

3.11 AI Soundtrack Master

Master is an option in AI Soundtrack in which an AI music director watches your video, chooses music from our catalog and edits it to your video. When you choose Master for a video, we process:

  • still frames taken from the video, at reduced resolution (at most 1280 pixels on the long side);
  • the audio track, which is transcribed;
  • information we derive from the video and its audio, such as the transcript of the speech, where speech and scene changes occur, and loudness and sound-event measurements.

Anthropic's AI models receive the still frames, the transcript and the derived information, and use them to describe the video and to choose and edit the music. The audio itself is not sent to Anthropic; it is transcribed by OpenAI (or, if that fails, by Replicate). The music searches that the AI director writes, which can describe what happens in your video, are processed by OpenAI to search our catalog. Modal extracts the frames and audio, detects speech and renders the result. The name of your video file is not sent to these providers. See Section 6.1.

The still frames and extracted audio are stored as private temporary files and are made available to the relevant providers only through access-controlled, time-limited links. We normally delete these temporary files within 48 hours after they are created. We keep the transcript and a record of the steps Master took — including working notes and searches that may describe your video — for up to 180 days after the relevant session activity, unless a shorter period is requested or a longer period is required by law. We then delete the text or irreversibly de-identify it and retain only aggregate operational figures. The finished soundtrack is kept with your AI Soundtrack session until you delete the session or your account, subject to our backup-deletion schedule. Provider-specific retention periods and processing locations are listed in our AI Service Provider List.

4. How We Use Your Information

We use collected information to:

  • Create and maintain your account
  • Authenticate users
  • Deliver AI-powered creator tools
  • Match licensed music to uploaded videos
  • Generate publishing assets
  • Process subscriptions and payments
  • Provide customer support
  • Detect fraud and abuse
  • Improve our Services
  • Analyze product performance
  • Monitor platform stability
  • Comply with legal obligations
  • Communicate product updates
  • Respond to support requests

We do not sell your personal information.

5. Legal Basis for Processing

Depending on your jurisdiction, we process information based on one or more of the following legal grounds:

  • Performance of a contract
  • Your consent
  • Legitimate business interests
  • Compliance with legal obligations
  • Protection of our legitimate rights

Where consent is required, you may withdraw it at any time, although doing so may affect certain features of the Services.

6. Third-Party Service Providers

To operate VividSpark efficiently, we rely on carefully selected third-party service providers. These providers process information only as necessary to perform services on our behalf.

  • Stripe — Payment processing and subscription management.
  • Resend — Transactional email delivery from noreply@vividspark.ai.
  • Supabase PostgreSQL — Primary application database, hosted in Southeast Asia (Singapore), AWS Region ap-southeast-1.
  • Cloudflare R2 — Object storage distributed through Cloudflare's global network. uploads/ deleted after ~24 hours; covers/ deleted after ~60 days, except images used in a Post Studio session, which are kept while you use the session (see Section 10).
  • Cloudflare Stream — Video streaming and delivery.
  • Pinecone — Vector database for AI search and similarity matching.
  • ACRCloud — Audio recognition services, Singapore region (ap-southeast-1).
  • Google Analytics 4 (ID: G-99EPQ9X2JL) — Website analytics. If a purchase is not reported from your browser, our servers report it to Google Analytics instead (Measurement Protocol), with the purchase details, your account's internal identifier and Google Analytics' own browser and session identifiers — not your email address, name or IP address.
  • Microsoft Clarity — User behavior analytics including heatmaps and session recordings.
  • Meta Pixel and Conversions API — Advertising measurement and campaign optimization. For a purchase, our servers also report it to Meta (Conversions API) with the purchase details, Meta's own browser identifiers (the _fbp / _fbc cookies) and your browser's user agent — not your email address, name, phone number or IP address.
  • Reddit Pixel — Measurement of ads shown on Reddit: page visits and account sign-ups, with no email address, name or phone number sent by us.
  • OpenAI Ads Measurement Pixel and Conversions API — Measurement of ads shown in ChatGPT. The pixel runs in your browser; when you sign up after following a ChatGPT ad link (an email sign-up counts once you verify your address), our servers also report the sign-up to OpenAI (see Section 7.3).
  • Sentry — Application monitoring and error reporting.
  • Zernio — Social media publishing, and reading comments and direct messages on accounts you connect, used only when you publish content or use the Growth Agent's Leads feature.
  • Exa — Web search used by the Growth Agent's lead search.
  • Brave Search — Web search used by the Growth Agent's lead search.

6.1 AI Service Provider List

These providers run the AI models and processing behind our features. Each receives only what the feature you are using needs. For each one we list the company, what it is used for and what it receives, where it mainly processes data, and how long it keeps it.

  • OpenAI — Transcription of the audio in your videos; analysis of still frames, on-screen text and transcripts; generating and editing cover images from frames of your video, reference images you provide and your instructions; checking those instructions for policy violations; interpreting music search requests, including the searches written by AI Soundtrack Master (see Section 3.11); and, in AI video production, generating voice-overs from the script you approve. This is separate from the OpenAI Ads Measurement Pixel and Conversions API listed above. Company: OpenAI OpCo, LLC (OpenAI Ireland Ltd for users in the European Economic Area and Switzerland). Location: United States. Retention: audio sent for transcription (/v1/audio/transcriptions) is not kept in OpenAI's abuse-monitoring logs; music search text sent for search (/v1/embeddings), and images and text sent to its other endpoints, may be kept in abuse-monitoring logs for up to 30 days, or longer where the law requires. OpenAI does not use API data to train its models by default.
  • Anthropic — AI models used to write captions, titles and cover text and to apply your requested changes; to run the AI Soundtrack conversation and its music analysis and quality checks; to answer customer support chats; to draft replies to comments and analyze performance on social accounts you connect; for the Growth Agent, including to assess leads (see Section 3.8); to run the AI agent that produces videos (see Section 3.9); and, for AI Soundtrack Master, to watch your video and choose and edit its music (see Section 3.11). It receives the text and summaries these features need and, for AI video production and AI Soundtrack Master, still frames and transcripts of your footage. Company: Anthropic, PBC. Location: United States. Retention: inputs and outputs are normally deleted within 30 days; content its automated systems flag as violating its Usage Policy may be kept for up to 2 years. Anthropic does not use API data to train its models by default.
  • Google (Gemini API)— Video understanding for Post Studio and AI Soundtrack, which receives the full uploaded video, including its audio and speech; designing and rendering the text on cover images, which receives the cover image and its text; and a fallback for generating cover images. Company: Google LLC. Location: United States and other countries where Google operates. Retention: prompts and responses are logged for a limited period, only to detect and prevent abuse and for disclosures the law requires, and are not used to improve Google's products.
  • Replicate — Hosted AI models used as a fallback for transcription and for removing burned-in text from frames used for covers. It receives the audio or video being transcribed, or the frame being processed. Company: Replicate, Inc. Location: United States. Retention: the inputs, outputs, files and logs of the jobs we send are removed after one hour.
  • Modal — Cloud computing used to process audio and video: extracting frames and audio, detecting scene changes and speech, separating voice from music, mixing and rendering videos, and passing videos to Google for analysis. In AI video production it also provides the isolated environment in which the AI agent works. It handles your videos and audio while they are being processed. Company: Modal Labs, Inc. Location: United States. Retention: files are processed in temporary working storage while a job runs and the results are returned to our own storage; its operational logs are kept under its terms with us.
  • ElevenLabs — Voice isolation when you remove background music from a video. It receives the voice part of your audio. Company: Eleven Labs Inc. Location: United States. Retention: under its terms with us.
  • Pinecone— Searching our music catalog. It receives numerical representations (embeddings) of music search text, including the searches written by AI Soundtrack Master, not the text itself. Company: Pinecone Systems, Inc. Location: United States. Retention: under its terms with us.

These providers may process data in the United States and in other countries (see Section 9). The retention periods above are those each provider publishes for the services and account settings we use, as of October 2026. We review this list against our contracts and account settings and update it, and notify you of material changes, when they change.

7. Cookies and Similar Technologies

We use cookies and similar technologies to operate our Services, maintain user sessions, improve functionality, measure performance, and understand how visitors interact with our platform.

7.1 Essential Cookies

  • vividspark.session_token — Secure authenticated login session (session duration)
  • vividspark.session_data — HMAC-signed session snapshot (~24 hours)
  • __ads_oauth_state — Temporary OAuth security validation (~5 minutes)

These cookies cannot be disabled without affecting core functionality.

7.2 Analytics Cookies

We use Google Analytics (_ga, _gid, _ga_*) and Microsoft Clarity cookies to understand website traffic, feature popularity, and user experience.

We also set our own cookie, vs_ft, when you first visit our site. It records how you found us: the campaign tags in the link you followed (such as utm_source), the website that referred you, the page you first landed on, and, if you came from an ad, which ad platform it was. For Google Ads it also keeps the click ID Google adds to the link; for other ad platforms it keeps only the platform's name. We use it only to record, when you create an account, where that account came from. It expires after 90 days and is not shared with third parties.

7.3 Advertising Cookies

Meta (Facebook) Pixel sets the _fbp cookie to measure marketing effectiveness.

The Reddit Pixel sets first-party cookies on our site to measure how ads shown on Reddit perform. At present these are _rdt_uuid, a randomly generated identifier for your browser, and, only when you arrive by following a Reddit ad link, _rdt_cid, which stores that ad's click identifier. Reddit's pixel decides the names of these cookies and how long they are kept, and may change them. The pixel reports the pages you visit on our site and, once, that you signed up — at the same moment as described for OpenAI below — with an internal identifier for your VividSpark account (not your email address). We do not send Reddit your email address, name or phone number.

The OpenAI Ads Measurement Pixel sets two cookies to measure how ads shown in ChatGPT perform: __oppref, which stores the identifier carried by a ChatGPT ad link (30 days), and __obref, a randomly generated identifier for your browser (365 days). When you enter contact details into a form on our site, such as your email address or name, the pixel converts them into a SHA-256 hash in your browser and sends only that hash with these measurement events, to help us measure ad performance. The details themselves are not sent as plain text.

When you sign up after following a ChatGPT ad link, our servers also report the sign-up to OpenAI through its Conversions API, so the ad can be credited even if your browser leaves the page before the pixel finishes. A sign-up is reported once, when it counts: for an email sign-up, when you verify your email address by opening the link we send you (an address that is never verified is never reported); for Google or Apple sign-in, when your account is first created. Signing in again later is not reported. That report contains an internal identifier for your VividSpark account (not your email address), the time the sign-up counted, the address of the page you signed up on (without its query string), the ad identifier from your __oppref cookie, the browser reference from your __obref cookie, and your browser's user agent. It does not contain your email address, name, phone number or IP address. We send it only when the browser that completes the sign-up (for an email sign-up, the browser in which you open the verification link) carries an ad identifier from a ChatGPT ad, and we do not store that identifier ourselves.

7.4 Cookie Management

VividSpark does not currently provide a dedicated cookie consent interface.

Most browsers allow you to manage or disable cookies through browser settings.

Disabling certain cookies may affect the availability or functionality of portions of the Services.

8. Where Your Information Is Stored

  • Primary Database: Supabase PostgreSQL, Singapore, AWS Region ap-southeast-1.
  • Object Storage: Cloudflare R2, globally distributed through Cloudflare's network.
  • Application Infrastructure: Deployed via Vercel, with globally distributed edge infrastructure.
  • Specialized AI Services: AI processing is carried out by the providers listed in Section 6.1, which may process data in the United States and in other regions depending on the feature used.

9. International Data Transfers

Because VividSpark serves users worldwide, your information may be processed outside your country of residence. When transferring personal information internationally, we take reasonable measures to ensure appropriate safeguards are implemented, including contractual, technical, and organizational protections where applicable.

10. Data Retention

  • Account Information: Retained while your account remains active.
  • Growth Agent Leads: Leads nobody has contacted are deleted 90 days after they were last updated; leads marked contacted, replied or won are kept with your account. Lists of already-assessed items (identifiers only) are deleted after 90 days.
  • Uploaded Files: uploads/ automatically deleted after ~24 hours; covers/ automatically deleted after ~60 days. Images used in a Post Studio session (the starting pictures and the covers you made) are an exception: they are kept while you use that session. Once a session has not been used for 12 months, its images return to the ~60-day rule. If you ask us to delete your account (Section 11), those older than 60 days are deleted immediately and the rest within ~60 days.
  • AI Video Production Working Files: Deleted about 24 hours after a video is produced (see Section 3.9).
  • Temporary Analysis Files: Still frames and audio extracted to analyze your video are stored as private files, shared with providers only through time-limited links, and normally deleted within 48 hours.
  • Speech Transcripts: Transcripts of the speech in videos analyzed by AI Soundtrack are deleted 180 days after the analysis.
  • AI Soundtrack Master: Still frames and extracted audio are normally deleted within 48 hours. The transcript and the record of the steps Master took are kept for up to 180 days; then the text is deleted or irreversibly de-identified and only aggregate figures are kept (see Section 3.11).
  • Data Processed by AI Service Providers: The provider, purpose, categories of data, principal processing locations, and applicable retention period or retention criteria are set out in our AI Service Provider List. We review that list against our contracts and account settings and notify users of material changes.
  • Payment Records: Retained for the period required by applicable accounting, tax, anti-fraud, or legal requirements.
  • Analytics Information: Retained according to the retention policies of the respective analytics providers.

11. Account Deletion

VividSpark currently does not provide a self-service account deletion feature.

To permanently delete your account, please contact us at support@vividspark.aior use the "Talk to Human" support option within the platform.

Upon receiving a valid request, we will delete or anonymize your personal information where reasonably practicable, except where retention is required by applicable law.

12. Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

  • Request access to your personal information
  • Request correction of inaccurate information
  • Request deletion of personal information
  • Withdraw previously granted permissions
  • Disconnect connected social media accounts
  • Request information about how your personal data is processed

Although VividSpark has not yet implemented formal GDPR or CCPA compliance workflows, we respect legitimate privacy requests and will make reasonable efforts to respond in accordance with applicable law.

Requests may be submitted to: support@vividspark.ai

13. Security

We implement reasonable administrative, technical, and organizational safeguards including encrypted password storage, HTTPS encryption, secure authentication, access controls, infrastructure monitoring, and trusted cloud infrastructure providers.

No system connected to the Internet can guarantee absolute security.

14. Children's Privacy

Our Services are not specifically directed toward children, and we do not knowingly collect personal information from children in violation of applicable law. Parents or guardians who believe a child has provided personal information may contact us at support@vividspark.ai.

15. Third-Party Websites

Our Services may contain links to third-party websites or social media platforms.

We are not responsible for the privacy practices or content of third-party websites.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When material changes are made, we will provide appropriate notice through our website, email, or within the Services. Continued use of the Services after an updated Privacy Policy becomes effective constitutes acceptance of the revised policy.

17. Contact Us

  • VIVIDTECH PTE. LTD.
  • Singapore
  • Website: https://www.vividspark.ai
  • General Support: support@vividspark.ai
  • Music Licensing: licensing@vividsoundlibrary.com
VividSpark logo
© 2025 VividSpark. All rights reserved.
Privacy PolicyTerms of ServiceMusic Licensing