Privacy Policy
This notice explains what RizzGen collects, why, who else sees it, and what you can do about it. It describes how the product actually works rather than how a template assumes it works, so it is specific about who processes your prompts and uploads, and it tells you plainly where your content goes.
1. Who we are
RizzGen is a sole proprietorship operated by Meet Animeshbhai Gondaliya, having its place of business at Priya, 2 Fulwadi Park, Nana Mauva Road, Rajkot, Gujarat 360005, India. In this notice, “RizzGen”, “we”, “us” and “our” mean that business.
This notice covers www.rizzgen.ai, the RizzGen studio at app.rizzgen.ai, and every related product and service that links to it. We are the data fiduciary under India’s Digital Personal Data Protection Act, 2023, and the data controller under the UK and EU GDPR, for the personal data described here.
2. Information you give us
Your account details, whatever you upload or type into the studio, and the voice recordings you submit if you clone a voice. We never receive your card number.
Account information
Your name, email address, and password. If you sign in with Google, we receive your Google account identifier, email address, name and profile picture from Google instead of a password. We also store the optional profile details you give us during onboarding: what you work on, your experience level, your primary platform and your preferred video length. These shape the studio’s suggestions.
Billing information
Your billing address, and a record of each credit purchase: amount, currency, credits bought, and the order and transaction identifiers issued by our payment provider.
We never receive, see or store your card, UPI or bank details. Those go directly to Razorpay, who process the payment and return only a result to us. Their handling of that data is governed by the Razorpay privacy policy.
Content you create and upload
Everything you put into the studio in the course of making a video: prompts, briefs, scripts, chat messages, storyboard notes, brand and project context, and any images, video, audio or documents you upload as references. It also includes the media we generate for you and the project structure around it.
Voice recordings and consent
If you use voice cloning, we store the reference recording you provide, the reference text, and the consent statement you record with it. A voice print is sensitive personal data under the DPDP Act and the GDPR, and we treat it as such. You may only submit a recording of your own voice, or one you have documented permission to clone. You can delete a cloned voice at any time from the studio.
Connected social accounts
If you connect an Instagram or YouTube account, we receive an access token from that platform along with your handle, display name, profile URL and account identifier. We use the token to read your public content and build a profile of your style, content patterns and audience so the studio can match them. Tokens are encrypted before storage. You can disconnect an account at any time, which revokes our access and deletes the stored token.
Support and correspondence
The contents of support requests, feedback, bug reports and any files attached to them, plus emails you send us.
3. Information collected automatically
Standard device and usage data, plus three third-party analytics and advertising tools. One of them replays your session to show us where the interface fails you — with the text of your work masked out.
When you visit or use RizzGen we automatically collect your IP address, browser type and version, device and operating system, referring page, the pages and features you use, timestamps, and diagnostic data when something fails. We also log the technical details of each generation — which model ran, how long it took, whether it succeeded, and what it cost in credits.
Session replay
We use PostHog session replay, which records how you move through the RizzGen interface — mouse movement, clicks, scrolling, navigation and errors — so we can diagnose faults and see where the product confuses people.
Your work is masked in these recordings. The text of what you type and of what the studio produces is obscured before the recording leaves your browser, so a replay does not carry the content of your prompts and briefs, your chat with Rizzi, your scripts, the files you stage for upload, or the notes we hold about your preferences. What we see is the shape of your session, not the substance of your work.
Masking covers text. A replay still shows the layout of the page, which includes thumbnails of images and video on screen. If you would rather not be recorded at all, tell us at [email protected] and we will exclude your account.
Advertising measurement
We use Google Ads conversion tracking and the Meta Pixel on our marketing site to measure which advertisements bring people to RizzGen. These set cookies and report back to Google and Meta, who may combine that signal with data they already hold about you.
4. How we use your information
To provide the service
To run your account, generate the videos you ask for, store your projects and media, carry your context between sessions, and let you export and share your work. This means sending your prompts, uploads and reference media to the AI providers listed in section 6, because that is how generation happens.
To bill you
To process credit purchases, maintain your credit balance, record what each generation cost, issue refunds, and meet our tax and accounting obligations.
To improve RizzGen
We analyse usage telemetry — which features get used, where generations fail, how long each step takes, where people abandon a workflow — to fix what is broken and decide what to build. This is product analytics, not model training. See section 5.
To keep the platform safe
We screen prompts and uploaded images through automated content moderation before generating. When something is flagged we record the categories, the scores, an excerpt of the prompt and a reference to the image, so that repeat violations can be acted on. Section 9 of our Terms of Service and our Acceptable Use Policy explain what happens next.
To communicate with you
To verify your email, reset your password, confirm purchases, tell you when a long generation finishes, answer support requests, and send occasional product updates. You can opt out of product updates without losing the transactional messages your account depends on.
Legal bases
Where the GDPR applies, we rely on: performance of a contract for running the service and billing you; legitimate interests for security, moderation, fraud prevention and product analytics; consent for advertising cookies, marketing email and voice cloning; and legal obligation for retaining financial records. Where the DPDP Act applies, we process your data for the lawful purpose of providing the service you signed up for, and on your consent where that Act requires it. You can withdraw consent at any time.
5. We do not train AI models on your content
We do not use your prompts, uploads, scripts, voice recordings or generated media to train, fine-tune or improve any AI model — ours or anyone else’s.
RizzGen operates no model training pipeline over customer content, and we do not sell or license your content to anyone who does. Where we send your content to a third party model provider so that a generation can run, we do so under their API terms and we do not authorise them to train on it.
These providers are independent companies. We choose providers whose API terms exclude training on submitted data, but we cannot audit their infrastructure, and their own policies govern what happens on their side. Section 6 describes the categories they fall into, and will tell you the current names on request.
This commitment is separate from, and should not be confused with, the product telemetry described in section 4. Telemetry tells us that a step failed or a feature went unused. It does not feed a model.
7. International transfers
RizzGen is operated from India. Most of the providers in section 6 are outside India, principally in the United States and the European Union, so using RizzGen necessarily involves transferring your data internationally. Those countries may not offer the same legal protections as your own.
Where we transfer personal data out of the UK or the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses or the provider’s own approved transfer mechanism. Under the DPDP Act, we may transfer personal data outside India except to territories the Central Government restricts.
8. How long we keep it
Your content stays while your account is open. Delete your account and you get 15 days to change your mind, after which we erase it — except the payment records tax law makes us keep.
- Account and content
- For as long as your account is open, and for 15 days after you request deletion
- Deleted account grace period
- 15 days, during which you can restore the account in full by signing back in
- Financial records
- Retained after account deletion for the period required by Indian tax and accounting law, then erased. These are kept separately from your account and are not used for anything else.
- Moderation records
- Retained while your account is open so that repeat violations can be identified, and after deletion only where needed to enforce a suspension or meet a legal obligation
- Analytics and session replays
- Retained according to our PostHog configuration, currently no longer than 12 months
- Support correspondence
- Up to 3 years, so we can follow up on recurring issues
Requesting deletion suspends your account immediately and schedules it for permanent erasure 15 days later. During that window you can undo it. After it, we permanently delete your projects, chats, generated media, uploads, cloned voices, connected accounts and context. That erasure is not reversible.
9. How we protect it
Traffic is encrypted in transit with TLS. Passwords are stored hashed, never in plain text. Access tokens for connected social accounts are encrypted before they are written to the database. Sessions use signed tokens that we can revoke centrally, so changing your password or deleting your account invalidates every existing session immediately. Media files are served through short-lived signed URLs rather than public links.
Administrator access. Our administrators can open any chat in read-only mode. We do this to diagnose faults, investigate abuse reports and answer support requests. We tell you because you should know it is possible, not because we do it routinely.
No system is perfectly secure, and we cannot guarantee that transmitting data to us is free of risk. If a breach affects your personal data we will notify you and the relevant authority as the DPDP Act and the GDPR require.
10. Your rights
Whatever your location, you can access and correct your profile from your account settings, download or delete your projects and media from the studio, disconnect a social account, delete a cloned voice, and delete your entire account. For anything else, write to [email protected]. We respond within 30 days.
If you are in India
Under the Digital Personal Data Protection Act, 2023 you have the right to access a summary of your personal data and how it is processed; to correction, completion, updating and erasure; to nominate someone to exercise these rights if you die or become incapacitated; and to grievance redressal. Contact details are in section 14. If we do not resolve your grievance, you may complain to the Data Protection Board of India.
If you are in the UK or European Economic Area
You have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Where we rely on consent you may withdraw it at any time without affecting processing already carried out. You may lodge a complaint with your national supervisory authority, or with the Information Commissioner’s Office in the UK.
If you are in the United States
Depending on your state, you may have the right to know what personal data we collect and disclose, to access and delete it, to correct it, to data portability, to opt out of sale or sharing for targeted advertising, and not to be discriminated against for exercising these rights. We do not sell personal data, and we do not share it for cross-context behavioural advertising beyond the advertising measurement described in section 3. To opt out of that, use your browser’s privacy controls or write to us.
Do Not Track
Most browsers offer a Do-Not-Track setting. No uniform standard for honouring it exists, so we do not currently respond to those signals. We will say so here if that changes.
12. Children
RizzGen is for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete the account and its data. If you believe a minor has given us personal data, write to [email protected] and we will act promptly.
13. Changes to this notice
We update this notice when the product changes. The “last updated” date at the top always reflects the current version. When a change materially affects your rights — a new category of data, a new purpose, a new provider receiving your content — we will tell you by email or in the studio before it takes effect.
14. Contact and grievance officer
For any question about this notice, to exercise your rights, or to raise a complaint about how we handle your data, contact our Grievance Officer:
Meet Animeshbhai Gondaliya
Grievance Officer, RizzGen
Priya, 2 Fulwadi Park, Nana Mauva Road, Rajkot, Gujarat 360005, India
Email: [email protected]
Phone: +91 98255 21452
We acknowledge grievances within 24 hours and resolve them within 15 days, as the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 require.