> For the complete documentation index, see [llms.txt](https://docs.trezalabs.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.trezalabs.com/terms-and-privacy/privacy.md).

# Privacy Policy

**Effective Date: July 11, 2026** · **Last Updated: August 18, 2026**\
Welcome to **Treza** ("Company," "we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our platform for building and running generative-media pipelines, available at trezalabs.com (collectively, the "Service"). By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

{% hint style="info" %}
This document describes how the Service handles data today. It is provided for transparency and is not a substitute for legal advice. Please review it with your own counsel before relying on it.
{% endhint %}

***

#### 1. Information We Collect

We collect the following types of information:

**Account Information:** When you create an account or contact us, we collect information such as your name, email address, authentication identifiers, and payment details. Authentication is handled by our identity provider (Privy).\
**Pipeline Content:** We process the prompts, files, and other content you submit ("Inputs"), the pipelines (graphs of nodes) you build, and the video, images, text, and other content you generate ("Outputs"). We also store run history, including per-node timing, token and credit usage, and status.\
**Usage Data:** We collect data on how you interact with the Service, including IP address, browser type, device information, pages visited, API requests, and timestamps.\
**API Keys and Secrets:** We store the provider keys and secrets you add to the Service in encrypted form so your pipelines can run. Treza API keys (`treza_live_...`) are stored hashed.\
**Connected YouTube Accounts (optional):** If you choose to connect a YouTube channel, we receive and store your YouTube channel identifier, channel display name, channel handle or custom URL, channel avatar URL, and an OAuth refresh token that we encrypt and store server-side. We use this information to display your connected channel(s) in the Service, to upload videos to your channel when you instruct the Service to do so, to retrieve performance statistics and analytics (such as views, likes, comment counts, watch time, and estimated revenue) for videos published through the Service so we can show them in your dashboard, and — when you enable these features — to post comments on your own published videos and to read and reply to viewer comments on those videos according to reply guidelines you configure. We do not access your YouTube watch history, playlists, subscriptions, or other Google account data beyond what is described here, and we only read comments on videos published to your channel through the Service.\
**Connected TikTok Accounts (optional):** If you choose to connect a TikTok account, we receive and store your TikTok open identifier, display name, username, avatar URL, and an OAuth refresh token that we encrypt and store server-side. We use this information only to display your connected account(s) in the Service, query allowed publish settings from TikTok, and publish videos when you instruct the Service to do so. We do not access your TikTok watch history, private analytics, direct messages, followers list, or other TikTok account data beyond this basic profile metadata.

***

#### 2. Third-Party Model and Infrastructure Providers

To run your pipelines, the Service transmits your Inputs and Outputs to third-party model and infrastructure providers, which may include, but are not limited to:

* Google (including Veo and Gemini models, and the YouTube Data API v3 when you connect a YouTube channel)
* TikTok (including the TikTok Content Posting API when you connect a TikTok account)
* OpenAI (including Sora models)
* Anthropic
* DeepSeek, Qwen, Meta (Llama), Mistral, and other open-model providers
* Together, OpenRouter, Fireworks, and Hugging Face
* Amazon Web Services (AWS)
* Pinecone
* Stripe (payments)
* Privy (authentication)
* Vercel (hosting)

These services process data according to their own privacy policies and terms. We do not control how third-party providers handle data once it is transmitted to them, and your use of a particular model or integration may be subject to that provider's policies.

***

#### 2.1 YouTube Data (when you connect a channel)

Treza uses YouTube API Services. If you connect a YouTube channel, Treza accesses Google user data through the YouTube Data API v3 and the YouTube Analytics API subject to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements. By using these features you also agree to the [YouTube Terms of Service](https://www.youtube.com/t/terms); the [Google Privacy Policy](http://www.google.com/policies/privacy) describes how Google handles data on its side.

We access and use this data as follows:

* **Channel ID, title, handle, and thumbnail** — to show which channel is connected and let you select a publish target. Stored while the channel remains connected.
* **OAuth refresh token** — to obtain short-lived access tokens when the Service acts on your channel (uploads, comments, statistics). Stored in encrypted form while the channel remains connected.
* **Video statistics and analytics** — view, like, and comment counts, watch time, and estimated revenue for videos published to your channel through the Service, to show a performance dashboard in your account. Stored alongside your publication history.
* **Comments on your published videos** — when you enable comment features, the Service posts a comment from your channel on videos it publishes for you, and reads viewer comments on those videos so it can post replies from your channel according to reply guidelines you configure. Viewer comments are processed to generate these replies and are not used for any other purpose.

We use YouTube and Google user data only to provide the connected-account, publishing, reporting, and comment features you request. We do not use it for advertising, sell it, or use it to train models. We share it only with Google as necessary to perform the actions you request and with infrastructure providers (such as AWS) solely to operate the Service.

You can disconnect a YouTube channel at any time in Settings → Connected accounts, which deletes Treza's stored OAuth credentials for that channel. You can also revoke Treza's access in your [Google Account permissions](https://myaccount.google.com/permissions) or via [Google security settings](https://security.google.com/settings/security/permissions).

***

#### 2.2 TikTok Data (when you connect an account)

If you connect a TikTok account, Treza accesses TikTok user data through the TikTok Content Posting API subject to [TikTok's developer terms](https://developers.tiktok.com/doc/terms-and-conditions) and applicable TikTok policies.

We access and use this data as follows:

* **Open ID, display name, username, and avatar** — to show which TikTok account is connected and let you select a publish target. Stored while the account remains connected.
* **Creator publish settings** (such as allowed privacy levels and interaction toggles) — queried from TikTok when you configure or confirm a publish action, so the Service can present only options TikTok allows for your account. Not stored beyond what is needed for the active publish flow.
* **OAuth refresh token** — to obtain short-lived access tokens when you initiate a publish. Stored in encrypted form while the account remains connected. TikTok may rotate refresh tokens; we store the latest token TikTok issues.

We use TikTok user data only to provide the connected-account and video-publishing features you request. We do not use it for advertising, sell it, or use it to train models. We share it only with TikTok as necessary to perform publishes you request and with infrastructure providers (such as AWS) solely to operate the Service.

You can disconnect a TikTok account at any time in Settings → Connected accounts, which deletes Treza's stored OAuth credentials for that account. You can also revoke Treza's access in your TikTok account settings or through TikTok's connected-apps controls where available.

***

#### 3. How We Use Your Information

We use your information to:

* Provide, maintain, and improve the Service
* Execute your pipelines and return generated Outputs
* Connect YouTube channels and publish videos you generate, when you choose to use that feature
* Connect TikTok accounts and publish videos you generate, when you choose to use that feature
* Process transactions and manage prepaid credits and payments
* Maintain run history, usage insights, and audit records
* Monitor usage and security, and detect fraud, abuse, or violations of our Terms of Service
* Comply with legal obligations and enforce our Terms of Service

We do not use your Inputs or Outputs to train our own models.

***

#### 3.1 Cookies and Similar Technologies

Treza stores and accesses information on your device to operate the Service and understand how it is used:

* **Authentication and session cookies** — `treza_session` keeps you signed in; short-lived cookies (such as `treza_oauth`) protect sign-in and account-connection flows against forgery; `treza_seen` remembers that you have visited before. These are first-party and required for the Service to function.
* **Browser storage (localStorage / sessionStorage)** — used for interface state such as in-progress flows, editor preferences, and draft inputs, so the app picks up where you left off. This data stays in your browser and is not a tracking mechanism.
* **Analytics and advertising cookies** — we use Google Analytics (and Google Ads conversion measurement) on our marketing site, which places cookies (for example `_ga`) to help us understand site traffic and measure sign-ups. Google's use of this data is described in the [Google Privacy Policy](https://policies.google.com/privacy). You can opt out with the [Google Analytics opt-out browser add-on](https://tools.google.com/dlpage/gaoptout) or by blocking these cookies in your browser.
* **Affiliate attribution** — pages describing our partner program load PromoteKit, which sets a cookie so that sign-ups can be credited to the creator who referred them.
* **Payments** — Stripe sets cookies during checkout for fraud prevention, as described in [Stripe's privacy policy](https://stripe.com/privacy).

You can control or delete cookies in your browser settings; blocking the first-party authentication cookies will prevent signing in. We do not use cookies to track you across unrelated third-party sites, and we do not allow third parties to collect information from your device through the Service except as listed above.

***

#### 4. Data Retention and Deletion

We retain collected data for as long as necessary to provide the Service or as required by law. Run history and generated assets are retained so you can access them from your account, and you can delete pipelines and assets from the dashboard. Connected YouTube channel credentials and metadata are retained until you disconnect the channel in Settings → Connected accounts or revoke access in your Google Account. Connected TikTok account credentials and metadata are retained until you disconnect the account in Settings → Connected accounts or revoke Treza's access through TikTok.

You may request deletion of your personal data by contacting [**hello@trezalabs.com**](mailto:hello@trezalabs.com), subject to our legal and contractual obligations. Some information may be retained where required for legal, accounting, or security purposes.

***

#### 5. Data Sharing and Disclosure

We do not sell your personal data. We may share data with:

**Service Providers:** Third-party providers that help us operate the Service, including the model, hosting, authentication, and payment providers listed above.\
**Legal Compliance:** If required by law, we may disclose information to law enforcement or regulatory authorities.\
**Business Transfers:** In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

***

#### 6. Security

We implement reasonable technical and organizational measures to protect your data, including encryption of stored secrets, provider keys, and OAuth refresh tokens for connected YouTube and TikTok accounts. However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and Treza API keys confidential and for not embedding them in client-side code.

***

#### 7. Your Content and Generated Output

You retain your rights to your Inputs, and, to the extent permitted by law and the applicable model provider's terms, you own your Outputs. Because of the nature of generative models, Outputs may not be unique. Generative models can also produce inaccurate content, and you should verify Outputs before relying on them. See our [Terms of Service](/terms-and-privacy/terms-of-service.md) for details on content ownership and acceptable use.

***

#### 8. Your Rights

Depending on your jurisdiction, you may have the right to:

* Access, update, or delete your personal information
* Object to or restrict certain processing of your data
* Request a portable copy of your data
* File a complaint with a regulatory authority

To exercise these rights, please contact [**hello@trezalabs.com**](mailto:hello@trezalabs.com).

***

#### 9. International Data Transfers

The Service and its providers may process and store data in countries other than your own. Where we transfer personal data across borders, we take steps to ensure it receives an appropriate level of protection consistent with applicable law.

***

#### 10. Children's Privacy

The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can delete it.

***

#### 11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will notify you through the Service or by other means. Your continued use of the Service after any modifications constitutes acceptance of the updated Privacy Policy.

***

#### 12. Contact Information

If you have any questions about this Privacy Policy, please contact us at: [**hello@trezalabs.com**](mailto:hello@trezalabs.com)

***

By accessing or using Treza, you acknowledge that you have read, understood, and agree to this Privacy Policy.
