> For the complete documentation index, see [llms.txt](https://docs.trezalabs.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.trezalabs.com/terms-and-privacy/privacy.md).

# Privacy Policy

**Effective Date: July 11, 2026** · **Last Updated: October 7, 2026**\
Welcome to **Treza** ("Company," "we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our platform for building and running generative-media pipelines, including the website at trezalabs.com, the in-app chat and editors, the Treza API, the Treza MCP server and the apps that connect to it, and pay-per-request x402 purchases (collectively, the "Service"). By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

{% hint style="info" %}
This document describes how the Service handles data today. It is provided for transparency and is not a substitute for legal advice. Please review it with your own counsel before relying on it.
{% endhint %}

***

#### 1. Information We Collect

**1.1 Information you provide or create**

**Account Information:** You sign in with Google (including Google One Tap), which shares your name, email address, profile photo, and Google account identifier with us. We use your email address as your account identifier and keep your name and photo in your signed-in session.\
**Pipeline Content:** We process and store the prompts, files, links, and other content you submit ("Inputs"), the pipelines (graphs of nodes), schedules, recipes, and timeline-editor projects you build, and the video, images, audio, text, and other content you generate ("Outputs"). We also store run history (including per-node status, timing, inputs and outputs, token and credit usage), the files in your library, and the share links you create.\
**Conversations:** We store your conversations with the in-app assistant, including the assistant panels in the pipeline and timeline editors, so you can return to them. This includes the messages, the media they reference, and any thumbs-up or thumbs-down feedback you give. Voice notes you record in the chat composer are stored as audio files. In live voice conversations, your microphone audio streams directly from your browser to OpenAI, and we store the text of each turn but not the audio.\
**Payment Information:** Card and other payment details are collected and processed by Stripe; we do not receive or store full card numbers. We store your Stripe customer ID, your purchase and credit history, and, if you turn on auto top-up, the saved payment method's ID and a short label such as the card brand and last four digits.\
**Crypto Payments:** If you pay for a request with USDC through x402, we receive and store the paying wallet address, the transaction reference, and the amount. Your wallet address becomes the identifier for that purchase history. Transactions on public blockchains are visible to anyone and cannot be deleted by us.\
**API Keys and Secrets:** We store a one-way hash of each Treza API key you create, which is how we authenticate requests made with it, and its last four characters so you can tell your keys apart. The full key is shown to you once, when you create it, and we cannot retrieve it later. We store the provider keys, cloud credentials, and other secrets you add to the Service in encrypted form so your pipelines can run, and we keep the last four characters of each secret unencrypted so you can tell them apart.\
**Connected Accounts (optional):** If you connect a YouTube channel, a TikTok account, or an AI assistant, we receive the information described in Sections 2.1 to 2.3.\
**Communications:** When you contact us, use the contact form, or reply to our emails, we receive your message and contact details. We also store your email preferences and a record of which product emails we have sent you.\
**Partner Program (optional):** If you join our partner (affiliate) program, we store your email address, the PayPal email address you give us for payouts, your referral code, the number of visits your link brings, and the sign-ups, purchases, commissions, and payouts attributed to you.\
**Credit Codes:** When you redeem a credit code, we record the code, your account, and the IP address it was redeemed from.

**1.2 Information collected automatically**

**Usage Data:** We collect data on how you interact with the Service, including IP address, browser type, device information, pages visited, features used, API requests, and timestamps. Our hosting provider records request logs, including IP addresses.\
**Sign-up Information:** When your account is created, we record the IP address it was created from and, where available, how you first found us: the page you landed on, the referring site, campaign (UTM) tags, and your device type (mobile, tablet, or desktop). If you arrived through a partner's link, we record which partner referred you.\
**Error Reports:** If the app crashes in your browser, it sends us the error message, the page address, the referring page, your browser's user agent, and your approximate location (country and region) so we can fix the problem.\
**Cookies and Analytics:** We and our analytics providers use cookies and similar technologies, as described in Section 3.1.

**1.3 Information about other people in your content**

Your Inputs and Outputs may include other people, for example their faces and voices in a video you upload or a podcast episode you clip, the email address of someone you ask to approve a pipeline step, or viewer comments on your YouTube videos when you turn on comment replies. We process this information only to run the pipelines and features you set up. You are responsible for having the right to submit it (see our [Terms of Service](/terms-and-privacy/terms-of-service.md)).

**1.4 Face detection and comparison**

Some features that frame vertical crops and choose thumbnails detect faces in your video. To avoid showing the same person twice in a thumbnail, the Service also computes numeric face measurements (face embeddings) and compares them within that video. This runs on our own servers, the measurements are held in memory only for that step, and they are discarded when the step ends. We do not store face measurements, build face databases, or use them to identify who a person is. Separately, to work out who is speaking, the Service sends video frames and audio to the AI models described in Section 2. They can label speakers with names taken from the source material, such as an episode description, and are instructed never to identify anyone from their face or appearance alone.

**1.5 Information from other sources**

We receive information from Google when you sign in, from YouTube and TikTok when you connect an account, from Stripe and our crypto payment facilitators about the status of your payments, and from AI assistants you connect (Section 2.3). To contact businesses that may be interested in Treza, we also obtain business contact information, such as a name, work email address, company, and role, from public sources and business-data providers such as Apollo.io. If we contact you this way, you can ask us to stop at any time by replying or by emailing us.

***

#### 2. Third-Party Model and Infrastructure Providers

To run your pipelines and operate the Service, we share data with the following providers. Each processes data under its own terms and privacy policy.

* **AI model access.** Most model requests go through **OpenRouter**, which passes your prompts, files, audio, and video frames to the developer of the model you or the assistant selected, such as Anthropic (Claude), OpenAI (GPT, Whisper), Google (Gemini, Veo, Lyria), ByteDance (Seedance, Seedream), Kuaishou (Kling), Alibaba (Wan, Qwen), MiniMax (Hailuo), Runway, Black Forest Labs (Flux), xAI (Grok Imagine), HeyGen, Meta, Mistral, DeepSeek, Tencent, and other model developers. The models available change over time, and you can choose any model OpenRouter offers.
* **fal.ai**, for motion transfer, lip sync, avatars, upscaling, background removal, speech isolation, and speaker labelling.
* **ElevenLabs**, for text-to-speech, sound effects, and music generated from your video.
* **OpenAI**, directly, for live voice conversations (Realtime API).
* **Web search** (Exa, through OpenRouter), to check names and facts in text the Service writes before it is published.
* **Amazon Web Services (AWS)**, for storage, databases, encryption keys, processing, and media delivery (Amazon S3, DynamoDB, KMS, SQS, Fargate, and CloudFront), in the United States.
* **Vercel**, for hosting, request logs, and Vercel Web Analytics and Speed Insights.
* **Stripe**, for card and other payments, auto top-up, and fraud prevention.
* **Coinbase** (x402 facilitator) and **PayAI** (Solana facilitator), to verify and settle crypto payments.
* **Resend**, to send email.
* **Google**, for sign-in, the YouTube Data and Analytics APIs when you connect a channel, and Google Analytics and Google Ads measurement.
* **TikTok**, for the TikTok Content Posting API when you connect an account.
* **Microsoft Clarity**, for session replay and heatmaps (Section 3.1).
* **IPRoyal**, a proxy network that the Media Download step uses to fetch media from the links you provide.
* **Apple** (podcast search), **GIPHY**, and **Pixabay**, which receive search terms when you use features that search them.
* **PayPal**, to pay partner commissions.

When a step in your pipeline sends data to a web address, webhook, cloud bucket, or other service you configure, such as an HTTP Request step or the AWS S3 delivery step, we send that data where you direct it.

We do not control how third-party providers handle data once it is transmitted to them. Some model providers may keep inputs for a limited time, for example to monitor for abuse, under their own policies, and your use of a particular model or integration may be subject to that provider's terms.

***

#### 2.1 YouTube Data (when you connect a channel)

Treza uses YouTube API Services. If you connect a YouTube channel, Treza accesses Google user data through the YouTube Data API v3 and the YouTube Analytics API subject to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements. By using these features you also agree to the [YouTube Terms of Service](https://www.youtube.com/t/terms); the [Google Privacy Policy](http://www.google.com/policies/privacy) describes how Google handles data on its side.

We access and use this data as follows:

* **Channel ID, title, handle, and thumbnail:** to show which channel is connected and let you select a publish target. Stored while the channel remains connected.
* **OAuth refresh token:** to obtain short-lived access tokens when the Service acts on your channel (uploads, comments, statistics). Stored in encrypted form while the channel remains connected.
* **Video statistics and analytics:** view, like, and comment counts, watch time, and estimated revenue for videos published to your channel through the Service, to show a performance dashboard in your account. Stored alongside your publication history.
* **Comments on your published videos:** each public or unlisted video the Service uploads for you receives one comment, posted from your channel, that says the video was made with Treza and links to our site (see Section 4 of our [Terms of Service](/terms-and-privacy/terms-of-service.md)). When you turn on comment replies, the Service also reads viewer comments on videos it published for you and posts replies from your channel according to reply guidelines you configure. Viewer comments are sent to an AI model to write those replies and are not used for any other purpose. We store the IDs of comments we reply to, not their text.

We use YouTube and Google user data only to provide the connected-account, publishing, reporting, and comment features described here. We do not use it for advertising, sell it, or use it to train models. We share it only with Google as necessary to perform the actions you request, with the AI model providers in Section 2 when the Service writes titles, descriptions, and comment replies, and with infrastructure providers (such as AWS) solely to operate the Service.

You can disconnect a YouTube channel at any time in Settings → Connected accounts, which deletes Treza's stored OAuth credentials and channel details. You can also revoke Treza's access in your [Google Account permissions](https://myaccount.google.com/permissions) or via [Google security settings](https://security.google.com/settings/security/permissions).

***

#### 2.2 TikTok Data (when you connect an account)

If you connect a TikTok account, Treza accesses TikTok user data through the TikTok Content Posting API subject to [TikTok's developer terms](https://developers.tiktok.com/doc/terms-and-conditions) and applicable TikTok policies.

We access and use this data as follows:

* **Open ID, display name, username, and avatar:** to show which TikTok account is connected and let you select a publish target. Stored while the account remains connected.
* **Creator publish settings** (such as allowed privacy levels and interaction toggles): queried from TikTok when you configure or confirm a publish action, so the Service can present only options TikTok allows for your account. Not stored beyond what is needed for the active publish flow.
* **OAuth refresh token:** to obtain short-lived access tokens when you initiate a publish. Stored in encrypted form while the account remains connected. TikTok may rotate refresh tokens; we store the latest token TikTok issues.

We use TikTok user data only to provide the connected-account and video-publishing features you request. We do not use it for advertising, sell it, or use it to train models. We share it only with TikTok as necessary to perform publishes you request and with infrastructure providers (such as AWS) solely to operate the Service.

You can disconnect a TikTok account at any time in Settings → Connected accounts, which deletes Treza's stored OAuth credentials for that account. You can also revoke Treza's access in your TikTok account settings or through TikTok's connected-apps controls where available.

***

#### 2.3 AI Assistants You Connect (ChatGPT, Claude, and other MCP clients)

You can connect Treza to an AI assistant, such as the Treza plugin in ChatGPT, a connector in Claude, or another app that supports the Model Context Protocol (MCP). To connect, you sign in to Treza and approve the permissions the assistant asked for. The assistant can then act on your Treza account within those permissions when you ask it to.

* **What we receive.** We receive the information the assistant includes in each request it sends to Treza, such as a video brief or prompt, a pipeline it is building, inputs for a run, the caption and title for a post, and files or links you share with it to add to your library. We do not receive your full conversation, your chat history, or the assistant's memory, except for whatever the assistant includes in a request.
* **What we record.** We record which assistant connected to your account (for example ChatGPT or Claude) and when it was first and last used, so we can show it in your account and help you if something goes wrong. We also keep a log of the tools an assistant calls on your account and their results.
* **What we send back.** We return the information needed to answer each request, such as your pipelines, the status and results of your runs, links to your media, your credit balance, and the names of your connected channels. Once returned, that information is part of your conversation with the assistant and is handled under the assistant provider's own terms and privacy policy, for example [OpenAI's Privacy Policy](https://openai.com/policies/privacy-policy) for ChatGPT or [Anthropic's Privacy Policy](https://www.anthropic.com/legal/privacy) for Claude.
* **How we use it.** We use information from an assistant's requests only to carry them out, the same way we handle a request you make in the Treza app. What the assistant creates is stored in your account as described in Section 1, for example a pipeline it builds or a file it adds to your library. We do not use this information for advertising, sell it, or use it to train models.
* **Access tokens.** When you approve a connection, Treza issues the assistant an access token that expires after one hour and a refresh token that expires after 90 days. The assistant holds these tokens; Treza verifies them on each request and does not store them.
* **Disconnecting.** You can disconnect Treza at any time in the assistant's settings, which removes the tokens the assistant holds. Pipelines, media, and runs created through the assistant stay in your Treza account until you delete them.

***

#### 3. How We Use Your Information

We use your information to:

* Provide, maintain, and improve the Service
* Execute your pipelines and return generated Outputs
* Connect YouTube channels and TikTok accounts and publish videos you generate, when you choose to use those features
* Carry out requests from AI assistants you connect, and return the results to them
* Process transactions, manage prepaid credits, auto top-up, and payments, and pay partner commissions
* Maintain run history, usage insights, and audit records
* Investigate errors and failed runs, and answer support requests you raise
* Send you service emails and, unless you unsubscribe, product emails (Section 3.2)
* Understand how the Service is used and measure our marketing and advertising, so we can improve them
* Credit partners for the customers they refer
* Monitor usage and security, and detect and prevent fraud, abuse, card testing, and misuse of free credits (for example, by limiting how many accounts created from one IP address receive free credits)
* Comply with legal obligations and enforce our Terms of Service

We do not use your Inputs or Outputs to train our own models.

**Automated checks.** Before the Service publishes text it wrote for you, such as a video title, description, caption, or comment reply, an AI model reviews it against the source material and may correct misspelled names or claims the source does not support. Text you typed yourself is not changed. The Service also screens prompts for certain prohibited requests, such as requests to undress a real person, and refuses them before they reach a model. Model providers apply their own safety filters too.

**Access by our team.** Your pipelines, Inputs, Outputs, and run history belong to you. A limited number of authorised Treza personnel can access them where it is necessary to operate the Service: to investigate a failed run or a billing question, to respond to a support request, to prevent abuse, and to understand which parts of the product work so that we can improve them. We keep that access to what the task requires, we do not use it to build competing content, and we do not share your content, your pipelines, or your connected channels with anyone outside Treza except as described in Section 5. If we would like to feature your work publicly, for example as a case study, we will ask you first.

***

#### 3.1 Cookies and Similar Technologies

Treza stores and accesses information on your device to operate the Service, remember your choices, and understand how the Service is used. We set these first-party cookies:

* `treza_session` keeps you signed in (30 days).
* `treza_oauth` and `treza_onetap` protect the Google sign-in flow against forgery (10 minutes and 24 hours).
* `treza_seen` remembers that this browser has signed in before (1 year).
* `treza_onboarded` remembers that you finished onboarding (1 year).
* `treza_attr` records how you first found us: landing page, referring site, campaign tags, and device type (1 year).
* `treza_via` records the partner whose link you followed, so the partner can be credited if you sign up or buy credits (60 days).
* `treza_partner` keeps partners signed in to the partner dashboard (90 days).
* `treza_share_<id>` remembers that you entered the password for a password-protected share link (12 hours).

We also use **browser storage** (localStorage and sessionStorage) for interface state, such as in-progress flows, editor preferences, and draft inputs, and to remember campaign tags and Google Ads click identifiers from the link that brought you to the site. Those tags and identifiers are attached to our analytics events and to your checkout, so we can tell which campaigns lead to purchases.

Third parties set cookies or collect information through the Service as follows:

* **Google Analytics and Google Ads.** We use Google Analytics on the website and in the app, and Google Ads conversion measurement, which set cookies such as `_ga` and `_gcl_au`. We also report purchases to Google Analytics from our servers, including the campaign tags and ad click identifiers saved at checkout. See [how Google uses information from sites that use its services](https://policies.google.com/technologies/partner-sites). You can opt out with the [Google Analytics opt-out browser add-on](https://tools.google.com/dlpage/gaoptout) and control ad personalization in [Google's ad settings](https://adssettings.google.com).
* **Microsoft Clarity.** We use Microsoft Clarity on the website and in the app to understand how people use the Service and to find bugs. Clarity records how you interact with pages, such as clicks, scrolling, and mouse movement, and the content shown on the page, and turns this into session replays and heatmaps. It sets cookies such as `_clck` and `_clsk`. Microsoft processes this data as described in the [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement).
* **Vercel Web Analytics and Speed Insights** measure page views and page performance without using cookies.
* **Google sign-in** sets a cookie (`g_state`) to remember whether you dismissed the One Tap prompt.
* **YouTube.** When you preview a connected channel's video in Settings, the embedded YouTube player may set YouTube cookies.
* **Stripe** sets cookies during checkout for fraud prevention, as described in [Stripe's privacy policy](https://stripe.com/privacy).

You can control or delete cookies in your browser settings; blocking the first-party authentication cookies will prevent signing in. We do not allow other third parties to collect information from your device through the Service except as listed above.

***

#### 3.2 Emails We Send

We send **service emails** that relate to your account and the things you asked the Service to do, such as purchase confirmations, failed payment and auto top-up notices, notices that your media is ready, and alerts about scheduled runs that fail or are paused. We also send **product emails**, such as a welcome message, reminders about an unfinished checkout or unused credits, notices that your free credits are used up, and occasional offers and feature announcements. Product emails include an unsubscribe link, and you can choose which notifications you receive in Settings. If a pipeline you build sends email to someone else, for example an approval request, we send it on your behalf to the address you entered.

***

#### 4. Data Retention and Deletion

We retain your information for as long as your account is open or as needed to provide the Service, and afterwards as needed to comply with legal, tax, and accounting obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements. Specifically:

* **Your content.** Pipelines, run history, Outputs, uploads, conversations, and editor projects are kept so you can return to them. You can delete pipelines, chat conversations, editor projects, saved secrets, API keys, and connected accounts yourself. Deleting an item removes it from your account, but related media files and run records may remain in our storage until you ask us to delete your account.
* **Connected accounts.** YouTube and TikTok credentials and profile details are kept until you disconnect the account in Settings → Connected accounts.
* **Share links.** A share link stays active until it expires (if you set an expiry) or you revoke it.
* **Payment and credit records** are kept as long as required for tax, accounting, and fraud-prevention purposes, even after an account is deleted.
* **Short-lived data.** Sign-in sessions expire after 30 days; sign-in and connection codes expire within minutes; rate-limit records, which can include IP addresses, expire automatically shortly after their time window ends; and the temporary working files created while a run is processed are deleted when it finishes. Our worker logs are kept for 14 days.
* **Backups.** Our databases keep point-in-time backups for up to 35 days, so deleted information can remain in backups for that period.

To delete your account and the content in it, or to request deletion of other personal data, contact [**hello@trezalabs.com**](mailto:hello@trezalabs.com) from the email address on your account. We will delete or de-identify your information, subject to the legal and contractual obligations above.

***

#### 5. Data Sharing and Disclosure

We do not sell your personal data. We share data only as follows:

**Service Providers:** Third-party providers that help us operate the Service, including the model, hosting, payment, email, and analytics providers listed in Sections 2 and 3.1.\
**Platforms and Destinations You Choose:** When you publish to YouTube or TikTok, deliver files to your cloud storage, or send data to a web address or email address from a pipeline, we send it where you direct.\
**AI Assistants You Connect:** At your direction, we send an assistant you connected the account information its requests ask for, as described in Section 2.3.\
**Share Links and Media Links:** Anyone who has a share link you create can view what it shares, unless you protect it with a password. Links to your media files are unlisted but not secret: anyone who has a media link can open that file, so share them with care.\
**Partners:** If you sign up or buy credits after following a partner's link, the partner can see that a referred sign-up or purchase happened and its amount, but not your name or email address.\
**Fraud Prevention:** If we block an account for fraud or abuse, we may add its payment customer ID and email address to Stripe's fraud-prevention block lists.\
**Legal Compliance:** If required by law, we may disclose information to law enforcement or regulatory authorities, or to protect the rights, property, or safety of Treza, our users, or others.\
**Business Transfers:** In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

***

#### 6. Security

We implement reasonable technical and organizational measures to protect your data, including encryption in transit, encryption of stored media and databases, encryption of stored secrets, provider keys, and OAuth refresh tokens for connected YouTube and TikTok accounts, signed links for media delivery, and access controls that limit which Treza personnel and systems can reach your data. However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and Treza API keys confidential and for not embedding them in client-side code.

***

#### 7. Your Content and Generated Output

You retain your rights to your Inputs, and, to the extent permitted by law and the applicable model provider's terms, you own your Outputs. Because of the nature of generative models, Outputs may not be unique. Generative models can also produce inaccurate content, and you should verify Outputs before relying on them. See our [Terms of Service](/terms-and-privacy/terms-of-service.md) for details on content ownership and acceptable use.

***

#### 8. Your Rights

Depending on where you live, you may have the right to:

* Know what personal information we hold about you and access a copy of it
* Correct, update, or delete your personal information
* Object to or restrict certain processing of your data, including processing based on our legitimate interests
* Request a portable copy of your data
* Withdraw consent where we rely on it
* Opt out of the use of your information for targeted advertising
* File a complaint with a regulatory authority

To exercise these rights, contact [**hello@trezalabs.com**](mailto:hello@trezalabs.com). We will verify your request using the email address on your account, and you may use an authorized agent where the law allows. We will not discriminate against you for exercising your rights.

**Legal bases (EEA, UK, and Switzerland).** We process your information to perform our contract with you (running the Service, processing payments, publishing to accounts you connect); for our legitimate interests (securing the Service, preventing fraud and abuse, understanding how the Service is used, measuring and improving our marketing, and contacting businesses about Treza); to comply with legal obligations; and with your consent where the law requires it.

***

#### 9. International Data Transfers

We store data in the United States, and our providers may process it in the United States and in other countries where they operate. Where we transfer personal data across borders, we take steps to ensure it receives an appropriate level of protection consistent with applicable law.

***

#### 10. Children's Privacy

The Service is intended for people who are at least 18 years old (or the age of majority where they live) and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us so we can delete it.

***

#### 11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will notify you through the Service or by other means. Your continued use of the Service after any modifications constitutes acceptance of the updated Privacy Policy.

***

#### 12. Contact Information

If you have any questions about this Privacy Policy or how we handle your data, please contact us at: [**hello@trezalabs.com**](mailto:hello@trezalabs.com)

***

By accessing or using Treza, you acknowledge that you have read, understood, and agree to this Privacy Policy.
