Privacy Policy
Last updated: October 2, 2026
This privacy policy describes how SiVideoAPI (sivideoapi.com) handles personal data. SiVideoAPI is an SI video API (SI = super intelligence; the same technology was formerly called AI): developers send a prompt or an image and get a rendered video clip back. The privacy policy covers the website, the dashboard where you manage API keys, and every request made to the /v1 endpoints.
Who this privacy policy is about
For your own account data, as the developer or business that signs up, buys credits and holds keys, we are the controller. When your app forwards its users’ prompts or photos to the API, you decide what is sent and why, so you are the controller of that content and we process it for you, as a service provider, only to render the videos you request.
Information we collect
This privacy policy groups the data we hold into seven kinds:
- Account details: email address and, with Google sign-in, your name, profile picture and Google ID, plus the approximate country of sign-up.
- API key records: each key’s name, its first 12 characters (the prefix), a SHA-256 hash of the full key, and when it was created, last used and revoked.
- Request content: prompts sent to
POST /v1/videos, images sent toPOST /v1/uploads, and the resulting videos. - Job records: model, mode, duration, resolution, aspect ratio, audio setting, credit cost, timing and any error message.
- Billing records: credit balance and ledger, claimed gifts, and orders (pack, amount, currency, date, payment reference). Card numbers go to Stripe, never to us.
- Feedback and invites: a star rating and comment sent through the gift center, and your invite code plus the sign-ups credited to it.
- Network data: IP address, user agent and timestamps in request and security logs, used for rate limiting and abuse prevention.
How your API keys are stored
You create keys in the dashboard after signing in with Google or a one-time email link, up to 10 active keys per account. The full key is displayed once, when it is created. After that we keep only its hash, prefix, name and timestamps, so nobody at SiVideoAPI can read or recover it; a lost key must be revoked and replaced. The last-used time refreshes at most every five minutes, which helps you notice a key that should be idle.
What happens when you call the API
- We hash the key in your
Authorizationheader and match it against the active keys on file. - The prompt text is screened by an automated filter (Meta Llama Guard on Cloudflare Workers AI). Uploaded images are not screened at this step. If the filter is briefly unavailable, the request continues and the model provider’s own safety checks still apply.
- The prompt, your settings and a link to any uploaded image are passed to fal.ai, the inference platform hosting the model you chose: Google Veo, ByteDance Seedance, Kuaishou Kling, Alibaba Wan, xAI Grok Imagine or MiniMax.
- The finished file is copied into our Cloudflare R2 storage and returned as
video_url. - The job record stays in our database so we can bill the render, refund failures and answer support questions.
Media links are unlisted, not private
Videos and uploaded images are served from long, random addresses under sivideoapi.com/media. They are practically impossible to guess, but they need no API key: anyone holding a URL can view or download the file. Treat every video_url like a secret link, and call DELETE /v1/videos/:id to remove a clip from storage straight away.
Content you send for your own users
If your product forwards end-user prompts or photos to us, you need the rights and any consent required, and your own privacy policy should tell users that a third-party video service processes their content. Leave out data the render does not need, such as names, contact details or health details inside prompts. We use end-user content only to deliver your videos. Questions about how we process data for you: support@sivideoapi.com.
How we use information
We use the data covered by this privacy policy only:
- to run your account, authenticate API keys and keep the dashboard signed in;
- to render, store and return your videos;
- to charge credits, process purchases, refund failed renders and answer support requests;
- to enforce rate limits, stop abuse and uphold the Terms of Service;
- to send sign-in links and account or purchase messages (no marketing email unless you opt in).
We do not sell personal data, none of your prompts, images or videos is used to train models, and we never publish your content.
Service providers we rely on
- Cloudflare: runs our servers, database, R2 storage, sign-in emails and the prompt filter.
- fal.ai and the model vendors behind it: the prompt and image of a request, only to produce that video, under their own privacy terms.
- Stripe: processes card payments; checkout is opened by our own payment gateway.
- Google: handles sign-in when you pick Continue with Google.
Some providers process data in the United States or in other countries than yours, relying on their published transfer safeguards.
Analytics on the website only
Our pages and dashboard load a self-hosted copy of Umami from our own domain, which records page views plus a handful of events, such as a key being created or revoked (never the key itself), with referrer, browser, device type and country. IP addresses are used to derive the country and are not stored raw, and Umami sets no cookies. API traffic never reaches analytics: calls to /v1 are logged only for operations and security.
Cookies and browser storage
We set a single cookie, sid, an essential session cookie for the dashboard that lasts up to 60 days. Google and Stripe place their own cookies on their sign-in and checkout pages. An invite code from a referral link is held in local storage for 30 days, and session storage remembers that you closed the offer banner. There are no advertising or cross-site tracking cookies.
How long we keep data
- Account and credit history: while the account exists.
- Rendered videos: until you delete them through the API or the account is deleted.
- Uploaded images: removed automatically 30 days after upload.
- Job records: kept for billing after a video is deleted; prompts and settings are cleared on account deletion.
- Revoked keys: name, prefix, hash and dates stay with the account as a security record; a revoked key never works again.
- Orders: as long as tax and accounting rules require.
- Sessions and sign-in links: up to 60 days and 20 minutes respectively.
Deleting your account
Email us from the account address and, within 30 days, we erase your videos and uploaded images, sign out all sessions, clear the prompts and settings in your job records, revoke every API key, and swap your email and profile for an anonymous placeholder. Orders and credit entries survive only in anonymized form, for accounting.
Security
All traffic uses HTTPS. API keys, session tokens and sign-in links exist in our database only as SHA-256 hashes, so even someone holding a full copy could not turn them into working credentials. Production access is restricted to the people who run the service. If a key may have leaked, revoke it at once and tell us.
Your rights under this privacy policy
To get a copy of your data, fix something or have it erased, write to support@sivideoapi.com from your account address. Residents of places such as the EU, the UK and California may have further rights, like objecting to or limiting processing and lodging a complaint with their regulator. We never sell personal information or share it for advertising, and using a right will not change how we treat you. End users of an app built on our API should contact that app first; we will help its developer respond.
For users in the EEA and the UK, this privacy policy relies on performing our contract with you, our legitimate interests in security, abuse prevention and improving the service, legal duties such as bookkeeping, and, where required, your consent.
Children
The service is restricted to people aged 18 or older. If we learn that a minor has opened an account, we close it and delete its data, so please tell us if you know of one.
Updates to this privacy policy
If the way we handle data changes, this privacy policy will be revised and its Last updated date moved forward; significant changes are also announced by email or in the dashboard. Send any question about this privacy policy to support@sivideoapi.com.
