Log in
Legal

Privacy Policy

Cloud Creator LLC · ozu.studio

Effective date: June 12, 2026 · Last updated: August 29, 2026

Ozu: Privacy Policy

Effective Date: June 12, 2026 Last Updated: August 29, 2026 Version: 1.7


Table of Contents

  1. Who We Are
  2. What We Collect
  3. How We Use Your Information
  4. How We Share Your Information
  5. Data Retention
  6. Your Rights and Choices
  7. Cookies and Tracking
  8. Children’s Privacy
  9. AI-Specific Disclosures
  10. International Data Transfers
  11. Security
  12. Changes to This Policy
  13. Contact Us

1. Who We Are

Ozu is operated by Cloud Creator LLC, a Wyoming limited liability company.

For purposes of data protection law (including GDPR where applicable), we are the data controller of your personal information.

Privacy Contact: Email: [email protected] Mailing: Cloud Creator LLC, c/o Northwest Registered Agent, 30 N Gould St, Ste N, Sheridan, WY 82801


2. What We Collect

2.1 Information You Give Us

Account Information When you sign up, we collect:

  • Name or display name
  • Email address
  • Profile information if you sign in with Google (name, email, profile photo, Google Account ID)
  • Profile information if you sign in with Apple (typically your name, email address or a private relay email Apple generates, and an Apple user identifier)
  • Password (stored as a cryptographic hash; we never store plaintext passwords)

Payment Information Payments are handled by Stripe, Inc. We don’t collect or store full card numbers. What we receive from Stripe:

  • Last four digits of your card
  • Card type and expiration date
  • Billing country
  • Stripe Customer ID
  • Subscription status and plan

We do not receive Apple payment card details or iCloud contents when you use Sign in with Apple or buy through the App Store. Apple purchase/transaction identifiers are described in Section 4.1.

Content You Create When you use the Service, we store in your account:

  • Project names and descriptions
  • Scripts and text you submit for analysis
  • AI generation prompts and parameters
  • Generated images, video, audio, and storyboard frames
  • Canvas layouts and node configurations
  • Audio metadata (file names, BPM data, lyric sync data)
  • Voice recordings you make in the app to use as a performance. The recording is saved on your device, and a copy is stored with each project you use it in. When you use it to generate dialogue it is sent to the provider that renders the dialogue, as reference audio (see Sections 4.1 and 9). You can delete either copy at any time.

BYOK API Keys (if you enable BYOK) Your third-party API keys are stored encrypted in our database. They are never stored in your browser, and are accessed only by our server infrastructure to make API calls on your behalf. See the BYOK Addendum.

Support Communications Messages and feedback you send us.

Likeness consent (people who may not have an Ozu account) If a user sends someone a likeness-consent form (for example, a friend who appears in a recording used as video-to-video reference), we collect from the person who signs:

  • Name
  • Email address
  • The fact of their agreement, the text they agreed to, and an electronic signature (typed name plus click, timestamp, and IP address)
  • The project the consent is attached to, and whether the permitted use is personal or commercial

We collect this so we have a record that the depicted person permitted this use. Signing the form does not create an Ozu account.

Waitlist / Request Access (people who may not have an Ozu account) If you submit an email on the landing page to request closed-beta access, we collect:

  • The email address you submit
  • A timestamp of the request
  • A source label from the form (where the request was submitted)

We store that record in Cloudflare KV. Signing up for the waitlist does not create an Ozu account. We keep the email so we can invite you when a closed-beta spot opens. It is not a marketing list unless you separately opt in, which this form does not do. The waitlist is for people 18 and over, same as the Service.

2.2 Information Collected Automatically

When you use the Service, we and our service providers automatically collect:

Usage Data

  • Features used and actions taken in the app
  • Credits consumed and types of operations performed
  • Session duration
  • Error and performance data

Diagnostics and Crash Reporting On the iPad app, we use Sentry to collect crash reports and performance diagnostics so we can keep the app stable. This includes device/OS context, stack traces, and related technical signals when something fails. Crash data is used for app functionality (reliability), is not linked to your identity, and is not used for tracking or advertising. Optional in-app bug reports you choose to send may include account context so we can help you. Sentry is not a browser cookie.

Device and Technical Data

  • IP address
  • Browser type and version
  • Operating system
  • Referring URL
  • Date and time of access

Authentication Session Data Firebase Authentication issues a short-lived ID token (about 1 hour, auto-refreshed while you’re active). On the web, that token is stored in your browser’s local storage and is used to verify your identity. It is separate from any first-party session cookie (__pp_session) described in our Cookie & Analytics Policy.

2.3 Information from Third Parties

If you sign in with Google, we receive your name, email address, Google Account ID, and profile photo. We don’t receive access to your Google Drive, Gmail, or other Google services.

If you sign in with Apple, we typically receive your name (if you choose to share it), an email address (your real address or Apple’s private relay address, depending on what you select), and an Apple user identifier. We do not receive your Apple payment details or the contents of your iCloud account.


3. How We Use Your Information

We use your information to:

PurposeWhy We’re Allowed (GDPR Basis)
Create and manage your accountContract performance
Authenticate your identity each sessionContract performance / Legitimate interests
Process subscription paymentsContract performance
Deliver AI generation and analysis featuresContract performance
Track credit usage and subscription limitsContract performance
Store your project data across sessionsContract performance
Send transactional emails (receipts, account notices)Contract performance
Respond to support requestsContract performance / Legitimate interests
Detect and prevent fraud and abuseLegitimate interests
Improve the Service (aggregate, de-identified analytics)Legitimate interests
Comply with legal obligationsLegal obligation
Record likeness permission from a depicted personContract performance / Legitimate interests / Consent of the signer
Invite you to closed beta / manage the waitlistLegitimate interests / Consent (you submitted the email for that purpose)

We do not sell your personal information.

We do not use your content to train AI models. Your scripts, prompts, and generated assets are yours. We may use content you provide to improve and develop the operational quality of the Service. If that ever changes we will tell you first, and nothing of yours is included without your explicit approval. Generating your outputs requires sending content to third-party AI providers (Section 4.1), whose own data-use practices vary. See Section 9 for a per-provider summary.

3.1 What we record to improve the app

When you generate or approve something, we store a short structural summary of what happened. An allowlist in our code controls this: anything not on the list is discarded before it reaches storage.

What we record

  • Project shape: genre, script word count, scene, shot, and beat counts, how many characters, props, and sets
  • Shot shape: shot type, camera direction, framing, whether it has dialogue, beat duration
  • What ran: which provider and model, which prompt template version, how many reference images
  • What happened: approved or reworked, which attempt, time to decide, credits to approval

What we never record

  • Your script text, dialogue, or prompts
  • Your images, video, or audio, in whole or in part
  • Your name, email, or account ID in readable form. Project, user, and asset identifiers are one-way salted hashes that cannot be reversed.

Because these records cannot be linked back to you, we keep them indefinitely.


4. How We Share Your Information

We share your data only in the following circumstances:

4.1 Our Service Providers (Sub-Processors)

We work with trusted third-party providers who process data on our behalf:

ProviderWhat They DoData Shared
Google LLC (Firebase)Account authentication, database (Firestore)Account info, project data, usage data
Functional Software, Inc. (Sentry)Crash reporting and performance diagnostics (iPad app)Crash/stack traces, device/OS context, performance signals; not linked to identity for automatic crashes
Cloudflare, Inc.Hosting, CDN, API proxy, file storage (R2), KV store, D1Network traffic, IP addresses, user assets, subscription state
Stripe, Inc.Payment processing (web)Billing info, subscription status, Stripe Customer ID
Apple Inc.App distribution, in-app purchases, and Sign in with Apple (iPad app and web sign-in)Purchase/transaction identifiers; Apple user identifier and name/email (or private relay email) if you use Sign in with Apple
Anthropic, PBCAI text analysis (Ozu assistant)Scripts and text submitted for analysis
OpenAI, L.P.Image generation, 360° panorama generationGeneration prompts, reference images
xAIImage, video, speech-to-text, and text-to-speech generationGeneration prompts, reference images, audio
EvoLinkAI generation gateway. Routes our Midjourney, Kling, Seedance/Seedream, Seed Audio, Suno, Qwen and VideoRetalk jobsGeneration prompts, parameters, reference images/audio
ElevenLabs, Inc.AI voice generation and audio tools (TTS, voice clone, sound effects, music)Dialogue text and reference audio
Replicate, Inc.Music structure analysis, dialogue/foley separationProduction audio
Google LLCAI image, video (Veo), music (Lyria), and speech/TTS modelsPrompts, reference media, audio, and text submitted for those features
Blockade Labs, Inc.Skybox generationEnvironment/scene text prompts
World Labs, Inc.3D environment generation (not currently reachable in the app)Panorama image inputs

Each provider is subject to its own privacy policy and terms. Where required by law (including GDPR), we maintain Data Processing Agreements with our processors. The set of AI model providers changes over time as models are released and retired.

Note on training practices: Providers differ on whether their terms permit training on what we send them. Midjourney and Kling, both reached through our generation gateway, and World Labs, permit it. Models reached through the gateway are operated by third parties whose practices we don’t control. Every model in the app carries a mark showing where its provider stands; Section 9 lists them provider by provider.

We may disclose your information if required by law, court order, or governmental authority, or if we have a good-faith belief that disclosure is necessary to:

  • Comply with a legal obligation
  • Protect the safety or rights of Ozu, our users, or the public
  • Prevent fraud or illegal activity

4.3 Business Transfers

If Ozu is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We’ll notify you before your information becomes subject to a different privacy policy.

We may share information in other ways with your explicit consent.


5. Data Retention

We don’t keep your information longer than we need to.

Data TypeHow Long We Keep It
Account information (name, email, UID)Until we remove the account from Ozu servers (see below) + 30 days to finish cleanup
Project data (scripts, assets, canvas layouts)Until we remove the account from Ozu servers + 30 days to finish cleanup
Payment and subscription records7 years from transaction date (tax and financial law)
Subscription consent records3 years from consent, or 1 year after cancellation (whichever is longer)
Support communications3 years
Fraud prevention and security recordsUp to 3 years from incident
BYOK API keysUntil BYOK is disabled + 30 days for cleanup
Likeness-consent records (signer name, email, signature, form text)Life of the associated account + 3 years, or 3 years after the signer revokes future use, whichever is longer. We keep the signed record even if the user deletes the clip. The clip is not the cover. The signature is.
Waitlist emails (Request Access)Until we invite you and you create an account, you ask to be removed, or we shut the waitlist down; then we delete the record from KV. If you become a user, the account-information row in this table applies instead.
Aggregate de-identified analyticsIndefinitely (cannot identify you individually)

Inactivity. If a paid subscription ends (you canceled or it lapsed) and you do not start a new paid plan, we treat that as inactivity. Twelve months after that end date we remove the account and project files from Ozu servers. About 15 days before, we email you. Signing in on the Free tier does not pause this clock. Resubscribing does. This is how we avoid holding project files forever. Canceling a subscription is not the same as asking us to remove the account.

When we remove an account from Ozu servers (after inactivity, after we terminate it, or after a valid request to [email protected]):

  • Account info and project data are taken off active databases within 30 days
  • Payment and subscription records are retained as required by financial and tax law
  • Likeness-consent records are kept for the period in the table above, so we can show permission existed
  • Aggregate, de-identified analytics data may be retained indefinitely

The Service does not include a self-serve account-removal button. You cancel. We remove.


6. Your Rights and Choices

6.1 All Users

Account Management: You can review and update your account info at any time in Account Settings.

Account removal: There is no in-app control to remove the account yourself. Cancel a paid plan from the Ozu app, Account Settings, or the Credit Purchase Screen. We remove inactive accounts from Ozu servers as described in §5. To ask us to remove an account sooner, email [email protected] or [email protected].

Email Opt-Out: Unsubscribe from non-transactional emails via the unsubscribe link in any such email. Transactional emails (receipts, critical notices) cannot be opted out of while your account is active.

If you signed a likeness-consent form and you do not have an Ozu account: email [email protected] or [email protected] to see what we hold, correct it, or to stop future use of your likeness in new generations. Stopping future use does not erase output already generated. We may keep the signed record as evidence that permission existed at the time.

If you joined the waitlist and you do not have an Ozu account: email [email protected] to be removed. You do not need to create an account.

California residents have the following rights under the California Consumer Privacy Act (CCPA):

Right to Know: Request information about what personal data we’ve collected about you, why we collected it, and who we’ve shared it with.

Right to Delete: Request deletion of your personal information (subject to exceptions required by law).

Right to Correct: Request correction of inaccurate information we hold about you.

Right to Opt Out of Sale/Sharing: We do not sell your personal information and do not share it for cross-context behavioral advertising. You can submit an opt-out request at ozu.studio/legal/privacy#do-not-sell or by emailing [email protected]. We’ll confirm and process your request within 15 business days.

Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

Global Privacy Control (GPC): We honor the GPC browser signal as a valid Do Not Sell or Share request.

To exercise any of these rights, contact [email protected].

If you’re in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under GDPR or equivalent law:

Right of Access (Art. 15): Request a copy of the personal data we hold about you.

Right to Rectification (Art. 16): Request correction of inaccurate data.

Right to Erasure (Art. 17): Request deletion of your data where we no longer have a compelling reason to keep it.

Right to Restriction (Art. 18): Request that we limit how we process your data in certain circumstances.

Right to Data Portability (Art. 20): Request your data in a machine-readable format for transfer to another service.

Right to Object (Art. 21): Object to processing based on our legitimate interests.

Right to Withdraw Consent: Where we rely on consent, you can withdraw it at any time.

Right to Lodge a Complaint: You have the right to complain to your local data protection supervisory authority.

To exercise GDPR rights, email [email protected] with “GDPR Request” in the subject. We’ll respond within 30 days (extendable by 2 months for complex requests).


7. Cookies and Tracking

What we use:

  • Firebase ID tokens: short-lived authentication tokens (~1 hour, auto-refreshed while you’re active) stored in your browser’s local storage. These are essential for keeping you logged in. They are not advertising cookies, and they are not the same thing as the first-party __pp_session cookie.
  • First-party session cookie (__pp_session): a separate session identifier, described in our Cookie & Analytics Policy. It can last up to 14 days of inactivity. It is not a Firebase ID token.
  • Cloudflare analytics: anonymized, aggregate performance and traffic data. No individual tracking. Cookieless.

What we don’t use:

  • Third-party advertising cookies
  • Cross-site behavioral tracking cookies
  • Social media tracking pixels

You can clear cookies and local storage from your browser settings, but this will log you out of the Service.

For full details, see our Cookie & Analytics Policy.


8. Children’s Privacy

The Service is not directed to children under 13, and we don’t knowingly collect personal information from anyone under 13 (consistent with COPPA). The Service also requires users to be at least 18 to create an account. The waitlist is the same: Request Access is for people 18 and over.

If we learn we’ve inadvertently collected information from a child under 13, we’ll delete it promptly. If you believe we may have a child’s information, contact us at [email protected].


9. AI-Specific Disclosures

You’re interacting with AI. Ozu’s Assistant Director (Ozu) is powered by Anthropic’s Claude. Image, video, voice, panorama, and 3D-environment features are powered by third-party AI models reached either directly or through our generation gateway (Section 4.1).

Your content goes to third-party AI providers. When you use AI generation features, your prompts, scripts, reference media, and related inputs are transmitted to the relevant third-party service to generate your output.

We do not train on your content. Ozu does not use your scripts, prompts, or generated outputs to train any AI model. We may use content you provide to improve and develop the operational quality of the Service. If that ever changes we will tell you first, and nothing of yours is included without your explicit approval.

On Studio+ BYOK, generation runs on your own API key instead of our credits. The request is still made by our servers rather than from your device, and we don’t log the content of those calls.

About third-party training practices. The bold mark opening each row below is exactly the mark shown beside that provider’s models in the app: the app reads this table, so the two can never disagree. They describe each provider’s published terms and the account settings we maintain with them, as of the Last Updated date. They are not behavior we can observe inside a provider or guarantee on its behalf.

ProviderWhat we sendTraining
Anthropic, Ozu, script analysisScripts, textRules out training. Their terms rule out training on API content
OpenAI, images, 360° panoramasPrompts, reference imagesRules out training. Their terms rule it out unless we opt in, which we have not
Google, image, video, music, speechPrompts, reference media, audioRules out training. Their paid-tier terms rule it out. We are on a paid tier
xAI, image, video, speech-to-textPrompts, reference images, audioRules out training. Requests held 30 days for abuse auditing, then deleted
ElevenLabs, voiceDialogue text, reference audioRules out training. Their terms permit it by default. We have turned it off at the workspace level, so nothing you send is used for training
Replicate, audio analysis, dialogue separationProduction audioNo commitment. Their terms license customer data to “train and generate Customer Derivative Models” without defining that scope
Seedance / Seedream, via gatewayPrompts, reference mediaNo commitment. Any no-training commitment runs to the gateway operator, not to Cloud Creator
Seed Audio, voice + sound effects, via gatewayDialogue text, reference audio, sound-effect promptsNo commitment. Reached through the gateway, so any commitment runs to the gateway operator rather than to us
Suno, music, via gatewayPrompts, lyricsNo commitment. Reached through the gateway, so any commitment runs to the gateway operator rather than to us
Qwen, speech, via gatewayDialogue textNo commitment. Reached through the gateway, so any commitment runs to the gateway operator rather than to us
Blockade Labs, skyboxesPromptsNo commitment. Silent on training
Midjourney, images, via gatewayPrompts, reference imagesAllows training. Their terms take a perpetual, irrevocable license over prompts and reference images, with no opt-out at any tier
Kling, video, via gatewayPrompts, reference mediaAllows training. An opt-out exists, but it belongs to the gateway operator’s account rather than ours
World Labs, 3D environmentsPanorama imagesAllows training. Their terms permit it. Not currently reachable in the app

A note on the gateway. Models marked “via gateway” are reached through EvoLink rather than a direct contract with the provider. Our agreement is with EvoLink, so we cannot audit or warrant what the underlying provider does with a request.

AI outputs may not be copyright-protected. Under US law, purely AI-generated works are generally not eligible for copyright protection. See our Terms of Service (Section 6.2) for the full disclosure.

AI outputs are not guaranteed. Generated images, text analyses, and other outputs are AI-generated creative tools, not verified facts. Don’t rely on them for legal, financial, medical, or safety decisions.


10. International Data Transfers

Ozu is based in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the United States.

For users in the EEA, UK, or Switzerland: we rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers of your personal data to the US, or the UK International Data Transfer Agreement (IDTA) as applicable.


11. Security

We protect your information using:

  • HTTPS encryption for all data in transit
  • Firebase Authentication for secure identity management
  • Firestore security rules restricting database access to authenticated users only
  • API keys stored encrypted at rest (not in your browser)
  • Cloudflare infrastructure with DDoS protection

No internet transmission or storage is 100% secure. While we take reasonable precautions, we can’t guarantee absolute security. In the event of a breach affecting your rights, we will notify you as required by law.

More detail is on our Security page.


12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Post the updated Policy at ozu.studio/legal/privacy with a new “Last Updated” date
  • Notify you by email or prominent in-app notice

We encourage you to review this Policy periodically.


13. Contact Us

For general privacy questions: Email: [email protected]

For California (CCPA) requests: Email: [email protected], Subject: “CCPA Request”

For EU/UK (GDPR) requests: Email: [email protected], Subject: “GDPR Request”

Mailing address: Ozu / Cloud Creator LLC c/o Northwest Registered Agent, 30 N Gould St, Ste N, Sheridan, WY 82801


Revised August 29, 2026 (v1.7): named voice recordings you make in the app as content we store — saved on your device with a copy in each project you use them in, and sent as reference audio to the provider that renders dialogue (§2.1). No change to the provider tables: a recorded voice travels the same route, and under the same terms, as the reference audio already described there.

Revised August 15, 2026 (v1.6): defined inactivity (12 months after a paid plan ends without a new paid plan); account and project files are then removed from Ozu servers, with a 15-day notice; cancel is not self-serve account removal. Same-day earlier revision (v1.5.1): reconciled the app and website copies onto one source of truth (the iPad app bundle, App/Resources/Legal/); the Seed Audio row now also names sound-effect generation, which it performs for the SFX room. No other substantive change.

Revised August 13, 2026 (v1.5): named the closed-beta waitlist / Request Access — email, timestamp, and form source label we store in Cloudflare KV; invite purpose; retention until invite, removal request, or shutdown; removal by email without an account (§2.1, §3, §5, §6.1, §8). Earlier same-day public revision (v1.4): added likeness-consent records for non-user signers (§2.1, retention, rights to stop future use); added Sign in with Apple to §§2.1 and 2.3; added xAI to the §4.1 sub-processor table and expanded the Google AI row to image, Veo video, Lyria music, and TTS; named Seed Audio on the EvoLink row and in the §9 table (via gateway; no training commitment — same posture as other gateway audio we do not contract with directly); clarified that Firebase ID tokens (~1 hour) and the __pp_session cookie (up to 14 days) are different; pointed cookies at /legal/cookies/; noted Sentry is iPad crash diagnostics, not a browser cookie. Earlier public revisions: July 25, 2026 (provider data-use audit; BYOK calls made by our servers; xAI 30-day abuse hold; OpenAI / Replicate / Midjourney disclosed; §9 per-provider table; §3.1 structural learning signals; ElevenLabs workspace training opt-out); June 12, 2026 (Wyoming entity and registered-agent address, iPad/Apple, current sub-processor list, training claim scoped to Cloud Creator).