Privacy Policy
This Privacy Policy explains how GhostLabs PVT LTD ("GhostLabs", "we", "us" or "our") collects, uses, shares and retains personal information when you visit or use GhostX, GhostXStudio and the websites, applications and creative services that link to this Policy (the "Services"). It also explains the choices available to account holders, visitors, collaborators, people appearing in uploaded material and recipients of shared projects.
1. Scope and responsibility
We are responsible for the personal information we process to operate accounts, provide the Services, manage payments, secure the platform and communicate with users. Where applicable law uses those terms, we act as a data controller or Data Fiduciary for these activities.
If a business customer supplies personal information for a project and determines its purpose, that customer may be the controller or Data Fiduciary and we may act as its processor under an applicable agreement. Contact the customer first about content it controls; you may also contact us and we will assist within our role. A signed data processing agreement governs processing covered by it.
External payment pages, AI services, sign-in providers, social networks and recipients of your content may process information under their own notices. Their independent activities are outside this Policy. This Policy is a notice about data handling; accepting our Terms is not a substitute for any separate consent required by law.
2. Information you provide
Account and profile information. We collect your name, email address, profile image, sign-in identifiers, verification status and account preferences. If you use a password, we store its hashed form. We also record account roles, subscription status and security restrictions.
Creative content. We process prompts, instructions, chat messages, scripts, documents, URLs, brand information, images, recordings, videos, music, project files, storyboards, pitch decks, edits and generated outputs. This material can contain personal information about you, performers, clients and other people. Project history can include previous versions and generation settings.
Voice and likeness information. Voice, dubbing, lip-sync and character features can process faces, voice samples, speech, descriptions, transcripts, reference images and declarations about permission. Cloning can create a reusable voice profile or model identifier. These materials may qualify as sensitive or biometric information under applicable law, depending on their use. Do not upload another person's voice or likeness without the required authority and permission.
Payments and billing. We record purchases, order and payment identifiers, amounts, currency, payment status, billing details you provide, discounts, subscriptions, invoices and credit transactions. Payment credentials entered into payment-provider interfaces are handled by those providers. Our payment records do not ordinarily include your full card number or card security code.
Connected accounts and provider keys. When you connect a social account or supply your own AI-provider credentials, we process the identifiers, permissions, access or refresh tokens, key labels and connection details needed to use that integration. You must have authority to connect the account and use the credentials.
Communications. We collect support requests, feedback, replies, communication preferences and inquiry information. Waitlist or enterprise forms may collect your name, email, company, role, experience, team size, requirements and an optional telephone or WhatsApp number.
3. Information collected automatically and from others
We collect technical and usage information such as IP address, browser and device information, timestamps, requested pages, referral and campaign parameters, job activity, model selection, performance, errors, estimated or actual processing costs and security events. Some features hash IP addresses; other records, including certain signup or waitlist records, may retain an IP address directly.
Safety screening may derive image fingerprints, indications of a face or apparent age, explicit-content scores, likeness flags and reasons for a moderation decision. These are automated inferences that can be inaccurate. The existence of a generated image or a screening result does not prove that no real person is depicted or that permission has been obtained.
Shared pitch decks may record link opens, visitor identifiers, pages or sections viewed, trailer playback and progress, and PDF exports. These reports may be available to the project owner. A recipient label attached to a share link can associate activity with an intended recipient even when the viewer has no account.
Campaign emails may contain a tracking pixel and tracked links that record opens, clicks and unsubscribe events. Email software can preload images, so an open event does not always mean that a person read an email.
We receive information from sign-in providers, connected platforms, payment providers, AI providers, customers or users who identify you in content or invite you where that functionality is enabled, and sources you ask us to retrieve. The information received depends on the permissions and feature involved.
4. How and why we use information
We process information for the following purposes:
- Create and authenticate accounts, maintain preferences, manage access and respond to account requests.
- Store projects, generate and transform content, maintain creative continuity, support editing, and deliver requested exports, shares or social posts.
- Process payments, deliver subscriptions and credits, reconcile transactions, prevent payment abuse and maintain required business records.
- Respond to support and feedback, send service messages, and send optional product or marketing communications where permitted.
- Detect unsafe content, misuse, impersonation, fraud, technical faults and security incidents; investigate complaints and enforce our Terms.
- Measure reliability and output quality, improve prompts and routing, learn from accepted or rejected takes and feedback, and improve the Services as described in section 5.
- Meet legal obligations, respond to valid legal requests, protect rights and establish or defend legal claims.
Where consent is required, we request it for the relevant purpose. Where permitted, processing may instead be necessary to perform a contract, comply with law, or pursue legitimate interests such as security, service reliability and customer support, subject to your rights. Under Indian law, we rely on consent or another ground actually permitted by the law in force; we do not treat a general commercial interest as an independent statutory permission.
If a requested item is necessary to deliver a feature, declining it may prevent that feature from working. We explain any materially different use and obtain additional permission where required before beginning it.
5. AI processing and improvement
To perform your request, relevant prompts, reference material, scripts, audio, images, generated intermediates and settings may be transmitted to one or more AI providers. Automatic routing, retries or multi-step workflows can involve more than one provider. Only the providers used for the selected workflow receive its relevant material; every provider does not receive every upload.
The Services maintain learning and quality records that may include account or project identifiers, prompt hashes, model choices, output links, ratings, accepted or rejected takes, defect reports, repair decisions and preference signals. We use these records to evaluate outputs and improve prompt recipes, model selection and workflow reliability. A prompt hash in one record does not mean that the original prompt is absent from other project or generation records.
Service improvement described here is distinct from training the underlying models of external AI providers. Provider retention, review and training practices depend on the selected service, account configuration and applicable contract. This Policy does not promise that all providers offer zero retention or exclude all training. Where consent or a separate agreement is legally required for a use, we must obtain it.
GhostLabs does not use private customer content to train its own general-purpose AI models without your separate, explicit opt-in consent. Any such consent must identify the proposed use and provide a way to withdraw it. Accepting the Terms, using a paid plan or submitting a support request is not that consent. This commitment does not remove the service-quality processing disclosed above, and it does not represent an unverified promise about an external provider's independent practices.
Automated screening may flag or block content, and automated quality checks may select or reject a generation. They can make mistakes. Contact support@ghostverse.ai to request review of a restriction or report an inaccurate result. These tools do not establish ownership, consent or legal clearance for your content.
7. Who receives information
Service providers. We use providers for hosting, databases, storage, authentication, AI processing, search and retrieval, payments, messaging, security and support. They receive information relevant to their function. Contracts and configurations must reflect the purpose and legal requirements of the processing.
Supported integrations include Razorpay for payments; Google, Firebase or GitHub for sign-in where offered; cloud database and S3-compatible storage services; Search Router for retrieval where enabled; and email delivery through Resend or an SMTP service. Depending on the feature and enabled configuration, AI processing can involve OpenAI, Anthropic, Google, ElevenLabs, Sarvam, fal.ai, Higgsfield, OpenRouter, RunPod, ByteDance or BytePlus ModelArk, MiniMax, Kling, xAI, Suno, Sync.so or OpenMontage. This describes supported integrations, not a representation that every integration is active for every customer.
An intermediary provider may route a request to another model provider. If you use your own provider account, that provider also processes information under your direct agreement. Contact us for the active recipients relevant to a particular workflow.
People you authorize. We disclose content to recipients of share links, collaborators or customer administrators where that functionality is enabled, and social platforms you instruct us to publish to. Administrators may manage access and account or project information within their authorized role.
Legal and business recipients. We may disclose relevant information to advisers, auditors, authorities or other parties where necessary to meet legal obligations, respond to valid process, protect rights or investigate abuse. Information may also be transferred in a merger, acquisition, financing, restructuring or sale, with appropriate protections and any notice required by law.
We do not sell personal information, share it for cross-context behavioral advertising, or use it to deliver behavioral advertising. Disclosures necessary to perform the requested service, process a payment or meet a legal obligation remain subject to the purposes and protections explained in this Policy. First-party service and email-engagement measurements described in section 3 remain disclosed uses; this no-advertising commitment does not mean that the Services collect no usage information.
9. International processing
GhostLabs operates from India. Your information may be processed in other countries where our providers, their infrastructure or authorized personnel operate. Those countries may provide different legal protections.
Processing locations: [INSERT VERIFIED HOSTING BACKUP AND MATERIAL PROVIDER PROCESSING COUNTRIES].
We use transfer arrangements required by applicable law. Where relevant, these may include adequacy decisions, standard contractual clauses, a UK transfer addendum or international data transfer agreement, and additional safeguards. Where Indian sensitive-data transfer rules apply, transfers must meet their protection and necessity or consent requirements. Contact us for information about the safeguards relevant to your data and for an available copy, subject to lawful redactions. We do not represent that a particular transfer mechanism is in place unless it has actually been implemented.
10. Retention and deletion
We retain personal information only for the relevant purpose and legally required or justified periods, considering account activity, the service requested, payment and tax requirements, security, disputes and backup recovery. Different copies can follow different schedules. An obligation to preserve evidence may delay deletion of the relevant records.
The operational retention periods are:
| Record category | Retention rule to be finalized |
|---|---|
| Account and profile records | While required for the account, then [INSERT PERIOD AND TRIGGER] |
| Projects, uploads, outputs and voice samples | During the storage service, then [INSERT POST DELETION OR CLOSURE PERIOD] |
| Learning, moderation, security and usage records | [INSERT PERIODS BY PURPOSE INCLUDING REQUIRED LOG RETENTION] |
| Payments, invoices and accounting records | [INSERT PERIOD REQUIRED FOR APPLICABLE ACCOUNTING AND TAX OBLIGATIONS] |
| Support, waitlist and communication records | [INSERT PERIODS AND SUPPRESSION RECORD RULE] |
| Backups and provider copies | [INSERT BACKUP EXPIRY AND VERIFIED PROVIDER DELETION ARRANGEMENTS] |
Deleting a project, voice profile or connection in the interface may remove the main record without immediately deleting every media file, log, backup or provider copy. An account-wide erasure request should be sent to legal@ghostverse.ai. We assess its scope, applicable exceptions and provider dependencies and explain material limits. Backups retained for recovery should not be used for unrelated active purposes.
Where feasible and lawful, information may be retained in a form that no longer identifies a person. Merely removing a name or replacing it with an identifier does not necessarily make information anonymous.
11. Security
We use access controls and technical measures appropriate to the processing. Existing measures include password hashing, protected authentication sessions, and encryption for stored provider keys and social connection secrets. Authorized personnel may access information when needed for support, operations, security or legal obligations.
No system is completely secure. The Services are not represented as end-to-end encrypted, and encryption of particular credentials does not mean that all project content has the same protection. Keep your credentials secure, use the available account protections and report suspected misuse to support@ghostverse.ai. We investigate incidents and provide notifications required by the law that applies.
12. Your choices and requests
Depending on the law that applies, you may be entitled to information about processing; access or a copy; correction; deletion; restriction or objection; portability; withdrawal of consent; and a complaint to a competent authority. Rights can depend on the processing and are subject to lawful exceptions and the rights of others. India-specific rights, including nomination and statutory grievance rights, apply when the relevant provisions are in force and applicable.
Send requests to legal@ghostverse.ai with the subject "Privacy request", the account email or affected content reference, and the action requested. You may also contact us at +91 73866 84771 for help submitting a request. Do not send a password, payment credential or identity document unless we explain why a proportionate verification step is necessary. We may verify identity or authority, clarify scope and retain a limited record of the request. We respond within the applicable legal deadline and explain any lawful refusal, extension or route to challenge our decision. Exercising a privacy right does not by itself justify discriminatory treatment.
You can use available account controls to update details, unsubscribe from optional communications, disconnect integrations or delete supported items. Unsubscribing does not stop necessary account, billing, safety or legal messages. Disconnecting a social account locally may not revoke the provider's authorization; review permissions with the provider as well. Deleting a saved key does not reverse work already submitted to its provider.
Withdrawing consent does not invalidate earlier lawful processing. It can limit a feature that needs the information, and it does not override processing required by law. If content submitted by another person identifies you, give us enough information to locate it without unnecessarily disclosing more personal information.
13. Children and sensitive material
The Services are intended for adults aged 18 or older and are not directed to children. Children may not create or use an account, including through an adult acting as a proxy. An adult must not submit a child's personal information, image or voice without the authority and verifiable permissions required by law and any feature-specific rules. Account eligibility does not authorize unrestricted processing of children appearing in content.
If you believe that a child has provided information unlawfully, contact us so we can investigate and take appropriate action. Do not upload government identifiers, financial credentials, health information or similarly sensitive material unless necessary for an expressly supported purpose and supported by a lawful basis.
14. Regional rights
European Economic Area and United Kingdom. For controller activities subject to the EU or UK GDPR, we use the following grounds as applicable to the specific activity:
- Contract necessity for account administration, requested generation, project delivery and payment administration when needed to perform our contract with you. For an organization's personnel who are not personally party to the contract, an applicable legitimate interest or other lawful basis is required instead.
- Legal obligations for duties recognized under the applicable EU or UK data-protection framework. A requirement under another country's law needs a separately assessed lawful basis where permitted. Legitimate interests, subject to necessity and the required balancing of rights, for fraud prevention, security, service reliability, complaint handling and proportionate quality analysis.
- Consent for uses that require it, including applicable optional tracking, marketing and any separately offered general-purpose model-training opt-in. Processing special-category information also requires an applicable additional condition; where this is explicit consent, it must be obtained for the relevant use.
You may request access, correction, erasure, restriction or qualifying portability, withdraw consent, and object where the law provides. We normally respond within one month; a necessary extension of up to two further months will be explained within the initial period. Any lawful adjustment for verification or clarification applies only to the request and circumstances the law permits. You may object to direct marketing at any time. You may complain to a competent supervisory authority, including the UK Information Commissioner's Office where applicable.
Where a qualifying solely automated decision has legal or similarly significant effects, the applicable restrictions and safeguards apply, including human intervention and an opportunity to contest the decision where required. Routine AI content generation does not by itself establish that every output is such a decision.
California. If the CCPA applies to us and your information, you may exercise its rights to know or access, delete or correct information, and any applicable sensitive-information limits and sale or sharing opt-out. We do not sell personal information or share it for cross-context behavioral advertising, as stated in section 7. We do not discriminate against you for exercising a protected right. Requests to know, delete or correct generally receive a response within 45 calendar days; a further 45 days may be used where permitted with notice.
An authorized agent may submit a qualifying request with the verification permitted by law. Contact legal@ghostverse.ai to exercise rights or seek voluntary review of a decision, without limiting regulatory complaints. The categories, sources, purposes and recipient descriptions appear in sections 2 to 7. Any required historical or notice-at-collection disclosure must describe actual practice rather than assume the new policy has always applied.
Other locations. Rights under another applicable privacy law, including any required appeal or opt-out, remain available. Send a request to legal@ghostverse.ai or use another method that the relevant law permits. We explain the applicable response and escalation process. Regional rights do not depend on a contractual waiver, and nothing in this Policy removes a right or remedy that cannot lawfully be excluded.
15. Our privacy and creative ethics
Our privacy commitments are no sale of personal information, no behavioral advertising and no use of private customer content to train our own general-purpose AI models without separate opt-in consent. They apply alongside the processing disclosures in this Policy and do not override a stronger protection required by law.
We expect users and operators to respect creator ownership, obtain valid permission for real people's voices and likenesses, protect children, preserve required synthetic-media disclosures, and avoid deceptive impersonation, exploitation and abuse. A model-provider safeguard must not be bypassed to evade a permission requirement. Content provenance, an AI label or a quality score is not a substitute for consent or proof of rights.
People must remain able to understand material uses of their information and raise concerns about automated decisions. We describe uncertainty and limitations rather than claiming that an automated check guarantees accuracy, safety or legal clearance. Complaints about a conflict with these commitments may be sent to the contact in section 16.
16. Complaints and contact
Contact GhostLabs PVT LTD at legal@ghostverse.ai, +91 73866 84771, or the postal address above. For complaints, use the subject "Privacy grievance" and describe the issue and requested resolution. General product and billing support remains available at support@ghostverse.ai.
Grievance Officer: [INSERT NAME AND DESIGNATION].
Grievance contact: legal@ghostverse.ai.
Grievance telephone: +91 73866 84771.
Officer postal address: [INSERT COMPLETE ADDRESS].
Where India's sensitive personal data rules apply, the Grievance Officer will address the grievance within one month, subject to any shorter applicable requirement. Other privacy complaints follow the deadline required by the law in force. You may use a competent regulator or court where entitled; any requirement to first use internal redress applies only where the relevant law requires it.
17. Changes to this Policy
We may update this Policy to reflect changes to the Services, processing or legal requirements. The updated Policy will state its effective date. We give notice of material changes through an appropriate channel and obtain fresh consent where required. A policy update does not retrospectively authorize a use requiring separate permission.
