Privacy Policy
Vgent has no accounts, no ad network and nothing to sell about you. This page states what the site handles, who else sees it, how long it stays and what you can ask us to do about it.
The short version: to render a clip we pass your prompt and settings to our model provider, and on our own servers we keep only what the free limits, duplicate protection and debugging genuinely need. There is no sign-up form, no advertising tag and no cross-site tracking on this site. The table below is the complete list.
| Data | Why we handle it | How long it stays |
|---|---|---|
| Anonymous session cookie (vv_anon) | Ties a generation to the browser that started it, so only that browser can follow it. Not an account. | 12 months, or until you clear cookies |
| Language cookie (vgent-locale) | Remembers the language you picked in the switcher. | 12 months |
| Prompt and generation settings | Sent to aivideoapi.ai to render the clip you asked for. | Not stored on our servers; a hash of the request is kept 24 hours |
| Request logs | Request id, anonymous session id, event, model, task status, error code, estimated cost and prompt length — never the prompt text. | Our hosting platform’s log retention; no separate archive |
| Hashed IP counters | Free rate limits and the shared daily budget, counted against a hash instead of the address. | 10 minutes to 48 hours |
| Task records | Task id, model, resolution and a request fingerprint, so a retry is never charged twice. | 24 hours |
| Browser storage | Your library, drafts and queue, kept in this browser under vv. and never uploaded. | Until you clear this site’s data |
| Attached media | Inspected in your browser to check format and size; uploads are not connected yet. | Never leaves your device |
1.Who we are
Vgent.ai is an AI video generation site operated by Vgent Labs Pte. Ltd.. This policy describes the product as it actually works today — anonymous, unbilled and rendered through an external model provider — rather than a roadmap of what it may become.
Anything on this page can be questioned, and the mailbox below is the right place to do it.
- Operator: Vgent Labs Pte. Ltd.
- Registered address: 68 Circular Road, #02-01, Singapore 049422. These registration details are provisional and are updated here once the entity’s filing is complete.
- Privacy contact: privacy@vgent.com
2.What this policy covers
It covers the vgent.ai website, the prompt composer on the home page, the workbench and the same-origin endpoints this site calls to submit and follow a generation. The public API is not open yet, so there is no developer key or webhook to describe here.
It does not cover what happens once a result leaves us: the model provider’s own notices, the platforms you publish to, or any external site you reach from a link.
- Covered: this website, the composer, the workbench and the generation endpoints they call.
- Not covered: the model providers' own products, the social platforms you upload results to, and external sites we link to.
- Not applicable yet: accounts, billing and public API keys, because none of them exist.
3.What we collect
A generation needs surprisingly little, and we ask for nothing beyond it. There is no registration form on this site, so we never receive a name, an email address or a payment detail.
- An anonymous session id. A random identifier in the vv_anon cookie, created the first time you submit a generation. It is http-only, unreadable by scripts, and tells us only that two requests came from the same browser.
- A language preference. The vgent-locale cookie, written only when you pick a language yourself. It holds a two-letter code.
- Your prompt, settings and any source reference. Passed to aivideoapi.ai so the clip can be rendered. On our side we keep a hash of the request, not the text of it.
- Request logs. Every request carries a correlation id; the log line records that id, the anonymous session id from the cookie, the event, model, task status, error code, estimated credit cost and the length of the prompt — never its content, and never media or keys.
- Abuse counters. Your IP address is hashed with SHA-256 into a counter key so the free limits hold across servers. Our own code never writes the address itself down, although access logs kept by our hosting platform may record it, as they do for any website.
4.What we do not collect
Part of this list is a deliberate choice and part of it simply does not exist yet. Either way, it is what the site does not do today, and this page changes before any of it does.
- No account profile: no name, email, password or payment detail, because there is no sign-up and no checkout.
- No advertising or analytics SDK: no third-party tag on the page, no pixel, no cross-site identifier and therefore no consent banner.
- No prompt archive: prompt text is passed on for the render and is not stored in any database of ours; the logs record its length.
- No history on our servers: your library, drafts and queue live in this browser’s local storage, not in an account.
- No device fingerprinting, no data brokers, and no sale or sharing of personal information for advertising.
5.Cookies and browser storage
Two cookies, both strictly functional. Neither is used for measurement or advertising, and the site sets nothing you would need to opt out of.
Everything else the workbench remembers is local storage in your own browser, under the vv. prefix: the clips in your library, the running queue and a couple of layout preferences. It is never uploaded and disappears when you clear this site’s data.
- vv_anon — anonymous session id, http-only, 12 months. Without it a submitted generation cannot be followed back to you.
- vgent-locale — the language you chose, 12 months, written only when you switch language.
- Local storage under vv. — library, queue and layout, held in this browser only.
- Clearing or blocking them is safe: you lose the local library and the link to running tasks, and nothing else.
6.How we use it
Every use below is either the thing you asked for or the thing that keeps a free, anonymous tier survivable for everyone else.
Where the GDPR or a comparable law applies, we rely on performing the service you requested for the render itself, and on our legitimate interest in a working, non-abused service for the limits, logs and security measures.
- Rendering: sending your prompt and settings to the provider and returning the result to your browser.
- Free limits: enforcing the 300 provider-credit cap on a single clip, 5 submissions per 10 minutes from one network address, and the daily provider budget shared by all anonymous traffic. The 200-credit allowance is a display figure; no per-visitor balance is counted on our servers.
- Duplicate protection: matching a retry to the request it repeats, so one submission is never billed twice.
- Debugging: following a single request id through the logs when a generation fails.
- Security: detecting automated abuse and protecting the service and its provider budget.
7.Model providers and transfers
Generation does not happen in-house. Your prompt, settings and any source reference are sent to aivideoapi.ai, which routes the job to the vendor behind the model you selected. They process it under their own terms and privacy notices, which are worth reading if your prompt is sensitive.
The rendered file is hosted by the provider, not by us. Where a model states a lifetime, its link expires roughly 24 hours after the render, and a finished clip stays eligible as a continuation source for 24 hours. Download anything you want to keep.
- aivideoapi.ai — runs the generation and hosts the output.
- The model vendor behind the model you chose — receives the job through the provider.
- Our hosting platform, and where configured a managed key-value store that holds the counters and task records described above.
- These providers may operate outside your country, so your prompt may be processed abroad. They receive it to render a video, never to profile you.
8.How long we keep it
Nothing here is built for the long term. Most of it expires in hours, and the parts that live longer are the two cookies you can delete yourself.
- Request fingerprints and task records: 24 hours.
- Rate-limit windows: 10 minutes. Daily budget counters: 48 hours.
- Cookies: 12 months from when they were set, or until you clear them.
- Application logs: retained by our hosting platform under its own policy; we do not export them into a separate archive.
- Outputs: held by the model provider under its policy, not by us.
9.Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a copy of it, and to complain to your local supervisory authority. Two of those you can exercise in seconds without us: clearing this site’s cookies and storage removes the only link between this browser and anything we hold.
For a server-side request, write to privacy@vgent.com and include the request id or task id shown with the generation. Without it we usually cannot tell which anonymous record is yours, because there is no name to look you up by. We aim to reply within 30 days and we never charge for a request.
- Access or deletion: privacy@vgent.com, quoting the request id or task id.
- Break the link yourself: clear this site’s cookies and local storage in your browser.
- Output hosted by the provider: ask us and we will pass the request on; the provider’s own retention still applies.
- Complaint: your local data protection authority, whether or not you write to us first.
10.Children
The service is for people aged 18 and over, as the Terms of Service require, and it is not directed to children. If the law where you live sets a higher age for using generative AI tools, that age applies to you.
We do not knowingly collect data from children. If you believe a child has used the site and left data with us, write to privacy@vgent.com and we will delete whatever we can identify. Sexualised or exploitative content involving minors is prohibited outright by the content policy, whoever submits it.
11.How we protect it
The design goal is that a leak of our systems would expose very little, because very little is there. The provider key never reaches the browser, prompts are not archived, and the identifiers we do keep expire on their own.
No system is perfectly safe, and we would rather hear about a weakness than not. The security page describes the controls in place and how to report a vulnerability.
- The provider API key stays in the server environment; generation is proxied, never called from your browser.
- The anonymous session cookie is http-only and same-site, so scripts cannot read it.
- IP addresses are hashed before they become rate-limit counters.
- Continuation sources travel as signed, expiring tokens rather than raw provider ids.
- Log lines are assembled from a fixed set of fields that excludes prompts, media and secrets.
12.Changes to this policy
This page changes when the product does. Uploads, accounts and payments are all still ahead of us, and each one will be described here before it ships rather than after.
We revise the dates at the top with every change and describe anything material on the page itself. Continuing to use the site after a change means you accept the updated policy.
13.Contact
Privacy questions, access requests and deletion requests all reach the same mailbox, and postal mail reaches the registered address below.
- Privacy and data requests: privacy@vgent.com
- Legal notices: legal@vgent.com
- Post: Vgent Labs Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422