Back to home

Privacy Policy

How Zombiv uses photos, keeps media private and handles deletion.

Last updated: 2026-10-10

What your photos are used for

Zombiv uses two authorized adult photos to validate and normalize the images, check safety, generate the predefined Zombie Love Story, and provide private playback and download. The service synthesizes the depicted people's likenesses into fictional AI video. We do not sell user photos. Your upload does not authorize us to publish it as an advertisement or sample.

Private by default

Ordinary uploads and creations are not publicly listed or automatically published. Playback and download require account authentication and ownership checks. Cloudflare R2 stores media privately. Time-limited media links can be used by anyone you share them with while they remain valid. You control any sharing or download outside Zombiv.

The homepage portraits and sample video are separately authorized promotional assets. They are deliberately public and are not ordinary customer uploads.

Photos on your device

Selection initially creates a local preview, not a cloud upload. Draft photos can be stored in this browser's IndexedDB for up to a 24-hour validity window to survive sign-in. Expired drafts are cleaned when you return; a closed browser cannot reliably delete them at exactly 24 hours. Clear photos, replacement and successful transfer can remove copies earlier. Clear drafts on shared devices.

Photos and base64 images are not placed in page URLs, OAuth state or analytics. The upload flow normalizes accepted images and removes EXIF metadata.

Required third-party processing

Cloudflare provides hosting and private R2 media storage. Waffo Prompt Sift receives the fixed server story text for a pre-generation safety check. We do not send user photos or signed media URLs to that text endpoint. When the Creem channel is enabled, its Moderation API additionally receives the fixed story text and an internal task/intent reference. This integration remains disabled pending configuration and acceptance; we do not claim that Creem retains no data. Waffo describes this check as stateless and not retaining prompt text after the response. We retain redacted verdicts and human decisions (request ID when available, task reference, template version/hash and timestamps) for safety review and disputes. When generation is enabled, Kie.ai and its selected model provider receive reference photos through expiring links and our fixed story instructions to create the video. Reference-to-video requests use the configured ByteDance Seedance model; historical tasks may use Kling. Provider safety restrictions apply; we do not bypass provider rejections of real-person references.

Authorized administrators may inspect private inputs and outputs for safety review. Optional automated moderation can send images/videos and safety instructions to Kie and its selected safety model, or to Google's Gemini API when that adapter is enabled. Automated moderation is not currently enabled for public generation. Public generation and purchases are currently unavailable.

Kie's published retention information describes generated media retained for 14 days and text/metadata logs for two months. It does not specify every input-photo copy's retention period. Provider terms and the applicable account contract govern those copies; Zombiv cannot promise that providers erase every copy within our 24-hour input window or that providers never retain safety logs. Input-photo handling and the selected provider/account terms still require confirmation before paid public launch.

If Google-direct Gemini moderation is enabled, the application requires confirmation of active billing. Google's paid API terms govern processing. Temporary video Files objects are requested for deletion after classification; failed requests are persisted for cleanup retry. Google's Files documentation describes automatic expiry after 48 hours. File deletion does not establish deletion of all provider logs or copies. We do not claim a universal no-training or immediate deletion guarantee for all providers.

Storage and deletion rules

Uploaded inputs become unusable for new creation after 24 hours and are scheduled for deletion. Temporary upload objects are also scheduled for cleanup after 24 hours. Saved videos are available for 30 days, with expiry shown in My Creations. Download before expiry if you want a copy.

Logical expiry blocks new access immediately. Physical deletion uses application cleanup and storage lifecycle rules; timing can vary. Delete creation removes access and schedules cleanup. Deleting an active task closes delivery so a late result is not made available. Previously downloaded or shared copies are outside our control.

Limited order, Credits, consent, moderation and security audit records can remain for bookkeeping, refunds, disputes and abuse prevention. Media deletion is separate from these records. Consent records include the accepted version, server timestamp, user/task references and photo references; they are not proof of verified age or identity.

Accounts and payment

Google sign-in provides basic profile information (name, email and profile image) for the application session. Essential session cookies keep you signed in. We do not request Google Drive or Gmail access. Waffo Pancake or Creem handles checkout and payment details when its payment channel is enabled. The selected processor is shown in checkout. Zombiv retains order references, amounts, currency, verified payment status and the Credits ledger; it does not store full card numbers.

Operational analytics use limited task/order/event identifiers, not private media, raw story prompts, signed URLs or secrets. Support and session replay tools must not capture photo previews. We use access controls and secure transport; these do not guarantee perfect security.

Request deletion or report a concern

Use Clear photos for device drafts and Delete creation for saved results. Email support@zombiv.com to request photo, video or account deletion, or access/correction/export. Include the account email and creation reference if known. We verify ownership and may retain records required for lawful purposes. Do not send secrets or unnecessary private imagery. A depicted person without an account can use Report Abuse to request removal of unauthorized likeness use. No fixed deletion completion time is promised for all copies.

Related policies

Terms · Privacy · Acceptable Use · Safety & Consent · Report Abuse · Refund Policy · Pricing · Support