Skip to main content

Privacy

PrivacyPolicy

What Azelify collects, why it collects it, who else touches it, and how to get all of it back or delete it.

Last updated September 12, 2026

In short

We collect the account details you give us, the projects and media you create, and the accounts you choose to connect. We never see your card number. We send your prompts and media to the AI vendors listed on the Subprocessors page so they can produce your output, and we do not sell your data or use it to train models for anyone but you. You can export everything or delete your account from inside the product, without asking us.

1.Who operates Azelify

Azelify is a short-form advertising studio operated from Seattle, Washington, United States. It is currently run as an unincorporated business; a Washington limited liability company is being formed, and this policy will be updated to name it as the controller when that filing is accepted.

For everything below, "we" means the operator of Azelify and "you" means the person or company using it. If you are in the EEA or the UK, we act as the controller for account and billing data, and as your processor for the content you create and the accounts you connect.

Questions about this policy, or any request under it, go to [email protected].

2.What we collect

The categories below are the ones the product actually stores. They mirror the export you can download yourself, so if something is missing from this list it is missing from the export too — tell us and we will fix both.

  • Account details — your name, email address, and optionally a phone number, address, and timezone. If you signed up with an email address and a password, we store a scrypt hash of that password; we never store, log, or are able to read the password itself. If you signed in with Google instead, there is no password and no hash, and your email comes from Google.
  • Billing records — your subscription tier, status, trial history, invoices, and Stripe identifiers. Not your card number; see section 3.
  • What you create — projects, timelines, uploaded and generated video, images, audio, voiceovers, scripts, captions, brand kits, fonts, and chat with the in-product assistant.
  • Connected accounts — when you connect TikTok, Instagram, YouTube, X, or Reddit, we store the access tokens that platform issues, encrypted, plus the account handle and the posts we publish or read on your instruction.
  • Research we run for you — search queries, pages, and public posts we retrieve when you ask Azelify to find evidence or study an account, and the notes it derives from them.
  • Usage and cost records — which features you ran, when, how much AI spend each one incurred, and errors the product hit. This is how metering and quotas work.
  • Support messages — anything you send us by email or through the contact form.

3.What we do not collect

Stated explicitly, because a generic privacy policy usually implies the opposite:

  • Card numbers. Payments go directly to Stripe, which returns an identifier. Your full card details never reach our servers.
  • Third-party advertising or analytics trackers. There is no Google Analytics, no advertising pixel, and no cross-site tracking anywhere on this site or in the product.
  • Nothing we could sell. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.

4.Why we process it, and on what basis

If you are covered by the GDPR or UK GDPR, these are the legal bases we rely on:

  • To perform our contract with you — running the studio, generating and rendering your ads, publishing to the accounts you connected, and billing you for it.
  • Our legitimate interests — keeping the service secure, preventing abuse, debugging failures, understanding aggregate usage, and metering AI spend so a runaway job cannot bill you for it.
  • Your consent — connecting a social account, and any optional research you explicitly ask us to run against a public account. You can withdraw either at any time by disconnecting.
  • Legal obligations — retaining tax and payment records for the period the law requires.

5.How AI providers process your content

Generating a script, a voiceover, an image, or a video means sending the relevant part of your content — your prompt, your brief, your brand kit, and where applicable your media — to a third-party model provider. The full list of those providers, and what each one receives, is on the Subprocessors page.

We do not use your content to train general-purpose models, and we contract with providers on terms that do not permit them to train on our API traffic. Where Azelify learns your taste — the models that decide what to suggest to you — that learning is scoped to your account, is built only from your own content and your own choices, and is deleted with your account.

Model output is probabilistic. Review anything before you publish it: see section 7 of the Terms.

6.Who else processes your data

We share data with the vendors that run the service — hosting, storage, authentication, payments, email, AI models, research, and the platforms you connect. Each is bound by its own contract to process the data only on our instruction.

Outside that list, we disclose data only when the law compels it, when it is necessary to investigate abuse or protect someone's safety, or as part of a merger or acquisition — in which case we will tell you before your data moves.

7.Where your data goes

Azelify is operated from the United States and every vendor listed on the Subprocessors page processes data in the United States. If you use Azelify from the EEA, the UK, or Switzerland, your data is transferred to the US. Those transfers rely on the Standard Contractual Clauses in our vendors' data-processing agreements, plus their own certifications where they hold them.

8.How long we keep it, and what deletion actually does

Deleting your account from the Account page does three things immediately: it anonymises your user record, it detaches your sign-in identity so the account cannot be resurrected by a still-valid token, and it queues a cleanup job. That job revokes and erases your connected-account tokens, removes the learned models built from your content, and deletes the stored copies of the research it ran for you.

Being precise about the parts that are not instant: cleanup runs as a background job rather than inside the click, archived research payloads in object storage are removed by a separate purge pass, and encrypted backups age out on their own schedule. Nothing is retained for a purpose other than completing that deletion.

  • Account and profile data — until you delete your account.
  • Projects, media, and generated output — until you delete them, or until you delete your account.
  • Connected-account tokens — until you disconnect the account or delete your account, whichever is first.
  • Invoices and payment records — retained after deletion for as long as tax and accounting law requires, then removed.
  • Operational logs — a rolling window measured in weeks, not years.

9.Your rights, and how to actually use them

Two of these are self-serve inside the product, which is the point — you should not have to email anyone to get your own data:

  • Access — know what we hold about you. This page is the summary; the export is the specifics.
  • Portability — download everything, as machine-readable JSON, from your Account page. It is generated from the same inventory this policy is written against.
  • Correction — edit your profile in the product, or ask us for anything you cannot reach.
  • Erasure — delete your account from your Account page. Section 7 describes exactly what that does.
  • Objection and restriction — ask us to stop or limit processing that relies on legitimate interests.
  • Complaint — if you are in the EEA or UK you may complain to your supervisory authority; if you are in California, Colorado, Connecticut, Virginia, or another state with a privacy statute, you have the equivalent rights there and we will not discriminate against you for using them.

For anything you cannot do yourself, write to [email protected].

10.Security

No system is perfectly secure, and any policy that claims otherwise is telling you something false. What we do:

  • Everything is encrypted in transit over TLS, and the database and object storage are encrypted at rest.
  • Connected-account tokens are encrypted with a separate key and are deliberately excluded from your data export, because an export is a plaintext file and a token in one is a credential leak.
  • Access to production data is limited to what is needed to operate the service, and every mutating request is authenticated and CSRF-protected.
  • If a breach affects your personal data, we will notify you and the relevant regulator within the deadlines the law sets.

11.Children

Azelify is a business tool and is not directed at children. You must be at least 16 to use it, or older if your country sets a higher age for consent to data processing. We do not knowingly collect data from children; if you believe a child has created an account, tell us and we will delete it.

12.Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we use data you have already given us, we will tell you by email or in-product notice before it takes effect, not after.

Anything unclear here is our fault, not yours — ask at [email protected].