ReanimatorBack to site

Privacy Policy

Last updated: July 24, 2026

Draft pending legal review. This policy describes our actual data flows, but it must be reviewed by qualified counsel before paid public launch.

This policy explains what personal data Reanimator collects, why we process it, who receives it, where it goes and how long we keep it. It applies to our website, applications and generation tools.

1. Controller

Al&Sha LLC, a limited liability company organized under the laws of the State of New Mexico, United States, company registration number 7378211, is the controller of personal data processed through Reanimator.

Registered address: 500 4th Street Northwest, 102 PMB 2861, Albuquerque, NM 87102, United States
Privacy contact: privacy@reanimator.app

Our activities are directed from Spain. We therefore process personal data in the context of the activities of an establishment in the Union within the meaning of Article 3(1) GDPR, and our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD). Because we are established in the Union for these purposes, Article 27 GDPR does not require us to designate a representative.

2. Categories of data we process

2.1 Account data

Email address, display name and a password hash. We never see your password in plain text. If you sign in through a third-party identity provider, we receive the identifiers that provider releases to us.

2.2 Inputs

Footage, images, audio, prompts, masks, annotations, keyframes and timing instructions you upload or create. Inputs may contain personal data — including images and voices of identifiable people — depending on what you choose to upload. You are responsible for having the right to submit that material.

2.3 Outputs

Video and other material generated in response to your instructions, together with the parameters used to produce it. Outputs are stored in your account so you can retrieve and compare them.

2.4 Generation metadata

Model selected, job status, duration, resolution, timestamps, error codes and credits consumed. We use this for billing, debugging, abuse investigation and capacity planning.

2.5 Billing data

Plan, subscription status, invoice history and the country you declare for tax purposes. Card numbers go directly to Stripe and never reach our servers.

2.6 Support data

Messages you send us and bug reports submitted through the in-app widget, including any screenshots you attach and the page you were on.

2.7 Technical data

IP address, user agent, request paths and timestamps recorded in server logs, plus session cookies needed to keep you signed in.

3. What we do not do

We do not sell personal data. We do not use your Inputs or Outputs to train our own generative models. We do not run advertising networks, behavioural profiling or third-party analytics trackers on the site. We do not make automated decisions producing legal or similarly significant effects about you.

4. Purposes and legal bases

Where the GDPR or UK GDPR applies, we rely on the following legal bases.

PurposeDataLegal basis
Provide the service, run generations, store projectsAccount, Inputs, Outputs, generation metadataPerformance of a contract (Art. 6(1)(b))
Take payment and manage subscriptionsBilling dataPerformance of a contract (Art. 6(1)(b))
Send account and security emailsAccount dataPerformance of a contract (Art. 6(1)(b))
Prevent fraud and abuse, keep the service secureTechnical data, generation metadataLegitimate interests (Art. 6(1)(f))
Answer support requestsSupport dataLegitimate interests (Art. 6(1)(f))
Keep tax and accounting recordsBilling dataLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they are not overridden. You may object at any time — see section 10.

5. Special category data

We do not ask for special category data as defined in Article 9 GDPR. Depending on what you upload, Inputs could contain such data — biometric-adjacent facial imagery, for example. We do not use Inputs to identify individuals, and we do not build biometric templates. Do not upload material you are not authorized to process.

6. Recipients

We share personal data with the subprocessors listed on our Subprocessor List, each acting under contract and only to the extent needed for its function. That page is the authoritative version; the summary below reflects it at the date above.

ProviderFunctionLocation
SupabaseDatabase, authentication and account storageUnited States (us-east-1)
CloudflareHosting, edge compute, media storage (R2) and CDNUnited States and global edge network
StripePayment processing and subscription managementUnited States and global
ResendTransactional email deliveryUnited States
Luma AIVideo generation, when you select this engineUnited States
fal.aiVideo generation and image editing, when you select this engineUnited States

Model providers deserve particular attention. When you run a generation, the frames and prompt you selected are transmitted to the provider you chose. Their handling of that material is governed by their own terms, summarised on our AI Provider Terms page. Do not upload material you are not comfortable sending to a third party.

We may also disclose data where required by law or valid legal process, to establish or defend legal claims, or in connection with a merger, acquisition or sale of assets — in which case we will notify affected users.

7. International transfers

Al&Sha LLC is incorporated in the United States, and our database, media storage and model providers are located there. Regardless of where you use Reanimator from, your personal data will be transferred to and processed in the United States, and potentially in other countries where our subprocessors operate.

The United States has not received an adequacy decision of general application. For transfers from the EEA and UK we rely on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), together with the UK Addendum where relevant, incorporated into our agreements with each subprocessor. Some providers are additionally self-certified under the EU–US Data Privacy Framework.

You may request a copy of the relevant transfer mechanism by writing to privacy@reanimator.app.

8. Retention

CategoryRetention
Account dataWhile the account is active, then 30 days
Uploaded footage and annotationsUntil you delete it, or 30 days after account deletion
Generated OutputUntil you delete it, or 30 days after account deletion
Prompts and job metadata12 months, for abuse investigation and billing disputes
Billing recordsAs required by tax law, typically 7 years
Server and security logs90 days
Support and bug reports24 months

Deleted material is removed from live systems promptly. Encrypted backups age out within 30 days. We may retain specific records longer where necessary to resolve a dispute, investigate abuse or comply with a legal obligation.

9. Security

Data is encrypted in transit using TLS and at rest by our infrastructure providers. Access to production systems is restricted, authenticated and logged. Media is served through time-limited signed URLs rather than public buckets.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the competent supervisory authority within 72 hours where required, and notify you without undue delay where the breach is likely to result in a high risk to your rights.

10. Your rights

Subject to the conditions in applicable law, you have the right to:

  • Access — obtain confirmation of whether we process your data and receive a copy.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — have your data deleted where one of the grounds in Article 17 applies.
  • Restriction — limit how we process your data in defined circumstances.
  • Portability — receive data you provided in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing rests on consent, withdraw it at any time without affecting prior processing.

Write to privacy@reanimator.app. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. Exercising these rights is free unless a request is manifestly unfounded or excessive.

You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD), but you may equally complain to the authority of your habitual residence or place of work in the EEA, or to the Information Commissioner's Office in the UK. We would appreciate the chance to address your concern first.

11. California residents

If you are a California resident, you may request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose and the categories of third parties with whom we share it, and you may request deletion or correction. We do not sell or share personal information for cross-context behavioural advertising as defined by the CCPA/CPRA, and we have not done so in the preceding twelve months. We will not discriminate against you for exercising these rights.

12. Cookies

We set only strictly necessary cookies. Details are in our Cookie Policy.

13. Children

Reanimator is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a minor has provided us personal data, contact privacy@reanimator.app and we will delete it.

14. Changes

We may update this policy. Material changes will be announced by email or in the service before they take effect, and the date at the top of this page will change. Continued use after the effective date constitutes acknowledgement of the updated policy, without prejudice to any consent separately required.

15. Contact

privacy@reanimator.app

Al&Sha LLC
500 4th Street Northwest
102 PMB 2861
Albuquerque, NM 87102
United States