Privacy Policy
visor.media
Effective: 2026-09-19
This policy explains what we collect when you use visor.media, why, who else handles it, where it
goes, how long we keep it and what you can ask us to do about it.
We have written it to be read, not to be survived. Where something works against you, we say so
rather than leaving you to find out.
"We" and "us" mean HKD VISOR STUDIO, the business that operates visor.media. Section 16 says how to
reach us.
1. About this policy
This policy covers visor.media. It does not cover visor.vn, which is operated as a separate
service with separate customer records and its own documents. An account on one is not an account on
the other.
It forms part of the Terms of Service published on visor.media.
Two things shape everything below. The first is that the product's whole purpose is to generate
media from material you give us — so your uploads and the files we generate are not a side effect of
the service, they are the service, and they are covered here in full. The second is that generating
them takes real computing infrastructure, which we rent. Section 7 lists who is involved and what
they handle.
2. What we collect
Account information. visor.media has no sign-up form. An account exists only once a third-party
sign-in provider — Google or Apple — has authenticated you successfully. From that
provider we receive the account identifier it issues, your email address and your display name,
where the provider returns them. Some providers return no email address; where that happens we
generate an internal placeholder instead of one. We also issue you a username, which is yours and
is never reissued to anyone else.
We do not store your profile picture. Some providers offer one; we do not keep it and there is no
field for it on your account.
Not your password. Passwords are handled entirely by our authentication provider. **We do not
store your password and we do not store an encrypted copy of it.** Resetting a password is done by
signing in again through a provider — we never send password-reset emails.
What you upload to make something. Images, video, audio files, and prompts written in words (up to
20,000 characters per prompt). Current size limits are 25 MB per image, 200 MB per video and 25 MB
per audio file.
What we generate for you. The images, video, audio, films and music videos our systems produce
from your account, plus the technical record of each job — the settings used, when it ran and how
long it took.
Payment information. visor.media accepts payment by PayPal only. We store the record of each
top-up: the amount, the pack you bought, the transaction reference, the date, and the fee the payment
provider charged. We never see and never store your card or bank details — you enter those on
PayPal's own pages.
Technical information and logs. Your IP address, browser and device information, server access
logs, system event logs, and the processing-time log of each job.
A device notification token — only if you turn on push notifications.
A referral relationship — only if you created your account through someone's referral link.
3. Faces and voices are sensitive data
**Photographs containing a real person's face, and recordings of a real person's voice, are sensitive
personal data — biometric data — under data-protection law in most countries.**
They are also central to what this service does. You upload a face to put a character into an image
or a video; you upload a voice sample to have a voice reproduced. We are not going to bury that in a
list.
We collect and process this data only to produce what you asked for. Not to identify anyone, not
to build a profile of anyone, not to match faces or voices across accounts, and not for any purpose
other than the job you submitted.
The condition attached to it is in the Terms, and it is absolute. For any image, video or audio
containing the face, voice or recognisable likeness of a real person, you promise that you are that
person, or that you have that person's consent for exactly the use you are asking us to make.
Content featuring the face or voice of a person under 18 is prohibited, unless you are their
parent or legal guardian and the content breaks none of the other rules in the Terms.
If you are not the person in the material, **the lawful basis for processing their data is the consent
you obtained from them**, and you are responsible for having obtained it. If someone tells us their
face or voice has been used without their consent, we act on it — Section 16 is the channel, and
anyone can use it, with or without an account.
4. What we do not collect
- No date of birth. The Terms require you to be 18 or the age of majority where you live. That is
a promise you make; we do not collect documents or a birth date to check it.
- No card or bank details. They never touch our systems.
- No third-party analytics, advertising or behavioural tracking of any kind. No tracking pixels,
no advertising identifiers, no session-replay, no third-party error monitoring. We do not profile
you, and there is nothing on visor.media that follows you elsewhere. - No contacts, no browsing history, no location beyond what an IP address implies.
5. Why we process it, and on what basis
We use what we collect for these purposes and no others:
- To make what you asked for — putting your images, video, audio and prompts through the
generation process.
- To run your credits and wallet — quoting a price before you submit, deducting credits when you
do, returning them automatically when a job fails or you stop it, and compensating you when a job
is unusually slow. - To show you and deliver your work — the job page, the queue and your Library.
- To notify your device when a job finishes, if you turned notifications on.
- To support you and handle complaints.
- To improve the quality of the service.
- To calculate referral rewards, where a referral relationship exists (Section 2).
- To keep the service secure — detecting and stopping abuse, attacks and payment fraud.
- To comply with the law, including lawful requests from competent authorities.
The basis for processing is the consent you give when you accept the Terms and this policy before
using the service, together with the performance of the contract between you and us. Where we keep
records we are legally required to keep — transaction documents, invoices, credit history, contract
records and system logs — the basis is that legal obligation, and it is why those particular records
survive a deletion request (Section 13).
Where local law gives you additional rights or requires a different basis — for example if you are
in the EU, the UK or another jurisdiction with its own data-protection regime — we honour those
rights. Write to us and say which ones you are relying on.
We operate from Vietnam, and there is no local office to write to. We have not appointed a
representative in the EU or the UK, and we have not appointed a Data Protection Officer. Every
request, wherever you live, reaches us the same way: contact@visor.media. Section 12 says how
quickly we answer.
6. Where your content goes while we make something
Making a video is not one operation on one machine. Here is the honest route your material takes.
- Your uploads and the files we generate are stored in cloud object storage, and are copied to a
graphics-processing machine to be rendered. When you upload a file and when you view it again, the
data travels directly between your browser and that storage. - **Where a prompt has to be translated into English before it reaches the generation systems, the
prompt text is sent to a machine-translation service.** Text that needs no translation is not sent
anywhere for that purpose. - In flows that need your content understood rather than rendered — writing an advertising script
from a product photo, describing a character's appearance from a reference photo, planning scenes
from a frame, checking text that was rendered into an image — **your text and your images are sent to
a third-party language-model service.** - Your video and audio files are never sent to those language-model services. They receive text and
images only.
- The generation itself — images, video, music, voice — runs on machines we operate. We do not send
your material to any third-party generation service.
Files we deliver carry a provenance tag. Every generated image, video and audio file we hand you
is marked in its metadata as AI-generated — see Section 6 of the Terms. That tag says only *how the
file was made. It does not contain your prompt, your account, or anything identifying you*, and
that is a deliberate design decision, not an accident.
We measured this rather than assuming it. On 2026-09-19 a file delivered by the production system
— a PNG — was inspected. It carries exactly one invisible metadata block: a 468-byte XMP tag stating
the standard digital-source-type for AI-composited media. Nothing else. No prompt, no settings, no
tool names. Be aware that the tag does not always survive: most social platforms re-encode what
you upload, and re-encoding strips metadata. We say so plainly rather than letting you assume a label
is travelling with your file when it may not be.
About training. We do not train AI models on your content, and the generation systems we run do
not learn from what you upload. The third-party language-model and translation services that receive
text — and, in some tools, images — handle that traffic under API terms that do not permit using it
to train their models.
7. Who else processes your data
**We do not sell your personal data. We do not rent it. We do not share it for advertising or
marketing.** There is no exception to that and no setting you need to find.
What does happen is that infrastructure providers process your data on our behalf, to the extent
needed to run the service, under our instructions and under a duty of confidentiality. This is not
optional: your files have to be stored somewhere and rendered on something.
We describe them by function rather than by name:
| What they do | What they handle |
|---|---|
| Sign-in providers — Google, Apple | Your sign-in request and the identity it returns: the account identifier, and the email, display name and picture where that provider returns them. Our authentication provider also holds your password |
| Payment processor — PayPal | We send them the amount and an internal reference to your account, and nothing else — no name, no email, no content. You then deal with them directly on their own pages, where they see your payment details and your IP address. Card and bank details never reach us |
| Cloud object storage and content delivery | Every file you upload and every file we generate |
| Application server hosting | Your account record, job records and system logs |
| Graphics-processing compute | Your input files, your prompts and the generated result, for as long as a job is being rendered |
| Push notification delivery | Your device notification token and the text of the notification. That text is fixed wording plus the name of the operation that finished — it never contains your prompt |
| Machine-translation service | Your prompt text, and images in the flows that send images |
| Language-model services | Your text and your images, in the flows described in Section 6. Never your video or audio |
| Web-font delivery | Your IP address, browser information and the page you are viewing — fonts load directly from the provider on every page |
| A link-media fetch service | Only if you paste a social-media link to use a video as input: the link you pasted, and the video stream it fetches. Your own content is never sent to those platforms |
| Competent authorities | Only on a lawful request |
*Who does not receive your data: we use no bulk email provider and *the product sends no
automated email at all** — not marketing, not password resets, not job notices. What you get instead
is a notification to your device, if you enabled them. When we reply to you, a person writes it from
contact@visor.media. We use no analytics provider, no advertising network and no third-party
error-monitoring service. Where we download AI model files, nothing of yours travels in the other
direction. Internal operational alerts about server health carry no user data.
Inside our own organisation: administrators can access the data of any account, to run the system,
fix faults and handle complaints. Moderators have exactly two powers — editing the platform's shared
library, and viewing the system job queue read-only — and **cannot read the private data of any
account.** Ordinary users see nothing but their own.
If you want the names, ask for them. Write to contact@visor.media and we will tell you which
providers we use for the functions in the table above.
8. Where your data is processed
We are established in Vietnam. The business that operates visor.media is registered there, and
Vietnamese law governs the contract between us (see the Terms).
Your data is processed outside Vietnam, and outside your own country. Our application servers are
located in Singapore. Cloud storage, graphics-processing compute, the sign-in providers, the payment
processor and the language-model services are all operated by organisations outside Vietnam and
process data abroad.
In plain terms: **the files you upload, the files we generate and your account record are stored and
processed on infrastructure located in several countries, and using the service means accepting
that.** If that is a problem for the material you were planning to upload, do not upload it.
9. How long we keep things
| What | How long |
|---|---|
| Temporary copies of your files on the rendering machines | Deleted automatically within 24 hours of the job ending — reduced to 6 hours automatically when disk space runs low |
| Your account data and the content in your Library | For as long as your account is active, until you ask us to delete it (note: deleting an item in your Library is not a deletion request — Section 13) |
| System logs (access logs, job logs, security logs) | At least 12 months, to keep the service secure and to meet lawful requests |
| Records of contracts concluded on the platform — top-ups, credits spent, when each was agreed | Accessible for at least 3 years |
| Invoices, accounting records and payment transaction documents | For the period accounting and tax law requires — at least 10 years for documents used directly in the accounts |
What is automatic, and what is not. Only the first row happens by itself: a cleanup process wipes
the rendering machines, and it runs whether or not anyone is watching. **Nothing else here expires on
a timer.** Your stored media and your records are kept while your account is active, and are deleted
when you ask us to delete them — Section 13 is how you ask, and it is the route that actually removes
things. The records in the last three rows are the exception: the law requires us to keep them for
the periods stated, and a deletion request does not reach them.
About the 24-hour rule. When you submit a job, your files are copied to a rendering machine. A
cleanup process runs every hour and removes everything there older than 24 hours, along with every
intermediate file the render produced. The principle is that **rendering machines do not hold data:
they receive, process, return the result to storage, and forget.**
We do not promise long-term access to the files we generate for you. Download them and keep your
own copies. This is not the same as saying they have been deleted — the table above says what is
actually kept. If we change how long we keep generated files, we give at least 30 days' notice in
your account and on the home page so that you can download them first.
This retention policy does not shorten the records of your purchases, your credit history and your
invoices, which are kept for the periods stated above regardless of anything else in this document.
10. Cookies
**visor.media uses only the cookies it needs to work. There are no advertising cookies and no
analytics cookies, first-party or third-party.**
| Cookie | What it is for | How long |
|---|---|---|
ms_session | Keeps you signed in | 30 days, or until you sign out |
ms_oauth_tx | Holds the security values for one sign-in attempt while it is in progress | 10 minutes |
ms_reauth | The short proof that you just signed in, required before you can set a password or close your account | 5 minutes |
ms_ref | Remembers a referral code from a link you arrived through, so the person who referred you is credited if you sign up | 30 days |
media_studio_locale | Remembers the language you chose, so pages do not switch back | 1 year |
media_studio_theme | Remembers light or dark mode | 1 year |
How they are protected. The first four are HttpOnly — scripts running in your browser cannot
read them — and are sent only over an encrypted connection. The last two hold nothing but a display
preference and are readable by the page, because the page sets them when you change the setting.
Your acceptance of the Terms is not stored in a cookie. It is recorded on your account, so that
clearing cookies never makes it look as though you had not agreed.
We do not show a cookie banner, because we do not use any cookie that would need one. Every cookie
above is either strictly necessary to deliver the service you asked for, or stores a preference you
set yourself. **There are no advertising cookies and no analytics cookies, first-party or
third-party.** If we ever add a cookie outside that description, we will ask you first.
Local storage. Your browser also stores a few values locally — a copy of your language choice, the
notification token if you enabled notifications, and flags for prompts you have already dismissed.
They stay on your device.
Three things on the page come from other companies' domains. The sign-in provider's software, the
payment provider's software (on the Credits page only) and the web-font provider load from their own
domains, and each may store data under its own domain when it does. That storage belongs to them, not
to us, and it is outside our control.
11. How we protect your data
We publish only measures that are actually running.
In transit. All access to visor.media goes over an encrypted TLS/HTTPS connection. Links to your
media files are signed and expire after 5 minutes — a link copied out of the page stops working
after that. Every page carries a policy that blocks unknown scripts and prevents the site being
embedded in someone else's page.
Your account. Your password is not on our systems. A sign-in session lasts 30 days, and you can
sign out of every device at once from Settings; changing your password also ends every other
session. Setting or changing a password needs a proof of ownership valid for five minutes, produced
by a sign-in you just completed. Sign-in attempts and credential changes are rate-limited per account
and per IP address, and successful sign-ins reset the counters.
Between accounts. Every record — job, output, character, voice — carries its owner, and every read
goes through one central ownership check before any data is returned. **Every delivery of image or
video bytes requires a positive access decision**; a path that cannot produce one is blocked rather
than allowed. Your identity and role are re-derived from your verified session at the door, so a
browser cannot declare itself an administrator, and an unrecognised role is dropped to the lowest
privilege.
Payments. Every notification from the payment provider is signature-verified before it is acted on;
one that fails verification is rejected. Where verification is not configured, the system refuses
rather than accepting.
Logs. Access logs rotate, and **credentials, cookies and payment signatures are stripped out of
them**. A separate append-only event log supports auditing and complaint handling.
Abuse limits. We cap upload sizes and prompt length, and we limit how many jobs an account runs at
once and how quickly it can submit. These limits act on the number and speed of requests — **they do
not read or assess what you are making.**
Content screening. We operate automated screening that flags content and accounts showing signs of
a breach of the Terms, and we review reports sent to contact@visor.media by anyone, with or without
an account. Content that a competent authority asks us to block or remove is actioned within 24
hours.
If something goes wrong. If a breach affects your data, we will inform you and the relevant
authorities as required by applicable law.
Your part. You are responsible for keeping your sign-in details secure and for everything done
under your account.
12. Your rights
What you can see and change yourself
| You want to see or change | Where |
|---|---|
| Your username, and which sign-in methods are linked | Settings |
| Your display name and email | The account card in the sidebar |
| Your top-up history and credit balance | Credits |
| Everything you have made | Library |
| Each job and its status | Queue, and the job's own page |
| Your referral figures, where a referral relationship exists | Referral |
In Settings you can set or change a password (after signing in again to prove the account is
yours), sign out of every device, change your language and appearance, and turn push notifications on
or off.
Everything you have made has a Download button. Take your own copies.
What you ask us for
Write to contact@visor.media to:
- access the personal data we hold about you;
- correct it — including your display name, email address or username;
- delete it (Section 13);
- withdraw your consent to processing;
- object to, or ask us to restrict, a particular use;
- ask us to explain a calculation, a charge or a decision.
We verify who you are before acting, so that someone else cannot ask us to delete your data. For
the same reason, requests about personal data are accepted only by email to contact@visor.media —
never through a public channel where other people could read what you wrote.
How long we take, counted from when we receive a valid request: **we respond within 2 working
days and complete within 20 days, or 30 days** where we need another provider's cooperation. If
we need longer we tell you why and extend once, by no more than 15 days.
There is no deadline for exercising these rights. You can ask at any time, about anything.
Complaining. If you are not satisfied with how we handled a request, say so at the same address
and we will look again. **You can also complain to the data-protection authority in your country, and
nothing here limits that right.**
13. Deleting content and closing your account
Deleting an item in your Library is not a deletion request. It removes the item from your list. The
file is still on our systems and the action can be undone. We say this because it is the single most
common misunderstanding about deletion on any service like this one.
To delete data from our systems, send a deletion request to contact@visor.media.
When you ask us to delete, we delete for real. The images, video and audio you uploaded, the files
we generated from them, and their copies across our processing infrastructure are removed
irrecoverably. We stop using your data for every purpose.
The only things kept are the ones the law requires us to keep, and they are exactly these five:
- payment transaction documents;
- invoices;
- your top-up and credit-spending history;
- records of contracts concluded on the platform — including the record of the promises you
acknowledged when you submitted work;
- system logs.
Section 9 gives the period for each. **Beyond those five, nothing of yours is kept after a deletion
request is carried out.**
If any part cannot be deleted, we tell you which part and why. By name, not in general terms.
Closing your account. Send a termination request from Settings → End service, or by email to
contact@visor.media. Termination takes effect when you send the request. **Jobs already running are
finished and delivered to you** at no further charge — download them before you go. Closing the
account does not by itself delete your content; say in the request if you want deletion too. The
Refund Policy covers what happens to credits you have not used.
14. Children
visor.media is not for children. You must be 18 or the age of majority where you live, whichever
is higher, and we do not knowingly collect personal data from anyone below that age.
The Terms also prohibit generating content featuring the face or voice of a person under 18, unless
you are their parent or legal guardian and the content breaks none of the other rules.
If you believe a child has an account here, or that content on the service uses a child's face or
voice, tell us at contact@visor.media and we will act on it.
15. Changes to this policy
We update this policy when the service changes or the law does. The effective date at the top always
tells you which version you are reading.
**When a change materially affects your rights, we ask you to accept the new version the next time
you use the service.** Smaller corrections — a clearer sentence, a fixed typo — are published without
re-asking.
16. Contact and complaints
HKD VISOR STUDIO
- Website: visor.media
- Email: contact@visor.media
- Registered address: 32/233 Nguyen Duc Canh Street, An Bien, Hai Phong, Vietnam
- Telephone: 0931226166 — the registered business telephone number. It is not a support line and
is not staffed for customer enquiries.
Email is our channel. Write to contact@visor.media for a data request, a privacy question, a
security concern, or to report content — including content that uses your face or voice without your
consent. You do not need an account to write to us.
How quickly we reply, counted from when we receive a request with enough information to act on:
| We acknowledge within | We resolve within | |
|---|---|---|
| A request about your personal data | 2 working days | 20 days, or 30 days where another provider's cooperation is needed |
| A security complaint — an incident, or a suspicion that data has leaked or been accessed or used without authorisation | 2 working days | 20 days, or 30 days where another provider's cooperation is needed |
| A content-removal request or a report of prohibited content | 3 working days | 7 working days |
Extensions: once, by no more than 15 days for the first two rows, and by up to 7 further working days
for the third — with our reasons given before the original deadline passes. Working days exclude
Saturdays, Sundays and public holidays in Vietnam. A request from a competent authority to block or
remove content is actioned within 24 hours.
You can also complain to the data-protection authority in your country. Nothing in this policy
limits that right, and you do not have to come to us first.