Privacy Policy

Last updated: October 21, 2025

1. Introduction

GPT Sora ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI video generation service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, and profile picture (via Google OAuth)
  • Payment Information: Processed by Stripe (we do not store credit card details)
  • Content Data: Text prompts, images, and other inputs you provide for video generation
  • Communications: Messages you send to our support team

2.2 Automatically Collected Information

  • Usage Data: Video generation history, credit usage, feature interactions
  • Device Information: Browser type, operating system, IP address
  • Cookies: Session cookies for authentication and preferences
  • Analytics: Anonymized usage patterns and performance metrics

3. How We Use Your Information

We use the collected information for:

  • Service Delivery: Processing video generation requests, managing your account and credits
  • Payment Processing: Processing credit purchases and managing billing
  • Communication: Sending service updates, responding to inquiries, and providing customer support
  • Improvement: Analyzing usage patterns to enhance the Service
  • Security: Detecting and preventing fraud, abuse, and security incidents
  • Legal Compliance: Complying with applicable laws and regulations

4. Information Sharing and Disclosure

4.1 Third-Party Service Providers

We share information with trusted third parties:

  • Stripe: Payment processing (subject to Stripe's privacy policy)
  • Google: Authentication services via Google OAuth
  • Veo3 & Sora 2 APIs: Video generation processing (your prompts and generated videos)
  • Hosting Providers: Cloud infrastructure for service operation
  • Analytics Services: Anonymized usage analytics

4.2 Legal Requirements

We may disclose your information if required by law, court order, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Data Retention

  • Account Data: Retained while your account is active and for 90 days after deletion
  • Generated Videos: Stored for the duration specified in your account settings, or until you delete them
  • Video Prompts: Retained for 90 days for service improvement and support purposes
  • Payment Records: Retained for 7 years for tax and accounting purposes
  • Analytics Data: Anonymized and retained indefinitely for service improvement

6. Data Security

We implement industry-standard security measures:

  • Encryption in transit (HTTPS/TLS) and at rest for sensitive data
  • Secure authentication using Better Auth with Google OAuth
  • Regular security audits and updates
  • Access controls and authentication for all systems
  • Secure payment processing through PCI-compliant Stripe

However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. Your Privacy Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data (subject to legal retention requirements)
  • Portability: Request your data in a machine-readable format
  • Opt-out: Unsubscribe from marketing communications
  • Restriction: Request restriction of processing in certain circumstances

To exercise these rights, please contact us at [email protected]

8. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Essential Cookies: Required for authentication and session management
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Understand how you use our Service

You can control cookies through your browser settings, but disabling essential cookies may limit functionality.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

10. Children's Privacy

Our Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on our Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. California Privacy Rights (CCPA)

California residents have additional rights under the CCPA:

  • Right to know what personal information is collected and how it's used
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell your data)
  • Right to non-discrimination for exercising privacy rights

13. European Privacy Rights (GDPR)

If you are in the European Economic Area, you have rights under GDPR:

  • Right to access, correct, and delete your personal data
  • Right to data portability
  • Right to restrict or object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

14. Contact Us

For questions about this Privacy Policy or our privacy practices, contact us at: