Privacy Policy
Last updated: 8/14/2026
This page is maintained by Virly to answer common privacy and security questions about our service. It describes the data we collect, how we use it, and the controls available to you. This is not an independent certification or legal guarantee.
Private uploads
Every product image and generated video is stored in a private, user-scoped storage bucket. No other user can access your assets. Access is gated by authentication and row-level security policies enforced at the database level.
Data retention
Your projects, product images, generated videos, scripts, and account data are retained as long as your account is active. You can delete individual projects or generated assets permanently at any time from your dashboard. If you cancel your subscription and close your account, your data will be removed from active chain within 30 days unless we are required by law to retain it.
Encrypted & secure
All uploads and downloads are encrypted in transit using TLS 1.3. Storage is encrypted at rest. We never train AI models on your product images or generated outputs. Your content is used solely to generate the outputs you request and is not incorporated into any general model training dataset.
1. Data we collect
We collect the following categories of data:
- Account information: Email address, display name, and authentication credentials provided during sign-up or Google OAuth.
- Product inputs: Images, prompts, descriptions, and configuration choices you enter into the project wizard.
- Generated outputs: Avatar previews, scripts, and lip-sync videos created through the service.
- Usage analytics: Basic interaction data (page views, feature usage, error logs) used to improve the product and diagnose issues. No advertising identifiers.
- Billing data: Subscription status, credit balance, and transaction history managed by our payment processor. We do not store your card details.
2. How we use your data
We use your data for the following purposes:
- To operate the service and process your AI generations.
- To manage your subscription, credits, and billing through our payment partner.
- To maintain account security and enforce row-level access controls.
- To improve the product through internal analytics and error tracking.
We do not sell your personal data to third parties. We do not use your product images or generated videos for advertising or model training.
3. Subprocessors and integrations
We rely on the following service providers to deliver Virly:
- Supabase — Authentication, database, and private storage for user assets.
- Polar — Subscription billing, checkout, and payment processing.
- AI model providers — Avatar generation, script writing, and lip-sync video rendering (API-only; no persistent storage of your inputs on their side unless required for processing).
Each provider is contractually bound to handle data only as necessary to perform their function and in compliance with applicable data protection obligations.
4. Cookies and analytics
We use essential cookies for authentication and session management. We also collect minimal usage analytics to understand product health and feature adoption. We do not use third-party advertising cookies or trackers. You can control cookies through your browser settings, though disabling essential cookies may prevent login.
5. Your rights and choices
You have the following rights regarding your data:
- Access and export: You can view your projects, scripts, and videos in your dashboard at any time.
- Correction: Update your display name and account information from your settings page.
- Deletion: Delete individual projects or your entire account. Account deletion will permanently remove your data within 30 days.
- Withdraw consent: Cancel your subscription at any time from your account or by contacting us.
To exercise any of these rights, email us at hello@virly.xyz.
6. Security practices
We enforce row-level security (RLS) on all database tables and storage buckets so that only the authenticated account owner can read or write their own data. All communications with our backend use HTTPS/TLS 1.3. Storage encryption at rest is provided by our infrastructure host. While we take reasonable measures to protect your information, no internet service can guarantee absolute security.
7. Data retention specifics
- Active accounts: Data is retained indefinitely while your subscription or free account remains active.
- Canceled subscriptions: If you cancel but keep your account, your projects and videos remain accessible. Credits expire according to plan terms.
- Account closure: Upon full account deletion, personal data and generated content are permanently removed within 30 days. Billing records may be retained longer for legal and tax obligations.
8. Children's privacy
Virly is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, contact us immediately and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised "Last updated" date. Significant changes will be communicated via email or an in-app notice.
10. Contact us
If you have questions about this Privacy Policy, your data, or how to exercise your rights, contact us at:
Virly operates virly.xyz and is responsible for the practices described in this policy. Infrastructure and payment processing are handled by the subprocessors listed above under their own terms and security commitments.
Virly