vgenv
GalleryFeaturesCreateDevelopersAPI Status
/
vgenv · legal

Privacy Policy

How we collect, use, disclose, and protect your information.

Effective
2026-08-18
Last updated
2026-08-18
Market
—
On this page1. Scope and controller2. Information we process3. Purposes and legal bases4. Processors, disclosure, and publication5. International processing6. Retention and deletion7. Security8. Your rights and choices9. Children10. Changes and contact

1. Scope and controller

This Privacy Policy applies to the vgenv (万境) website, creator workspace, developer API, and related services (the “Service”). The controller is vgenv.com.

It explains what we process, why we process it, how we disclose and protect it, and how you can exercise your rights. If you use the Service for an organization, you must have authority and provide any notices required for its members or end users.

2. Information we process

Account and identity

Nickname, email address, verification status, salted password hash, the default project, memberships, and roles. We do not store plaintext passwords.

Third-party sign-in

Google sign-in requests openid email profile and returns your Google subject identifier, verified email, and display name. GitHub sign-in requests read:user user:email and returns your account identifier, username or display name, and verified email. Provider access tokens are discarded after the profile is read and are not retained as vgenv sessions.

Content and jobs

Prompts, reference images, generation settings, product tier, sharing choice, generated videos, job status, errors, and execution records. Selecting an image on a creation page starts its upload immediately so preparation can run while you edit the prompt. Do not upload unnecessary personal or sensitive data, or data about others that you cannot lawfully process.

Developer, transaction, and communications data

Projects, hashed API Keys and hints, API requests and usage, quotes, prepaid balances, orders, ledger entries, payment status, and refund records. Stripe, WeChat Pay, or another payment provider processes payment credentials; we generally do not receive full card or payment-account credentials. If you contact support through WeChat, QQ, or email, we process the contact details and communications you choose to provide.

Device data, logs, and cookies

IP address, request time, route, response status, browser or device information, and security or rate-limit events. Authentication uses a secure HttpOnly session cookie; language preference is stored in browser Local Storage. We currently do not use cross-site advertising cookies.

3. Purposes and legal bases

We use information to create and secure accounts; provide generation, storage, queues, delivery, and APIs; administer quotes, top-ups, charges, refunds, and reconciliation; send verification and service messages; answer inquiries; prevent abuse and security incidents; troubleshoot and improve reliability; comply with law; and protect legal rights.

Depending on applicable law, we rely on performance of a contract, legal obligations, consent, and legitimate interests that do not override your rights. You may withdraw consent where processing relies on it.

Google user data

We use Google user data only for sign-in, account linking, security, and providing or improving user-facing vgenv features. We do not sell it or use it for advertising, credit decisions, or training general-purpose AI models, and we do not transfer it for those purposes.

4. Processors, disclosure, and publication

We disclose only what is needed to providers supporting the purposes above, including Cloudflare and other networking or private object-storage providers; GPU capacity and inference providers; Resend or Alibaba Cloud for transactional email; Stripe and WeChat Pay for payments; Google or GitHub when you choose their identity service; hosting, monitoring, security, and professional advisers.

Providers may process information only under our instructions or their independent legal duties. Information may transfer in a merger, financing, reorganization, or asset sale subject to confidentiality and security safeguards. We may also disclose it to comply with law, respond to competent authorities, or protect users and the Service.

Free videos carry a watermark and may appear in the public Gallery, product showcases, or marketing. Paid videos are private by default and are published only if you opt in. See the Terms of Service for the content license.

5. International processing

China and global deployments use separate market environments and ledgers, but infrastructure, identity, email, payment, or GPU providers may process data outside your location. Where required, we use contractual safeguards, assessments, certifications, separate consent, or another lawful transfer mechanism and minimize transferred data.

If law requires a separate notice or consent before a transfer, we will complete that process before enabling the relevant feature; this Policy does not replace it.

6. Retention and deletion

We retain information only as long as needed to provide the Service, maintain accounts, resolve disputes, and satisfy tax, payment, audit, and legal obligations. Sessions generally expire after 7 days. Uploaded input assets that are not attached to a generation job are generally cleaned up after about 24 hours, while job-linked inputs are generally extended to at least about 30 days. Generated results created through the REST API use a 30-day object-storage TTL and are then removed automatically by a storage lifecycle rule. APP user works do not use that REST API TTL and are generally retained until the user deletes them, account data is removed, or legal obligations require other handling. Availability may still vary because of deletion requests, job state, backups, disputes, or legal duties.

You can use available asset deletion controls or contact us to delete your account and personal information. When retention ends or a valid request is completed, we delete, anonymize, or isolate the information. Backup copies age out on the backup cycle, and legally retained data is restricted.

7. Security

We use measures such as encryption in transit, private object storage and signed URLs, password/session/API-Key hashing, least privilege, access controls, rate limits, verified payment webhooks, and auditable ledgers. A complete API Key is displayed only once when created or rotated.

No system is perfectly secure. Protect your password and API Keys, revoke exposed keys promptly, and contact us about suspected compromise. We will remediate and give notices required by applicable breach laws.

8. Your rights and choices

Depending on where you live, you may have rights to know, access, copy, correct, supplement, delete, port, restrict, or object to processing; withdraw consent; close your account; obtain an explanation; and complain to a regulator.

Email service@vgenv.com to submit a request. We may verify your identity, authority, and Project role and will respond within the period required by law.

You can revoke third-party access in Google or GitHub settings. Revocation does not itself delete your vgenv account; contact us separately for deletion.

9. Children

The Service is for users aged 18 or older and is not directed to children. A person under 18 must not independently create an account, purchase a balance, or use the API. Contact service@vgenv.com if you believe a minor provided data without proper authorization.

10. Changes and contact

We may update this Policy as the Service, processing, or law changes. We will provide prominent notice of material changes and obtain consent again where required. The date at the top identifies the current version.

Privacy requests or complaints: service@vgenv.com. Operator: vgenv.com.

vgenv

Free AI video generation and a stable REST API.

FeaturesMiniMax H3MiniMax H3 APIAPI GuidesGitHubAPI StatusPrivacy PolicyTerms of ServiceContact
© 2026 vgenv
隐私政策 / Privacy Policy · vgenv