This explains what we collect, who we send it to, and how long we keep it. In short: we collect as little as we can, we don't sell anything, and your uploads go to the AI providers that process them and nowhere else.
We do not use tracking pixels, advertising cookies, or third-party analytics.
We don't run AI models ourselves. To edit or generate anything, your file and your prompt are sent to the provider that does the work:
| Provider | What we send | Used for |
|---|---|---|
| BytePlus (Seedream, Seedance) | images, video, audio, prompts | photo edits, video generation, the Automation tab, understanding your audio |
| Kling AI | video, images, audio, prompts | video editing, speech synthesis, talking avatars |
| Render, Netlify | hosting and file storage | running the service |
| Paddle | your email and the amount | payments and tax |
These providers are outside your country and process data under their own privacy terms. To let a provider fetch your file, we host it at a temporary web address. That address is unguessable, but it is not password-protected while a job is running.
The Cut tab is the exception: trimming happens entirely inside your browser. Nothing is uploaded and no provider sees it.
Ask us to delete your files and we'll remove them from our storage. We can't retract what a provider has already processed, though they operate their own deletion schedules.
Editing footage of real people is a normal use of this service, so this deserves saying plainly. When you upload material showing someone, you're asserting that you have their permission — see section 4 of the Terms. We don't build face databases, we don't run recognition to identify anyone, and we don't use your uploads to train models.
Some providers refuse footage containing recognisable faces. When that happens the request is rejected before anything is generated, and you aren't charged.
We do not use your files, prompts or outputs to train AI models, and we don't licence them to anyone for that purpose. Providers' own training practices are governed by their terms; where a provider offers a no-training setting for API traffic, we use it.
We store a session identifier so you stay signed in and your credits follow you. That's it — no advertising or cross-site tracking. Clearing your browser data signs you out.
You can ask us to show you what we hold, correct it, delete it, or send you a copy. Email hi@drawreplace.com and we'll respond within 30 days. Deleting your account removes your files and personal details; anonymous records we must keep for accounting are retained without identifying you.
Traffic is encrypted in transit. Payment details never reach our servers. We keep provider API keys server-side only. No service is perfectly secure, and we'd rather say so than imply otherwise — if a breach affects you, we'll tell you.
This service isn't for under-13s, and we don't knowingly collect their data. Creating sexual or suggestive content involving anyone under 18 is prohibited and results in immediate account closure.
We'll update this page as the service changes and move the date at the top. For anything material, we'll tell you in the app.
Questions or requests: hi@drawreplace.com.