Privacy Policy
Effective: April 01, 2026
1. Introduction
This Privacy Policy describes how Aktelo India Priviate Limited ("Hathion," "we," "us," or "our") collects, uses, and shares information when you use our AI-powered music and video production platform (the "Service").
2. Information We Collect
Account Information
When you register, we collect your email address, name, and a hashed password (bcrypt). If you sign in via Google OAuth, we receive your Google profile information (name, email, profile image).
User Content
We collect the content you provide, including song ideas, prompts, lyrics, uploaded images, audio files, and artist information.
Generated Content
We store AI-generated outputs including songs, images, videos, lyrics alignments, and production metadata.
Usage Information
We collect cost records, generation job logs, and platform interaction data for billing and service improvement.
OAuth Tokens
When you connect third-party platform accounts (YouTube, TikTok, Instagram), we store OAuth access and refresh tokens server-side. These tokens are never exposed to your browser.
Cookies
We use session cookies for authentication. We do not use tracking cookies or third-party analytics cookies.
3. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Generate content via third-party AI providers at your direction
- Distribute content to connected platforms at your direction
- Process billing and track credit usage
- Provide customer support
- Protect against abuse, fraud, and security threats
- Comply with legal obligations
4. Third-Party AI Providers
To generate content, we transmit your inputs (prompts, lyrics, images, audio) to third-party AI providers, including but not limited to:
- OpenAI — text generation, image generation, speech, transcription
- ElevenLabs — speech synthesis, voice cloning
- Replicate — video generation, lip sync, music (ACE-Step), image generation
- MiniMax — music generation, image generation
- Suno — music generation, music video generation
Each provider processes your data under their own privacy policies. We encourage you to review their policies. Do not submit confidential or sensitive personal information as prompts or content inputs.
5. Third-Party Platforms (OAuth)
When you connect YouTube, TikTok, or Instagram accounts, we request only the minimum OAuth scopes necessary:
- YouTube: Upload videos, manage your videos, read channel information and analytics
- TikTok: Publish and upload videos
- Instagram: Basic profile access, content publishing
OAuth tokens are stored server-side, encrypted at rest, and automatically refreshed as needed. You can revoke access at any time by disconnecting the platform account in Hathion or revoking permissions in the platform's settings.
6. Google API Services User Data Policy
Hathion's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Hathion uses Google data only to:
- Display your YouTube channel information within the Service
- Upload videos to YouTube on your instruction
- Fetch analytics and statistics for your uploaded videos
- Read public comments on your uploaded videos
Hathion will never:
- Sell Google user data to any third party
- Use Google user data for advertising or ad targeting
- Transfer Google user data to third parties except as necessary to provide the Service, comply with applicable law, or as part of a merger or acquisition with adequate data protection
- Use Google user data to train AI or machine learning models
- Allow humans to read Google user data, except with your explicit consent, for security purposes, to comply with applicable law, or when aggregated and anonymized for internal operations
7. How We Share Information
We may share your information with:
- AI providers — to generate content at your direction (see Section 4)
- Connected platforms — to distribute content at your direction (see Section 5)
- Service providers — hosting, infrastructure, and payment processing
- Legal compliance — when required by law, subpoena, or legal process
- Business transfers — in connection with a merger, acquisition, or sale of assets, with adequate data protection
We do not sell your personal information.
8. Data Retention
We retain your account data and content for as long as your account is active. Usage logs and cost records may be retained for up to 24 months for billing and legal purposes. When you delete your account, we will remove your data within a reasonable timeframe, subject to legal retention requirements.
9. Security
We implement security measures including bcrypt password hashing, TLS encryption in transit, server-side storage of OAuth tokens (never exposed to the browser), and role-based access controls. However, no system is completely secure. You are responsible for maintaining the confidentiality of your account credentials.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access and receive a copy of your personal data
- Correct inaccurate personal data
- Request deletion of your personal data
- Export your data in a portable format
- Withdraw consent for data processing
- Object to or restrict certain processing
These rights may apply under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and similar laws. To exercise your rights, contact us at coach@aktelo.com.
11. International Transfers
Your data is processed in the United States and may be transmitted to AI provider infrastructure in other regions. By using the Service, you consent to the transfer of your data to these locations.
12. Children's Privacy
The Service is not directed at children under 13 (or under 16 in the European Union). We do not knowingly collect personal information from children. If we learn that we have collected such information, we will take steps to delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the Service. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
14. Contact
For questions about this Privacy Policy or to exercise your data rights, contact us at coach@aktelo.com.
Data Protection Officer: coach@aktelo.com