Privacy Policy

This policy explains what information MixVio AI processes, why we process it, who receives it, how long we keep it, and the choices available to you.

1. Scope and who we are

Orvyno LLC, a Wyoming limited liability company, operates the MixVio AI product (“MixVio,” “we,” “us,” or “our”), including its website, creative workspace, and related services (the “Service”). This policy applies to personal information processed through the Service unless a separate workspace agreement says otherwise.

Product, privacy, security, abuse, and legal questions can be sent to support@mixvio.ai or mailed to Orvyno LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States.

2. Information we process

  • Account and authentication information: name, email address, profile image, verification status, sign-in provider, session information, IP address, user agent, locale, and security credentials or tokens managed for authentication.
  • Workspace and collaboration information: workspace name, membership, role, invitations, projects, comments, review status, preferences, and audit events.
  • Customer Content: prompts, generation settings, uploaded reference images or other media, filenames, generated results, project data, and information you include in feedback or support requests.
  • Generation and asset records: selected model, capability, task state, Provider job identifiers, errors, timestamps, output metadata, download activity, and private storage records.
  • Billing and credit information: plan, credit balance and ledger entries, order and subscription status, payment-provider customer and invoice identifiers, billing address, tax status, refunds, disputes, and related support records. Payment card details are collected through hosted checkout; MixVio does not store full card numbers.
  • Technical, analytics, and security information: page path, device and browser details, approximate location, product events, pseudonymous analytics identifiers, rate-limit signals, logs, and error diagnostics.

We receive information directly from you, from members of a workspace you join, from authentication and payment providers, from your device and browser, and from AI Providers that return task status and results. Some information is required to create an account, secure the Service, complete a generation, or process a purchase. If you do not provide it, the relevant feature may not work.

3. Why we process information

  • Provide the Service: authenticate users, operate workspaces, process generations, store private assets, maintain history, deliver downloads, and provide support.
  • Billing and credits: quote and reserve credits, process purchases, reconcile payments, issue refunds, maintain the ledger, and meet accounting, tax, and dispute obligations.
  • Safety and reliability: moderate requests, prevent abuse and fraud, enforce limits, debug failures, secure accounts, and recover interrupted tasks.
  • Product improvement: understand aggregate feature usage and performance through analytics.
  • Communications: send service, account, billing, security, support, and permitted product messages.

Depending on applicable law, we rely on performance of our contract with you, our legitimate interests in securing and improving the Service, consent where we ask for it, and legal obligations such as payment and accounting requirements. You may withdraw consent where applicable without affecting earlier processing.

4. AI generation and Customer Content

To complete a request, we send the selected AI Provider the prompt, settings, and minimum media required for that generation. We do not send your account email or full MixVio account profile as part of the generation payload. A selected model may be delivered through an API Provider and the model’s operator, so more than one service provider may participate in the request.

MixVio does not use Customer Content to train a model owned by MixVio. Third-party Provider retention and training practices may differ by route and contract. We only describe a route as “no-training” when that commitment has been verified. Do not submit confidential or sensitive personal information unless the selected workflow and Provider terms are appropriate for it.

Uploaded media may contain faces or voices. MixVio uses that media to perform the creative request and does not use it to identify a person or create a biometric identity template. You must have permission to use another person’s face, voice, or other personal information. Requests may be checked or rejected for safety and abuse prevention. To perform those checks, we may send prompts and short-lived access to uploaded or generated media to a service provider that classifies content-safety risks.

5. Service providers and other disclosures

We share limited information with service providers that help us operate the Service, including the following categories:

  • Authentication and account providers that support sign-in, account security, and session management.
  • Payment and billing providers that process hosted checkout, subscriptions, tax, refunds, and payment-fraud controls.
  • Cloud infrastructure providers that provide hosting, databases, private storage, network delivery, and operational security.
  • AI processing providers that operate the API or model selected for image, video, or audio generation.
  • Email, analytics, and security providers that deliver service messages, measure product usage, monitor errors, and prevent abuse.

We may also disclose limited information when required by law, to protect users or the Service, to investigate abuse, or as part of a corporate transaction subject to appropriate confidentiality and notice. We do not sell personal information, and we do not use Customer Content for targeted advertising.

6. Team workspaces

Content created in a team workspace can be accessed by active workspace members according to their role. Workspace owners and administrators may manage members, review shared content, and view usage information. Only the workspace owner may request a structured workspace-data export or workspace deletion review. The export is a JSON copy of selected workspace records; it excludes media files, Provider payloads, secrets, signed URLs, internal cost strategy, and some billing, security, and operational records. An export can contain information contributed by other members, so it must be handled as confidential workspace data.

7. Cookies and analytics

Necessary cookies, session storage, and local storage support sign-in, account security, fraud prevention, temporary drafts, feature state, and your privacy preference. They operate without an optional-cookie choice because the requested Service cannot work reliably without them.

Anonymous previews use a signed guest-session cookie (mixvio_guest_session) so the browser can resume the same preview session without creating a login account. That cookie is necessary for the free-preview flow, is scoped to MixVio, and is not used for advertising. Guest previews also require Cloudflare Turnstile human verification before a generation starts; Turnstile tokens are validated by MixVio and processed by Cloudflare under its terms for that verification service.

Analytics and performance storage is off until you choose to enable it. If enabled, Google Analytics, privacy-filtered product events, and sampled web-performance metrics may process page paths, device and browser information, approximate location, usage events, and a pseudonymous identifier. Google advertising storage and advertising signals remain disabled. Google Analytics cookies are configured to expire no later than 90 days after they are first set and are not refreshed to extend that period.

Referral-attribution storage is also optional. If a referral program is enabled and you allow attribution, its cookie remembers the referring partner for the configured referral window. The current implementation limits that window to no more than 365 days. We do not use analytics or referral choices for targeted advertising.

You can reject optional storage without losing core Service access and can change or withdraw your choice through “Privacy choices” in the site footer. Withdrawing analytics permission stops new analytics collection and removes MixVio-readable Google Analytics identifiers; withdrawing attribution permission removes supported referral cookies. Your privacy preference remains in local storage until you change it, clear browser storage, or MixVio replaces the preference version.

If your browser sends a recognized Global Privacy Control signal, MixVio keeps optional analytics and referral attribution off on that browser. MixVio does not sell or share personal information for targeted advertising, so the current Service has no advertising preference to turn off.

We do not intentionally send prompts, reference media, generated results, email addresses, private asset identifiers, Provider payloads, or signed asset URLs to product analytics or error monitoring. Error details are filtered before optional external error reporting.

8. Storage and retention

Uploads and generated results are stored in private object storage. Provider output URLs are treated as temporary and successful results are archived before the Service presents them as completed. Private assets are delivered through short-lived authorized URLs.

  • Account and workspace records: kept while the account or workspace remains active and while needed to provide shared history. Eligible records enter a reviewed deletion process after an approved request. We delete or de-identify eligible personal information from active systems within 30 days after the request is approved. Encrypted backup copies may remain for up to 90 days after active-system deletion before they are overwritten through normal rotation.
  • Paid generated media: results settled with subscription or purchased credit-pack lots stay accessible after subscription cancellation while the account remains active, subject to plan storage limits, user-initiated workspace deletion review, and legal or safety requirements. Exceeding a storage limit after a downgrade blocks new uploads and generations; it does not delete existing paid results.
  • Free generated media: results settled only with non-paid credit lots are retained for 7 days from creation, then queued for automatic deletion by the retention maintenance job.
  • Anonymous preview media: unclaimed guest results expire about 24 hours after creation and are removed by the guest-asset cleanup job. Claiming a still-valid preview into an account moves it into that user’s private history under free retention rules.
  • Legacy generated media: outputs created before retention classification launched remain available and are not deleted solely because retention launched.
  • Uploads (reference inputs): kept in private storage until the user deletes an eligible ready input or an approved workspace-deletion request is completed. Incomplete uploads older than 30 minutes are treated as stale and queued for cleanup. A user-deleted ready input normally enters physical deletion after a 15-minute safety window, unless an active generation still needs it.
  • Plan active storage: each plan includes a configured allowance for private uploads plus generated outputs. Current allowances are shown on Pricing and in Credits & usage. Over-limit workspaces cannot start new uploads or generations until space is freed or the plan increases.
  • Authentication and security records: sessions remain until they expire or are revoked. Guest-session cookies and Turnstile verification records remain only as needed for the preview and abuse-prevention windows. Routine security, fraud, abuse-prevention, and audit records are retained for up to 12 months after creation. Records connected to an incident, dispute, legal hold, or repeat-abuse investigation may be kept longer while needed.
  • Billing and credit records: invoices, ledger entries, refunds, and related transaction records are normally retained for seven years after the relevant transaction for reconciliation, accounting, tax, fraud prevention, and legal obligations. Applicable law may require a different period, and these records may outlast account or workspace deletion.
  • Analytics, support, and diagnostics: optional browser analytics follows the periods described in the Cookies section, and identifiable analytics event data is deleted or de-identified within 14 months after collection. Routine service logs and diagnostics are retained for up to 90 days after creation. Support messages and related email-delivery records are retained for up to 24 months after the last interaction. Aggregated or de-identified data may be retained longer because it no longer identifies you.
  • AI Provider copies: retained according to the selected route, Provider configuration, and Provider terms. MixVio treats Provider output URLs as temporary and archives successful results to private MixVio storage. Contact support for the current boundary of a specific route before submitting sensitive information.

Workspace owners may request a structured JSON export of selected workspace records; that export excludes media files, Provider payloads, secrets, and signed URLs. Account or workspace deletion is a reviewed process rather than an immediate automated purge because a workspace can contain shared assets and immutable billing records. We delete or de-identify eligible data and retain only the limited records required for security, disputes, accounting, or law.

9. Security and international processing

Private assets use short-lived, authorized URLs. Provider and infrastructure secrets stay on the server, access is checked against workspace membership, and payment pages are hosted by payment providers. No internet service is risk-free.

Our providers may process information in countries other than where you live. Where applicable law requires a transfer mechanism, we use an applicable contractual or other lawful safeguard. Contact us for information relevant to a specific transfer.

10. Your privacy rights

Depending on where you live, you may request access to, correction of, export of, or deletion of eligible personal information. You may also have rights to restrict or object to processing, withdraw consent, appeal a decision, receive portable data, or complain to a privacy regulator. We do not discriminate against users for exercising applicable privacy rights.

Use the in-product workspace export or deletion review where available for selected workspace records, or email support@mixvio.ai. We may verify your identity and authority over the relevant account or workspace. Some billing, ledger, security, and legal records are not eligible for immediate deletion.

We will acknowledge a privacy request within seven calendar days and respond to a verified request within 30 calendar days. If a request is complex or numerous, we may extend that period where applicable law permits; we will notify you within the initial 30 days and explain the reason. The storage and backup deletion periods in Section 8 apply after a deletion request is approved.

11. Children

The Service is intended for users who are at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has provided information to the Service, contact support@mixvio.ai.

12. Changes to this policy

We may update this policy as the Service, Providers, or applicable requirements change. We will post the updated date here and provide additional notice through the Service or by email when a change is material.

What changed

Updated the product name to MixVio AI, the product domain to mixvio.ai, and the monitored product support address; Orvyno LLC remains the service operator.

Effective . Last updated .

Your privacy choices

Choose whether MixVio can use optional analytics to improve the product and referral cookies to credit partners. We don’t sell or share personal information for targeted advertising. Learn more.