最終更新: August 13, 2026 · 本書は英語版のみの提供であり、英語版が正文となります。
This Privacy Policy explains how Zuler Technology Pte. Ltd. (“we”, “us”, “our”), a company incorporated in Singapore with its registered office at 991D Alexandra Rd, #02-17, Singapore 119972, collects, uses, discloses, and protects your personal data when you use the VerseIn mobile application and this website (together, the “Service”). We handle personal data in accordance with the Singapore Personal Data Protection Act 2012 (“PDPA”) and, where applicable, other data protection laws of the regions we serve. This document is provided in English; if it is translated, the English version prevails.
Information we collect
- Account information. When you register we collect your email address and a password (stored only in salted, hashed form). If you sign in with Google or Apple, we receive the identifier and email address shared by that provider. You may optionally provide profile details such as a display name.
- Guest and device identifiers. On first launch the app creates an anonymous guest account keyed to a randomly generated, per-install device identifier, so your balance and creations can be restored across ordinary app sessions before you register. Recovery after uninstalling, reinstalling, clearing app data, or changing devices is not guaranteed. This identifier is not your hardware serial number.
- Content you provide. Photos (including images of faces), text prompts, and other images or videos you submit for generation, and the results generated for you. Results are stored with your account so you can revisit, download, and manage them.
- Transaction information. Coin-pack and subscription purchases are processed by Apple, Google, or our payment providers (such as Stripe, and RevenueCat for subscription management). We receive transaction records — product, price, currency, time, and store receipt or token — but never your full card details. We also keep your coin ledger (credits, deductions, refunds).
- Usage and diagnostic data. App version, device model, operating system, language, IP address, time zone, basic interaction events, and crash logs, used to operate, secure, and improve the Service.
- Analytics and advertising data. When permitted by applicable law, we process core funnel events (such as visits, registration, and purchases), campaign parameters, advertising click identifiers, and related browser or device data to measure performance and attribute installs or registrations to their source. Our analytics and advertising partners may include AppsFlyer, Google (Firebase, Google Analytics, and Google Tag Manager), Meta, and TikTok. On iOS, tracking occurs only as permitted by your App Tracking Transparency choice; if you decline, attribution may fall back to Apple’s privacy-preserving SKAdNetwork.
- Referral data. If you use an invite code, we record the referral relationship to grant rewards.
- Support correspondence. Messages you send to support@versein.app and the information you include in them.
Photos and facial data
VerseIn’s core feature swaps a person from a photo you provide into video templates. Your photos — including the facial features in them — are used solely to fulfil the generation requests you make. They are transmitted securely to the third-party AI providers that process your request on our behalf (named in Third-party AI processing below), under contracts that limit their use to providing the Service. We do not use your photos or creations to train AI models, we do not build a database of facial templates for identification, and we never sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. You may only upload photos of yourself or of people who have given you their consent.
Retention of photos and facial data. Uploaded photos and the facial data in them are retained only while needed to provide, secure, and account for the Service. Deleting a creation removes it from your account view and, if published, from the public feed. Limited job, transaction, safety, and media records may remain where reasonably needed for billing, fraud prevention, dispute handling, legal obligations, or backup integrity, and are then deleted or anonymized when those purposes no longer apply. Deleting your account removes the account and its association with your creations, subject to the same limited exceptions. You can request access, correction, or erasure by contacting our Data Protection Officer below.
Third-party AI processing
VerseIn does not run AI models on its own servers. To create your results, the content you choose to submit for a generation is sent to third-party AI services that perform the generation on our behalf. The recipient depends on the feature and model selected for a generation.
- What is sent. Only the photos and text prompts you choose to submit for that generation, together with the technical parameters needed to run it. We do not send your account credentials, contacts, location, or payment details to these providers.
- Who receives it. Depending on the feature, our AI processing platforms may include Replicate, PixVerse, Kling AI, MiniMax, Packy, Kie.ai, and fal.ai, as well as model providers behind the selected feature, which may include Google, Black Forest Labs, OpenAI, Alibaba, and Kuaishou.
- How it is used. These providers process your content to generate and return your result and to keep the service safe. We select settings that prevent provider model training where the provider offers them, do not authorize providers to sell your content or use it for advertising, and instruct them to retain submitted content only as long as needed to process and secure your request. Their handling is also governed by their own privacy terms.
- Equivalent protection. We share personal data with these providers only under contracts that require them to safeguard it to a standard comparable to this policy and to applicable data protection law, and to use it only to provide the generation service to us.
Your permission and control. Before any of your content is sent to a third-party AI service for the first time, the app asks for your explicit consent and explains this sharing; no generation occurs until you agree. You can withdraw that consent at any time from Settings → Data & Privacy in the app. Once you withdraw it, we stop sending your content to these providers, which means new generations are no longer available until you turn it back on. You may only upload photos of yourself or of people who have agreed to appear.
Sharing to Explore (public content)
The app includes Explore, a public feed of works users choose to share. Publishing is always opt-in: nothing you create is visible to anyone else unless you explicitly share it. If you publish a work, the following becomes publicly visible to all users of the Service: the generated work itself (with a VerseIn watermark), your display name and avatar, the title of the template or the text prompt the work was made from, and its view, like, and reuse counts. Other users may reuse the work’s creation parameters (prompt, template, and settings) to create their own version. Your uploaded source photos, your email address, and your other creations are never made public. You can withdraw a published work at any time from its page, which removes it from the feed; copies may persist briefly in caches and backups until purged.
- Feed ranking. To order the Explore feed, viewing and liking signals for published works are processed on our behalf by our recommendation service provider, under contract and only for this purpose.
- Reports and blocks. If you report a published work we record the report, the reason you select, and your account, and use them solely for content moderation. If you block a user we store that choice to filter their published works out of your feed; the blocked user is not notified.
How we use your information
- To provide the Service: running your generation requests and delivering results.
- To operate your account and wallet: authentication (including verification codes sent to your email), crediting purchases, deducting coins, and processing automatic refunds when a generation fails.
- To secure the Service: preventing fraud, abuse, and unauthorized access.
- To measure and improve the product, including aggregated or de-identified usage analysis and advertising attribution as described above.
- To communicate with you about the Service — verification, receipts, material changes, and replies to your support requests.
- To comply with legal obligations and enforce our Terms of Service.
Consent and withdrawal
By providing your personal data and using the Service, you consent to its collection, use, and disclosure for the purposes above, as permitted by the PDPA. You may withdraw consent at any time — by turning off AI data sharing in Settings → Data & Privacy, adjusting your device’s tracking permission, declining optional permissions, or deleting your account — and we will stop the corresponding processing within a reasonable time. Withdrawing consent that is necessary for the Service (for example, sharing your photos with the AI providers that generate your results) means we can no longer provide the affected features.
Disclosure of your information
We do not sell personal data. We disclose it only to: (a) service providers who process it on our behalf and under our instructions — cloud hosting and object storage, the AI generation providers that run your requests, payment and subscription processors, email delivery, and the analytics/advertising partners listed above; (b) authorities or other parties where disclosure is required or authorized by law; and (c) a successor entity in a merger, acquisition, or asset sale, subject to this policy. Every third party with whom we share user data — including analytics and attribution tools, advertising networks, and third-party SDKs (such as AppsFlyer, Google, Meta, and TikTok), payment and subscription processors, the AI providers described above, and any parent, subsidiary, or other related entity that may have access to user data — is contractually required to provide the same or equal protection of your personal data as set out in this policy and required by applicable law, and to use it only for the purposes we permit.
International transfers
Our infrastructure and service providers may store or process data outside Singapore. Where personal data is transferred overseas, we take steps required by the PDPA to ensure the recipient provides a standard of protection comparable to the PDPA, including contractual safeguards.
Retention
We keep personal data only as long as needed for the purposes above: account data and creations are kept while your account is active; when you delete your account (or a creation), the personal data and stored media are deleted or anonymized, except for records we must retain for legal, accounting, dispute, or fraud-prevention purposes, which are kept only as long as those purposes require.
Security
We protect personal data with technical and organizational measures appropriate to its sensitivity — encryption in transit, hashed credentials, access controls, and environment-segregated credentials. No method of transmission or storage is completely secure; if a data breach occurs that is likely to result in significant harm, we will notify the Personal Data Protection Commission (PDPC) and affected users as required by the PDPA.
Website cookies, local storage, and analytics
The website uses browser storage for several purposes. Essential storage includes a secure, HTTP-only refresh cookie that keeps you signed in for up to 60 days and functional storage for your language, theme, workspace preferences, and in-progress authentication flows. We also store your privacy choice in a first-party cookie for up to one year. For every visitor, regardless of their privacy choice, we perform privacy-preserving first-party measurement for aggregate service and campaign performance. A tab-scoped session record retains only a sanitized acquisition source, medium, campaign label, and coarse route group. It excludes advertising click identifiers, full URLs, persistent visitor identifiers, and account or user IDs, and it ends when the tab is closed. Page-group and conversion-category totals are sent only to our backend as separate anonymous events with a fresh event identifier; they are not linked to your account, shared with advertising platforms, or used to follow you across sites. The “Limited measurement only” choice keeps measurement at this level.
If you choose “Allow analytics” and arrive through a marketing link, we store campaign parameters and advertising click identifiers in a first-party attribution cookie for up to 90 days and mirror that record to local storage for measurement continuity. The local copy is removed when the 90-day window expires, when you withdraw consent, or when it is replaced or removed by the Service.
Only after you choose “Allow analytics”, and when configured, may Google Tag Manager load analytics and advertising tags from partners such as Google, Meta, and TikTok. These partners may receive page-view, campaign, device, and conversion information under their own privacy terms. Use the “Privacy choices” control to withdraw consent; doing so removes the attribution cookie and local copy and reloads the page so optional tags are no longer active. Limited anonymous first-party measurement continues after withdrawal as described above. You can also clear browser storage directly; clearing essential storage may sign you out or reset preferences.
Children
The Service is not directed to children under 13 (or the equivalent minimum age in your region), and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.
Your rights
Under the PDPA you may request access to, and correction of, the personal data we hold about you, and information about how it has been used or disclosed in the past year. Depending on your region you may have additional rights (such as portability or erasure). Most actions — editing your profile, deleting creations, deleting your account — are available directly in the app; for anything else, contact our Data Protection Officer below. We will respond within the time required by law. You may also lodge a complaint with the PDPC (www.pdpc.gov.sg) or your local supervisory authority.
Changes to this policy
We may update this policy as the Service or the law evolves. Material changes will be announced in the app or on this site, with the “Last updated” date revised. Continued use after changes take effect constitutes acceptance.
Contact & Data Protection Officer
Our Data Protection Officer can be reached at support@versein.app, or by mail to Zuler Technology Pte. Ltd., 991D Alexandra Rd, #02-17, Singapore 119972.