Legal / Privacy
Privacy
Longtake is a video studio you run on your own provider keys. That shapes this document: most of what happens to your work happens between you and the model providers, and this page says exactly which parts pass through us.
In force since 14 August 2026
Who is responsible
Longtake is operated by IE Pavel Ilin. For anything in this document — questions, access or deletion requests, complaints — write to [email protected]. We answer within a few working days.
What we store
- Account. Your email address, display name and avatar, as provided by Google (or Apple) when you sign in. We never see or store your password to those accounts.
- Provider API keys. Stored encrypted (AES-256-GCM) and used only to make the requests you ask for. They are never shown back to you in full — only the last four characters — and never sent anywhere except the provider they belong to.
- Your work. Prompts, projects, scenes, characters, uploaded images and audio, generated videos and stills. This is content you created; we store it so the studio can show it back to you.
- Billing. Subscription status and renewal date. Card details are handled by Stripe and never reach our server.
- Usage analytics. Which features are used and how they end — see below.
- Technical logs. Ordinary server logs: request paths, status codes, timing, error messages. They are kept short-term for debugging.
Why we may process it
- To provide the service you asked for — the account, your projects, the renders, the subscription. Without this data there is no studio.
- Our legitimate interest in keeping the service working and safe — technical logs, abuse protection, and product analytics in the aggregate.
- Legal obligations — payment records kept for accounting purposes.
What leaves the studio
To render anything, we pass your prompt and any references you attach to the model provider you selected, using your key:
- BytePlus ModelArk — video generation, standard image generation, and (as a separate product) voice synthesis.
- Google Gemini — the alternative image engine, and prompt translation when it is enabled.
- fal.ai — upscaling a finished take, when you ask for it.
Those providers process that content under their own terms and privacy policies, and they — not us — decide what a model may refuse. Nothing is sent to them unless you start a generation.
Who else is involved
- Google Firebase — sign-in and analytics.
- Stripe — subscription payments.
- Railway — hosting and the disk your projects live on.
- Cloudflare — traffic in front of the site.
We do not sell your data, and we do not share it with anyone beyond what is needed to run the service.
Where the data goes
The studio's server and the disk holding your projects are located in Singapore (Railway). The companies listed above operate internationally as well: Google and Stripe process data in the United States, and BytePlus renders in its Asia-Pacific region. So your account data and your work are stored and processed outside the European Union, and starting a generation sends your prompt and references to the provider whose key you configured. If you are in the EU or the UK, those transfers rely on the providers' own safeguards (standard contractual clauses and equivalent frameworks) and, for the studio itself, on your explicit choice to use a service hosted there.
Analytics
We use Google Analytics for Firebase to understand how the studio is actually used: which steps people finish, which settings they choose, how often a render succeeds. Events carry categories and numbers — a model name, a resolution, a duration, an error category.
Prompts, project and character names, file contents, email addresses and API keys are never sent to analytics. That is enforced in code, not just promised: the analytics layer accepts only short values and discards anything else. If your browser sends a “Do Not Track” signal, analytics stays switched off entirely.
Cookies
One cookie, cf_token, carries your sign-in session so that videos and images load — those requests cannot send an authorisation header, which is the whole reason it exists. It is required for the studio to work. Analytics may set its own cookies through Google.
How long we keep things
Your account and work are kept while your account exists. Delete a project, an asset or a take and its files are removed from the server immediately. Ask us to delete the account and everything belonging to it goes with it — there is no self-service button for that yet, so write to us and we will do it by hand.
Technical logs are kept for about a week. Payment records are kept as long as accounting rules require. Analytics data follows Google's own retention settings for the property.
Your choices
- Get a copy of your data, or have it deleted — write to us and we will do it.
- Remove your API keys at any time from “API keys” in the account menu; the encrypted values are erased.
- Cancel the subscription at any moment from the same menu, through the Stripe portal.
- Turn analytics off at the source: a browser with “Do Not Track” enabled is never tracked.
- If you are in the EU or the UK and think we handled your data wrongly, you may complain to your national data protection authority — but please write to us first, it is usually faster.
Children
The studio is not intended for people under 16.
If the studio closes
Longtake is a small product. If it ever shuts down, we will announce it in advance and give you time to download your work before anything is deleted.
Changes
If this document changes in a way that matters, the date at the top changes with it, and we will say so in the studio.