Privacy policy
Last updated 4 October 2026
This policy says what we collect, why, who sees it and how to control it. If something isn't clear, contact us through support@vimitron.com.
Who we are
Vimitron ("we", "us") is an AI content platform at vimitron.com. You can generate images, videos and captions, build automated workflows, and publish to your social media accounts. This policy explains what personal data we collect when you use Vimitron, why we collect it, who we share it with and the choices you have. It applies to the website and every feature on it.
Information we collect
Account information
- Your email address, username and display name.
- If you sign in with Google or GitHub: your name, email address and profile picture from that account. We never receive your Google or GitHub password.
- If you sign up with email: a password, which we store only as a one-way bcrypt hash.
Content you create
- Prompts, negative prompts, styles and the settings you choose.
- Images, videos and audio you generate or upload, including photos of yourself that you upload to try a template.
- Templates you publish, workflows you build, captions and scheduled social posts, and suggestions you send us.
Connected social accounts
When you connect Instagram, Facebook, X, LinkedIn, YouTube, TikTok or Pinterest, we store the access tokens that platform gives us, encrypted, plus basic profile details such as the account name and picture. We use them only to publish the posts you ask us to.
Telegram chats
When you connect a Telegram chat, group or channel for workflow alerts or the Telegram node, we store its Telegram chat ID, its type and its title (for a private chat, your Telegram first and last name). We use them only to send the alerts and messages you set up. We don't store the messages we send. Removing the chat on the Socials page deletes these details.
Payments
Token packs are paid through Razorpay. Your card, UPI or bank details go straight to Razorpay; we never see or store them. We keep the order and payment IDs, the pack, the amount, the payment method type (for example "upi" or "card"), the status and, if a payment fails, Razorpay's reason.
Technical information
- Your token balance and a history of what you spent tokens on.
- Short-lived counters keyed to your account or IP address, used to stop abuse (for example, limits on login attempts, coupon attempts and payment orders).
- Standard server logs from our hosting provider, such as IP address, browser type and the pages requested.
We do not use third-party analytics or tracking scripts.
How we use your information
- To create and secure your account, sign you in and keep you signed in.
- To run the features you use: generating media, saving it to your library, running workflows and publishing posts.
- To grant daily tokens, process purchases, add bought tokens and show your token history.
- To send account emails, such as email verification and password resets. We don't send marketing email.
- To prevent fraud and abuse, and to fix problems.
- To review suggestions and, if a suggestion is approved, reward you with tokens.
Explore and public content
New images and videos you generate are public by default. They appear in the Explore gallery with your prompt, display name and profile picture. Public copies are watermarked, and anyone can view them; signed-in users can like them or buy a clean download.
You can make any item private from your Library, and it disappears from Explore straight away. Photos you upload of yourself, and anything generated from them, are always private unless you publish them. Templates you publish are public until you delete them.
Moderation and reports
To keep Explore safe, we automatically check the prompt of each new generation for clearly prohibited requests. Items that match stay off Explore until a moderator looks at them. Signed-in users can report a public item. A report stores who sent it, the reason, any details they wrote and when. The creator never sees who reported them.
Our admins can see reported and flagged items, including the original file, the prompt and the creator's name and email, so they can decide whether to keep or remove them. We may also use reports to act against accounts that repeatedly break the rules.
Who we share information with
We do not sell your personal data. We share it only with the service providers below, and only what each one needs to do its job for us.
- fal.ai generates images and videos. It receives your prompt, settings and any reference images, including photos of yourself when you try a template.
- OpenRouter generates text such as captions. It receives the text prompt.
- Cloudflare R2 stores your generated and uploaded files. Private files are only reachable through links that expire.
- Razorpay processes payments. See Razorpay's privacy policy.
- Google and GitHub handle sign-in, if you choose them.
- Social platforms you connect receive the posts, media and captions you publish to them.
- Telegram delivers the workflow alerts and Telegram node messages you set up, to the chats you choose. It receives the message text and any media link. See Telegram's privacy policy.
- Infrastructure providers host the site and its data: Vercel (hosting), a managed PostgreSQL database, Upstash Redis (sessions and caching), Inngest (background jobs and scheduling) and our email provider (account emails).
We may also disclose information if the law requires it, or to protect our users, Vimitron or the public from harm.
Cookies and local storage
- Session cookie. When you sign in we set one cookie,
session_token. It keeps you signed in for up to 7 days and can't be read by scripts on the page. We don't need your consent for it because the site can't work without it. - Local storage. Your browser keeps some workflow drafts and editor settings on your device so your work survives a reload. It is not sent to us unless you save the workflow.
Advertising
We may show ads served by Google AdSense on some public pages. Third-party vendors, including Google, use cookies to serve ads based on your previous visits to this and other websites. Google's advertising cookies let it and its partners show you ads based on those visits.
You can opt out of personalised advertising in Google Ads Settings, or opt out of other vendors' personalised-ad cookies at aboutads.info. Learn more in how Google uses information from sites that use its services.
Where ads are shown to visitors in the European Economic Area, the UK and Switzerland, they are first asked for consent through a Google-certified consent message. You can change your choice at any time from the privacy link that message adds to the page.
How long we keep your information
- Account details, generated media, templates and workflows: while your account exists, or until you delete them.
- Photos you upload of yourself: until you remove them or delete your account.
- Sign-in sessions: 7 days. Email verification and password reset links expire within hours.
- Daily free tokens expire at midnight UTC. Bought tokens expire 365 days after your most recent purchase.
- Payment records: as long as Indian tax and accounting law requires, even if you delete your account.
- Content reports and moderation decisions: until the reported item or the reporting account is deleted.
- Abuse-prevention counters: minutes to hours.
How we protect your information
Passwords are stored only as bcrypt hashes, social account tokens are encrypted, and all traffic uses HTTPS. The session cookie can't be read by scripts on the page, and private files are served through expiring signed links. No system is perfectly secure, but we work to protect your data and will notify you as the law requires if a breach affects you.
Your rights and choices
Depending on where you live, including under India's Digital Personal Data Protection Act, 2023 and the EU/UK GDPR, you can ask to access, correct or delete your personal data, and withdraw consent you gave us. You can do a lot of this yourself:
- Edit your profile in Settings.
- Make media private, or delete it, from your Library.
- Disconnect social accounts on the Social page; we delete the stored tokens.
- Opt out of personalised ads using the links in the Advertising section above.
To access your data, delete your account, or make any other request, contact us through support@vimitron.com. We reply within 30 days. If you're not satisfied with our answer, you can complain to your local data protection authority.
Children
Vimitron is not meant for anyone under 18, and we don't knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
International transfers
We are based in India, and some of our providers, including fal.ai, OpenRouter, Vercel and Cloudflare, process data in other countries such as the United States. When we transfer data, we rely on those providers' contractual and security commitments.
Changes to this policy
We'll update this page when our practices change and update the date at the top. If a change is significant, we will also tell signed-in users in the app before it takes effect.