Last updated September 22, 2026
Privacy Policy
This policy describes how the Veylumi Android app and the website at veylumi.xyz handle information. It matches how the app works today.
Developer: Vladyslav Lehkyi
Country: Ukraine
Email: video.ai.owltech@gmail.com
The website
veylumi.xyz is a static website. It has no account, no Google sign-in, no cookies set by Veylumi, and no analytics script. The pages are hosted on GitHub Pages. GitHub may process connection data under GitHub’s Privacy Statement. If you email support, we receive the address you write from and the message you send, and we use that to reply. Support messages are not stored in the app database, and this policy does not set a separate retention period for email.
Who can use the app
Veylumi is for people aged 13 and older. We do not knowingly collect personal information from a child under 13. If you believe a child under 13 has sent personal information, email video.ai.owltech@gmail.com.
Accounts
You can use the app as a guest or with Google.
A guest account is created on the Veylumi server. It stores an account id, a guest id, the credit balance, the daily-reward record, and the date the account was created. The app also stores the account, the session token, and the library list on the device.
Google sign-in asks for the email and profile scopes. The app sends a Google ID token to the Veylumi server. The server checks that token with Google and stores the Google account id, email address, name, and profile photo when Google provides them. Veylumi does not receive your Google password.
If you connect Google to a guest profile, that profile is updated with the Google details and keeps its credits and generations. If that Google account already has a Veylumi profile, the guest generations are moved to the existing profile. The credit balance kept is the higher of the two balances. The balances are not added together.
Signing out deletes the current session token on the server and removes the saved account, token, and library list from the app. It does not delete the account.
What you submit
To make a video you may submit a text prompt and a photo. Photos are chosen with the Android system photo picker. The app does not request access to the whole gallery. A request can also include the template, model, duration (5 or 10 seconds), aspect ratio (9:16, 1:1, or 16:9), and quality (Standard or HD).
The prompt, photo, and settings needed for that generation are sent to a third-party AI service, which produces the video. That service processes the material under its own terms and privacy policy. Veylumi does not use your photos, prompts, or generated videos to train its own AI models.
What the server stores
The server stores the account fields above, a session token, and a record for each generation. A generation record can include the prompt, template, settings, status, credit cost, error text, timestamps, and links to media. Uploaded photos and finished video files are stored as files on the server until the events described under Retention.
The app talks to this server over HTTPS. Download links for media are signed and stop working 7 days after they are created. That limit applies to the link. It is not a date on which your account or library record is deleted.
The server may hold an IP address in memory for up to 24 hours to limit how many guest accounts can be created from one network. That address is not written into the account database.
What stays on the device
The app stores your account, session token, library list, and a few interface flags on the device. After a video is ready, the app downloads a copy into its own storage so the Library can play it. If you tap save, a copy is written to your gallery. The gallery copy remains until you delete it yourself.
Credits and Premium
A new account starts with 25 credits. A daily reward can be claimed about once every 24 hours. The amount follows a seven-day streak: 8, 10, 12, 16, 20, 25, then 40. If more than 48 hours pass, the streak starts again. Credits are spent when a generation starts. They are returned if that generation fails, or if you cancel it while it is still queued or processing. The app does not expire unused credits. They remain until they are spent or the account row is deleted.
The app can show one-time credit packages. Credits from a package are added only when the server accepts a verified store purchase. Granting credits without that verification is turned off.
Premium is a weekly or yearly subscription billed by Google Play. RevenueCat is used to read the subscription status. The app sends your Veylumi account id to RevenueCat for that purpose. Veylumi does not receive your full card number or Google Play payment credentials. Premium currently unlocks the Veylumi 3.0 and Veylumi 3.0 Fast models, 10-second videos, HD quality, and the templates marked Premium. Deleting the app or the Veylumi account does not cancel the Google Play subscription.
Clarity and AppsFlyer
The app includes Microsoft Clarity. Clarity records in-app sessions, including which screens are shown and how they are used. The app does not send Clarity a separate copy of your account id.
The app includes AppsFlyer for install and session attribution. AppsFlyer is allowed to collect the device advertising identifier. The app also sends your Veylumi account id to AppsFlyer as the customer user id.
The app does not include a third-party advertising SDK that displays ads.
Veylumi does not sell personal information.
Who else receives information
- Google, to check the sign-in token and to process Play purchases and subscriptions.
- RevenueCat, to match a subscription to the Veylumi account id.
- Microsoft Clarity and AppsFlyer, as described above.
- The third-party AI service that runs a generation, which receives the prompt, photo, and settings for that request.
- GitHub Pages, for this website, as described above.
These companies may process information outside Ukraine under their own policies. We may also disclose information when the law requires it.
Retention and deletion
There is no automatic date on which an account or a generation record is deleted.
When the app confirms that a finished video has been saved on the device, the server deletes that job’s result file and the uploaded source file. The generation record stays in the database, including the prompt, settings, and status.
If you delete one video from the Library, that generation row is removed. If the files are still on the server, those files are deleted too.
Delete Account is shown for Google-signed-in accounts. It deletes the account row, the session rows, and the generation rows on the server. It does not delete media files that are still on the server disk. It does not send a deletion request to Google, the AI service, Microsoft Clarity, AppsFlyer, or RevenueCat. It does not cancel a Google Play subscription.
On the device, Delete Account removes the saved account, session, and library list, signs out of Google, and signs out of RevenueCat. It does not delete videos already stored in the app’s local cache or in your gallery.
Guest accounts do not have a Delete Account button. Removing the app from the device does not delete the guest record on the server.
To ask about access, correction, or deletion, email video.ai.owltech@gmail.com. Where the law gives you a right to complain to a supervisory authority, you may also contact the authority in your country. In Ukraine, personal-data complaints can be made to the Ukrainian Parliament Commissioner for Human Rights.
Security
The app uses HTTPS for API requests, checks Google ID tokens on the server, and uses expiring signed links for media files. No method of storage or transmission is completely secure.
Changes
If this policy changes, the date at the top of this page will change. The current text is the one published at veylumi.xyz/privacy.
Contact
Vladyslav Lehkyi
Ukraine
video.ai.owltech@gmail.com