Data Processing Notice
Version 2026-10-01
This notice is part of the API Terms. It explains how HAKKO AI PTE. LTD. ("Cuddler", "we") handles the data your organization sends to and receives from the Cuddler Platform API. It is written for businesses; it is not a data processing agreement. If you need one, write to [email protected].
1. What we process
| Data | Examples | Why |
|---|---|---|
| Inputs | Prompts, uploaded images, videos and audio, request parameters, metadata | To generate your videos and check them against our policies |
| Outputs | Generated videos and last frames | To deliver them to you |
| Account data | Organization name and country, contact names and emails, billing email | To run your account, answer you and bill you |
| Usage and logs | Request ids, keys used, timestamps, IP-derived abuse signals, job results, token counts | To bill accurately, secure the service and handle abuse |
| Billing data | Invoices and payment status (card details are handled by Stripe, not by us) | To collect payments and meet accounting duties |
2. How we use it
We use this data only to provide the API, to bill you, to keep the service secure, to enforce the Acceptable Use Policy and to meet legal obligations.
We do not use your Inputs or Outputs to train AI models, and we do not sell them.
3. Where it is processed
Videos are generated by our model provider Volcano Engine in Beijing, China. Your prompts and the reference files a job uses are sent there to generate the video, and the result is returned to us. Other data is stored and processed with the providers below, in the United States and in other countries where they operate. By using the API you instruct us to transfer data to these locations.
4. Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Volcano Engine | Video generation and the provider's own safety checks | Beijing, China |
| Cloudflare | Storage of uploads and outputs, and delivery | Global network |
| Google Cloud | Hosting of the API, databases, logs and prompt and image checks | United States and other regions |
| Stripe | Invoicing and payments | United States and other regions |
| Resend | Sending email to your contacts (application decisions, low-balance notices) | United States |
We will give at least 14 days' notice before adding a sub-processor that handles your Inputs or Outputs.
5. How long we keep it
| Data | Kept for |
|---|---|
| Finished videos and last frames | 7 days after the job completes, then deleted |
| Uploads (the file) | 30 days after the upload is completed, then deleted; uploads never completed expire sooner. The upload record (type, size, dimensions or duration, and a fingerprint of the content) stays with your job records |
| Prompts and job metadata | 180 days after the job finishes, for abuse handling, then removed from the job record |
| Webhook delivery records (the copy of the video object sent to your endpoint, prompt included) | 180 days, then deleted |
| Request logs (request ids, keys used, timestamps, status codes; never prompts or files) | Up to 180 days |
| Job records (parameters, upload ids, provider task ids, status, token counts, charges) | For as long as your organization is active, and as long as accounting law requires after that |
| Account and billing records | As long as accounting and tax law requires |
6. Deletion requests
You can ask us to delete Outputs or uploads before their retention period ends by writing to [email protected] with the relevant ids. Records we must keep for billing, security or legal reasons are kept for the periods above.
7. Personal data in your Inputs
You decide what you send us, and you are responsible for having a lawful basis to do so. Send personal data only where you need it for your production. Where your Inputs contain personal data, we process it on your behalf and on your instructions, which are these terms and your API requests. References showing real human faces are rejected by the model.
8. Security
We encrypt data in transit, keep uploads and outputs in private storage reachable only through short-lived signed links, store only hashes of API keys, sign webhooks, and limit staff access to the people who need it to run the service.
9. Contact and changes
Questions and requests: [email protected]. We may update this notice under the change rules in the API Terms. The English version is the binding one.