Caelia Privacy Policy

Operated by SLTR Digital LLC

Effective Date: September 22, 2026 | Last Updated: September 23, 2026

#1. Introduction

This Privacy Policy explains how SLTR Digital LLC ("SLTR Digital," "Caelia," "we," "us," or "our") collects, uses, stores, shares, and protects personal information when you use the Caelia mobile application, the website at caelia.io, and related services (together, the "Service"). It also explains the rights you have and how to use them.

Caelia works with some of the most personal information there is: photos of human faces, and videos that bring them to life. We built our practices around one principle: your photos and videos are yours, they exist in Caelia only to make your videos, and we protect them accordingly.

Capitalized terms not defined here have the meanings given in our Terms of Service.

#2. Who Is Responsible for Your Information

SLTR Digital LLC is the controller of your personal information (the business responsible for deciding how and why it is processed).

  • SLTR Digital LLC, 696 S New Hampshire Ave, Apt 2811, Los Angeles, CA 90005, United States
  • Privacy questions and requests: privacy@caelia.io

EU and UK representative: where we are required to appoint a representative under Article 27 of the EU or UK General Data Protection Regulation, their contact details will be listed in this Section. Until then, and at any time, you may contact us directly at privacy@caelia.io.

#3. Our Core Commitments

  • We never use your photos, audio, text, or videos to train or improve any AI model, ours or anyone else's.
  • We never sell or rent your personal information, and we never "share" it for cross-context behavioral advertising.
  • We never use your content for marketing or advertising, and we never make it public.
  • We never use facial data to identify people, recognize faces across photos, or build a face database.
  • Facial data derived from your photos is temporary. It exists only while your video is being generated and is permanently deleted immediately afterward, and in all cases within 24 hours.
  • You stay in control. You can delete any photo, video, or your entire account at any time from inside the app.

#4. Information We Collect

#4.1 Information you provide

  • Account information: your email address, a display name if you choose one, and your authentication credentials. If you use Sign in with Apple, we receive the name and email Apple shares with us, which may be a private relay email address that hides your real address.
  • Input Photos: the photos you upload or capture in the app to create videos, including the faces and any other people or objects shown in them, and the file metadata that comes with the image (such as file type, dimensions, and, if present, date and camera information). We remove location metadata from uploaded images before storing them.
  • Speech content: audio you record or upload, or text you enter, to tell the Service what the person in the video should say.
  • Outputs: the talking videos generated from your Inputs.
  • Consent and permission records: records of the consents you give in the app, such as your biometric consent, your confirmations that you have permission to use the people in your photos, and your age confirmation, including the date, time, and version of the consent text.
  • Communications: messages you send us, including support requests, reports of misuse, removal requests, appeals, and feedback, and any attachments.

#4.2 Information generated when you use the Service

  • Facial data: to animate a face, our system detects the face in your Input Photo and computes temporary measurements of facial features, such as the positions of the eyes, nose, mouth, and jawline and how they should move (the "Facial Data"). Section 6 explains exactly how Facial Data is handled.
  • Usage and service data: actions you take in the app, features used, generation requests, processing times, errors, and performance data.
  • Device and technical data: device model, operating system version, app version, language and region settings, time zone, IP address, and a device or installation identifier used to operate and secure the Service. We do not access your device's advertising identifier (IDFA) and do not track you across other companies' apps or websites.
  • Safety data: results of automated checks for prohibited content, moderation decisions, and records of reports and enforcement actions.

#4.3 Information from third parties

  • Apple and RevenueCat: when you buy credits in the app, Apple takes the payment, and RevenueCat, which processes purchases on our behalf, passes the result to us: the credit pack bought, a transaction identifier, the date, the country of purchase, and whether the purchase was later refunded. We never receive your full payment card number or billing address.
  • Stripe: when you buy credits on our website, Stripe takes the payment and tells us the credit pack bought, a transaction identifier, the date, your billing country, and whether the payment succeeded or was later refunded. Your card details go to Stripe directly; we never receive your full card number.
  • People who report content: if someone reports content you created, we receive the information in their report.

#4.4 Information about people who are not Caelia users

Your Input Photos may show people who do not use Caelia. We process their images and derived Facial Data only to generate the video you requested and for the other purposes described in this Policy. Section 14 explains the rights of people who appear in photos.

#5. How We Use Information

We use personal information only for the following purposes:

  • To provide the Service: create and manage your account, generate your Outputs, store your Inputs and Outputs in your library, and let you download and share them.
  • To process payments: verify purchases, add the credits you have bought to your balance, unlock Paid Services, and handle refunds and cancellations.
  • To keep people safe and enforce our Terms: detect and prevent prohibited content, fraud, impersonation, abuse, and misuse of likeness; review reports; take enforcement actions; handle appeals; and report child sexual exploitation to the National Center for Missing and Exploited Children as the law requires.
  • To secure the Service: authenticate users, prevent unauthorized access, monitor for attacks, and investigate security incidents.
  • To maintain and improve the Service: diagnose errors, monitor performance and render times, and improve reliability using aggregated or de-identified usage and technical data only. This never includes training or improving AI models with your photos, audio, text, videos, or Facial Data.
  • To communicate with you: respond to support requests and send service messages such as account, security, billing, and policy notices. We will send marketing emails only if you opt in, and you can unsubscribe at any time.
  • To comply with law: meet legal, tax, accounting, and regulatory obligations, respond to lawful requests, and establish, exercise, or defend legal claims.

#6. Facial Data and Biometric Information

This Section is our written policy on facial and biometric data, including for purposes of the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act, the Washington biometric identifier law (RCW 19.375), the Colorado Privacy Act, other United States state laws, and the EU and UK General Data Protection Regulations.

#6.1 What Facial Data is

Facial Data means the measurements of facial features and facial movement parameters computed from the faces in your Input Photos so that our models can animate them. Some laws may treat this as biometric information, a biometric identifier, or a scan of face geometry. We treat it with that level of protection regardless of where you live.

We do not process Facial Data until you have given express, written (electronic) consent in the app after being shown what Facial Data is, why we process it, and how long we keep it. You may withdraw consent at any time by emailing privacy@caelia.io or deleting your account; after that, we will not generate new videos for you, and withdrawal does not affect processing that already took place. When you upload a photo of someone else, you confirm under our Terms that you have informed that person and obtained any consent the law requires from them.

#6.3 The only purpose

We process Facial Data solely to generate the Output you requested. We do not use Facial Data to identify or verify any person, to recognize faces across photos or accounts, to infer anyone's race, ethnicity, health, emotions, or other sensitive characteristics, to build any face database or template for later reuse, or to train or improve any model.

#6.4 Retention and destruction schedule

Facial Data is held only in temporary working memory and temporary processing storage on our computing infrastructure while your video is being generated. It is permanently destroyed as soon as the Output is generated or the generation request fails or is canceled, and in every case no later than 24 hours after it was created. It is never written to your library, our databases, or our backups. This is well within the legal maximum under BIPA, which requires destruction once the initial purpose is satisfied or within 3 years of an individual's last interaction, whichever occurs first.

#6.5 No sale, no profit, no disclosure

We do not and will not sell, lease, trade, or otherwise profit from Facial Data. We do not disclose Facial Data to anyone except to the computing service providers that process it on our behalf, under contracts that prohibit any other use, or where disclosure is required by law or valid legal process.

#6.6 Protection

We store, transmit, and protect Facial Data using a standard of care at least as protective as the way we protect other confidential and sensitive information, and in line with reasonable industry standards, as described in Section 11.

#7. What We Never Do

  • We never train, fine-tune, evaluate, or improve AI models on your Inputs, Outputs, or Facial Data.
  • We never sell your personal information or share it for targeted advertising.
  • We never show ads based on your content, and we do not include third-party advertising software in the app.
  • We never publish, showcase, or use your photos or videos for marketing.
  • We never let our employees or contractors browse your content. Access is limited to what is necessary to operate the Service, respond to your support request with your permission, review content that has been reported or automatically flagged for safety, or comply with law, and every such access is restricted and logged.

If data protection law in the EEA, UK, or Switzerland applies to you, we rely on the following legal bases:

PurposeLegal basis
Creating your account; generating, storing, and delivering your Outputs; managing your credit balance and purchasesPerformance of our contract with you (Article 6(1)(b) GDPR)
Processing Facial Data and any photos that could reveal special category dataYour explicit consent (Articles 6(1)(a) and 9(2)(a) GDPR), which you can withdraw at any time
Processing the images of other people in your photosOur legitimate interest and yours in providing the video you requested, relying on your confirmation that you have their permission (Article 6(1)(f) GDPR); where required, their explicit consent obtained by you
Safety, abuse prevention, content moderation, and securityOur legitimate interests in protecting users, depicted persons, the public, and the Service (Article 6(1)(f) GDPR), and legal obligations where applicable
Service performance and reliability using de-identified dataOur legitimate interest in operating a reliable Service (Article 6(1)(f) GDPR)
Tax, accounting, legal requests, and mandatory reportingCompliance with legal obligations (Article 6(1)(c) GDPR)
Optional marketing emailsYour consent (Article 6(1)(a) GDPR)

Where we rely on legitimate interests, we have balanced those interests against your rights, and you may object as described in Section 13.

#9. How We Share Information

We share personal information only as described below. We never sell it.

#9.1 Service providers (processors)

We use a small number of carefully chosen providers that process data on our instructions, under written contracts requiring confidentiality, security, and use only for our purposes:

ProviderWhat they do for usData involvedLocation
Amazon Web Services, Inc.Cloud hosting, databases, file storage, user authentication, and security infrastructureAll categories, including Inputs and Outputs, encryptedUnited States
Lambda, Inc.GPU computing used to generate OutputsInput Photos, speech content, temporary Facial Data, Outputs during generation onlyUnited States
Apple Inc.App distribution, in-app purchases, Sign in with Apple, push notificationsAccount and transaction information, notification tokensUnited States and worldwide
RevenueCat, Inc.Processing and validating in-app purchases, and recording which credit packs an account has boughtYour Caelia account identifier, purchase and transaction records, and app and device version informationUnited States
Stripe, Inc.Taking payment for credits bought on our websiteEmail address, your Caelia account identifier, billing country, and transaction records. Card details are collected by Stripe directly; we never receive your full card numberUnited States
Our email service providerSending and receiving support and service emailsEmail address and message contentsUnited States

We will update this list before adding any new provider that receives your Inputs, Outputs, or Facial Data, and you can request the current list at any time at privacy@caelia.io.

We may disclose information if we believe in good faith it is necessary to comply with law, regulation, subpoena, court order, or other valid legal process; to report child sexual exploitation to the National Center for Missing and Exploited Children as required by 18 U.S.C. Section 2258A; to protect the rights, safety, or property of any person, including people depicted in content; to detect or prevent fraud or security threats; or to enforce our Terms. Where legally permitted, we will notify you of government requests for your data.

#9.3 Business transfers

If SLTR Digital is involved in a merger, acquisition, reorganization, financing, or sale of assets, including a transfer of Caelia to an affiliated entity formed to operate it, your information may be transferred as part of that transaction. The recipient will be bound by this Policy's commitments for information collected under it, including the commitments in Sections 3, 6, and 7, and we will notify you before your information becomes subject to a different privacy policy.

#9.4 With your direction

When you choose to share an Output to another app or person, you are sharing it directly, and the recipient's use is governed by their own terms.

#10. International Data Transfers

We are based in the United States, and our Service is hosted in the United States. If you use the Service from outside the United States, including from the EEA, UK, or Switzerland, your information will be transferred to and processed in the United States, which may not have the same data protection laws as your country. For transfers from the EEA, UK, and Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum and Swiss equivalents) with our providers, or on a provider's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions where applicable, together with supplementary security measures such as encryption. You can request a copy of the relevant safeguards at privacy@caelia.io.

#11. How We Protect Information

We use administrative, technical, and physical safeguards designed to protect your information, including:

  • encryption in transit using TLS for all communication between the app and our servers;
  • encryption at rest for stored photos, audio, text, and videos;
  • a dedicated cloud environment used only for Caelia, isolated from any other product or business;
  • private storage that is never publicly accessible, with time-limited, access-controlled links for downloads;
  • least-privilege access controls, multi-factor authentication for administrative access, and logging of access to user content;
  • automatic destruction of Facial Data as described in Section 6.4;
  • monitoring for security threats and a documented process for responding to incidents.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach affects your personal information, we will notify you and the relevant authorities as required by law, including within 72 hours to supervisory authorities where GDPR applies.

#12. How Long We Keep Information

We keep personal information only as long as necessary for the purposes described in this Policy:

CategoryRetention period
Facial DataDestroyed as soon as the Output is generated or the request ends, and never later than 24 hours after creation. Never backed up.
Input Photos, speech content, and OutputsKept in your library until you delete them or delete your account. Deleted from active systems within 30 days of deletion and from encrypted backups within 90 days.
Temporary processing copies on computing providersDeleted automatically when generation completes or fails, and no later than 24 hours.
Account informationFor the life of your account, then deleted within 30 days of account deletion (backups within 90 days).
Inactive accountsIf you do not sign in for 24 months, we will email you, and if you do not respond within 30 days, we will delete your account and content.
Consent recordsFor the life of your account plus 3 years, to demonstrate lawful consent.
Purchase and transaction records7 years, to meet tax and accounting obligations.
Support communications3 years after the conversation ends.
Security and access logs12 months.
Records of serious violations and bansUp to 5 years, limited to the minimum needed to prevent banned users from returning and to defend legal claims.
Content we are legally required to preserveAs long as the law requires (for example, material reported to the National Center for Missing and Exploited Children must be preserved for the period set by federal law), or for the duration of an active legal hold.

Aggregated or de-identified data that cannot reasonably be linked to you may be kept longer.

#13. Your Rights and Choices

#13.1 Rights available to everyone

Wherever you live, you can:

  • view, download, and delete any Input Photo or Output in the app at any time;
  • delete your account in the app under Settings, then Account, then Delete Account, which deletes your content on the schedule in Section 12;
  • request a copy of your personal information, correction of inaccurate information, or deletion, by emailing privacy@caelia.io;
  • withdraw consent to Facial Data processing;
  • unsubscribe from any marketing email.

#13.2 EEA, UK, and Switzerland

You have the right to access, rectify, erase, restrict, and port your personal data; to object to processing based on legitimate interests; to withdraw consent at any time without affecting prior lawful processing; and to lodge a complaint with your local data protection supervisory authority. In the UK, that is the Information Commissioner's Office. We will respond within one month, which may be extended by two further months for complex requests, as the law allows.

#13.3 California residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), California residents have the right to know what personal information we collect, use, and disclose; to access and receive a portable copy; to delete; to correct; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.

In the past 12 months we have collected the following categories of personal information, for the business purposes in Section 5, and disclosed them only to the service providers in Section 9.1:

CCPA categoryExamplesSold or shared for advertising?
IdentifiersEmail, account ID, IP address, device identifierNo
Customer recordsName, emailNo
Commercial informationCredit purchases and transaction historyNo
Biometric informationTemporary Facial Data (Section 6)No
Internet or network activityApp usage, errors, performance dataNo
Audio, electronic, and visual informationInput Photos, audio, OutputsNo
Sensitive personal informationAccount login credentials; Facial DataNo

We use sensitive personal information only for purposes permitted under the CCPA regulations (such as providing the Service you requested and ensuring security), so the right to limit is honored by default. We do not sell or share personal information and have no actual knowledge of selling or sharing the personal information of consumers under 16.

Shine the Light: we do not disclose personal information to third parties for their own direct marketing purposes.

#13.4 Other United States states

Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with comprehensive privacy laws may have rights to confirm processing, access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. We do not engage in targeted advertising, sale, or profiling that produces legal or similarly significant effects. If we deny your request, you may appeal by replying to our decision or emailing privacy@caelia.io with the subject line "Privacy Appeal," and we will respond within the time required by your state's law. If your appeal is denied, you may contact your state Attorney General.

#13.5 How to make a request

Email privacy@caelia.io from the email address on your account, or through the in-app support option. To protect you, we will verify your identity by confirming control of your account email or account, and we may ask for more information where necessary. You may use an authorized agent; we will ask for proof of their authority and may ask you to confirm your identity directly. We will respond within 45 days where United States law applies (extendable once by 45 days with notice) and within the GDPR timeline where GDPR applies. We do not charge a fee unless a request is manifestly unfounded or excessive.

#13.6 Global Privacy Control and Do Not Track

Because we do not sell or share personal information or engage in targeted advertising, there is nothing for these signals to opt you out of. Our website honors Global Privacy Control signals as a valid opt-out request under applicable law.

#14. People Shown in Photos Who Are Not Caelia Users

If you believe your image, your child's image, or the image of a deceased family member was uploaded to Caelia without permission, you have rights even without an account. Email privacy@caelia.io or legal@caelia.io with a description of the content and your relationship to the person shown. We will review the request, may ask the uploading user to confirm their permission, and will delete the content where appropriate or where the law requires. For intimate imagery created without consent, email safety@caelia.io; we will act within 48 hours as described in our Terms of Service. We will not ask you to upload a photo of yourself to prove who you are unless there is no other reasonable way to verify your request, and any such photo will be used only for verification and deleted afterward.

#15. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 as users. If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete it promptly. In the EEA and UK, where a higher age of digital consent applies, we require the user to meet that age or have verified parental consent. Parents and guardians may contact privacy@caelia.io to review or delete their child's information.

Parents and guardians may upload photos of their own children to create videos for personal use, as allowed by our Terms. That content is protected under this Policy like all other content, is never used for training or marketing, and may be deleted at any time.

#16. Automated Decision-Making

We use automated systems to detect content that may violate our Terms and to block generation of prohibited content. These systems do not make decisions that produce legal or similarly significant effects about you. Account suspensions and terminations based on automated detection can be appealed to a human reviewer as described in our Terms of Service, and you may request human review of any automated moderation decision.

#17. AI-Generated Content Transparency

Outputs may contain visible labels, invisible watermarks, and embedded metadata identifying them as AI-generated by Caelia, to support transparency and comply with laws such as the EU Artificial Intelligence Act. This provenance information identifies the content as synthetic and generated by Caelia; it does not contain your name, email, or contact details.

#18. Cookies and Similar Technologies

The Caelia app does not use third-party advertising or cross-app tracking technologies. Our website at caelia.io uses only cookies and similar technologies that are strictly necessary for it to function and be secure. If we ever add analytics or other non-essential cookies, we will update this Policy first and, where required, ask for your consent through a cookie banner.

The Service may contain links to, or let you share to, third-party websites and apps. Their privacy practices are governed by their own policies, and we encourage you to read them.

#20. Changes to This Policy

We may update this Privacy Policy as our Service or the law changes. If we make material changes, especially any change affecting how we handle Inputs, Outputs, or Facial Data, we will notify you in the app or by email at least 30 days before the change takes effect and, where required by law, ask for your consent. We will never apply a less protective practice to content you uploaded before the change without your express consent. The "Last Updated" date at the top shows when this Policy was last revised.

#21. Contact Us

SLTR Digital LLC

696 S New Hampshire Ave, Apt 2811

Los Angeles, CA 90005, United States

Privacy: privacy@caelia.io | Support: support@caelia.io | Legal: legal@caelia.io | Safety: safety@caelia.io

If you are in the EEA, UK, or Switzerland and are not satisfied with our response, you may lodge a complaint with your local data protection supervisory authority.