Privacy Policy — Merge
Effective Date: May 2026
Last Updated: September 2026
1. Introduction
Merge ("we", "us", "our") is an AI-powered video generation app that lets you create motion-controlled videos using your photos and reference videos. This Privacy Policy explains what personal information we collect, how we use it, and your rights regarding your data.
By using Merge, you agree to the practices described in this policy.
2. Information We Collect
2.1 Account Information
When you sign in with Apple, we receive:
- Your Apple-provided user ID (a stable, anonymized identifier — not your Apple ID email unless you choose to share it)
- Your name (first time only, if you share it with the app)
- Your email address (only if you choose to share it — Apple may relay it through a private address)
We do not receive your Apple ID password or any payment information from Apple.
2.2 Profile Information
Information you voluntarily provide:
- Display name and username
- Bio text
- Profile photo (avatar)
2.3 Content You Create
- Character photos: The images you select as your character source. When you tap Generate, the photo is uploaded to temporary storage (Supabase Storage, under
temp/) and sent from there to Wan AI (Alibaba's Wan video-generation model, which we access through our processor fal.ai) to create your video. Temporary uploads are deleted automatically within about 48 hours; we keep no permanent copy.
2.3a Photos and Face Data
The character photo you choose typically shows a person, so it may contain an image of a face. We want to be explicit about how this is handled:
- No facial recognition or biometric processing. Merge does not detect, scan, map, measure, or recognize faces on your device. We do not create or store any faceprint, face template, facial-geometry data, or other biometric identifier, and we never use your photo to identify or authenticate you. The app uses no face-detection, Vision, or biometric APIs.
- What is collected: the whole photo you selected (as a standard image), not any extracted facial features.
- Who it is sent to: the photo is sent to Wan AI (Alibaba's Wan video-generation model, provided to us through fal.ai; app versions before 1.1 use the Kling model via fal.ai) solely to animate it into the video you requested. This transfer is disclosed in the app and requires your explicit in-app consent before any photo is sent.
- How it is used: only to generate your requested video. It is not used to train AI models and is not used for identification, advertising, or profiling.
- Retention: we keep the photo only in temporary storage until our daily cleanup deletes it (within about 48 hours). fal.ai processes it transiently to produce the video under its own retention policy; it is not used to train AI models.
- Any face detection that occurs (for example, an error telling you no clear face was found in the photo) happens on our AI provider's servers (Wan AI via fal.ai), not in the Merge app.
- Reference motion videos: The clip you select as your motion reference. When you tap Generate, the app trims it to your chosen length, converts it to at most 720p, and uploads the clip and its audio track to temporary storage (Supabase Storage, under
temp/) so Wan AI can read them. The audio track is added back to your generated video. These files are deleted automatically within about 48 hours. - Generated videos: AI-generated videos. If you choose to publish a video, it is stored in Supabase Storage and appears in the public feed. If you choose to save privately, the video is saved only to your device.
2.4 Usage and Analytics
We use Mixpanel to collect anonymous usage analytics, including:
- Feature interactions (e.g., generation started, published, liked)
- App performance events
- Funnel and retention data
Mixpanel data is associated with your Supabase user ID (not your name or email) unless you explicitly provide an email.
2.4a Advertising Measurement (Meta)
We use the Meta (Facebook) SDK to measure how well our ads work. It records app installs and opens and when you create an account with Sign in with Apple, together with a Meta anonymous ID and, only if you allow tracking in the iOS App Tracking Transparency prompt, your device's advertising identifier (IDFA). Purchases are reported to Meta by RevenueCat on our behalf, linked to the same anonymous ID, so we can measure purchases that came from our ads.
We never send your photos, videos, prompts, name, or email to Meta. You can decline tracking when asked, or turn it off later in iOS Settings → Privacy & Security → Tracking.
2.5 Purchase and Subscription Data
We use RevenueCat to process in-app purchases. RevenueCat receives:
- Your Apple App Account Token (anonymous purchase identifier)
- Product IDs and transaction IDs from Apple
- Your Supabase user ID (to match purchases to your account)
We never see or store your full credit card or billing details — all payment processing is handled by Apple.
2.6 Technical Data
Automatically collected when you use the app:
- Device type and iOS version
- App version
- Crash and error reports (via Supabase error logging)
- API request logs (IP address, timestamp, endpoint — retained for 30 days)
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Creating and managing your account | Contract performance |
| Generating AI videos | Contract performance |
| Showing your content in the public feed (if published) | Contract performance / Consent |
| Processing credit purchases and subscriptions | Contract performance |
| Detecting and preventing abuse (rate limiting, fraud) | Legitimate interest |
| Analytics to improve the app | Legitimate interest |
| Measuring ad performance (Meta) | Legitimate interest; your consent (App Tracking Transparency) for the advertising identifier |
| Responding to support requests | Legitimate interest |
| Legal compliance | Legal obligation |
4. Information We Share
We share data only as necessary to operate the service:
| Recipient | What is shared | Why |
|---|---|---|
| Wan AI (Alibaba's Wan model, via our processor fal.ai) | Character photo, reference video and its audio track (temporary storage URLs), generation prompt | AI video generation (app versions before 1.1 use Kling via fal.ai) |
| Supabase (supabase.com) | All database content, authentication, file storage | Backend infrastructure |
| RevenueCat (revenuecat.com) | User ID, product purchases | Subscription and credit management |
| Mixpanel (mixpanel.com) | Anonymous usage events | Analytics |
| Meta Platforms (facebook.com) | Meta anonymous ID, install/open and sign-up events, purchase events (via RevenueCat), advertising identifier only if you allow tracking | Ad measurement |
| Google Cloud Run | API request data | Backend hosting |
We do not sell your personal information to any third party.
We may disclose information if required by law, court order, or to protect the rights and safety of our users.
5. Data Retention
| Data | Retention Period |
|---|---|
| Account and profile data | Until account deletion |
| Published videos | Until you delete or unpublish them |
| Generation task records | 30 days (Provider CDN links expire; records are then purged) |
| Credit transaction ledger | 7 years (financial record requirement) |
| API request logs | 30 days |
| Analytics data (Mixpanel) | 2 years |
| Temporary uploads (photo, reference video, audio) | Deleted automatically within about 48 hours of upload (daily cleanup) |
| Character photos (incl. any faces they contain) | Kept only in temporary storage until the daily cleanup (within about 48 hours); processed by Wan AI (via fal.ai) only to generate the video |
6. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you.
- Correction: Request correction of inaccurate profile information (via the app's Edit Profile screen).
- Deletion: Delete your account and all associated data at any time via Settings → Delete Account in the app. This permanently removes your auth account, profile, posts, credits, and storage files.
- Data portability: Request an export of your data.
- Withdraw consent: Disable analytics tracking by opting out of Mixpanel data collection (contact us).
To exercise any of these rights, contact us at: [email protected] (or the contact email provided in your App Store listing).
7. Children's Privacy
Merge is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us immediately and we will delete it.
8. International Data Transfers
Our infrastructure providers (Supabase, Google Cloud, fal.ai, RevenueCat, Mixpanel, Meta) may process data in countries outside your own. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms to ensure adequate protection.
9. Security
We protect your data using industry-standard security practices:
- HTTPS/TLS for all data in transit
- Supabase Row Level Security (RLS) ensuring users can only access their own data
- API keys and secrets stored in Google Secret Manager (never in source code)
- Supabase JWT authentication on all backend API calls
- Google Cloud Armor (WAF and DDoS protection)
Despite our best efforts, no method of transmission over the internet is 100% secure.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via an in-app notice or by updating the "Last Updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy, please contact us:
Email: [email protected]
App: Merge — available on the Apple App Store
This Privacy Policy was drafted for the Merge iOS app. It covers data processing as of the Effective Date above.