← bravely.dev

Privacy Policy — Vai

Last updated: September 10, 2026 · Effective: September 10, 2026

Vai is a video editor from Bravely Studios LLC. This policy covers local editing and optional shared workspaces, media storage and connected workers. Availability depends on your build and which services are enabled; describing a feature here does not mean it is enabled for every account.

Local Editing and Optional Sharing

Local editing reads the files you open and saves projects and exports on your device. Built-in transcription and rendering run on the device doing that work. Syncing an edit sends project data to our service; sharing a workspace can also transfer original media according to its storage setting. On-device editing does not mean that content you choose to share stays on one computer.

Shared Projects and Collaborators

Our collaboration service stores workspace names and membership, project structure and settings, media identifiers and file metadata, edit operations and their authors, comments and read state, and worker authorization records. Other authorized workspace members can receive the project and comments according to their role. Live presence communicates activity such as the current timeline, playhead and selection. Local file paths and account credentials are not included in the shared project document. Bravely Account identity and sign-in data are covered at bravely.dev/privacy/bravely-account.

Where Original Media Is Stored

The initial internal collaboration beta stores shared originals in a selected Google Drive folder. Vai Cloud original storage and the option to use both providers are disabled. Shared project edits and comments use Vai's collaboration service separately from original media. Originals are read from or uploaded to the configured Google Drive folder using the connected person's Google permissions. Drive-only storage does not silently create a Vai Cloud copy. A storage-setting change does not automatically erase an existing copy, and disabling a storage option does not delete data already stored.

Connecting Google Drive

Connecting Google Drive is optional and separate from signing in to Vai. We use the Google account identifier and verified email to identify the connection, and folder and file identifiers, names, types, sizes, versions, permissions and file contents to select, verify, download and upload media for your project. Reading existing footage requires Google's permission to read Drive files, which is broader than one folder. Vai uses that access for the folder and media you select for the workspace. Permission to create or manage files is requested for files and folders selected or created through Vai. Workspace membership does not grant Drive access: each participant needs their own Google authorization and access to the folder. The native app keeps its Google connection credentials in this device's protected credential store. They are not placed in shared projects or sent to collaborators. A connected worker uses its own explicitly authorized Google connection; its access token is kept in memory for that run and it does not retain a refresh token. You can disconnect within Vai or revoke access from your Google account. Revocation stops future authorized requests but does not recall copies already downloaded.

Google API Data and Limited Use

Vai follows the Google API Services User Data Policy, including its Limited Use requirements, when using or transferring data received through Google APIs. We use this data to provide the editing, media storage and sharing features you authorize. We do not sell it, use it for advertising, or use it to train generalized AI models. Transfers are limited to the features you authorize, security needs, legal obligations, or a business transfer with the consent Google requires. Human access by us is limited to your affirmative permission for specific data, necessary security or legal purposes, or appropriately aggregated internal operations as permitted by that policy. Sharing footage with collaborators or a connected worker is a feature you choose, not permission for unrelated reuse.

Google API Services User Data Policy

Manage your Google account connections

Remote Workers and AI Tools

You can authorize a worker on another computer to work on a shared project. Its grant controls whether it may edit, comment or read original media. An authorized worker can receive project data and, when granted media access, download originals to its own device. Vai records who authorized the worker and its actions. If you connect an external AI tool, its operator and provider may process the data you give it under their own terms and privacy practices. Vai does not choose or launch that external tool for you. Revoking a worker grant stops further service access; it cannot remove data the worker already received.

Device Copies and Retention

Projects, pending edits and comments, transfer progress, downloaded originals, previews and exports can remain on the devices that use them. Pending work is retained so it can recover after a connection failure. Cache cleanup removes eligible Vai-managed copies; it does not delete your original source files, exports or remote copies. We retain shared project history and comments to operate the shared service and preserve shared work. Requests to delete this data are handled through the contact process below. Removing a member, disconnecting Google, changing storage mode or uninstalling Vai does not by itself delete those records or copies. Google Drive originals remain under the folder owner's control and Google's retention rules. This release does not provide a self-service purge of all shared project data. For access, export or deletion of data held by Bravely, email privacy@bravely.dev from your account address and identify the workspace or project. We verify the request and address it subject to other participants' rights and applicable legal requirements. Ask the relevant owner or provider to remove copies outside our control.

Service Requests and Feedback

Sign-in, sync, transfers and update checks send the request information needed to operate those services, such as your account identifier, app version, network address and connection or error details. If you send feedback, we receive your message, app and system information, and any screenshots or log you choose to attach so we can investigate. Account-level records are described in the Bravely Account policy. Do not include private footage or other people's information in feedback unless you intend to share it with us.

Children's Privacy

Vai is intended for adults. We do not knowingly collect personal information from children under 13, or under 16 where that is the relevant age for consent to information-society services.

Your Privacy Rights

Depending on where you live, you have rights over the personal data we hold about you. We honor these rights for everyone who asks, regardless of where you live. • Access — ask what personal data we hold about you and get a copy. • Correction — ask us to fix data that is wrong or incomplete. • Deletion — ask us to delete your personal data by emailing privacy@bravely.dev from the address on your account. Where a product has a built-in Delete Account control you can use that instead; bravely.dev/delete-account explains what applies to each product. • Portability — ask for your data in a portable, machine-readable format. • Objection and restriction — ask us to stop or limit certain processing. • Withdraw consent — where we rely on consent (marketing email, optional analytics), you can withdraw it at any time without affecting processing that already happened. • Non-discrimination — we will not degrade your service or charge you more for exercising any of these rights. EEA and UK residents also have the right to lodge a complaint with your local supervisory authority. California residents may use an authorized agent; we may verify the agent's authority and confirm the request with you first. Other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect) have equivalent rights, including a right to appeal a denied request — reply to our decision email with "Appeal" and we will respond in writing within the period the law requires. Canadian residents have access, correction, and consent-withdrawal rights under PIPEDA; Australian residents have access and correction rights under the Australian Privacy Principles. To exercise any right, email privacy@bravely.dev. We respond within the timeframe the applicable law requires — generally 30 days under GDPR and 45 days under the CCPA, with an extension where the law permits one. We may need to verify your identity before acting, usually by confirming control of the email address on the account.

Legal Basis for Processing

If you are in the EEA or UK, we rely on these lawful bases under the GDPR and UK GDPR: • Performance of a contract — creating and securing your account, delivering the features you paid for, syncing your content, processing purchases, and providing support. • Legitimate interests — keeping the service secure and reliable, preventing fraud and abuse, understanding aggregate product usage, and improving the product. We balance these against your rights and do not use them to justify intrusive tracking. • Consent — marketing email, and optional analytics where a client offers a toggle. You can withdraw consent at any time. • Legal obligation — keeping tax, accounting, and consent records, and responding to lawful requests.

International Data Transfers

Bravely Studios LLC is a US company. We and our sub-processors process data in the United States and in other countries where they operate. For personal data originating in the EEA, UK, or Switzerland, we rely on appropriate transfer safeguards in our processor agreements — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — where those safeguards are required. Email privacy@bravely.dev if you want more detail about the safeguards that apply to you.

California Notice at Collection

For California residents, the categories of personal information we collect for this product are: • Identifiers — your Bravely Account identifier, display name, email, and connected Google account identifier and email. • Your content — shared project and edit data, comments, original media you choose to upload or access through a connected folder, and feedback you submit. • Internet or other electronic network activity — connection and authorization records, collaborator presence, service errors, app version and request metadata. We collect this from you, your device, and our own systems, and we use it to run the product, honor what you have bought, keep the service secure, and support you. We disclose it to the service providers listed under "Sub-processors," each for a business purpose under a written contract. We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA and CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose that would trigger the right to limit. If that ever changes we will update this policy and provide the required opt-out before the practice begins. Retention is described under "Data Retention" above and, for account-level data, in the Bravely Account privacy policy.

Sub-processors

We use the following service providers to run this product. They receive only what they need to perform their service for us, and each is bound by the data-processing terms that apply to our use of their service. Where a provider is not yet covered by a written data-processing agreement with us, its entry below says so. If you need a data-processing agreement in place before you use this product, email privacy@bravely.dev: • Cloudflare, Inc. — hosts Vai services and stores shared project records, edit history and comments. Original-media storage in Vai Cloud is disabled in the initial internal collaboration beta. See cloudflare.com/privacypolicy. • Google LLC — provides optional Google account authorization and Google Drive file access and storage. See policies.google.com/privacy. Bravely Account sign-in is described separately in its account policy. • Apple Inc. — provides Sign in with Apple when you choose that sign-in method. See apple.com/legal/privacy. If we add or change a sub-processor in a way that materially changes how your data is processed, we will update this policy and give additional notice where the law or our data-processing commitments require it.

Security

We protect your data with authenticated accounts, encryption in transit, access controls on our backend systems, and a deliberately small number of people who can reach production. No system is perfectly secure, and we do not claim guarantees we have not built and verified. Where a product makes a specific security claim, that claim appears in the app-specific sections above and is limited to what we have actually shipped. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make a material change — a new category of data, a new sub-processor, a new purpose, or a new legal basis — we will update the "Last updated" and "Effective" dates and give additional notice where the law requires it. Where a change requires fresh consent under the GDPR, UK GDPR, CASL, or a similar regime, we will ask for it before relying on the new purpose. Non-material changes (typos, clarifications, link fixes) are reflected by updating the "Last updated" date.

How to Contact Us

Bravely Studios LLC Privacy and data rights: privacy@bravely.dev Product support: support@bravely.dev Website: https://bravely.dev Postal address: available on request to privacy@bravely.dev.