virtualcam.ai
Loading…

legal

Privacy Policy

What we collect, how your live video is processed, who processes it for us, and the rights you have.

Last updated: 24 July 2026

1. The short version

2. What we collect

DataWhere it livesWhy
Account (name, email, sign-in identity)Clerk (our authentication provider)Sign-in, account management, billing status
BillingClerk Billing / StripeSubscriptions. We never see your full card details.
Session metadata (start/end times, duration, queue state)Our databaseRunning sessions, metering your daily plan time
Live video (your webcam feed and the transformed output)A per-session cloud GPU, in memory onlyThe transformation itself - not stored
Moderation-flagged frames (if any)Restricted secure storageHuman review and enforcement - see section 4
Usage analyticsPlausible (cookieless, aggregate)Understanding page traffic - no ad tracking, no cross-site profiles

3. How live video is processed

When you go live, we provision a private GPU instance for your session with a cloud GPU provider. Your camera feed streams to it directly over an encrypted connection (WebRTC), each frame is transformed in memory, and the result streams back to you. Frames are not written to disk and nothing from your video is used to train AI models without your explicit opt-in consent.

3a. Recording (opt-in)

Recording is off by default and only ever starts when you press Record in Backstage. While a take is running, your microphone audio is sent to the GPU instance as well as your camera, so the sound can be lined up with the transformed video - it is used for the recording only, and it is not streamed back to you or to anyone else. Muting your microphone stops it at the source, so a muted take records silence.

Finished recordings are stored encrypted in our object storage and are visible only to you, in your Recordings tab. You can download or delete them at any time, and deleting one removes the stored file. During the beta, recordings are automatically deleted after 30 days. Ending a session mid-take still saves what was captured up to that point.

4. Safety moderation

To keep the service safe (and to enforce our Acceptable Use Policy), we are rolling out automated safety checks during the beta: occasional still frames from the transformed output of live sessions will be sampled and analysed automatically for prohibited content (for example nudity, sexual content, or content involving minors), using Sightengine, a specialist moderation provider. Frames are analysed and immediately discarded unless flagged.

5. Who processes data for us

Clerk (authentication and billing), Stripe (payments), our cloud GPU compute providers (per-session video processing; currently RunPod-class datacenter providers, which may be located in the United States), and our self-hosted Plausible analytics. As the safety checks in section 4 roll out, Sightengine (automated content moderation) will join this list. Providers act on our instructions to run the service; as we open access in the EU/UK, transfers outside your region will be covered by appropriate safeguards such as Standard Contractual Clauses.

6. Cookies

We use only essential cookies (Clerk’s authentication session). Our analytics (Plausible) is cookieless. We do not use advertising or cross-site tracking cookies.

7. Retention

DataKept for
Live video framesNot stored - processed transiently in memory
Moderation-flagged framesUp to 90 days (or until enforcement concludes), then deleted
Account and session metadataWhile your account is active. When you delete your account, tell us at [email protected] and we purge the associated records within 30 days; an automatic purge on account deletion is being added.
Billing recordsAs required by tax and accounting law

8. Your rights and legal bases

For users in the EU/UK, our legal bases are: your consent for facial processing — given today by choosing to start a live session, with a dedicated recorded consent step rolling out during the beta (see the Biometric Privacy Notice) — performance of our contract with you for account, billing, and session data, our legitimate interests in keeping the service secure and safe (including the moderation described in section 4), and legal obligation where we must keep records.

Depending on where you live (including under the GDPR, UK GDPR, and US state privacy laws such as the CCPA/CPRA), you may have rights to access, correct, delete, or export your data, to withdraw consent, and to complain to your supervisory authority. You can delete your account at any time from your account settings, and you can stop facial processing at any time by ending your session or not starting one - facial processing only ever happens during a live session you chose to start. For any request, contact [email protected] and we will action it. We do not sell your personal information.

9. Age

virtualcam.ai is for adults (18+). We do not knowingly collect personal data from anyone under 18; if you believe a minor is using the service, contact [email protected].

10. Changes and contact

We will notify you of material changes to this policy. Privacy questions and data-rights requests: [email protected].