Legal / Privacy policy

Your footage never leaves the room

Huko edits on your computer and calls our servers for one thing only: generating media that does not exist yet. This policy explains exactly what that means for your data — what we receive, what we never see, and how long we keep any of it.

  • Effective 31 August 2026
  • Applies to huko.ai and the Huko desktop app
  • Operator Crevolve Infosoft Pvt Ltd

01 Overview and scope #

Crevolve Infosoft Pvt Ltd, a company incorporated in India, trading as Huko ("Huko", "we", "our", "us"), operates the website at huko.ai, the Huko desktop application for macOS and Windows, and the API service the app talks to (together, the "Service").

This policy explains what personal data we collect when you use the Service, why we collect it, who else sees it, and what you can do about it. It applies whether you use Huko without an account, with a free account, or on a paid plan.

We aim to meet the standard set by the strictest law that applies to you, including the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA, Brazil's LGPD, Canada's PIPEDA, and India's Digital Personal Data Protection Act 2023.

By downloading the app or creating an account you confirm you have read this policy. If you disagree with it, please stop using the Service — and note that the app will still open and edit local files with the network switched off entirely.

02 What never leaves your computer #

Huko is a desktop application, not a website pretending to be one. It is built on a single rule: the network is for generating, the machine is for editing. A request leaves your computer for exactly one reason — something needs an AI model to produce media that does not yet exist. Everything else runs on your own CPU and GPU.

Never uploaded, on any plan

  • Media you import. Video, audio and images you drag into a project are read from your disk and stay there. They are not copied to us, and we could not open them if they were.
  • Your project files. A Huko project is a file on your machine. Timeline, clips, keyframes, transitions, colour work, masks — all of it is saved locally.
  • Every edit. Trimming, splitting, transitions, effects, chroma key, transforms, keyframes and 200 steps of undo happen entirely offline.
  • Captions. Speech recognition runs on your machine. The transcriber and the speech model ship inside the app, so captioning a forty-minute interview uploads nothing, needs no network, and costs no credits.
  • Previews, proxies and thumbnails. Generated locally as you scrub.
  • Exports. Rendering is a local operation at every quality up to 4K. There is deliberately no server-side render endpoint in our API — not merely unused, but absent, so no future version can quietly start uploading your timeline.
  • Your saved libraries. Characters you design and motion clips you shelf are stored with the app on your computer.
What this means in practice

If you import your own footage, cut it, caption it and export it, Huko sends us nothing about that project at all. Our support team cannot watch your video, read your timeline or recover your project, because no copy of it has ever existed on our systems.

What does travel

When you ask Huko to generate something — a script, an animated scene, a motion graphic, an image, a voiceover — that request goes to our API service and on to the AI providers that produce the media. That is covered in section 03 and section 05.

03 Information we collect #

3.1 Account information

Created when you sign up, and only then:

  • Your email address, and a display name if you give one.
  • A cryptographic hash of your password, produced with argon2id. We never store or see the password itself, and we cannot recover it — only reset it.
  • If you enable two-factor authentication, your TOTP secret, encrypted at rest with AES-GCM.
  • Sign-in safety counters: failed attempt counts and any temporary lockout, kept so a password can't be brute-forced.

3.2 Devices and sessions

Because Huko is a desktop app people run on more than one machine, we keep one record per signed-in device holding a hashed refresh token and basic device details. This is what lets you see where you are signed in and revoke a single machine without signing out the others.

Signing in from the app uses a pairing handshake: the app shows you a short code, you approve that code in your browser after signing in normally, and only then is a token issued. The desktop app never sees your password. Pairing codes are short-lived and are deleted once claimed or expired.

3.3 Generation requests and their output

When you submit a job, we receive and process what that job needs in order to run:

  • Your prompt or brief — the idea, script, instruction or edit request you typed.
  • Media you deliberately attach to that job, such as a reference image or an audio file you asked to have processed. Files sitting on your timeline that the job does not need are not included.
  • The media that comes back — the generated clip, image, voiceover or motion graphic — while it is on its way to your app.
  • Job metadata: the kind of job, its status, timestamps, duration, failure reasons, and what it cost in credits.

3.4 Credits and billing records

  • Your plan, subscription state, renewal dates and credit balance.
  • An append-only ledger of every credit movement — grants, reservations, settlements, refunds and expiries — with the breakdown behind each charge, so any deduction can be explained rather than re-derived.
  • Payment records from our payment processor: the payment identifier, amount, currency, status and which plan it was for.
Card data

Your card number never reaches Huko. Checkout happens on Dodo Payments's own hosted pages, and we receive only the outcome of the payment.

3.5 Things you send us on purpose

  • Emails you send to us, and our replies.
  • Bug reports and feature requests you file from inside the app, including the title, description and any detail you choose to include.

3.6 Technical logs

Our web server and API keep short-lived operational logs — IP address, timestamp, requested path, response status and user agent — which is how we notice an outage or an abuse pattern. The app itself sends no background telemetry, no usage analytics and no crash reports to us.

3.7 What we do not collect

  • No advertising or cross-site tracking identifiers.
  • No third-party analytics SDK on this website or in the desktop app.
  • No contact list, location, microphone or camera access.
  • No special-category data. Please do not send us any.

04 How we use your information #

4.1 To run the Service (contractual necessity)

To sign you in, keep you signed in on the machines you chose, accept and run your generation jobs, deliver the results back to your app, and keep your credit balance correct.

4.2 To take payment (contractual necessity)

To create a checkout, apply the plan you bought, grant credits on the right schedule, and keep the accounting records the law requires us to keep.

4.3 To keep the Service safe (legitimate interest / legal obligation)

To detect and stop credential stuffing, credit fraud, automated abuse of generation quota, and use that breaks the acceptable use rules.

4.4 To fix and improve things (legitimate interest)

Aggregate job outcomes tell us which kinds of generation fail and where the pipeline is slow. This works on counts and error codes, not on reading your prompts for interest.

4.5 To talk to you (contractual / consent)

Service email — password resets, receipts, renewal notices, security alerts and material changes to this policy — is part of having an account and cannot be switched off while the account exists. Anything promotional is opt-in and has an unsubscribe link.

4.6 To meet legal obligations

Tax and accounting records, and responses to valid legal process as described in section 06.

05 AI generation and model training #

Generating video, images, speech and motion graphics requires AI models. Huko routes your request through our own API service to the model providers that produce that media. Your request and any media attached to it are shared with the provider handling that job, for the sole purpose of returning a result.

5.1 We do not train on your content

Commitment

We do not use your prompts, your uploads, your projects or the media generated for you to train, fine-tune or evaluate any model, and we do not sell or license that content to anyone who would.

We choose providers on the basis that they process a request to answer it, and we require them by contract not to use content routed through Huko for their own model training. A provider's own policy is not something we can change, so if a provider's terms are material to you, ask us at [email protected] which providers are currently in use and we will tell you.

5.2 What a provider receives

The prompt and the media that job needs. Not your account details, not your billing information, and not the rest of your project.

5.3 What AI output is, and is not

Generated media is produced by a statistical model. It can be wrong, can resemble something that already exists, and is not reviewed by a human before it reaches you. What you may do with it, and who owns it, is covered in the Terms of Use.

5.4 Captions are the exception

Speech recognition runs entirely on your machine, so audio you caption is not sent to us or to any provider — even when the rest of the app is online.

06 Who we share data with #

We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under the CCPA/CPRA definitions, Huko has not sold or shared personal information in the preceding twelve months.

6.1 Service providers

We use a small number of processors, each bound by contract to act only on our instructions:

  • AI model and media providers — to generate the video, images, speech and motion graphics you ask for. They receive the job, not your account.
  • Dodo Payments — our payment gateway and merchant of record. It handles checkout, cards, tax and invoicing. We receive the outcome; it never gives us your card number.
  • Object storage and hosting — where generated media and our database live while they are needed, and where our API and website run.
  • Transactional email — to deliver password resets, receipts and service notices.

6.2 Legal requirements

We disclose data when a valid legal order compels it. Where we are lawfully permitted to tell you first, we will, so that you have the chance to object.

6.3 Protecting people

We may disclose data where we believe in good faith that it is necessary to prevent imminent harm, fraud, or a serious threat to the security of the Service or its users.

6.4 Business transfers

If Huko is acquired or merged, account data may transfer to the acquiring entity. This policy continues to apply until you are notified of a replacement, and you may delete your account before any change takes effect.

07 International data transfers #

Huko is operated from India, and our processors operate in a number of countries. Using the Service therefore involves your data being transferred and processed outside the country you live in.

For personal data moving out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), together with technical measures — encryption in transit, tight retention, and no bulk export of content — that reduce what a transfer actually exposes.

You may request a copy of the transfer mechanism we rely on for a particular processor by writing to [email protected].

08 How long we keep things #

Generated media is not archived on our systems for your convenience — it is delivered to your app and then swept. Keeping your own copies is your job, and Huko makes that the default by saving results into your project on your disk.

Retention period for each category of data Huko holds
Data Kept for
Media you imported, projects, exports Never held. It stays on your computer.
A job's result payload About one hour after the job finishes, then discarded.
Generated media cached for delivery About 72 hours, then swept from the cache.
Sign-in tokens Access tokens expire in minutes. A device's refresh token expires after 60 days, or immediately when you revoke that device or sign out.
Pairing codes Minutes. Deleted once claimed or expired.
Account record Until you delete your account.
Job history and credit ledger While your account exists, so a charge can always be explained. Anonymised or deleted on account closure, except what the row below requires.
Payment and tax records As long as tax and accounting law requires — generally up to eight years — even after the account is deleted. These are financial records, not profile data.
Support correspondence Up to 24 months, so a recurring problem has a history.
Server logs Up to 30 days.

8.1 Deleting your account

You can ask us to delete your account at any time. We remove your profile, credentials, devices, remaining credits and job history, and we cancel any active subscription. Deletion is permanent — we do not keep a shadow copy to restore from.

Before you delete

Deleting your Huko account does not touch the projects and exports on your computer, and it cannot bring back credits. Anything you still want generated should be generated first.

09 Your rights and choices #

9.1 Rights everyone has here

We extend these to every user, wherever you live:

  • Access — a copy of the personal data we hold about you.
  • Correction — fix anything inaccurate, from your account settings or by asking us.
  • Deletion — close your account and have your data removed.
  • Portability — your data in a structured, machine-readable format.
  • Objection — object to processing we base on legitimate interest.
  • Withdraw consent — for anything we do on the basis of consent, without affecting what came before.
  • No retaliation — exercising a right never degrades your plan, your credits or your support.

9.2 If you are in the EEA, UK or Switzerland

You additionally have the right to restrict processing, the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we make no such decisions), and the right to complain to your national supervisory authority. We would rather you came to us first, but that right does not depend on it.

9.3 If you are in California

You have the rights to know, delete, correct, and to opt out of sale or sharing — an opt-out that has nothing to switch off, because we do neither. You may designate an authorised agent to make a request for you; we will ask for proof of that authorisation.

9.4 If you are in India

Under the DPDPA 2023 you have rights of access, correction, erasure, grievance redressal and nomination. Write to the address in section 14 and mark your message as a grievance if that is what it is.

9.5 How to exercise a right

Email [email protected] from the address on your account, say which right you are exercising, and we will acknowledge within 72 hours and answer substantively within 30 days — sooner where the law requires it. If we need more time on a complex request we will tell you why before the 30 days are up. We verify identity through the account email rather than by collecting documents from you.

10 Cookies, local storage and tracking #

There is no cookie banner on this site, because there is nothing to consent to.

10.1 The marketing site

huko.ai is a static site. It sets no cookies, runs no analytics, and loads no advertising or social tracking scripts. Web fonts are requested from Google Fonts, which means your browser contacts that service to fetch the font files.

10.2 The account pages

Sign-in, account and billing pages store your session tokens in your browser's local storage rather than in a cookie. That is a deliberate technical choice — our API is on a different origin, and a cookie there would depend on third-party cookie support that browsers are removing — and it has the side effect that nothing is transmitted to us automatically on every request. Signing out clears it.

10.3 The desktop app

The app stores your session and your preferences on your own machine. It sets no cookies and contains no tracking code.

10.4 Do Not Track

We honour it by construction: there is no tracking to signal against.

11 Security #

These are the measures that matter most, stated plainly:

  • Passwords are hashed with argon2id. A database leak would not reveal them.
  • Two-factor authentication is available, and TOTP secrets are encrypted at rest.
  • Sessions are per device. Each machine holds its own hashed refresh token, so revoking one does not disturb the others — and a stolen laptop can be cut off on its own.
  • The desktop app never handles your password. Sign-in happens in your browser and is confirmed with a code shown in both places.
  • Brute force is limited by attempt counting and temporary lockout.
  • Everything is in transit over TLS.
  • Payment webhooks are signature-verified and replay-protected, so a forged notification cannot grant credits or change a plan.
  • Least data. The strongest control here is architectural: most of your work is never in our custody in the first place.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant regulator within the timeframes the law sets — 72 hours under GDPR.

Reporting a vulnerability

Email [email protected] with "Security" in the subject line. We will acknowledge within 24 hours. Please give us a reasonable window to fix an issue before disclosing it, and we will not pursue researchers who act in good faith.

12 Children's privacy #

Huko is not intended for children. You must be at least 13 to use the Service, and at least 16 if you are in the EEA or the UK unless a parent or guardian consents on your behalf.

We do not knowingly collect personal data from anyone below those ages. If you believe a child has created an account, write to [email protected] and we will delete it and any associated data promptly.

13 Changes to this policy #

We update this policy when the Service changes. The effective date at the top always reflects the current version.

For material changes — a new category of data, a new purpose, a new kind of recipient — we will email account holders at least 14 days before the change takes effect and show a notice in the app. For clarifications and corrections we simply update the page.

Continuing to use the Service after a change takes effect means you accept the updated policy. If you do not, delete your account before that date.

14 Contact us #

One inbox handles privacy questions, data requests, security reports and everything else. Put the topic in the subject line and it reaches the right person faster.

Entity
Crevolve Infosoft Pvt Ltd
Trading as
Huko · huko.ai
Email
[email protected]
Subject
"Privacy request — [your name]"
Response
Acknowledged within 72 hours; answered within 30 days

EEA, UK and Swiss residents may also ask us for the contact details of our data protection contact. If you have a complaint we have not resolved, you can escalate it to your local supervisory authority.

Effective 31 August 2026 Back to top ↑