Privacy Policy
Last updated: 15 August 2026 · Effective: 15 August 2026
1. In short
Debut is an AI video generation service. To build videos for you, we necessarily handle what you write, what you upload and what the Service generates. This policy explains exactly what happens to it.
The things people usually want to know first:
We do not use your content to train AI models — not ours, and we do not license it to anyone else for that purpose.
Your prompts and files are sent to third-party AI providers to generate your video. That is how the Service works. Section 8 says who receives what and where they are, and we will name them on request.
We store your data in the European Union (Paris). Some of our providers are in the United States; section 9 explains the safeguards.
There is no advertising tracker on this site, and no cookie banner, because we set no cookies other than the ones needed to keep you signed in. Our analytics run on our own servers, not in your browser.
A person at Debut can see your project content in a few specific situations — support, abuse investigation, fault diagnosis, legal obligation. Section 7 lists them.
2. Who is responsible for your data
The controller of the personal data described in this policy is:
Benjamin Soukiassian, Paris, France — operating the service known as Debut (debut.video).
Contact for anything in this policy: hello@debut.video
Our full publisher details, including our postal address and telephone number, are in our Legal Notice.
We have not appointed a Data Protection Officer, as we are not required to. Data protection questions go to the address above and are handled by us directly.
This policy applies to the Debut application, its website and its API. It does not apply to third-party sites we link to, or to Stripe’s own pages where you enter payment details — those are governed by their own policies.
3. What personal data we process
Account and identity data. Your email address; your name and profile picture if you sign in with Google; whether your email is verified; your account role; the dates your account was created and updated.
Sign-in and session data. One-time sign-in codes; if you use Google sign-in, the tokens Google issues us; the IP address and browser user-agent recorded for each of your sessions; the timestamps of your sessions.
Waitlist data. If you request access before having an account, we store the email address you gave us, the status of your request, and when it was reviewed. We keep this whether or not you go on to create an account.
Service input and output. This is the heart of it, and it is the largest category:
your chat messages to the AI agent and your project briefs;
files you upload — images, video, audio and fonts, along with their filenames and any descriptions you add;
the generation prompts written by you or by the agent;
the scenes, characters, locations, titles and timeline edits that make up your project;
project memory — durable preferences, instructions, terminology and decisions the agent records about how you like your videos made, and loads again on later turns;
everything the Service generates for you: images, video clips, voices, music, sound effects, transcripts, stills, the project’s source code, and rendered videos.
Billing data. Your billing account, its status, and the identifiers Stripe gives us for your customer record, subscription and payments; your credit balance; and a permanent ledger of every credit transaction — what was generated, on which project, with which model and provider, when, and what it cost. We never see, receive or store your card number, expiry date, security code or billing address. Those go directly to Stripe.
Usage and product analytics. Server-side records of what happens in the Service: signing up, creating a project, sending a chat message, starting and finishing an agent session, requesting and completing generations, uploading an asset, interacting with the timeline, starting and finishing a render, buying credits, spending credits, running low on credits.
AI interaction traces. Records of the agent’s model calls: which model, how long it took, how many tokens, what it cost — and the text of the prompt sent, the model’s response, and its reasoning. See section 6, which explains this in full.
Diagnostic data. When something breaks: the error, its stack trace, which part of the Service failed, the project or job identifier, and your user identifier. We deliberately exclude job payloads because they contain your prompts, but an error message can still incidentally include text you supplied.
Support and feedback data. What you write to us. Separately, if the agent judges that you asked for something the Service could not do, it reports that to us together with your own message, quoted verbatim.
4. Why we process it, on what legal basis, and for how long
Purpose
Data used
Legal basis (GDPR)
Retention
Create and run your account, sign you in
Account, identity, sign-in and session data
Contract — Art. 6(1)(b)
For as long as your account is open. Session records, including IP address, are deleted 12 months after the session ends
Manage the waitlist and decide who gets access
Waitlist email and status
Legitimate interest — running a controlled roll-out and being able to tell an applicant what happened to their request
For as long as the waitlist operates, and 24 months after a rejected request
Build videos for you: run the agent, call model providers, store and render your project
Service input and output
Contract — Art. 6(1)(b)
For as long as your account is open. Deleted within 30 days of account closure (see section 11)
Take payment, run subscriptions and credits, prevent payment fraud
Billing data
Contract — Art. 6(1)(b), and legal obligation for accounting records — Art. 6(1)(c)
Accounting and invoice records are kept 10 years (Article L123-22 of the French Commercial Code). Other billing data follows your account
Keep the Service working: monitor errors, diagnose faults, restore service
Diagnostic data, service input and output where needed to reproduce a fault
Legitimate interest — we need to know when the Service breaks, and for whom, in order to fix it, and we cannot do that without recording the failure and the account it affected
90 days
Understand and improve how the Service is used
Usage and product analytics
Legitimate interest — we need to know which features are used, where people get stuck and what fails, to decide what to build and fix. These are server-side counts and events tied to an account identifier; we do not build advertising profiles, we do not track you across other sites, and you can object at any time
24 months
Monitor and improve the quality and cost of AI generations
AI interaction traces, including prompt and response text
Legitimate interest — a video the agent gets wrong can usually only be diagnosed by reading what was actually asked and answered, and we monitor model cost per generation because it sets our prices. See section 6 for the limits we place on this, and your right to object
12 months
Understand what users needed and could not get
Support and feedback data, including verbatim quotes
Legitimate interest — knowing in the user’s own words what the Service failed to do
24 months
Prevent abuse, investigate reports, enforce our Acceptable Use Policy
Service input and output, account data, IP address, moderation decisions
Legitimate interest — protecting the Service, other users and third parties against illegal or abusive generation, and meeting the obligations our model providers impose on us
12 months, or longer where we have confirmed a serious breach or must keep evidence
Send you service messages (sign-in codes, receipts, security and service notices)
Email address
Contract — Art. 6(1)(b)
For as long as your account is open
Send you product news and marketing
Email address, engagement
Consent — Art. 6(1)(a)
Until you withdraw consent, then 3 years on our suppression list so we do not email you again
Deal with legal requests, establish or defend legal claims
Whatever is relevant
Legal obligation — Art. 6(1)(c) — and legitimate interest in defending ourselves
For the applicable limitation period
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can ask us for that assessment or object at any time (section 12).
5. We do not train AI models on your content
We do not use your prompts, your uploaded files, your projects or your generated output to train, fine-tune or improve any artificial intelligence model, and we do not license your content to anyone for that purpose.
Your content is sent to third-party model providers, because that is how a generation is produced, and what they may do with it is governed by their own terms. We select providers on the basis that content sent through their APIs is not used for training, and we enable a no-training or zero-retention mode wherever one is offered. Section 8 describes who receives your content and where they are, and we will give you the named list on request.
6. AI interaction traces — what we record about your conversations with the agent
We want to be explicit about this.
When the agent works on your project, it records a trace of each model call into our product analytics tool, hosted in the European Union. That trace includes the text of the prompt sent to the model, the model’s output, and its reasoning, together with the model used, the duration, the token counts, the cost, the project identifier and your user identifier.
We use these traces to find out why a generation went wrong, to improve the agent’s instructions, and to monitor what generations cost us. They are not used for advertising, they are not sold, they are not shared beyond the processor that stores them, and they are not used to train any model.
You can object to this processing at any time by writing to hello@debut.video. We will stop recording the content of your prompts and outputs, and stop sending the reports described below, keeping only timings, token counts and costs. Doing so may make it slower for us to diagnose a problem you report.
Separately, when the agent detects that you asked for something the Service cannot do, it sends us a short report that includes your message quoted exactly as you wrote it, with your user and project identifiers, so we can see what people actually need. Nothing redacts it.
7. When a person can see your project content
A person at Debut can access the content of your projects — your chat, your prompts, your files, your generated media — only in these situations:
(a) you have asked us for support and we need to look at your project to help you;
(b) we are investigating a specific report, complaint or signal of abuse, illegal content or a breach of our Acceptable Use Policy;
(c) we are diagnosing a technical fault affecting your account or the Service;
(d) we must, to comply with the law or a valid legal request.
Access is limited to the people who need it. We do not browse user projects for any other reason, and we do not review them to build datasets.
8. Who else processes your data
We use a small number of providers to run the Service. Each processes personal data on our instructions under a data processing agreement, except where marked as an independent controller. Where a model is reached through a gateway, our agreement is with the gateway operator, which is responsible for its own sub-processors.
You can ask us for the current list of named providers at any time. Write to hello@debut.video and we will send it to you.
What they do
What they receive
Where
AI model providers — the models that generate your images, video, voice and music, and the gateway that routes requests to them
Your prompts and project content, and the files you upload where a generation needs them. One provider also receives reference images you upload, to describe them
United States, and China for one video model
Hosting, storage and database
Everything we store: your account, your projects, your files, your rendered videos
France (Paris)
Product analytics and error monitoring
Usage events, error reports, AI interaction traces (section 6), feedback reports, and your email address on the sign-up and waitlist events
European Union
Transactional email
Your email address and the message we send you, including your sign-in code
United States
Network protection
Your IP address and the addresses you request, as traffic passes through it
Global network
Two companies you deal with directly, each an independent controller for what it collects on its own pages:
Stripe, for payments. We send it your billing account identifier and the amounts. Stripe separately collects your name, email, card and billing details on its own checkout and portal pages — those never reach our servers.
Google, only if you choose to sign in with Google. We receive your Google account identifier, email, name and profile picture, and Google learns that you sign in to Debut.
We also disclose personal data where we must: to comply with a legal obligation or a valid order, to establish or defend legal claims, or to protect the rights, safety and property of our users, our providers or ourselves. And if the business is transferred to a successor entity — including a company formed to continue operating Debut — your data transfers with it, on the same terms; we will tell you before that happens.
We do not sell personal data, and we do not share it for advertising.
9. International transfers
Your data is stored in the European Union. Some of the providers above process data in the United States or elsewhere outside the EEA.
For each such transfer we rely on:
the European Commission’s Standard Contractual Clauses (Module 2, controller-to-processor, Commission Implementing Decision (EU) 2021/914), which we enter into with our processors including our model providers; and, where applicable,
an adequacy decision, including the EU–US Data Privacy Framework where the provider is certified under it.
We assess each transfer and apply additional measures where needed. You can ask us for a copy of the safeguards in place by writing to hello@debut.video.
10. Security, and one thing you need to know about how files are stored
We protect your data with encryption in transit, access controls, isolated per-project environments that are destroyed when your session ends, and restricted, credential-based access to production systems.
But you should understand how project files are served. For the Service to work — for your browser and our model providers to fetch images and video — the files you upload and the media the Service generates are stored at web addresses that are unguessable but not password-protected. Anyone who has the address can open the file, and that stays true until the file itself is deleted — when you close your account, or sooner if you ask us to remove it. The same applies to the live preview of a project while your session is running; its address contains your user identifier.
Your rendered video exports are the exception: they are stored privately and can only be downloaded through your authenticated account.
Do not put confidential information into a project. If you need a file taken down, write to hello@debut.video and we will delete it.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to your rights, we will tell you and notify the CNIL as the law requires.
11. How long we keep data
The table in section 4 gives the retention period for each purpose. In addition:
When you close your account, your data stays available for 30 days so that you can ask us for a copy, and we delete it within 60 days of closure, except for what we must keep: accounting and invoice records for 10 years, our credit transaction ledger with your identifier removed, records needed to prevent repeated abuse, and anything needed to establish or defend a legal claim.
When you delete a project, we remove it from your account and delete its source repository. Its stored files and history are deleted when you close your account, or sooner if you ask us.
Backups are rotated, and a copy of deleted data may persist in them for up to 90 days before it is overwritten.
Our credit transaction ledger is permanent, because we must be able to reconstruct our accounts. When an account is closed, the user identifier on those rows is removed, leaving a financial record that is no longer linked to you.
12. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing (including our legitimate-interest processing, and at any time for direct marketing), to portability, and to withdraw consent at any time without affecting what was done before.
We do not make decisions producing legal or similarly significant effects about you by automated means alone.
To exercise any of these rights, write to hello@debut.video. We will reply within one month, and will tell you if we need longer, which we may do by up to two further months for complex requests. We may need to verify your identity first. It is free, unless a request is manifestly unfounded or excessive.
To complain. You can lodge a complaint at any time with the French supervisory authority:
Commission Nationale de l’Informatique et des Libertés (CNIL) 3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, France — www.cnil.fr
If you live in another EU country, you can complain to your own national authority instead. We would rather hear from you first, but you do not have to contact us before complaining.
13. Cookies and tracking
We do not use a cookie banner, because we do not set any cookie that requires your consent.
What we set:
Cookie
Purpose
Duration
better-auth.session_token (with a __Secure- prefix)
Keeps you signed in. Strictly necessary
7 days, refreshed as you use the Service
Short-lived sign-in state cookies
Complete a Google sign-in securely
Minutes
We also store a few interface preferences — your project view mode, panel sizes, timeline zoom — in your browser’s local storage. These never leave your device and contain no personal data.
What we do not set. There is no analytics script, no advertising pixel, and no third-party tracker in the Debut application. Our marketing site runs on Framer, whose built-in analytics is cookieless and stores nothing on your device. Our analytics and error monitoring run on our servers, not in your browser, which is why they need no cookie and no banner. Nothing else reads or writes to your device — no analytics script, no advertising pixel, no third-party tracker.
Elsewhere. When you go to Stripe to pay, or to Google to sign in, those companies set their own cookies on their own pages, under their own policies. Our network-protection provider may set a security cookie.
If we ever add analytics or marketing trackers that run in your browser, we will ask for your consent first, with a real choice to refuse.
14. Children
The Service is not for children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to hello@debut.video and we will delete it. Users between 16 and the age of majority need the authorisation of a parent or guardian, as set out in our Terms of Service.
15. Changes to this policy
We may update this policy. If a change is material, we will tell you by email or in the app before it takes effect. The date at the top always shows the current version.
16. Contact
For privacy questions, exercising your rights, support, and legal notices:
hello@debut.video
Controller. Benjamin Soukiassian, Paris, France. Full details in our Legal Notice.
