Enliven Privacy Policy

Last Updated: 27 August 2026

This page covers Enliven only. It is a complete policy in itself — you do not need to read anything else. Our multi-app privacy policy covers our other apps.

Enliven turns a drawing into a short video. You draw a creature on the in-app canvas, or photograph one you drew on paper, and the app returns an eight-second video of it moving, with sound. It is made by Appd, an Australian software developer. This policy explains exactly what Enliven collects, who receives it, how long it is kept, and how to have it deleted.

The short version

If you read nothing else, read these six points.

  • Your finished video is served from a public link. Anyone who has the link can watch it without signing in. That is deliberate — sharing is the point of the app — but you should know it before you share. See Your finished video is publicly reachable.
  • Your drawing is sent to AI providers — Google and Alibaba — because that is how the video gets made. See Where your drawing goes.
  • We hold almost nothing about you personally. An email address and a user ID. No name, age, phone number, address or location.
  • The name you sign your drawing with is burned into the video. Whatever you type there travels with every share. See The name you sign with.
  • No ads, no data sold, no cross-app tracking. There are no advertising SDKs in the app.
  • Enliven is for people aged 13 and over. See Age and children.

Age and children

Enliven is not directed to children under 13, and accounts are for adults. You must be at least 13 years old to hold an Enliven account. If you are under 18, you should have a parent or guardian's permission to use it.

We know the app is fun for children, and we expect parents to sit alongside a child while they draw. That is fine — but the account, the email address on it, and the decision to share a video are the adult's. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, email us at [email protected] and we will delete it and everything stored for it.

If you are a parent supervising a child, the two things worth your attention are the public share link and the signature field, both below.

Signing in and what identifies you

Enliven signs you in with either an email magic link or Google sign-in (OAuth). Authentication is handled by Supabase Auth.

  • There is no password, and none is ever created or stored. A magic link is a one-time link sent to your email address; Google sign-in returns a verified identity to us without sharing your Google password.
  • We store your email address and a user ID. That is the whole of what identifies you.
  • We do not collect your name, age, date of birth, gender, phone number, postal address, or location.

A note on our shared backend. One Supabase project hosts several of our apps. Enliven's data lives in its own database schema, isolated by row-level security: every table is restricted so that a signed-in user can read only their own rows, and the app has no permission to insert, update or delete directly — all writes go through our controlled server-side functions. Other apps on that project cannot read Enliven data, and Enliven cannot read theirs.

What you create, and where it is stored

Each creature you make produces several files. They are not all treated the same way, so here is the complete picture:

File Stored in Who can reach it
Your original sketch, and a transparent-background copy of it enliven-sketches Private — you only
The photoreal still image generated from your sketch enliven-sketches Private — you only
The untouched model output (kept for troubleshooting) enliven-sketches Private — you only
The finished video, and its poster image enliven-renders Public link — see below

We want to be plain about this rather than leave it in a table.

The finished video and its poster image are stored in a public bucket. Anyone who has the link can open and watch them, on any device, without signing in to Enliven and without an account of their own.

This is deliberate. Sharing a creature is the whole point of the app, and the places you share to — messaging apps, social apps, AirDrop, a link pasted into a family chat — need a link they can actually fetch. A video locked behind a login could not be shared at all.

What that means in practice:

  • The link is unguessable, but it is not secret. It contains a long random identifier, so nobody will stumble across your video by chance and there is no directory or browsable index of everyone's creations. But the link carries no further protection: once you send it to someone, they can send it on, and whoever receives it can watch it.
  • Treat sharing a video the way you would treat sharing a photo. Once it is out, you cannot control where the link travels.
  • If you want a video taken down, email us and we will delete the file — see Deleting your data. After that the link stops working.
  • Your original sketch is not public. Only the finished video and its poster leave the private bucket.

If you are a parent, this is the setting to explain to a child before they tap share.

The name you sign with

Enliven lets you sign a drawing with a short line of text — for example “Brodie · 12yrs”. It is free text that you choose, limited to 40 characters.

That text is rendered into the finished video file itself. It is not a caption we can strip out later; it is part of the picture. It therefore travels with the video everywhere the video goes, including to anyone who is passed the public link.

We do not require a real name, and we would gently suggest not using one. A first name, a nickname or an initial does the job. If a full name, a school, or anything else identifying goes into that field, it becomes part of a shareable file.

Because the text is burned in, the only way to remove it is to delete the video. Editing the field afterwards does not change a video that has already been made.

Where your drawing goes

This is the part most worth reading carefully, so we will state it directly.

When you create a creature, your drawing is uploaded to our backend and sent to third-party AI services to be turned into a video. There is no way to make the video without this. Specifically:

  • Google (Gemini) receives your sketch. It looks at the drawing and describes it in words, and it generates the photoreal still image from it.
  • Alibaba (Wan) receives that generated still and produces the eight-second video and its audio.
  • Vercel AI Gateway routes these requests to the providers above. Your images pass through it in transit.
  • Vercel (our compositor) receives the finished video to add the name card, the logo and the music before it is saved.

The drawing is sent for that single purpose and nothing else. It is not accompanied by your email address or anything else identifying you.

On training AI models: we do not use your drawings, images or videos to train models of our own, and we do not permit them to be used to train or improve a third party's models. We send content to these providers on their commercial API terms for that purpose. Each provider's own handling of the data is additionally governed by its terms — Google's by its Privacy Policy, and Alibaba Cloud's by its Privacy Policy. If this ever changes, we will update this policy and give notice in the app before the change takes effect.

No AI or machine learning provider other than those named above receives your drawing.

Everything else we store

The complete list. There is nothing else.

  • Account record — your email address and user ID.
  • Credit ledger — every credit granted, spent and refunded, with the reason and the time it happened. This is how your balance is calculated and how we can put a credit back if a generation fails.
  • Purchase records — the platform you bought on, the product ID, and the store's transaction ID. We never see or store your card details; Apple and Google process the payment. See Credits and payments.
  • Generation records — the status of each job, the text prompt that was generated from your drawing, the content-moderation result, and any error message if it failed.
  • Moderation counters — a count of submissions that were rejected as unsafe, and a flag showing whether the account is locked. Repeated unsafe submissions lock the account. This exists to keep the service safe, particularly given that finished videos are shareable.
  • Push notification tokens — the device token that lets us send you the “your video is ready” notification. See Notifications.
  • The signature text you attach to a drawing, as described above.

Credits and payments

Enliven is paid for with consumable credits bought through the app store. Payment is processed entirely by Apple or Google. We never receive, see or store your card number, billing address or any other payment detail.

RevenueCat validates purchases on our behalf — it confirms with the store that a purchase was genuine so that credits can be added to your balance. It receives the purchase identifiers and your user ID, not payment details.

Credits are consumable, not a subscription, so there is nothing recurring to cancel. Refunds for store purchases are handled by Apple or Google under their own policies.

Analytics

Firebase Analytics (Google) is present in the app to tell us roughly how it is being used. We want to be precise about how little this is:

  • We log no custom events at all. We have not instrumented the app to record what you draw, what you generate, what you share, or which screens you visit.
  • What is collected is Google's automatic collection only: app opens, session length, device model, operating system version, country, and a resettable app-instance ID.
  • This is not linked to your drawings or videos, and there is no advertising identifier involved.

Google's handling of this information is governed by its Privacy Policy.

Notifications

Generating a video takes a little time, so Enliven can notify you when yours is ready. This uses Firebase Cloud Messaging and requires us to store a push token for your device.

Notifications are optional. If you decline the permission, or turn notifications off in your device settings, the app still works — you simply check back in the app instead.

Who receives your data

The complete list of third parties, and why each one is there:

  • Supabase — sign-in, database, and file storage for your sketches and videos.
  • Vercel AI Gateway — routes generation requests to the AI providers below.
  • Google (Gemini) — reads your sketch to describe it, and generates the still image.
  • Alibaba (Wan) — generates the video and its audio.
  • Vercel — runs the compositor that adds the name card, logo and music to the finished video.
  • Firebase Analytics (Google) — automatic app usage measurement, as described above.
  • Firebase Cloud Messaging (Google) — delivers the “your video is ready” notification.
  • RevenueCat — validates in-app purchases.
  • Apple and Google Play — process payments for credits.

That is the complete list. No other company receives data from Enliven. These providers may use the information only to perform their service for us, and are bound to keep it confidential and secure.

We may also disclose information where the law requires it — in response to a valid legal request, or where disclosure is necessary to comply with a legal obligation, prevent fraud or a security threat, or protect the safety of a person or the public.

Device permissions

  • Camera — used only to photograph a drawing you made on paper. It is optional: the in-app drawing canvas needs no permission at all. The camera is never used in the background.
  • Photo library (add only, on iOS) — used to save your finished creature to your own photos. This is an add-only permission: the app can write a file, and cannot browse, read or index the rest of your library.
  • Internet — required, because the video is generated on our servers.
  • Notifications — optional, as described above.

Enliven does not request location, contacts, calendar, microphone, health data, or an advertising identifier.

What Enliven does not do

  • No advertising. No ads, no ad networks, no third-party ad SDKs, no IDFA or Android Advertising ID.
  • We do not sell your personal information, and we never will.
  • No cross-app or cross-site tracking. We do not follow you around other apps or websites, and we do not buy data about you from anyone else.
  • No behavioural profiling or automated decision-making about you, beyond the content-safety check that decides whether a submission can be generated.
  • No location data of any kind.
  • No chat, comments, messaging, or public feed inside the app. Nobody can contact you through Enliven, and there is no gallery of other people's creations to browse.
  • No marketing email. We use your email address to sign you in and to answer you if you write to us.

Where your data is processed

Enliven's data is processed outside Australia. Our providers — Supabase, Vercel, Google and Alibaba Cloud — operate infrastructure in a number of countries, including the United States and locations in the Asia-Pacific region, and your drawings and videos are processed there.

If you are in Australia, the EEA or the UK, this means your information is transferred overseas for processing. We rely on appropriate safeguards for these transfers, including Standard Contractual Clauses where required, and we take reasonable steps to ensure our providers handle the data consistently with this policy.

How long we keep things

We would rather tell you the truth than a comfortable version of it.

At present, nothing expires automatically. Your sketches, generated images, finished videos, credit ledger, purchase records and generation history are kept for as long as your account exists. There is no scheduled deletion job, and we do not currently delete inactive accounts.

Deletion happens when you ask for it — see the next section. If we introduce automatic expiry later, we will update this policy and say so in the app before it takes effect.

Deleting your data

There is currently no delete button inside the app. We are saying that plainly rather than describing a feature that does not exist yet. Deletion is by email request, and we do it by hand.

To delete your account and everything in it, email [email protected] from the email address you signed in with, and ask us to delete your Enliven account. We will confirm when it is done, within 30 days of your request.

What deletion removes:

  • Your account and email address
  • Your credit ledger, purchase records and generation history
  • Your moderation counters and push notification tokens
  • Your files in both storage buckets — every sketch, transparent copy, generated still, master file, poster image and finished video. We remove these as a separate, deliberate step, because storage does not delete itself when an account is removed. After this, any share link you have sent out will stop working.

Deletion is permanent and cannot be undone. Unused credits are forfeited when an account is deleted — if you have a balance you care about, spend it first. Deleting your account does not itself produce a refund; refunds are handled by Apple or Google under their policies.

To delete a single video rather than your whole account, email us with the link and we will remove that video and its poster.

To stop all further collection, stop using the app and uninstall it. Nothing is collected when it is not running. Note that uninstalling does not delete what we already hold — email us for that.

We do not charge for any of this, and we will not treat you differently for asking.

Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to have it deleted, to obtain a copy in a portable form, and to object to or restrict certain processing. Enliven holds very little about you, so in practice most requests resolve quickly.

To exercise any of these, email [email protected] from your account email address. We will respond within 30 days.

Security

We take reasonable steps to protect information from unauthorised access, disclosure, alteration and destruction. Data is encrypted in transit using HTTPS/TLS and encrypted at rest by our infrastructure providers. Database access is restricted by row-level security so that a signed-in user can reach only their own records, and the app holds no direct write permission.

The one deliberate exception to this is the finished video and poster, which are served from a public bucket so they can be shared — explained in full above.

No method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

Complaints

If you are unhappy with how we have handled your information, please tell us first at [email protected] so we can put it right. You may also complain to a regulator: in Australia, the Office of the Australian Information Commissioner at oaic.gov.au; in the EEA or UK, your local data protection authority.

Changes to this policy

We may update this policy to reflect changes to the app or to legal requirements. When we do, we will update the “Last Updated” date above and post the revised policy here. If a change materially affects how we handle your information, we will give notice in the app before it takes effect.

Contact us

We would rather answer a question than have you guess. For anything about Enliven and your privacy:

Email: [email protected]
Website: https://appd.com.au