MOVOPOP

Privacy information

Updated 2026-10-09

This page describes the current MovoPop app and its own service. Public release is still being prepared.

Your photos and creations

You choose which photos to share. AI generation sends those selected photos and the style instructions through our Cloudflare service to Volcengine. Portrait assets approved by Volcengine are stored separately from temporary uploads.

Temporary photo uploads stop being available after 48 hours. Our service schedules a cleanup about once an hour; failed deletions are retried. Saved originals on the server, job records and approved portraits do not have that 48-hour expiry. They are included when you delete your profile.

The creation library on your device can contain source photos, original videos, template music and GIFs. Template examples are also cached on your device. Files you separately save to Photos or share with another app are managed by those destinations.

Guest profiles and Apple sign-in

You can browse without interactive sign-in. A random device profile provides access to your own records. Its credentials are stored in Keychain; the server stores credential hashes. Apple sign-in is optional. If you use it, the service stores your Apple user identifier and the name or email you share, plus an encrypted authorization token used to manage your Apple authorization.

Purchases and notifications

Apple processes payments. MovoPop does not receive your card details. Our service verifies signed purchase records and keeps transaction identifiers, product and purchase status, and the credit ledger needed to reconcile deliveries and refunds. These records have no automatic expiry and are retained separately when a profile is deleted.

If completion reminders are available and you enable them, the service stores a device push token linked to your profile and uses Apple Push Notification service to notify you that a video is ready. Reminders are optional.

Portrait authorization

The person pictured completes Volcengine’s own liveness and authorization page. MovoPop does not collect identity documents or the liveness recording from that page. Our service receives the authorization result and stores the provider identifiers and portrait status needed to use and delete the recorded portrait assets.

Volcengine manages its own authorization records. Deleting a MovoPop profile does not promise deletion of all records independently retained by that provider.

Services that process information

Cloudflare hosts our service, database, private media storage and cleanup queues. Volcengine processes the selected media for AI generation and portrait authorization. Apple provides optional sign-in, payments and optional push delivery. These services may process information outside your country.

See Cloudflare privacy information, Volcengine privacy information and Apple privacy information.

These public information pages do not set tracking cookies or run analytics scripts. Hosting providers may process ordinary network request information to deliver and protect the service.

Deletion and your choices

In MovoPop, open Profile → Delete profile and data. Confirming closes that profile, revokes its MovoPop sessions and starts deletion of its server uploads, saved original videos, job records and recorded portraits. The app erases that profile’s local creation library and credentials. Provider cleanup may need retries; keep the cleanup request ID until the app reports completion.

Minimal purchase, deletion and verification records remain to reconcile purchases, avoid duplicate fulfillment and prove cleanup. Removing the app alone does not request server deletion. Deleting a profile does not cancel an Apple subscription. See our deletion instructions.

Contact and requests

Service operator: MovoPop.

Our support contact is being prepared before public release. Please do not send personal information through other apps or unrelated accounts.