Trust
Your brand's work, handled carefully.
The short answers
Your content is not used to train AI models — not by us, and not by the model providers we route to, whose paid API terms exclude training. Your generations and uploads are private to your account. Everything moves over TLS and rests encrypted at our storage providers. Payments are Stripe's problem, by design. Charges are visible before every generation, and failures refund themselves.
Unreleased work
We know brand teams upload pre-launch material. It is treated as confidential by default: nothing you make or upload appears anywhere public, and KIZAO's own marketing uses only media we generated for ourselves.
Subprocessors
| Netlify | Application hosting and delivery |
| Neon | Database (PostgreSQL) |
| Amazon Web Services | Media storage (S3) |
| Stripe | Payments — card data never touches our servers |
| OpenAI / Google / Anthropic | AI generation, paid APIs, no training on your content |
Certifications
KIZAO is early and honest about it: we hold no SOC 2 or ISO certification yet. The practices above are how the system is built today; formal audits arrive as enterprise customers need them.
Found something?
Security reports go to support@kizao.co and are read by the people who can fix them. We appreciate responsible disclosure and will credit it if you want us to.
The details live in the Privacy Policy and Terms of Service.