Privacy Policy
Effective: 26 July 2026 · prepared with reference to the Personal Data Protection Act 2010 (Malaysia)
1 · Who is responsible
META VIABLE SDN. BHD. (Reg. 202201024382 (1470079-D)), Malaysia, is the data user responsible for personal data processed through SAGEmini. All data matters, requests, and complaints: support@nexovia.io (our designated privacy contact).
2 · Scope
This Policy covers personal data processed when you use SAGEmini. It does not cover third-party sites or platforms you publish content to, or the independent practices of AI Providers beyond our instructions to them.
3 · What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | name, email, authentication identifiers, session tokens | you, via Clerk sign-in |
| Content you provide | chat messages, prompts, photos, documents, voice notes, brand details | you |
| Generated content | images, videos, voice-overs, decks created for you | the Service |
| Usage & diagnostics | feature events, job outcomes, error logs, problem reports (screen, time, device type) | automatic + your reports |
| Billing data | subscription status, credit ledger, payment references | Billplz — we never receive full card/bank credentials |
| Device basics | browser type, approximate locale, app version | automatic |
- The Service is for adults (18+) and business use; we do not knowingly collect children's data — if you believe a minor has used the Service, contact us for deletion.
- Personal data inside your Inputs (e.g. faces in photos you upload) is data YOU choose to provide; you are responsible for having the right to share it (see Terms §8).
4 · Purposes & basis
- Service delivery (contractual necessity): transmitting your prompts and reference images to AI Providers to generate what you request; storing your content; operating campaigns and vault features.
- Security & integrity: authentication, abuse and fraud prevention, fair-use enforcement, debugging with diagnostic events.
- Billing & records (legal obligation): subscription management, credit accounting, tax and audit records.
- Service communications: renewals, incidents, material changes. We do not send third-party marketing and do not sell personal data.
- We use no automated decision-making producing legal effects about you; safety filtering of content is performed by AI Providers as part of generation.
5 · Processors & disclosures
| Provider | Function | Data involved |
|---|---|---|
| Clerk | sign-in & sessions | account/auth data |
| Convex | application database | chats, settings, ledgers, events |
| Cloudflare R2 | file storage | uploads & creations |
| OpenRouter → AI model providers | text generation routing | prompts/context per request |
| fal.ai (hosted models) | image & video generation | prompts + reference images per request |
| fish.audio | voice-over generation | script text per request |
| Billplz | payments (Malaysia) | payment processing end-to-end |
- Some processing occurs on servers outside Malaysia. By using the Service you consent to cross-border transfer of your data to the extent necessary to deliver it.
- We disclose data beyond processors only: with your direction, to comply with law or lawful requests, to enforce our Terms, to protect rights/safety, or in a business transfer (with continuity of this Policy).
6 · AI training
VAPI does not use your content to train AI models. AI Providers process Inputs solely to produce your Outputs under their API terms; where providers offer business/API tiers excluding training on customer data, those are the tiers we use. We cannot control third-party policy changes, but will not knowingly route your content to training uses.
7 · Cookies & local storage
Strictly functional only: Clerk session cookies (sign-in), and local flags (theme, which tours you've seen, drafts in progress). No advertising or cross-site tracking cookies. Blocking these may break sign-in.
8 · Retention
| Data | Kept for |
|---|---|
| Voice notes | 30 days, then deleted |
| Diagnostic events & problem reports | 30 days, then deleted |
| Chats, files, creations | until you delete them or close your account |
| Billing & credit ledger | as required by Malaysian tax/audit law |
| Backups | rotated on infrastructure providers' standard cycles |
9 · Your PDPA rights
- Access & correction — request a copy of, or corrections to, personal data we hold about you. You are responsible for keeping account data accurate.
- Withdrawal of consent — you may withdraw consent to processing; because processing is essential to the Service, withdrawal generally requires closing your account.
- Deletion — request deletion of your content and account; some records must be retained under law (billing, audit).
Requests: support@nexovia.io. We may verify identity before acting, respond within 21 days, and may charge the modest fee permitted under the PDPA for access requests. Complaints may also be directed to Malaysia's Personal Data Protection Department (JPDP).
10 · Security & breach
- Measures include: TLS encryption in transit, secret-guarded internal routes, least-privilege access, payment credentials never touching our servers, and logged admin operations.
- No system is perfectly secure and we cannot guarantee absolute security; you accept this residual risk. If a breach materially affects you, we will notify you and authorities as required by law.
11 · Changes
We may update this Policy; material changes will be announced in-app with a new effective date. Continued use after that date is acceptance. English prevails over translations.
META VIABLE SDN. BHD. · Business Reg. No. 202201024382 (1470079-D) · support@nexovia.io · Malaysia