Genreach

Privacy Policy

Effective date: August 21, 2026

This Privacy Policy explains how Richen Labs LLC, the Texas company that operates Genreach (“we”, “us”, “Genreach”), at genreach.app (the “Service”), collects, uses, stores, and protects information about you. By creating an account or using the Service you agree to the practices described here.

1. Who we are

Genreach is a software-as-a-service tool that lets creators generate images, videos, scripts, and captions using AI, and — at the creator’s explicit request — publish that content to their own connected social media accounts.

2. Information we collect

We collect only what we need to run the Service:

  • Account data — your email address and a securely hashed password. We never store your password in plain text.
  • Content you create — the prompts you submit and the images, videos, scripts, and captions generated from them.
  • Photos of real people you upload for likeness features — some tools (e.g. AI Dance, Life Story, Talking Photo, Product Ads, Group Photo, and AI Image when you use a reference photo of a person) let you upload a photo of yourself, or of someone who has given you their explicit permission. We handle these photos in two ways:
    • One-time photos — a photo you upload for a single generation is used only to run that job. It is sent to the AI provider that performs the generation (see section 5), and where that provider needs a URL we stage a copy in our storage just long enough for the job; that copy is deleted when the job finishes, and swept automatically shortly afterwards as a backstop if a job crashes. After that, only the finished video or image you created is kept, under the same retention rules as your other content.
    • Photos you choose to save — some pages let you save a photo to your own library so you can reuse it: the saved-dancers library in AI Dance (up to 12 photos), the portraits of your AI Characters (including your own face if you make a character of yourself), and your profile photo. Saving is always an explicit action, never automatic. Saved dancers and character portraits stay in your account until you delete them from the corresponding page or delete your account; your profile photo stays until you replace it or delete your account. None of these are auto-expired by the media retention windows in section 6.
    Before any real person’s face is processed we require an explicit confirmation that the person is you or has given you permission, and we keep a record of that confirmation (the feature, the version of the consent text, the time, and the IP address it was given from) linked to the job. We do not use your photos to train or fine-tune AI models, and we never claim any rights to your likeness.
  • Voice samples & cloned voices — on paid plans you can enroll a cloned voice by uploading a short recording of speech, and some video tools let you record yourself reading the opening line (the “hook”) so the video opens in your real voice. We collect these recordings only to narrate the videos you ask us to make in that voice. Enrolling a cloned voice requires an explicit confirmation that the voice is yours or that you have the speaker’s permission — we refuse to enroll a voice without it — and we keep a record of that confirmation in the same way as for photos. The recording is stored in our storage (Cloudflare R2) as the voice’s reference clip, together with a transcript of it and a short generated preview; each time you generate narration in that voice, the reference clip is sent to our voice provider (see section 5), which produces the speech from it. Cloned voices are kept until you delete the voice from your Voices page or delete your account, at which point the recording, transcript, and preview are deleted from storage; hook recordings are kept until you delete your account or ask us to remove them (section 7). Neither is auto-expired by the media retention windows in section 6. We do not use your voice to train or fine-tune AI models, and we do not train AI models of our own.
  • Connected social accounts — when you connect a TikTok, YouTube, Instagram, Facebook or LinkedIn account, we receive and store OAuth access and refresh tokens, plus basic public account info (such as your display name / channel handle and ID) and, where you granted a reporting scope, the performance figures for posts on that account. See section 4 for details.
  • Billing data — if you purchase credits or a subscription, payments are processed by Stripe. We do not see or store your full card number; we keep a customer/subscription reference and your credit balance.
  • Usage & technical data — job history, credit transactions, and standard server logs (IP address, request identifiers, timestamps) used for security, debugging, and abuse prevention.

A note on face and voice data. Depending on where you live, images of a face and recordings of a voice that are used to recognize or recreate a person may be treated as biometric or sensitive personal information, and the law may require a separate, explicit consent before they are processed, or set limits on how long they may be kept. We only process a real person’s face or voice after you give the explicit confirmation described above, we use it solely to produce the content you requested, and you can delete saved faces and voices at any time. If you would rather not provide this consent, most likeness features offer AI-generated presenters or characters and a library of stock voices instead.

3. How we use your information

  • To provide the Service: generate content and run the jobs you request.
  • To publish content to your connected social accounts — only when you explicitly choose to publish a specific piece of content.
  • To read how those posts performed, where you granted a reporting scope, and show you that performance on your Analytics and Grow pages — including using it to rank your own past posts and suggest what to make next. This is shown only to you.
  • To manage your account, credits, and billing.
  • To secure the Service, prevent abuse, and comply with legal obligations.
  • To notify you about your jobs (e.g. completion) and important account matters.

We do not sell your personal data, and we do not use your content or connected-account data for advertising.

4. Social media account connections (TikTok, YouTube, Instagram, Facebook, LinkedIn)

Connecting a social account is entirely optional and is initiated by you via the platform’s standard OAuth consent screen. When you connect an account:

  • Scopes we request. Only what publishing and, where you have it, performance reporting require:
    • TikTok user.info.basic (to show which account is connected), video.publish (to upload videos you choose to publish), and video.list (to read the view, like, comment and share counts of posts you published through Genreach).
    • YouTube — Genreach uses YouTube API Services. We request youtube.upload (to upload videos), youtube.readonly (to read basic channel info), and yt-analytics.readonly (to read per-video performance — views, watch time and retention, shares, subscribers gained — for the videos on your channel). Google’s handling of your data is described in the Google Privacy Policy (http://www.google.com/policies/privacy). You can revoke Genreach’s access to your Google account at any time from the Google security settings page (https://security.google.com/settings/security/permissions).
    • Instagram instagram_basic (to identify the connected professional account), instagram_content_publish (to publish Reels, images and carousels you choose to publish), and pages_show_list (to find the Facebook Page your Instagram account is linked to, which Instagram requires for publishing). Where Instagram insights are enabled for your account we also request instagram_manage_insights, to read the performance of posts you published through Genreach.
    • Facebook pages_show_list (to list the Pages you manage, so you can choose one), pages_manage_posts (to publish to the Page you chose), and pages_read_engagement (to read the performance of those posts).
    • LinkedIn openid and profile (to identify the connected member and show their name), and w_member_social (to post to that member’s own feed). Genreach does not request access to LinkedIn company pages.
  • What we do with access. Two things, and nothing else. First, we publish the specific content you explicitly choose to publish from your Genreach library — we never post, modify, or delete content on your behalf without a deliberate action by you. Second, where you granted a reporting scope above, we periodically read the performance of posts on your connected account, so the Analytics and Grow pages can show you what resonated and suggest what to make next. We do not read your inbox, your followers’ personal data, or content you did not publish through Genreach, except that YouTube channel-level analytics necessarily cover videos already on your channel.
  • How tokens are stored. OAuth tokens are encrypted at rest and used only to perform the actions above.
  • Revoking access. You can disconnect a social account at any time from your Genreach account, which deletes the stored tokens. You may also revoke access directly at the platform: TikTok (Settings → Security & permissions → Manage app permissions), Google (Account → Security → Your connections to third-party apps, or directly at security.google.com/settings/security/permissions), Facebook and Instagram (Settings → Business integrations), and LinkedIn (Settings → Data privacy → Permitted services).
  • What happens when you disconnect. Disconnecting an account in Genreach (or deleting your Genreach account) asks the platform to revoke our access, deletes the stored tokens, and deletes the data we obtained through that platform’s API — the performance figures, comment-derived signals, the platform’s own post IDs and URLs, and, for YouTube, the scanned channel catalog. This happens immediately when you disconnect, which is within the 7 days YouTube’s policies allow for deleting Authorized Data after you revoke access. Your own Genreach records — the content you made, its caption, the platform, and when it went out — stay in your account.

Sharing, transfer, and disclosure of Google user data. “Google user data” means the data we receive through Google APIs when you connect a YouTube account — your basic channel info (channel name, handle, and ID), the videos you choose to upload, and the per-video performance figures returned by the YouTube Analytics API (views, watch time and retention, shares, and subscribers gained). We share, transfer, or disclose this data only as follows, and for no other purpose:

  • YouTube / Google — we transfer the specific video and its metadata back to YouTube via the official YouTube Data API, solely to complete the upload you explicitly requested.
  • Cloudflare R2 / CDN — our storage and content delivery provider, which holds the video file until you publish it and serves it within the Service.
  • Cloud hosting & infrastructure — the servers and managed database that run Genreach store your connected-account tokens (encrypted) and channel info so the Service can operate.
  • Legal & safety — we may disclose data if required by law, regulation, legal process, or to protect the rights, safety, or property of our users or the public.
  • Business transfer — if Genreach is involved in a merger, acquisition, or sale of assets, data may be transferred subject to this Policy, and we will notify you of any change in how your data is handled.

We do not sell Google user data, transfer or disclose it to data brokers or advertisers, use it for advertising, or use it to train generalized AI/ML models. Humans do not read your Google user data except where you give explicit consent, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized.

Genreach’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

5. Third-party services we rely on

We share data with a small set of processors strictly to operate the Service:

  • Cloudflare R2 / CDN — stores and serves your generated media files.
  • AI generation providers — receive what is needed to fulfil the generation you requested, and nothing else:
    • OpenRouter — an API gateway that routes our text and image requests to third-party model providers (for example Google’s Gemini models). Receives your prompts and scripts and, for features that use a photo, the photo you uploaded (for example the reference photo for a person-matched AI Image, or the photo behind a Life Story video). We also run uploaded photos through a vision model on OpenRouter for safety checks — for example to confirm a photo saved as a dancer shows a single person.
    • fal.ai — hosts the video, motion, talking-presenter, speech, and audio models we use (for example Kling, Wan, OmniHuman, MiniMax speech, F5-TTS voice cloning, Whisper transcription, and music, sound-effect, and background-removal models). Receives your prompts; the photos you upload for AI Dance, Talking Photo, and other likeness features; your voice reference clip when you generate narration in a cloned voice; and the audio or video you upload for dubbing, clipping, and transcription.
    • Pexels — stock photo search used for some image and video scenes. Receives a search query derived from your prompt.
    Depending on configuration we may also call Google’s Gemini API directly (for image generation, with the same inputs as via OpenRouter), MiniMax and ElevenLabs directly (for narration — they receive only the text to be spoken), and Replicate (as a fallback for talking-presenter rendering — it receives the presenter image and narration audio). Some steps run on our own servers and never leave our infrastructure — for example the English narration voices and caption timing.
  • Stripe — processes payments.
  • TikTok, YouTube, Instagram, Facebook and LinkedIn — each receives the specific content you choose to publish to it (the video, image or card images, and the caption, title and hashtags you send with them), via that platform’s official API. A platform receives your content only when you publish to it.
  • Email delivery — sends transactional emails (account and job notifications).

6. Data retention

We keep your account data for as long as your account is active. Server logs are retained for a limited period for security and debugging.

Generated media. On the free plan, the media you generate (images, videos, audio) is kept for 30 days, then automatically removed to keep free storage tidy — we email you a reminder before this happens so you can download it or upgrade. On a paid plan, your generated media is kept for as long as your subscription is active. Your job history and credit records are always preserved; only the downloadable media is removed when it expires.

Saved faces, characters, and voices. Photos you chose to save (saved dancers, AI Character portraits, your profile photo), cloned voices, and hook recordings are reusable assets, so they are not subject to the media windows above: they stay until you delete them or delete your account.

When you delete your account, we delete or anonymize your personal data and connected-account tokens, ask each connected platform to revoke our access, and remove your generated media, saved photos, cloned voices, and recordings, except where we must retain certain records to comply with legal or accounting obligations.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to withdraw consent. You can disconnect social accounts, delete saved dancers (AI Dance), AI Characters, and cloned voices (Voices) from their pages, and delete your account from within the Service, or contact us at [email protected] to exercise any of these rights.

8. Data security

We protect your data with encryption in transit (TLS), encryption at rest for sensitive credentials such as social OAuth tokens, hashed passwords, scoped access controls, and rate limiting. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard practices.

9. International data transfers

Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.

10. Children

The Service is not directed to children. You must be at least the age of majority in your jurisdiction (and at least 13) to use it. We do not knowingly collect data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, by notifying you.

12. Contact us

Questions about this policy or your data? Email [email protected] or [email protected].