Seedance 2.5 is here. Every model is included on every plan.
Dolly
Sign inSign up

Privacy Policy

Last updated: September 11, 2026

This policy lists exactly what Dolly collects and why. No more, no less. We run no ads and we don't sell data; we do use aggregate analytics, and we use abuse-prevention signals described plainly in section 3. A plain-English summary sits above each section; the full text governs.

1. What we collect

In plain English: Your email, your prompts and images, billing records (never card numbers), moderation logs, your IP at signup, and a device identifier your browser computes for abuse prevention.

Account: your email address and authentication data, managed by our auth provider. Content: the prompts you write, reference images you upload, media you generate, and your chats with the agent. Moderation records: every moderation check is logged with a content fingerprint (hash) and verdict; for rejected prompts, the prompt text itself is retained for enforcement; rejected image uploads are never stored, only their fingerprint. Billing: transaction identifiers, amounts, and credit history. Card and payment details go directly to our payment processor. They never touch our servers. Abuse-prevention signals: your IP address at signup, a device identifier computed in your browser, and a normalized form of your email address — section 3 explains each one, what it decides, and how to get a human review. Technical: short-lived server logs.

2. How we use it

In plain English: To run the service, keep it safe, and bill correctly. We use aggregate analytics to understand traffic. No ads, and we never sell your data.

We use this data to operate the service (run your generations, store your library, maintain your balance), to enforce the content policy and prevent abuse, and to process payments and refunds. We do not sell personal data or run advertising. We use an analytics provider to measure aggregate traffic and which features are used — page views and a few product events (sign-up, first generation, purchase) — so we can improve the product.

3. Abuse prevention and automated decisions

In plain English: At signup, an automated check decides your account's risk tier and whether video waits for a card check. It looks at a browser-computed device id, your signup IP, and whether your email is disposable or a variant of an existing account's. It never touches paid credits, it's never used for ads, and a human will review any decision if you email us.

The device identifier. When you sign up, and while you use the service signed in, our web app computes a device identifier in your browser using an open-source fingerprinting library — it is not computed while you browse our public pages anonymously. The computation runs entirely on your device and no data is sent to the library's maker; the resulting identifier is stored on your account profile, cached in your browser, and sent to us with your signed-in requests. We use it for exactly one purpose: detecting duplicate and abusive signups. It is never used for advertising, tracking across other sites, or anything else.

The other signals. We record the IP address you sign up from and check whether other recent signups came from it (a rolling seven-day window). We also store a normalized form of your email address — lowercased, with common alias tricks like plus-suffixes and provider-specific dot variants removed — to detect one person signing up repeatedly, and we check whether the email domain is a disposable-address service.

What the automated decision does. These signals feed an automated check at signup that decides what a new account receives: a clean signup gets the full free-credit grant with everything unlocked; a signup that looks risky gets the grant with video generation held until a payment card is verified; a signup that matches an existing account's device or normalized email may have the free grant withheld entirely. The decision affects only free promotional credits and the video hold — never your ability to create an account, buy credits, or use credits you paid for. Every decision is logged, and a human review is available on request: email support@dolly.to and a person will look at your account and can change the outcome. New information — like verifying a card — also updates it automatically.

Card verification. Where video is held, you can unlock it by verifying a payment card through our payment processor's hosted page in setup mode: no charge is made, and your card details go directly to the payment processor — they never touch our servers. We store only the processor's customer reference and the fact that verification completed.

EU/UK visitors. Our legal basis for these abuse-prevention signals is legitimate interest — protecting a prepaid service from bonus farming and duplicate-account abuse — and the identifier is not used for advertising or profiling beyond that purpose. You may object, and you may request human review of any automated decision, at support@dolly.to.

4. Who processes it

In plain English: Named outright: Cloudflare hosts and stores, Supabase holds identity and the database, Stripe takes payments, the AI providers run your generations, Anthropic runs moderation and the agent, Google handles sign-in and analytics, Rewardful attributes referrals, Formspree carries support mail. The fingerprint library sends nothing anywhere.

Cloudflare (USA): hosts the site and API and stores your generated media and uploads. Supabase (USA): stores your account record, credentials, and our database. Stripe (USA): processes all payments and card verification; its own privacy policy applies to checkout. AI generation providers: your prompts and any reference media are sent to the model platforms we route through — Kie.ai and fal — which run models from the providers named in each model's label, currently including ByteDance (Seedance, Seedream), Google (Veo, Imagen, Nano Banana, Gemini), OpenAI, xAI, Black Forest Labs (Flux), Kling, Alibaba, MiniMax, Luma, Recraft, Bria, ElevenLabs, Suno, Kokoro, and Dia. The models available change over time; the current list is always on the pricing page. Anthropic (USA): automated moderation of prompts, uploads, and generated media, and the in-app agent — which receives your chat messages and the media in that chat (section 6). Google: optional sign-in with Google (One Tap / OAuth), and Google Analytics for the aggregate product analytics described in section 2. Rewardful: if you arrive through a partner link, the referral code and the resulting signup or purchase are recorded so the partner can be credited. Formspree: carries your support messages and bug reports to us — what you wrote plus your email, account id, the page you were on, and on a bug report your model, last job id, browser, and window size.

The device-identifier library (FingerprintJS, open source) is code that runs in your browser, not a service: it sends no data to its maker. We share data with the processors above only as needed to provide the service, and with authorities where the law requires.

5. Cookies and local storage

In plain English: No advertising cookies. Your login session and device id live in your browser; our analytics, affiliate-attribution and checkout providers set their own.

We set no advertising cookies. Your sign-in session, theme choice, and the device identifier from section 3 are kept in your browser's local storage. Our analytics provider sets first-party cookies to measure aggregate traffic (which pages are visited and a few product events). Our affiliate-attribution provider stores a referral id when you arrive from a partner link, and signing in with Google loads Google's own identity script. Checkout happens on our payment processor's hosted page, which sets cookies under its policy.

6. Chats with the agent, and who can read them

In plain English: Your chats are kept until you delete them. Each turn is sent to our assistant provider so the agent can respond. Dolly operators CAN open a chat transcript in our admin console for support and abuse investigation — and every such access is itself logged, permanently, before the transcript is shown.

What a chat stores. Your messages, the agent's replies, text extracted from documents you attach, pages you ask the agent to read, and links to the media in the conversation. Deleting a chat removes the conversation and its history; it does not delete the generations it produced — those stay in your library until you delete them there.

Who else receives it. On every turn, the recent history of the active conversation is sent to our assistant provider (Anthropic) so the agent can respond in context, and it is cached on their side between turns to keep responses fast. Media in the conversation may be sent to them or fetched by them from its storage link.

Operator access. Dolly operators can view your account details, generation history, and full agent chat transcripts through an internal admin console, for two purposes only: support you've asked for, and investigating abuse or policy violations. Every access of this kind is written to a permanent audit log — which operator, what they viewed, whose data, from what address, and when — and the log entry is written before the data is shown, so an unlogged access is technically impossible. We do not read chats for any other purpose.

7. Retention and media access

In plain English: Media is kept until you delete it; money records as long as the law requires; moderation, risk, and audit logs for enforcement — we run no automatic cleanup on those today. Finished media is served over a public, unguessable link.

How your media is served. Finished generations are delivered over a public content-delivery link with a long, random address. The link is not password-protected and needs no login, so anyone who has it can view or download the file. The address can't practically be guessed, and your media is never listed or searchable — but generated media should not be treated as fully private. Deleting a generation removes its file from storage.

Generated media and uploads are stored until you delete them; chats until you delete them. Credit and payment records are retained as required for accounting and legal obligations. Moderation logs, the abuse-prevention records from section 3 (device identifier, signup IP, normalized email, risk decisions), and the operator-access audit log from section 6 are retained for enforcement and safety and are not automatically deleted today. To close your account, or to have your stored media and personal data removed, email support@dolly.to and we will action it; financial, moderation, and safety records are retained as required for legal, accounting, and safety purposes. Server logs are short-lived.

8. Your rights

In plain English: Ask for your data, ask for deletion, ask for a human. Email us and we'll do it.

You can access your content anytime in the app, and delete generations and chats individually. Regardless of where you live, we honor requests to access, correct, or delete your personal data, and to have a human review any automated decision described in section 3. Email support@dolly.to and we will action it. Account closure is handled by us on request at that same address: we remove your account and generated media; transaction records are retained as required for financial and tax compliance. Where your local law (such as EU/UK GDPR or California CPRA) grants further rights, including data portability, objection to legitimate-interest processing, or complaint to a supervisory authority, we honor those too.

9. India (DPDP Act)

In plain English: If you're in India: you have rights to access, correct, and erase your data and to raise a grievance. The grievance officer is the operator, reachable at the support address.

If you are in India, the Digital Personal Data Protection Act, 2023 applies to our processing of your personal data. You have the right to access a summary of the personal data we hold about you, to correction and erasure, to nominate a person to exercise your rights if you are unable to, and to a readily available grievance process. Our Grievance Officer is Tristan Hakert, reachable at support@dolly.to; we respond to grievances within the timelines the Act prescribes, and if you are not satisfied with our response you may escalate to the Data Protection Board of India. Where we rely on consent under the Act, you may withdraw it at any time at the same address.

10. Security and children

In plain English: Encrypted in transit, minimal keys, no card data on our side. Dolly is 18+ only.

Traffic is encrypted in transit; secrets and API keys are scoped server-side; payment details never reach our infrastructure. You must be at least 18 years old to use Dolly, everywhere; the service is not directed at children or teenagers, and we delete accounts we learn belong to users under 18.

11. Changes and contact

In plain English: If this policy changes materially, we tell you before it applies.

Material changes to this policy will be announced by email or on the site before taking effect; a summary of changes is kept in the changelog below. Questions and privacy requests: support@dolly.to.

Changelog

  • September 11, 2026Corrected §3: the signup check decides your account's risk tier and whether video waits for a card check. It no longer decides how many free credits you get, because Dolly no longer issues them. What is collected and how to get a human review are unchanged.
  • September 1, 2026Added: abuse prevention and automated decisions (§3 — device identifier computed only at signup and while signed in, IP, email normalization, the signup risk decision and how to get a human review, card verification), agent chats and operator access (§6), an India DPDP section (§9). Named every processor, including the AI model providers, in §4. Minimum age raised to 18 everywhere (§10). Corrected the introduction: we do use aggregate analytics.
  • August 20, 2026First published version.