Privacy policy

How Viki handles your information.

Last updated: October 6, 2026

Viki provides an API and workspace for text, image, and video generation. This notice describes the information used to sign you in, process your requests, and manage prepaid credits.

Your account and Google sign-in

When you continue with Google, Viki receives your Google account identifier, name, email address, and email-verification status. We use these details to create or identify your Viki account and authenticate you. Your account identifier, name, and email are stored with your Viki account.

Viki requests only the basic sign-in permissions: openid, email, and profile. It does not request access to your Gmail, Google Drive, or contacts. Google passwords are not provided to Viki. Google access and refresh tokens are not retained by the application.

API keys, credits, and usage

We store your account creation date, credit balance, reserved credits, and purchase, refund, and usage records. API-key records include a name, visible prefix, a cryptographic hash, creation and last-use dates, and revocation status. A newly created key is shown once; its full secret is not stored in the database.

Usage records include request and model identifiers, generation type, timestamps, status, token counts when available, and cost information. Video jobs also store status and response metadata, including references used to retrieve generated output. These records support your workspace, billing, and reconciliation of pending requests.

AI requests and other services

When you make a generation request, Viki processes the prompts, messages, settings, and other content you submit. The content needed to complete the request is sent through third-party routing and model services to your chosen model. Those services process the request and return generated content or job information. Their handling of that information is also subject to their own policies.

Viki is hosted on Railway and stores application records in PostgreSQL. Hosting and database infrastructure process information needed to run the service. Google processes sign-in requests. If you contact support, the information in your message is available to the person handling your request.

Payments, when enabled

Credit purchases use Stripe Checkout when payment processing is configured. Viki sends Stripe your email address, Viki account reference, and purchase amount. You provide payment details to Stripe through its checkout. With your permission, Stripe can save a card for future credit purchases and automatic top-ups. Viki stores Stripe customer and payment-method references, card brand, last four digits, expiry, payment amounts, refund information, and your top-up settings and consent. Viki does not store your full card number or security code. You can remove your saved card and turn off automatic top-ups in Billing.

Cookies and security

Viki uses a session cookie to keep you signed in and a short-lived cookie to protect the Google sign-in flow. The session cookie is valid for up to seven days; the sign-in transaction cookie is valid for five minutes. Signing out clears the session cookie. Blocking these cookies can prevent sign-in from working.

The service also stores rate-limit identifiers derived from network addresses or account identifiers, request counts, and short-lived sign-in or account-linking records to protect authentication and control request volume.

Retention and your choices

Account, billing, API-key, and usage records are kept to operate your account and reconcile requests and payments. The current service does not provide automatic account deletion or a published fixed retention period.

You can revoke API keys in your workspace, sign out, or remove Viki's connection in your Google Account settings. Removing Google access does not itself delete Viki's stored records. To request access, correction, or deletion of your account information, contact us below. We may need to verify account ownership before acting on a request.

Contact and changes

For privacy questions or account-data requests, email shaahalabja@gmail.com.

Changes to this notice will be published on this page with an updated date.