Privacy Policy
What we collect when you use kling4.io, why, and what you can do about it
2026/09/28
Kling 4 (kling4.io) is an independent third-party tool. It is not affiliated with, endorsed by, or operated by Kuaishou, Kling AI, or any other AI model provider.
This Privacy Policy explains how the operator of kling4.io ("we", "us", "our") collects, uses, shares, and protects personal data when you use the website, the web app, the developer API, billing, and support (together, the "Service"). It applies together with our Terms of Service and Cookie Policy.
1. Who Is Responsible
The operator of kling4.io is responsible for the personal data described here. For anything privacy-related, write to support@kling4.io or use our contact page.
2. What We Collect
Account data. When you sign in with Google or GitHub we receive the name, email address, and profile picture that provider shares. When you register with an email address we store that address and a hashed password. We also keep your account settings and preferences.
Billing data. Stripe processes your payments and shares with us what we need to run your account: what you bought, when, for how much, and the payment status. We never receive or store your full card number.
Content you submit and content we generate. Prompts, the reference images and audio you upload, the videos and images generated for you, and the metadata around each job (model, settings, credit cost, timestamps, status).
Usage and device data. IP address, browser and device type, pages visited, actions taken, referring site, timestamps, error logs, and security signals. If you use the developer API we log each request — endpoint, status, credits used, IP address, and time — and keep those logs for 90 days.
Communications. Messages you send us, including support requests, refund requests, feedback, and abuse reports.
3. Why We Use It
- To run the Service: sign you in, keep your credit balance, send your generation requests to the model that will process them, and return the results to your account.
- To take payment, send receipts, apply refunds, and detect fraudulent or abusive purchases.
- To keep the Service safe: enforce our Acceptable Use Policy, detect attempts to bypass moderation, and limit sign-up bonus abuse (for example by noticing many new accounts from one network).
- To answer your questions and resolve problems.
- To understand how the Service is used and to improve it.
- To send you service messages (receipts, security alerts, changes to terms) and, unless you opt out, product news. Every marketing email has an unsubscribe link.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
Where the GDPR or similar laws apply, we rely on performance of our contract with you, our legitimate interests (security, fraud prevention, understanding and improving the Service), our legal obligations, and your consent where we ask for it.
4. AI Model Providers and Your Content
The Service does not run AI models itself. To generate a video or image, we send your prompt, any reference files you uploaded, and the settings you chose to a third-party AI model provider or an infrastructure partner that hosts the model. The provider returns the result to us and we store it in your account.
Providers process this content under their own terms and privacy policies, and may keep it for a limited time for abuse monitoring or service operation. We do not use your Inputs or Outputs to train any model ourselves. Prompts and uploads may also be checked by an automated content-moderation service before generation.
5. How We Share Personal Data
We do not sell personal data, and we do not share it with advertisers. We share it only with:
- Service providers that work on our behalf: hosting and content delivery, database and file storage, AI model providers and inference infrastructure (Section 4), content moderation, the payment processor (Stripe), sign-in providers (Google, GitHub), email delivery, and analytics (Google Analytics).
- Authorities, courts, or professional advisers where the law requires it, or where it is necessary to protect the rights, safety, or property of users, the public, or the Service.
- A successor if the Service is sold, merged, or reorganised, in which case this policy continues to apply to your data.
6. Cookies and Similar Technologies
We use cookies and local storage to keep you signed in, remember your language and preferences, protect against abuse, and measure how the Service is used. Details, including how to control them, are in our Cookie Policy.
7. How Long We Keep Data
- Account data, generation history, and credit balance: for as long as your account exists. They are deleted when you delete your account (Settings → Security).
- Uploaded and generated files: available in your account while it exists, though we do not guarantee permanent storage — download anything you want to keep. Deleting your account removes your access to them; to have the stored files erased as well, email us and we will do so within 30 days.
- Billing records: Stripe, our payment processor, keeps transaction records for as long as tax and accounting law requires, including after your account is deleted.
- Usage and security data: for as long as it is useful for security, fraud prevention, and diagnostics; the data linked to your account is deleted with it. Developer API request logs are deleted after 90 days.
- Support communications: for as long as needed to handle your request and any follow-up.
We may keep specific data longer when needed to resolve a dispute, enforce our agreements, or comply with a legal obligation.
8. International Transfers
The Service uses global infrastructure and providers located in several countries, so your data may be stored or processed outside the country you live in, including in countries whose privacy laws differ from yours. Where the law requires, we rely on recognised safeguards such as standard contractual clauses and on the safeguards our providers commit to.
9. Security
We protect your data with access controls, encryption in transit, hashed passwords, least-privilege access for our providers, and monitoring for abuse. No online service can promise perfect security, so please use a strong, unique password or a trusted sign-in provider and keep your API key secret. If you believe your account has been compromised, contact us immediately.
10. Your Rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct data that is inaccurate or incomplete;
- delete your data — you can do this yourself by deleting your account, subject to the retention exceptions in Section 7;
- object to or restrict certain processing, including direct marketing;
- withdraw consent where processing is based on consent, without affecting what was done before;
- receive your data in a portable format;
- complain to your local data protection authority.
To exercise a right, email support@kling4.io from the address on your account. We may ask for more information to confirm your identity, and we respond within the time the applicable law allows, normally within 30 days. We do not treat you differently for exercising your rights.
11. Marketing and Opt-Out
You can stop marketing emails at any time with the unsubscribe link in any such email or by contacting us. Service messages that are needed to run your account — receipts, security notices, changes to these terms — are sent regardless.
12. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has provided us with personal data, contact us and we will review the account and remove the information.
13. Changes to This Policy
We may update this policy as the Service or the law changes. The date at the top shows the latest revision; material changes will be announced on the Service or by email before they take effect.
14. Contact
Questions, requests, or complaints: support@kling4.io, or our contact page.