Privacy Policy

Last updated: February 20, 2026

1. Introduction

MLALab.ai ("Company," "we," "us," or "our") operates the website https://mlalab.ai and the MLALab AI video dubbing and localization service (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our Service. Please read it carefully.

MLALab.ai is operated from Ontario, Canada. By using the Service, you consent to the data practices described in this policy.

2. Information We Collect

2a. Information You Provide

  • Account Information: When you sign in via Google OAuth, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password.
  • Uploaded Content: Audio files, video URLs, scripts, and SRT caption files you submit for processing.
  • Payment Information: Billing details are collected and processed by our payment processor (Stripe). We do not store your credit card number, CVC, or full card details on our servers.
  • Communications: Emails, support requests, and any information you voluntarily provide when contacting us.

2b. Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent, and interactions with the Service.
  • Device Information: Browser type, operating system, screen resolution, and language preference.
  • IP Address: Used for security, fraud prevention, and approximate geographic location (country level).
  • Cookies & Similar Technologies: See Section 6 below.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process your audio/video files for AI dubbing, translation, and MLA packaging
  • Process payments and manage your credit balance
  • Send transactional emails (welcome, purchase confirmation, project completion)
  • Respond to your support requests within 24 hours
  • Detect, prevent, and address fraud, abuse, or technical issues
  • Analyze usage patterns to improve the Service
  • Comply with legal obligations

We do not sell your personal information to third parties. We do not use your uploaded content to train AI models.

4. Third-Party Service Providers (Sub-Processors)

We share your information with the following third-party service providers solely to operate the Service. Each provider processes data under their own privacy policy:

ProviderPurposeData Shared
Google (OAuth)Authentication & sign-inName, email, profile picture
StripePayment processingEmail, billing address, payment method
SupabaseDatabase hostingAccount data, credit balance, project metadata
VercelWebsite hosting & CDNIP address, request logs
ResendTransactional email deliveryEmail address, name
OpenAIAI translation & content generationText content submitted for processing
Microsoft (Edge TTS)Text-to-speech voice generationText content submitted for speech synthesis
Cloudflare (R2 & CDN)Media file storage & content deliveryGenerated media files (video, audio segments)
RailwayBackend API hostingAPI request data, uploaded content for processing
Google AnalyticsWebsite analyticsAnonymized usage data, page views (no PII)

We require all sub-processors to maintain appropriate security measures and to process your data only as instructed by us. We do not permit sub-processors to use your data for their own purposes. Our AI sub-processors are configured so that your content is processed ephemerally and is not used to train their public AI models.

5. Data Retention

MLALab.ai is a processing service, not a file storage service.

  • Uploaded files & generated outputs: Not retained after your session ends. Download your results immediately — files cannot be recovered later.
  • Account information: Email, name, and credit balance are retained until you request account deletion.
  • Transaction records: Payment history is retained for 7 years for tax and legal compliance.
  • Usage logs: Anonymized usage analytics are retained for up to 24 months to improve the Service.
  • Dormant accounts: Accounts inactive for 90+ days may have credits cleared per our Terms of Service.

6. Cookies & Tracking Technologies

We use the following types of cookies:

Essential Cookies (Required)

Authentication session cookies from NextAuth.js. These are strictly necessary for you to log in and use the Service. They cannot be disabled.

Analytics Cookies (Optional)

We use Google Analytics and Vercel Analytics to understand how users interact with the Service. Google Analytics may set cookies such as _ga and _gid to distinguish unique users and throttle request rates. These analytics tools collect anonymized usage data (pages viewed, time on site, general geographic region). They do not track you across other websites and do not sell data to advertisers. You may opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

Payment Cookies (Stripe)

When you interact with our payment system, Stripe may set cookies for fraud prevention and payment processing. These cookies are controlled by Stripe and are subject to Stripe's Privacy Policy.

We do not use third-party advertising cookies, tracking pixels, or retargeting technologies. We do not participate in ad networks.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including Canada and the United States, where our sub-processors operate. These countries may have different data protection laws than your jurisdiction.

Where we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required by applicable law.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • All data transmitted via HTTPS/TLS encryption
  • Database access restricted by role-based permissions
  • Authentication handled by Google OAuth (no passwords stored)
  • Payment data handled entirely by PCI-DSS compliant Stripe
  • No long-term storage of uploaded media files

No method of transmission over the Internet is 100% secure. While we strive to use commercially reasonable means to protect your information, we cannot guarantee absolute security.

9. Your Rights (GDPR — EU/EEA/UK Residents)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Service you requested (account creation, content processing, credit management).
  • Legitimate Interests (Art. 6(1)(f)): Fraud prevention, security monitoring, service improvement, and analytics.
  • Consent (Art. 6(1)(a)): Optional analytics cookies. You may withdraw consent at any time.
  • Legal Obligation (Art. 6(1)(c)): Transaction records retained for tax compliance.

Your Rights

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention obligations.
  • Right to Restrict Processing: Request that we limit how we use your data.
  • Right to Data Portability: Request your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at privacy@mlalab.ai. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

For enterprise customers requiring a Data Processing Agreement, visit our DPA page.

10. Your Rights (CCPA/CPRA — California Residents)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected.
  • Right to Delete: Request deletion of your personal information.
  • Right to Opt-Out of Sale: We do not sell your personal information. No opt-out is necessary.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at privacy@mlalab.ai. We will verify your identity and respond within 45 days.

11. Canadian Privacy Law (PIPEDA)

As a Canadian company, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to access your personal information held by us, challenge its accuracy, and withdraw consent (subject to legal or contractual restrictions). Contact our Privacy Officer at privacy@mlalab.ai.

12. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible. If you believe a child has provided us with personal information, please contact us at privacy@mlalab.ai.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email. Your continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Information

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:

MLALab.ai — Privacy Officer

Email: privacy@mlalab.ai

General Support: support@mlalab.ai

Website: https://mlalab.ai