
When you upload, your browser asks for a short-lived permission slip and then sends the bytes directly to object storage. The file never travels through our application servers. That is why a large upload is as fast as your connection allows rather than as fast as our queue allows, and why an interrupted upload leaves nothing half-written in your project.
The permission slip is good for fifteen minutes and only for the one address it was issued for. When the upload finishes, we look at the bytes that actually arrived — the real size and the real file type — rather than believing what the browser said it was sending.
Every image and video you see in the app is shown through a signed address with an expiry on it. Think of it as a long, unguessable URL rather than as a locked door. We do not publish these addresses and they are not listed anywhere, but if one is copied out of the app, whoever holds it can open the file for as long as it is valid.
That is worth knowing before you paste a preview link into a group chat. If you want to show someone a finished clip, use the share button instead — that produces a proper page with a stable address you can reason about, and it is covered in its own guide.
The addresses are deliberately long-lived and stable rather than rotated every few minutes. A URL is also a browser's cache key: an address that changes constantly means your own gallery re-downloads every thumbnail every time you open it.
To generate anything from a reference — a character sheet, a location plate — that reference has to be fetchable by the service doing the generating. So we publish a copy of it at an address that service can read, and hand over the address.
Two consequences worth being plain about. First, a published reference is readable by its address, not just by us. Second, it may be copied into storage in whichever region the model service runs in, which is not necessarily the region your account's own data sits in. If you are working with material that must not leave a particular jurisdiction, that is the constraint to weigh before uploading it.
Only what you upload. Every image and video we generate for you — setup images, every take of every segment, every composited episode — is stored at our expense and does not consume your quota. The quota exists to bound how much raw material one account parks with us, not to meter the thing you came here to make.
The quota is reserved at the moment the upload is authorised and given back when you delete. An upload you start and abandon leaves its reservation behind for a while; a background job reconciles those away, so the number settles back to what is actually stored.

Deleting an asset, an episode or a project takes it out of your account straight away. The underlying file goes into a cleanup queue and is removed later rather than on the spot.
The delay is not a recycle bin. There is no restore — not in the app, and not by asking. The window exists for our own operational safety, and nothing about it is a service we offer you. Treat deleting as final.
Before a file is actually removed we check whether anything still points at it. Copying a character into another project shares the same underlying image, and an episode override can be the same file as something in your library. If a reference is still live, the removal is dropped and the file stays.
Closing an account erases the personal details on it — the address it was registered with, the phone number, the profile — and replaces them with a tombstone. The account row itself is kept, because orders, payments and the credit ledger have to remain auditable and they reference it.
Two things to know before you do it. Any remaining credits are cleared and are not refunded. And the objects belonging to the account are queued for removal, which is the same one-way street as any other delete.
| File | Counts against quota | On delete |
|---|---|---|
| Something you uploaded | Yes | Queued for removal; reserved space returned |
| A generated setup image | No | Queued for removal if nothing else uses it |
| A segment take | No | Queued for removal |
| A composited episode | No | Queued for removal |
It is unguessable, not private. We do not publish it, but anyone who gets hold of it can open the file until it expires. For showing work to other people, use the share page instead.
No. Only files you upload count. Everything generated for you is stored at our expense.
No. There is no restore in the app. Files are cleaned up after a delay, but that window is internal — treat deleting as permanent.
No. Before a file is removed we check whether anything still points at it, and if something does, the removal is dropped and the file stays.
The personal details on the account are erased and replaced with a placeholder, the account row is kept for billing audit, remaining credits are cleared without refund, and the objects are queued for removal.
References we hand to a model service are copied to storage that service can reach, which may be in a different region from where your account's data normally sits.
Download what you care about as you go. Deleting here is one-way, and there is no restore button to fall back on.
Updated October 2, 2026
Pricing·Novel to Video·Guides·Samples·Support·Privacy·Terms·Legal·Contact·© 2026 SceneMixer