Privacy Policy
This policy describes how wan-3.run (the “site”, “we”) handles information when you use https://wan-3.run.
It applies only to this website. It does not describe Alibaba Cloud Model Studio, the official API, or Alibaba’s own consumer apps.
Effective 26 August 2026. Contact for privacy requests: hello@wan-3.run.
We are an independent third-party interface for the Wan 3.0 video model. We are not Alibaba and not Alibaba Cloud.
1. Information we collect
Account information (if you sign in)
- Email address
- Name, if you or your sign-in provider supplies one
- A hashed password if you register with email
- Sign-in tokens from Google or GitHub when you use those buttons
- Locale, first-touch marketing source (UTM), and an IP address recorded when the account is created
Generation information
- Prompts, settings (duration, ratio, resolution, scene), and any images, clips, audio, documents, or web links you supply
- The resulting files and task status
- Which model ran the job. This is the same
wan3.0-videomodel on the free clip and on every paid plan — the tier changes the resolution and the allowance, not the engine — and the model id and task id are shown to you against each result
Billing information
We do not store full card numbers. The processor named at checkout (typically Stripe; PayPal or another listed processor if offered) handles the charge. We keep a customer or subscription token, the plan or pack you bought, credit movements, and whether a refund succeeded.
Usage, device, and security information
- Pages viewed and feature events (for example generate started or failed)
- Approximate IP (Cloudflare
cf-connecting-ipfor quota; a hashed form is used for the free-tier allowance and for the cap on accounts per network) - Browser and error logs
- Bot-check tokens (Cloudflare Turnstile) when that check is shown
Cookies and similar storage
h3_vid: first-party visitor id, HttpOnly, up to 1 year. Used so the rate limits on the free no-account tools are per visitor rather than per refresh. The name is inherited from the template this site was built on and does not mean anything about which model runs- Session / sign-in cookies from our auth library (Better Auth)
NEXT_LOCALE, banner-dismiss, andutm_sourcewhen present- Browser localStorage for UI flags (for example that you already used your free clip)
- Google Analytics and Microsoft Clarity, only when those integrations are switched on in site settings. They set their own cookies or similar identifiers
We do not collect health, biometric, or precise GPS data. We do not knowingly collect information from children (see section 11).
2. How we collect it
- Directly from you — forms, sign-in, prompts, uploads, emails you send us
- Automatically — cookies, logs, quota counters, Turnstile
- From providers — Google or GitHub profile fields on social sign-in; Stripe (or the checkout processor) payment status; model providers returning a clip or an error
3. How we use it
- Run the generator and show results in My Creations
- Keep credits, plans, and history on the same account
- Refund unused credits on the published 7-day rule
- Rate limits, fraud and abuse prevention, debugging failed jobs
- Emails you asked for (sign-in, verification). We do not run a marketing newsletter from this policy
- Understand which pages fail, when analytics are enabled
- Comply with tax, dispute, and legal process
We do not use your prompts or clips to train a public dataset of our own, and we do not sell them as a product.
4. Legal bases (where a privacy law requires one)
- Contract — creating an account, running a paid or free generation, billing, refunds
- Legitimate interests — security, rate limits, fraud, server logs, improving reliability
- Consent — non-essential analytics cookies when those tools are enabled and the law requires a choice
- Legal obligation — tax records, responding to a valid legal demand
If you are in the EEA, UK, or Switzerland, you may object to processing based on legitimate interests. Write to the email above.
5. Who we share it with
We share only what that party needs to do its job:
| Party | Why |
|---|---|
| Model providers (Alibaba Cloud for Wan 3.0 jobs, on the free clip and on every paid plan alike) | Prompt, media, and settings for that job |
| Payment processors (Stripe and any other processor named at checkout) | Charge, invoice, refund |
| Cloud infrastructure (Cloudflare Workers, D1, R2 object storage) | Host the site, database, and files |
| Email (Brevo, or Resend, when verification or transactional mail is on) | Deliver the message |
| Analytics (Google Analytics, Microsoft Clarity — only if enabled) | Usage measurement |
| Auth providers (Google, GitHub) | Complete sign-in you started |
| Bot protection (Cloudflare Turnstile) | Tell humans from automated abuse |
| Authorities | When the law requires it |
We do not sell personal information as that term is used in CCPA/CPRA. We do not share it for cross-context behavioural advertising.
Processors may be outside your country. Cloudflare and typical US processors rely on Standard Contractual Clauses or an adequacy decision where they say they do. We do not operate a separate “EU-only” region.
6. International transfer
The site is hosted on Cloudflare. Generation providers and Stripe (or the checkout processor) may process data in the United States or other countries. If a transfer tool is required, it is the one that provider documents (usually Standard Contractual Clauses).
7. How long we keep it
| Data | Period |
|---|---|
| Uploads to the free no-account tools | Kept only as long as the request needs. Those tools read a file and return text; they do not build a library on your behalf |
| Signed-in finished work | About 7 days on the account unless you download or delete sooner. The upstream link expires after 24 hours, so we copy the file to our own storage the moment a job completes — otherwise a clip you paid for would disappear |
| Account profile | While the account is open, then deleted or anonymised after a deletion request except as below |
| Billing and credit ledger | As long as tax, accounting, and card-dispute rules require (often years, not days) |
| Security and error logs | A short operational window, then rotated |
Visitor cookie h3_vid | Up to 1 year, or until you clear cookies |
“Eligible for deletion” means we schedule removal from our storage; copies in backups or a provider’s cache may linger for a short technical period.
8. Your rights
You can ask us to:
- Access a copy of the account data we hold
- Correct inaccurate account fields
- Delete the account and associated generations we still control
- Export account data we can reasonably provide
- Restrict or object to processing, where a law such as GDPR gives you that right
- Withdraw consent for analytics by blocking those cookies in your browser (and writing to us if a tool stays enabled site-wide)
- Opt out of “sale” or sharing — we do not sell; this is how we treat a CPRA request anyway
- Lodge a complaint with your data protection authority (for example a EU supervisory authority, the UK ICO, or the California Attorney General)
Send requests to hello@wan-3.run from the email on the account. Say which right you are using. We will not charge for a request we are required to honour. We may need to verify it is you.
We aim to reply within 30 days, or the shorter period your local law sets.
9. Cookies and tracking
Strictly necessary: h3_vid, session and sign-in cookies, security (Turnstile). The generator and the free-tool rate limits do not work without them.
Preferences: locale, banner dismissed, localStorage UI flags.
Analytics (optional, only if enabled in settings): Google Analytics, Microsoft Clarity. Disable them with your browser’s tracking protection, an analytics opt-out add-on, or by asking us to turn the integration off.
We do not run a separate cookie-consent wall today. If we enable non-essential analytics for visitors in a region that requires prior consent, we will add a choice before those scripts run.
10. Security
- HTTPS in production, with HSTS on our application responses
- HttpOnly session and visitor cookies
- Access to admin tools is limited to signed-in operators
- Payment card data stays with the processor
- Prompts and media go to model providers over their APIs so a clip can be made — that path is inherent to the product
No method is perfect. If we learn of a breach that legally requires notice, we will email affected accounts and say what we know.
11. Children
The service is not directed at children under 16. Do not create an account or upload a child’s face or voice for them. If we learn we have collected personal information from a child under 16, we will delete it. US COPPA uses 13 as a floor; we set 16 so the same rule covers stricter regional ages.
12. Contact
- Email: hello@wan-3.run
- Subject line:
Privacy requestplus the right you want (access, delete, …) - We do not publish a postal address on this page. If a law requires a physical address for notices, we will add it here when we have one to give.
We have not appointed a Data Protection Officer. Privacy mail is read by the operator of this site.
13. Changes
We will change the date at the top when this policy changes. If a change is material (new category of data, new sale, or a weaker right), we will also note it on Updates or email signed-in users when we can. Continued use after the new date is acceptance of the updated policy.
14. Other
- Third-party sites we link to (Alibaba Cloud, Artificial Analysis, payment processors) have their own policies. We are not responsible for them.
- Related pages: Terms · Refund Policy · Responsible Use · Contact
Written and maintained by the wan-3.run editorial teamPublished Last updated