Privacy Policy
This policy explains what Videophile ("we"), operated by [LEGAL ENTITY NAME], collects, why, and what we do with it. It applies to videophile.app and the Videophile application.
What we collect
| Data | Why |
|---|---|
| Email address and password hash | To create and secure your account. We never see your password in plain text. |
| Content you create — topics, scripts, transcripts, generated video and audio | To provide the Service and let you review and publish your work. |
| Access tokens for platforms you connect | To publish on your behalf. Stored encrypted at rest. |
| Usage and billing records — credits consumed, plan, transactions | To operate plans, prevent abuse, and answer billing questions. |
| Public performance metrics of videos you publish | To show you what performs, and to improve the topics we suggest for your channel. |
| Basic technical logs — IP address, browser, timestamps, errors | Security, abuse prevention and debugging. |
Google and YouTube data
When you connect a YouTube account, we request only these permissions:
- youtube.upload — to upload videos you have approved.
- youtube.readonly — to read your channel name and the public statistics of videos we published, so we can show you how they performed.
We do not read your private videos, comments, subscriber lists or messages. We do not delete or modify content we did not create. We do not use YouTube data to build advertising profiles, and we do not sell it.
Videophile's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke our access at any time at myaccount.google.com/permissions, or by disconnecting the account in Videophile.
Your use of YouTube through the Service is subject to the YouTube Terms of Service and the Google Privacy Policy.
How your content is processed
Generating a video sends your topic and script to AI providers. This is necessary to produce the output you asked for.
| Provider | What is sent |
|---|---|
| Anthropic (Claude) | Topic, niche description and script text, to write and evaluate copy. |
| Google (Gemini, Veo) | Scene descriptions and narration text, to generate images, video and speech. |
| Supabase | Database and authentication. Hosts your account and content records. |
| Google Cloud / Firebase | Rendering and file storage. |
| Vercel | Application hosting. |
| Paddle | Payments. Paddle is the merchant of record and handles your payment details — we never see your card. |
We do not sell your data, and we do not use your content to train AI models. Our providers process it under their own terms; we select providers that do not train on API data by default.
Legal bases (UK/EU users)
- Contract — to provide the Service you signed up for.
- Legitimate interests — security, abuse prevention, and improving the Service.
- Legal obligation — retaining transaction records where required.
How long we keep it
- Account and content — while your account is active. After cancellation or deletion, content remains downloadable for 30 days, then is deleted.
- Platform tokens — deleted immediately when you disconnect an account or close your account.
- Billing records — retained as long as tax and accounting law requires, typically several years.
- Technical logs — around 90 days.
Your rights
You can request access to your data, correction, deletion, a portable copy, or object to certain processing. Email hello@superappsdomain.com and we will respond within 30 days. You may also complain to your local data protection authority.
Security
Data is encrypted in transit and at rest. Platform access tokens are stored encrypted and are never exposed to the browser. Access to production systems is limited to those who need it. No system is perfectly secure, and we will notify affected users and regulators of a breach as required by law.
International transfers
Our infrastructure and providers are located in the United States and other countries. Where data is transferred out of the UK or EEA, that transfer relies on appropriate safeguards such as Standard Contractual Clauses.
Children
The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
Cookies
We use only what is necessary to keep you signed in and to keep the Service secure. We do not use advertising or cross-site tracking cookies.
Changes
We will post updates here and, for material changes, notify you by email.
Contact
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
hello@superappsdomain.com