Privacy policy
What we collect, how we use it, who we share it with.
LAST UPDATED · JUL 02 · 2026 · EFFECTIVE IMMEDIATELYIntroduction
VidFlow ("we," "us," or "our") protects your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our AI video platform.
By using the Service you consent to the practices described here. If you don't agree, please discontinue use.
Information we collect
Account data: name, email, password (stored as a secure hash). Profile: display name, photo, optional bio. Payment: billing name and address — card numbers are stored exclusively by Stripe, never by us. Project data: scripts, prompts, style preferences. Generated content: AI-produced scripts, images, voiceovers, renders. Communications: messages to support.
Automatic data: device + browser metadata, IP address, page usage events, and feature interactions to understand how the Service is used.
How we use your information
To provide and operate the Service. To process payments. To improve features (in aggregate, anonymized). To send transactional emails (renders complete, billing receipts). With explicit consent: marketing emails — opt-out at any time.
We do NOT train models on your private content without explicit consent.
Sharing & disclosure
We share with vendors solely to operate the Service: Stripe (payments), AWS / R2 (hosting), Resend (email), Sentry (error monitoring), Inworld (voice synthesis — and voice cloning when you submit a voice sample with your explicit consent), KIE (image and video generation), OpenRouter (language-model calls for scripts and suggestions), AssemblyAI (audio-to-text alignment).
We do not sell personal data. We disclose only when legally required (court order, subpoena) or to protect rights and safety.
Google & YouTube data
If you connect a YouTube channel, VidFlow uses Google OAuth and YouTube API Services. We request access only when you explicitly ask for it — never at sign-up: read-only channel access to list the channels you own (so you can pick one to connect) and to show that channel's title, avatar and subscriber count inside your workspace; upload access to publish videos you created in VidFlow to your own channel when you click Publish. If you use channel-branding push or analytics features, we request those additional YouTube permissions at that moment, and only with your consent.
We store your Google OAuth tokens encrypted and use them solely to act on your behalf at your request. We never see your Google password, never access anyone else's data, and never use Google user data for advertising or sell it. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect a channel anytime from VidFlow settings, or revoke our access at myaccount.google.com/permissions. By connecting a channel you also agree to the YouTube Terms of Service and acknowledge the Google Privacy Policy.
Your rights
Access, export, or delete your data anytime from Settings → Advanced → Export My Data / Delete Account. Object to processing or restrict it. Lodge a complaint with your local data protection authority.
EU/UK residents: GDPR applies. California residents: CCPA applies. We respond to verified requests within 30 days.
Data retention
Account and project data: retained while your account is active and for 30 days after deletion (to allow recovery). Logs: 90 days. Backups: 90 days rolling. Anonymized analytics: indefinite.
Children
The Service is not directed to children under 16. We do not knowingly collect data from minors.
Updates to this policy
We may update this policy. Material changes will be flagged via email and an in-app notice 14 days before effect.
Contact
Email: · Response within 24 hours.