VEDEO · Legal

Privacy Policy

Last updated: September 2026

VEDEO turns a written idea into a finished short video. This policy explains what we collect to do that, who processes it on our behalf, how long we keep it, and the choices you have.

This is our current published policy. It describes how the service actually works today; we update it when the service changes, and the date above always reflects the latest revision.

What we collect

We collect only what the service needs to operate. There is no advertising network behind VEDEO and we do not buy or sell personal data.

  • Account details — your email address and, if you provide one, a display name. Your password is never stored; we keep only a cryptographic hash of it.
  • Content you create — the ideas and prompts you write, the generation settings you choose, and the videos produced from them.
  • Generation records — what was requested, which stage a render reached, and any error, so we can support you and diagnose failures.
  • Billing records — your subscription state, credit balance and transaction history. Card details are handled entirely by our payment processor and never reach our servers.
  • Operational data — the time you last signed in, a hashed form of the network address a session was created from, and your browser's user-agent string, used to secure your account.

How we use it

  • To operate your account and keep you signed in.
  • To generate the videos you ask for, and to deliver them back to you.
  • To meter and account for credits, and to process subscriptions and purchases.
  • To prevent abuse — rate limiting, suspending accounts that break our Acceptable Use policy, and protecting the service from automated misuse.
  • To diagnose faults and improve reliability.

We do not use your prompts or generated videos to train our own models, and we do not publish your work. The example videos on our marketing pages are our own demonstrations, never customer content.

How AI processing works

Generating a video is a pipeline, and different stages involve different specialist providers. Understanding where your text goes matters, so here is the actual sequence:

  • Script — your idea, together with the creative direction implied by the style you picked, is sent to a large language model provider, which returns a script.
  • Narration — the script text is sent to a speech synthesis provider, which returns spoken audio.
  • Footage — short search terms derived from the script are sent to stock media libraries, which return clips. Your original prompt is not sent to these libraries.
  • Captions and composition — subtitle timing, music and the final render happen on our own rendering infrastructure. No third party is involved in this stage.

Only the text needed for a stage is sent to that stage's provider. Your email address, account identifier and billing details are never sent to any AI or media provider — those providers receive content, not identity.

Outputs from generative systems can be inaccurate. Review anything you intend to publish; you remain responsible for the content you post.

Who processes data for us

We use a small number of specialist providers to run VEDEO. Each is bound by a contract limiting them to processing data on our instructions. We describe them by role rather than by name because the specific vendor in a role can change; the roles, and the data each receives, do not.

RoleWhat it receivesWhy
Cloud hosting providerAll application and rendering data, in transit and at restRuns the application, the rendering service and its file storage
Managed database providerAccount, project, generation and billing recordsStores the platform's structured data
Payment processorYour email address and payment detailsTakes payment and manages subscriptions
Email delivery providerYour email address and message contentsSends transactional email such as password resets
Language model providerYour prompt and creative directionWrites the script
Speech synthesis providerThe generated script textProduces the narration audio
Stock media librariesShort search terms derived from the scriptSupply the footage

We keep an internal register of the specific providers filling each role and will tell you which they are on request. Business customers who need advance notice of changes should see our Data Processing Addendum.

How we protect it

  • Passwords are hashed with Argon2id — a memory-hard algorithm chosen to resist offline cracking — and combined with a server-side secret that is never stored in the database, so a database copy alone is not enough to attack them.
  • Sessions are opaque random tokens held in an HttpOnly, Secure, SameSite cookie. Only a hash of each token is stored, so session records cannot be replayed if the database is exposed.
  • All traffic is encrypted in transit. Our rendering service is not reachable from the public internet at all; it accepts requests only from the application over a private network, authenticated with a service credential.
  • Your browser never contacts the rendering service directly. Video downloads are proxied through the application, which verifies you own the file before streaming a single byte.
  • Sign-in, registration and video generation are rate limited, and we can suspend an account immediately if it is being abused.
  • Administrative access is restricted and audited, and administrative views exclude credential material by design.

How long we keep it

  • Account and billing records are kept while your account is open, and afterwards only as long as we are required to for tax and accounting purposes.
  • Your projects and finished videos are kept until you delete them or close your account.
  • Intermediate render working files — the audio, subtitle and clip fragments produced while composing a video — are cleaned up on a rolling retention window. Finished videos are deliberately excluded from that cleanup so they are not removed from under you.
  • Credit ledger entries are immutable and retained as a financial record; corrections are made by adding new entries, never by editing history.
  • Sessions expire automatically, and are destroyed immediately when you sign out, sign out everywhere, or change your password.

International transfers

Our infrastructure is operated in the United States, and some of the providers described above operate in other countries. Where personal data is transferred out of the United Kingdom or European Economic Area, we rely on Standard Contractual Clauses (and the UK Addendum where applicable) together with the safeguards described in the security section.

Your rights and choices

  • Access — ask for a copy of the personal data we hold about you.
  • Correction — update your display name from your account page at any time.
  • Deletion — delete individual projects and videos, or request that your account and its content be removed entirely.
  • Portability — download any video you have generated, at any time, from your project page.
  • Objection and restriction — ask us to stop or limit a particular use of your data.
  • Complaint — raise a concern with your local data protection authority.

Contact us through the support address published at vedeo.studio and we will respond within one month.

Cookies

VEDEO sets one cookie: the session cookie that keeps you signed in. It is strictly necessary for the service to work, it is not used for advertising or cross-site tracking, and we run no third-party advertising or analytics trackers. Your browser may also store a draft of an idea you typed on the homepage, so it survives sign-up — that stays in your browser and is cleared once the draft is used.

Children

VEDEO is not intended for children under 13, and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will remove it.

Changes to this policy

When we change this policy we update the date at the top of this page. If a change materially affects how we handle your data, we will tell you directly rather than relying on you to notice.