Last updated:
Privacy Policy
How Vidquel collects, uses, stores, and shares personal data.
1. Introduction
AI Video Generator Labs Inc. ("AI Video Generator Labs Inc.", "we", "us", or "our") operates the Vidquel video generation platform (the "Service"), including the website, dashboard, editor, batch campaigns, exports, social publishing integrations, and AI Mentor assistant.
This Privacy Policy explains what personal data we process, why we process it, who we share it with, how long we keep it, and what rights you may have. It is written to reflect the data flows implemented in our application codebase, not a generic template.
By creating an account or using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.
2. Data controller & contact
Controller: AI Video Generator Labs Inc.
Address: [Registered business address — street, city, state/province, postal code, country]
Privacy inquiries: privacy@example.com
Support: support@example.com
If you are in the UK or EEA and require a representative or Data Protection Officer, contact us at the privacy address above. [Add EU/UK representative details if applicable before launch.]
3. Personal data we collect
3.1 Account & identity (our database)
We use Better Auth for authentication, hosted within our own infrastructure. When you sign up or sign in, credentials and session data are processed by our server and stored in PostgreSQL, including:
- Email address and email verification status
- Optional first name, last name, and profile image URL
- Internal user identifier, plan tier, subscription status, and credit balances
- Billing customer identifiers (e.g. Polar customer id)
- Account creation and update timestamps
3.2 Video projects & user content
When you create or edit videos, we store project and scene data you provide or that our pipelines generate on your behalf, including:
- Project titles, prompts (sourcePrompt), template keys, platform settings, and pipeline status fields
- Per-scene scripts, media URLs, narration audio URLs, ordering, and JSON metadata (e.g. subtitles, composition settings)
- Editor timeline revision markers and export state
- Batch campaign names, per-slot labels, and generation payloads (JSON)
- Uploaded or replaced media files (processed via our APIs and stored on Cloudinary when configured)
3.3 AI Mentor (conversational assistant)
If you use AI Mentor, we persist chat threads (conversation title, optional linked project/campaign/export anchors) and messages (role, text content, optional JSON metadata). We may also store a rolling text summary and lightweight preferences in AiMentorUserMemory.
Message content and operational context (including excerpts of project/scene data sent to the planner) are transmitted to Google Gemini when you send prompts, subject to your plan and feature usage.
3.4 Billing & credits
We record subscription state, payment events received via webhooks, and an internal credit ledger (CreditTransaction rows with amounts, reasons, and metadata). Checkout is initiated through Polar.
We do not store full payment card numbers on our servers. Payment instruments are handled by Polar.
3.5 Social publishing (optional)
If you connect a social account, we store OAuth tokens (access and optional refresh tokens), platform type, scopes, display name, and scheduling metadata for posts. Publishing sends video URLs and captions to the relevant platform APIs.
3.6 Technical & usage data
- Server logs, request metadata, and error reports (including Sentry, which may receive request and user-related context when errors occur)
- PostHog analytics (page views and page leave events) when NEXT_PUBLIC_POSTHOG_KEY is configured
- Job queue metadata for exports and campaigns when Redis is configured
- Theme preference in browser localStorage (not sent to our servers unless included in analytics)
4. How we use personal data
- Provide and secure the Service (authentication, authorization, fraud prevention)
- Run AI video pipelines: script generation, TTS, stock media fetch, image generation, FFmpeg/Remotion rendering
- Enforce plan limits (active projects, credits, watermarks per plan catalog)
- Process subscriptions, renewals, and credit refills via billing webhooks
- Operate batch campaigns and export job queues
- Publish content to connected social accounts at your direction
- Provide AI Mentor assistance and improve reliability (monitoring, debugging)
- Comply with law and enforce our Terms
5. Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases:
- Contract — processing necessary to provide the Service you request (account, generation, exports, publishing you initiate)
- Legitimate interests — security, abuse prevention, product analytics, service improvement, and internal reporting, balanced against your rights
- Consent — where required for non-essential cookies/analytics or certain marketing (implement consent tooling before relying on this basis in the EEA/UK)
- Legal obligation — tax, accounting, or regulatory requirements
6. AI & automated processing
The Service uses third-party AI and media APIs to transform your prompts and scripts into scripts, speech, images, and video. Depending on configuration and template, inputs may be sent to Google Gemini, OpenAI, ElevenLabs, xAI/Grok, Pexels, Pixabay, and Cloudinary.
Outputs may be inaccurate, incomplete, or unsuitable for your use case. You are responsible for reviewing outputs before publication. We do not guarantee that AI-generated content is non-infringing, factual, or free of bias.
AI Mentor plans are produced by automated models; tool execution on your account only occurs when you enable "Allow actions" and the action is permitted for your template.
8. International transfers
We and our processors may process data in the United States and other countries. Where required, we use appropriate safeguards such as Standard Contractual Clauses or UK IDTA addenda. Contact us for a copy of relevant transfer mechanisms.
9. Data retention
When you delete your account, we delete the User row in our database, which cascades to related sessions, projects, campaigns, posts, and other linked records per our schema.
- Account data — retained while your account is active and for a reasonable period afterward for billing, disputes, and legal compliance
- Projects, scenes, exports, and campaign records — retained until you delete them or delete your account, subject to backup cycles
- Mentor conversations — retained until you delete threads or your account; summaries may persist in AiMentorUserMemory until cleared
- Billing webhooks & ledger — retained as needed for accounting and fraud investigation (typically multi-year where required by tax law)
- Cloudinary media — retained until replaced or deleted through our deletion flows; prior public IDs may persist in backups
- Logs & Sentry events — rolling retention per provider defaults unless configured otherwise
10. Security
We use industry-standard measures including HTTPS, authenticated APIs, hashed password storage, webhook signature verification (Polar), and access controls on dashboard routes. No method of transmission or storage is 100% secure.
11. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object, port data, and withdraw consent. You may also lodge a complaint with a supervisory authority.
- Email privacy@example.com to exercise rights (we may verify identity via your account login)
- Use dashboard settings and editor controls to update or delete projects where available
- Disconnect social accounts to revoke tokens stored for publishing
- Cancel subscriptions via Polar/customer portal links provided at checkout (when available)
12. Children
The Service is not directed to children under 16 (or the age required in your country). We do not knowingly collect children’s data. Contact us if you believe a child has provided data.
13. Changes
We may update this Policy. We will post the new date at the top of this page. Material changes may be notified by email or in-app notice where appropriate.
14. Contact
AI Video Generator Labs Inc.
[Registered business address — street, city, state/province, postal code, country]
Email: privacy@example.com
