Privacy Policy

Last Updated: October 9, 2025

1. Introduction

Welcome to Video Summary Autopilot ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, name (optional), password
  • Profile Information: Profile picture, preferences, notification settings
  • YouTube Connection: OAuth tokens to access your YouTube subscriptions

2.2 Automatically Collected Information

  • Usage Data: Pages visited, features used, time spent on the service
  • Device Information: Browser type, operating system, IP address
  • Cookies: Session cookies, preference cookies (see Cookie Policy below)

2.3 Information from Third Parties

  • YouTube Data: Your subscribed channels, video metadata (titles, descriptions, thumbnails)
  • AI Processing: Video summaries generated by OpenAI's GPT models

3. How We Use Your Information

We use your information to:

  • Provide and maintain our service
  • Generate personalized video summaries from your YouTube subscriptions
  • Send you daily digest emails with video summaries
  • Improve and optimize our service
  • Communicate with you about updates, security alerts, and support
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

4. Data Sharing and Disclosure

4.1 We Share Your Information With:

  • Service Providers: AWS (file storage), Supabase (database), OpenAI (AI processing), Resend (email delivery)
  • YouTube API: To access your subscribed channels (with your explicit consent)
  • Legal Requirements: When required by law or to protect our rights

4.2 We Do NOT:

  • Sell your personal information to third parties
  • Share your data with advertisers
  • Use your data for purposes other than providing our service

5. Data Retention

We retain your information for as long as your account is active or as needed to provide our service:

  • Account Data: Until you delete your account
  • Video Summaries: 180 days (configurable)
  • Email Digests: 90 days
  • Usage Logs: 30 days
  • Audit Logs: 2 years (for security and compliance)

6. Your Rights (GDPR & CCPA)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Data Portability: Export your data in a machine-readable format
  • Withdraw Consent: Revoke consent for data processing at any time
  • Object: Object to processing of your data for certain purposes

To exercise these rights, visit your Settings → Data page or contact us at privacy@videosummaryautopilot.com.

7. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (TLS/SSL) and at rest
  • Secure authentication with bcrypt password hashing
  • Row-level security (RLS) in our database
  • Regular security audits and monitoring
  • Rate limiting and DDoS protection

8. Cookie Policy

We use the following types of cookies:

  • Necessary Cookies: Essential for authentication and security (always enabled)
  • Analytics Cookies: Help us understand how you use our service (optional)
  • Marketing Cookies: Used for promotional content (optional)

You can manage your cookie preferences at any time through the cookie banner or in your browser settings.

9. Third-Party Services

9.1 YouTube API Services

Our service uses YouTube API Services. By using our service, you agree to be bound by the YouTube Terms of Service. You can revoke our access to your YouTube data at any time through the Google security settings page.

9.2 OpenAI

We use OpenAI's GPT models to generate video summaries. Video metadata (titles, descriptions) is sent to OpenAI for processing. OpenAI's data usage policy applies. We do not send any personal information to OpenAI.

10. Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable data protection laws.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@videosummaryautopilot.com
  • Data Protection Officer: dpo@videosummaryautopilot.com

14. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

  • Consent: You have given explicit consent (e.g., YouTube OAuth)
  • Contract: Processing is necessary to provide our service
  • Legitimate Interests: To improve our service and prevent fraud
  • Legal Obligation: To comply with applicable laws