Last updated: 15 September 2026

Privacy Policy

What we collect, why we collect it, and who else gets to see it.

This is our own plain-English agreement; if you need a lawyer's review before relying on it, get one.

1. The short version

We collect the least we can and still run the product: your email address, what you ask us to turn into a video, and the videos we make from it. We do not sell your data, we do not share it with advertisers, we run no analytics or advertising cookies, and we do not use your content to train our own models. Your brief and your script are sent to the AI providers in section 5, because that is how a video gets made. If you connect a social account, its tokens are encrypted and used only to post what you asked us to post.

2. What we collect

  • Account — your email address, and your name and profile picture if you sign in with Google. No password: sign-in is a magic link or Google.
  • What you submit — prompts, scripts, article and video URLs you ask us to read, PDFs and photos you upload, the topics and feeds behind an Auto-Mode schedule, and the settings you pick.
  • What we generate — the script, the scene images and clips, the narration audio, the captions and the finished MP4, plus the brief a video was remixed from.
  • Billing — your plan, your credit balance, and a credit ledger of every deposit, settlement and refund. Subscriptions are handled by Stripe, which gives us a customer id and a subscription status. We never see your card number.
  • Connected social accounts — the platform, your account id and display name, the scopes you granted, the token expiry, and the access and refresh tokens themselves. The tokens are encrypted before they are written and decrypted only in the moment a post is made; a database read does not yield a usable credential.
  • Publishing — which video went to which platform and when, the platform's post id, and the view, like, comment and share counts we read back about six-hourly.
  • API keys — a name, the first few characters, and a SHA-256 hash. The key itself is shown once and stored nowhere, so we cannot recover it and nor can anyone reading the database.
  • Technical — ordinary server logs from our host: IP address, user agent, path and status, kept for security and debugging.

3. Why we use it

To generate your videos; to keep your account, plan and credit balance correct; to take payment and prevent abuse of the credit system; to publish to the accounts you connected and show you how those posts did; to email you about your own account and your own videos; and to find and fix what breaks. That is the entire list. We do not build profiles, we do not run behavioural advertising, and we do not sell or rent anything to anyone.

Where the law asks for a lawful basis: most of it is performance of the contract between us, security and abuse prevention are our legitimate interests, and keeping invoices is a legal obligation.

4. Who else sees it

Veedio is assembled from other people's services, and each one gets only what it needs to do its job. The optional rows are only ever called if that feature is switched on for your account.

  • SupabaseAccounts, sign-in, the database, and file storage for your videos and scene assets
  • VercelHosting, request routing and server logs
  • StripeCheckout, subscriptions and invoices. Card details go to Stripe, never to us
  • ResendTransactional email: the welcome email, video-ready and video-failed notices
  • fal.aiThe script model, scene images, motion clips, sound effects and presenter scenes. Receives your brief, script, image prompts and — for a presenter scene — the narration audio
  • ReplicateAn alternative to fal.ai for the same visual work, where configured
  • ElevenLabsNarration. Receives your script text and returns audio and word timings
  • HeyGenPresenter scenes, where this deployment is configured to use it rather than fal.ai. Receives the narration and returns a lip-synced avatar clip
  • PexelsStock-footage scenes only. Receives a two-to-four word search query, nothing else
  • TikTok, Instagram (Meta) and YouTube (Google)Only when you connect an account: your video, its caption, and the post stats we read back
  • YouTube Data APIDiscovery and the trending pages. Receives a search term, never anything about you

These providers are mostly in the United States, so using Veedio means your data is processed there and in the other countries our providers operate from. We will also disclose data where the law genuinely requires it, and if the business is ever sold the new owner takes it on under this policy.

5. AI providers, and what they get

Making a video means sending your material out. Your brief goes to the script model; each scene's text and image prompt goes to the image and motion models; the narration text goes to ElevenLabs; a stock scene sends a short search query to Pexels; a presenter scene sends the finished narration audio to the avatar model (fal.ai, or HeyGen where this deployment is configured for it). We do not send your email address or your account id with any of it.

We do not use your content to train models, and we ask the same of our providers — but their own terms govern what they do with what they receive, so read them if your material is sensitive, and do not paste confidential information into a video brief.

6. Where your files live

Rendered videos and scene assets are stored in Supabase Storage and served from a long, effectively unguessable public URL, because that is what a video player and the social platforms need in order to fetch the file. It is not listed or indexed anywhere — but treat the link as the secret it is: anyone you send it to can watch the video.

Nothing you make is public on this site unless you ask for it. We only feature a video in our showcase or marketing when you have marked it public or told us we can, and you can withdraw that at any time.

7. How long we keep it

  • Videos and assets — until you delete them or close the account. Deleting a video removes its stored files as well as its row.
  • Social tokens — until you disconnect the account, which deletes them, or until you revoke us on the platform.
  • API keys — revoking one marks it dead immediately; the hash is kept so the key can never be re-used or reissued.
  • Publication records and post stats — kept with the video, and deleted with it. Deleting here does not remove a post from the platform; do that there.
  • Billing records — kept as long as tax and accounting rules require, which is longer than the account lives.
  • Server logs — a short rolling window, set by our host.

8. Cookies

Session cookies only — the ones that keep you signed in and protect the sign-in flow. There are no analytics cookies, no advertising cookies and no third-party trackers on any page of this site, which is why there is no cookie banner. Your theme preference is kept in your browser's local storage and never sent to us.

9. Your rights

You can see and change your account details in Settings, read your whole credit history on the billing page, delete any video from its editor, and disconnect any social account in one click.

For anything else — a copy of your data, a correction, or deletion of your account and everything attached to it — email hello@veedio.co from the address on the account. We will do it within 30 days and confirm when it is done; deletion is permanent and takes your videos with it. Depending on where you live you may also have rights to object to or restrict processing, or to complain to your data protection authority.

10. Children

Veedio is for adults. You must be 18 or older to hold an account, and the service is not directed at children. We do not knowingly collect anything from a child; if you believe a child has an account here, email us and we will delete it.

11. Changes, and who to ask

If we change this policy in a way that matters — a new processor, a new category of data — we will email account holders before it takes effect, and the date at the top of this page always tells you when it last moved. Questions, requests and complaints all go to hello@veedio.co, and a person reads them.

Questions? Email hello@veedio.co — or read the terms of service.