Privacy Policy
Last updated: September 10, 2026
1. What we collect
We collect the minimum data needed to run the Service:
- Account data: email address, name (optional), password hash (bcrypt), Google account ID, or Apple account identifier and private relay email if you use those sign-in methods.
- Content data: YouTube URLs you submit, audio/video files you upload, derivative transcripts, summaries, learning notebooks, review progress, and video frames generated from your uploaded videos, plus the chunks and embeddings used for search and chat.
- Udemy preview imports: lecture URLs, course and lecture identifiers and titles, and available timed captions that you review and explicitly choose to import. Imported captions and generated notes are linked to your account under the same content retention and deletion controls.
- YouTube comment data: when you request comment analysis, VidBrief retrieves a sample of public top-level comments, excludes commenter identity fields, and stores a limited set of representative excerpts and VidBrief-generated findings for up to seven days.
- Subscription data: subscription tier, product, status, period dates, and provider transaction identifiers. Apple and Stripe process payment credentials; VidBrief never receives full card numbers.
- Usage data: anonymized event logs (page views, button clicks) via PostHog. IP addresses are stored only transiently for rate-limiting.
- Integrations: Notion integration secret and database ID (if you connect Notion); Discord webhook URL (if you connect Discord); Google OAuth tokens and IDs of Google Docs created by VidBrief (if you connect Google Drive). These are stored encrypted at rest.
2. How we use it
- Operate the Service: process videos, run AI summaries, analyze public audience comments when requested, and build your personal knowledge base.
- Provide account support and notifications (welcome email, payment-failed reminders, channel-subscription alerts).
- Provide and synchronize paid access purchased through Apple or Stripe.
- Aggregate anonymized usage analytics to improve the product. We do not sell personal data.
In the iOS app, VidBrief asks for explicit permission before a video link, transcript, or question is processed by third-party AI or transcription providers. Declining this permission leaves non-AI account and subscription controls available.
3. Who we share data with
We use a small set of subprocessors, each with their own security commitments:
- Vercel — hosting, serverless functions, and private Blob storage for video frames generated from user uploads (US data center).
- Neon — Postgres database (US-East).
- Stripe — payment processing.
- Apple — App Store distribution and in-app subscription billing.
- RevenueCat — subscription purchase status and entitlement synchronization across platforms.
- Resend — transactional email.
- PostHog — product analytics (US-hosted; events are pseudonymized).
- DashScope (Alibaba) — Paraformer audio transcription and embedding model. Audio is sent transiently and not retained by DashScope per their API terms.
- DeepSeek — LLM for summary, outline, chat, and requested comment analysis. Transcripts or sampled public comment text are sent transiently.
- Anthropic / OpenAI — optional LLM providers used in some code paths.
- YouTube and Google — public video metadata, captions, and requested public comment samples are fetched through YouTube services, including the YouTube Data API. Use of these features is also subject to the YouTube Terms of Service and Google Privacy Policy.
- Google Drive and Google Docs — optional export destination. VidBrief requests the narrow
drive.filepermission and can access only files it creates or that you explicitly share with it.
We never sell your data. We disclose data only when legally required by valid court order.
4. Cookies
We use a session cookie for authentication (set by NextAuth) and a small set of first-party analytics cookies via PostHog to count visits and feature usage. We do not use third-party advertising cookies.
5. Chrome extension
The VidBrief Chrome extension supports YouTube watch pages and an account-gated preview on Udemy course learning pages. On YouTube, it reads the current YouTube video ID and title so it can request a summary, show an outline, and seek the player when you click a timestamp. It checks the active tab in the panel's browser window to follow supported videos. It does not collect unrelated browsing history, form entries, or private messages from the pages you visit.
In the Udemy private preview, bundled extension scripts read available timed captions and metadata from an individual lecture you can already access. You review the content locally and explicitly confirm before importing it to VidBrief over HTTPS. Imported captions are processed by the AI and embedding providers listed above to create summaries, learning notes, and search results. The extension does not collect Udemy passwords or cookies, download video or audio, bypass DRM, or capture Udemy video screenshots. Udemy preview access is limited to enabled accounts; owning the extension does not grant access to Udemy courses.
Connecting the extension opens a VidBrief authorization page. After you approve, the extension stores a revocable session token in Chrome extension storage; it never receives or stores your password. Requests, selected video URLs, chat questions, and generated answers are sent to VidBrief over HTTPS to provide the features you request. We do not use extension data for advertising or sell it to third parties.
6. Your rights
- Access — see every video, transcript, and summary tied to your account from your dashboard.
- Export — download any summary as Markdown / push to your own Notion / Obsidian.
- Delete — permanently delete your account and account-linked content from the mobile app. You may also contact us for assistance; required accounting records are anonymized or retained only as required by law.
- EU/UK residents (GDPR) — you also have rights to rectification, portability, and to lodge a complaint with a supervisory authority.
7. Data retention
Account-linked data is retained while your account is active. If you cancel and the account is unused for 6 months, we may delete inactive data after notice. Backup snapshots are rolled-over within 30 days.
Uploaded source files sent for transcription remain transient. If an upload contains video, VidBrief may retain a limited private storyboard of derivative JPEG frames for learning notes. These frames are removed when the last account link to that uploaded video is deleted.
Public YouTube comment samples and their cached VidBrief analysis expire after seven days. Expired comment excerpts and analysis are deleted automatically. Refreshing an analysis replaces the previous sample. VidBrief does not store commenter names, profile images, or channel identifiers for this feature.
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest (Neon AES-256). Passwords are hashed with bcrypt. Third-party tokens (Notion, Discord) are encrypted in the database. We follow least-privilege access for production credentials.
9. Children
The Service is not directed at children under 13. We don't knowingly collect their data.
10. Changes
Material changes to this policy will be announced via email or an in-app notice at least 14 days before they take effect.
11. Contact
Questions or privacy requests: contact@zczy318.com.
See also: Terms of Service.