Legal
Privacy policy
The short version. We ask for your email address so you can sign in and so we can tell you when your clips are ready. The video you upload is processed on our server and deleted the moment your clips are rendered. The finished clips are deleted after 30 days (7 days on the free plan). We do not sell data, we do not run advertising, we do not use third-party analytics or tracking SDKs, and this website sets no cookies at all. The website counts visits with analytics we host ourselves, with no cookies and no cross-site tracking (see section 12).
1. Who we are
The Video To Reel privacy policy is a statement of exactly what Video To Reel collects from you, why, and how long each thing is kept. Video To Reel asks for 1 piece of personal data at sign-up: your email address, used to sign you in with a six-digit code and to tell you when your clips are ready. The video you upload is processed on our servers and deleted the moment your clips finish rendering, together with every intermediate file. Finished clips are deleted after 30 days on a paid plan and after 7 days on the free plan. Video To Reel sells no data, runs no advertising and embeds no third-party analytics or tracking SDKs, and videotoreel.com sets no cookies at all. The data controller is Neu Software LLC (Delaware, United States), and this policy is written to the GDPR standard and applied to everyone, wherever they are.
Video To Reel is operated by Neu Software LLC (Delaware, United States). We are the data controller for the personal data described here. Because the service is offered in the EU, this policy is written to the standard of the EU General Data Protection Regulation (GDPR), and we apply the same protections to you wherever you are.
You can reach us about anything in this policy at support@videotoreel.com.
2. What we collect and why
Your email address
Signing in creates an account keyed to your email address. We send a six-digit code to that address to verify it, and we use the address to answer support requests and, rarely, to send a service message (for example, that a job failed or that a plan lapsed). We do not send marketing email.
The videos you upload
A video you upload is stored on our processing server only while the job runs. When the clips are rendered, the source file and every intermediate file made from it are deleted from disk immediately. That deletion is part of the job, not a nightly clean-up. If a job fails or you abandon an upload, the file is removed by a sweep that runs at least every 24 hours.
Whatever is in your video, from faces to voices to the things people say, is content you have given us to process on your instruction. We do not watch it, use it to train models, or share it with anyone beyond the processors listed below.
We also store a one-way fingerprint (a SHA-256 hash) of files uploaded on the free plan. It cannot be turned back into your video; its only purpose is to stop the same file being run as a free video over and over on new accounts.
What we derive from your video
- A transcript with word-level timings, produced on our own server by a speech-recognition model that runs locally. It is kept for as long as your clips exist so that re-rendering a clip does not require transcribing the video again.
- Short source-quality segments ("mezzanines") around each selected moment, kept for the same period, so you can trim or restyle a clip after the source file is gone.
- The finished clips themselves, plus the quote each was cut around and its timestamps.
Account and usage data
- Subscription state: which plan you are on, when the period started and ends, and how many minutes you have used. Payments happen inside Google Play or the App Store; we never see your card details.
- First-party product events: a small append-only log of things like "upload started", "job finished", "clip saved", written to our own database. It is used to see what is breaking and what people use. There is no third-party analytics SDK in the app, no advertising identifier, and no cross-app or cross-site tracking.
- A push notification token for each device you enable notifications on, so we can tell you when a render is done.
- Technical logs: request logs and crash reports containing IP address, device model, OS version and error details. These are kept short-term for security and debugging.
3. Legal bases
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email, account record | Sign-in, account, support | Contract, Art. 6(1)(b) |
| Uploaded video, transcript, mezzanines, clips | Producing the clips you asked for | Contract, Art. 6(1)(b) |
| Subscription state, minutes used | Enforcing plan limits, billing reconciliation | Contract, Art. 6(1)(b); legal obligation for accounting records, Art. 6(1)(c) |
| Push token | Telling you a render finished | Consent (the OS permission prompt), Art. 6(1)(a) |
| Product events, logs, crash reports, upload fingerprints | Keeping the service working, preventing abuse of the free video | Legitimate interests, Art. 6(1)(f) |
4. How long we keep things
| What | Kept for |
|---|---|
| The video you uploaded | Deleted immediately after your clips finish rendering. Failed or abandoned uploads are swept within 24 hours. |
| Finished clips | 30 days on a paid plan, 7 days on the free plan, then deleted from storage. Clips you saved to your phone are unaffected. |
| Transcript and mezzanine segments | The lifetime of the clips they belong to; deleted with them. |
| Account record and email | Until you delete your account. |
| Subscription and billing records | Kept in anonymised form after account deletion for as long as applicable tax and accounting law requires (up to seven years). |
| Product events | Up to 24 months, and retained only in a form no longer linked to your email or any other identifying detail once your account is deleted. |
| Server logs and crash reports | Up to 90 days. |
| Free-plan upload fingerprints | Up to 12 months, purely to enforce the monthly free video per person. |
5. Who processes data for us
These are our sub-processors. Each is bound by a data processing agreement, each only receives what the column says, and none of them is permitted to use your data for their own purposes.
| Processor | What it does | What it can see | Where |
|---|---|---|---|
| Hetzner Online GmbH | Hosting: the server that runs the API, the database and the render pipeline | Everything, while it is being processed: your uploads, transcripts, clips and account record | Germany (EU) |
| Cloudflare, Inc. | R2 object storage and delivery of finished clips; DNS and TLS for our domain | Your finished clips and the request metadata needed to serve them | EU storage region; global network |
| OpenRouter, Inc. | Routes one request per job to a large language model that chooses which moments to cut | Transcript text and timings only. No video, no audio, no email address, no account identifier | United States |
| Google Ireland Ltd. (Firebase Cloud Messaging) | Delivers push notifications to your device | Your device push token and the notification text ("Your 3 clips are ready") | EU / United States |
| Functional Software, Inc. (Sentry) | Crash and error reporting for the app and the server | Error details, device and OS information, IP address, an account identifier | EU region (Frankfurt) |
Google is also the seller of the subscription in its own right, so that part of the transaction is governed by Google's own privacy policy. We verify your purchase directly with Google Play using the receipt your device hands us, and receive back only the plan, its status and its renewal date. No card details ever reach us, and no third party sits between us and the store.
6. Automated moment selection
Choosing which moments become clips is done by a language model, called once per job through OpenRouter. It receives the timestamped transcript text and the number of clips you asked for, and returns the segments to cut. It does not receive the video, the audio, your email address or any account identifier, and its output is validated against your video's own word timings before anything is rendered. If the model is unavailable or returns something invalid, a plain algorithm on our own server picks the moments instead.
No decision with a legal or similarly significant effect on you is made by automated means.
7. International transfers
Your uploads and clips are stored in the EU. Two processors, OpenRouter and (for some traffic) Google, process limited data in the United States. Those transfers are made under the European Commission's Standard Contractual Clauses, or under the EU-US Data Privacy Framework where the processor is certified, together with the technical measures described above (in OpenRouter's case, transcript text with no identifiers attached).
8. Security
- Everything travels over TLS; clips are served through private links that expire.
- Uploads are isolated per account and are never listed or browsable by other users.
- Source files live on encrypted disk for minutes, not months, and are deleted as part of the job that created the clips.
- Access to production systems is limited to the people who operate the service.
- If a breach ever affects your personal data, we will notify the competent supervisory authority within 72 hours and tell you directly where the law requires it.
9. Your rights
Under GDPR you have the right to:
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate data corrected.
- Erasure: have your data deleted. The next section explains how to do it yourself.
- Restriction: ask us to pause processing while a dispute is resolved.
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on our legitimate interests.
- Withdraw consent: turn off notifications at any time, in the app or in your OS settings.
Email support@videotoreel.com to exercise any of these. We answer within 30 days and we do not charge for it. If you are not satisfied and you are in the EU, you may complain to the data protection supervisory authority of your own country.
10. Deleting your account
You can delete your account in two places, and both do exactly the same thing:
- In the app: Account → Delete account.
- On the web: videotoreel.com/delete-account. Verify your email with a six-digit code and confirm.
Deletion removes your uploads, your clips and their stored files, your transcripts and mezzanines, and your push tokens, and it detaches your email address from the account record immediately. What remains is a stripped, anonymised record of the subscription for accounting purposes. It cannot be undone, and the clips are gone, so save anything you want first.
Your subscription itself lives in Google Play or the App Store: deleting your Video To Reel account does not cancel it, and those stores keep their own billing records regardless of what we delete. Cancel the subscription in the store before deleting the account.
11. Children
Video To Reel is not directed at children. You must be at least 16 (or the age of digital consent in your country, if lower) to have an account. If we learn that an account belongs to a child below that age, we delete it.
12. Cookies and this website
This website sets no cookies. It measures visits with Umami, an open source analytics tool that we run on our own server (not a third party service): it uses no cookies, stores no advertising identifiers, does not follow you across other sites, and keeps only aggregate counts such as page views, referrers and country. Beyond that one measurement script from our own infrastructure, pages here embed no third-party scripts and load no fonts or images from other domains. The only other network request any page makes is on the account deletion page, which talks directly to our own API to verify your email and delete your account.
13. Changes
If this policy changes we will update the date at the top, and for anything material we will tell you in the app before it takes effect. Past versions are available on request.
14. Contact
Neu Software LLC (Delaware, United States)
support@videotoreel.com
We have not appointed a Data Protection Officer, because we are not required to, so privacy questions go to the address above and are answered by the people who run the service.