Updated 2026-09-09
Privacy Policy
This policy explains what Vujo.ai collects, why we collect it, who processes it on our behalf, how long we keep it, and how to export or erase it.
DRAFT — NOT LEGAL ADVICE
This page is a working draft written by the product team, not a lawyer. Items marked [VERIFY] are placeholders the owner must confirm before launch; the wording has not been reviewed for legal sufficiency in any jurisdiction.
1. What we collect
- Account data: your email address, name (if you provide one), password hash (scrypt, salted — we never store the password) or Google identity, and whether you have confirmed your address.
- Workspace content: channels, topics, videos, scripts, uploaded media, brand assets and generated graphics.
- Billing data: your Stripe customer and subscription identifiers, invoices and refunds. Card details never reach our servers — Stripe handles them.
- Usage and credit ledgers: how many credits you were granted and spent, exports, storage used, and the provider cost of each generation (for margin reporting).
- Operational logs: request ids, timings and error details. Log lines redact secrets by construction.
2. Why we collect it
- To provide the service you asked for (contract).
- To take payment, prevent fraud and keep accounting records (contract and legal obligation).
- To keep the service safe and reliable: rate limits, abuse prevention, error diagnosis (legitimate interests).
- To measure the landing page, only after you consent (consent — you can withdraw it at any time).
3. Who processes it
We use the following processors. Each receives only what it needs:
- Stripe — Payments, subscriptions, invoices, refunds, tax handling [VERIFY: DPA signed + data region]
- PostgreSQL hosting — Application database (accounts, workspaces, videos, ledgers) [VERIFY: provider + region]
- S3-compatible object storage — Uploaded media, renders, brand assets [VERIFY: provider + region]
- Redis — Job queue and rate limiting (no customer content) [VERIFY: provider + region]
- AI model providers — Script, voiceover, image and video generation on your behalf [VERIFY: the exact provider list this deployment uses]
- Plausible Analytics — Privacy-friendly landing-page analytics — loaded ONLY after you consent [VERIFY: self-hosted or cloud]
- Stock media providers — Licensed footage and images used in your videos [VERIFY: provider list]
[VERIFY] A signed Data Processing Agreement and the exact sub-processor list (names, purposes, regions) must be confirmed by the owner before launch.
4. How long we keep it
- Account and workspace content: until you delete your account.
- Financial records (credit ledger, provider cost ledger, subscription and usage rows): retained after deletion in anonymised form, because accounting and tax rules require it.
- Operational logs: a short, fixed window. [VERIFY: retention period]
[VERIFY] Retention periods and the legal basis for each category must be confirmed by the owner.
5. Your rights
You can download everything we hold about you as a JSON file from Settings → Account ("Download my data").
You can delete your account from the same page. Deletion is immediate: workspace content and stored media are removed, and the account row is anonymised (no email, name, image, password or Google identity). Financial records survive in anonymised form.
Depending on where you live you may also have the right to correct data, object to processing, or complain to a supervisory authority.
6. Cookies and analytics
The application uses one strictly-necessary cookie to keep you signed in, and one to remember whether you prefer the light or dark theme.
Landing-page analytics (Plausible) is OFF by default and only loads after you press "Accept" on the consent banner. Declining leaves the site fully functional.
7. Contact
Questions, access requests or complaints: [email protected].
[VERIFY] Data-protection contact / DPO and the EU or UK representative (if required) must be supplied by the owner.