This policy describes how VidiScoop handles personal data. It is a plain-language document and not legal advice; if you operate VidiScoop yourself or in a regulated market, have it reviewed against the law that applies to you before you rely on it.
1. What we collect
We keep the collection deliberately small. There are three categories:
Account data
- Your name and email address, supplied at sign-up.
- A cryptographic hash of your password. We never store the password itself and cannot recover it.
- Session records — a random token, its creation and expiry times.
Workspace data
- Channels you create: name, niche description, keywords, language, region, sections, custom feed URLs and score thresholds.
- Scan results cached for up to 24 hours, and video packages you generate and save.
- Settings, including which AI provider you selected and, if you supplied them, provider API keys.
Operational data
- Standard server logs, which may include IP address, user agent, request path and timestamp, kept for a short period for security and debugging.
We do not collect payment card details directly. If you subscribe to a paid plan, the payment processor handles card data under its own policy and we receive only the subscription status and the billing identifiers needed to operate your account.
2. Why we process it
| Purpose | Data used | Basis |
|---|---|---|
| Providing the service | Account and workspace data | Performance of a contract |
| Keeping accounts secure | Session records, server logs | Legitimate interest |
| Support you have asked for | Account data, what you tell us | Legitimate interest |
| Billing a paid plan | Email, subscription identifiers | Performance of a contract |
| Legal obligations | As required | Legal obligation |
3. What we do not do
- We do not sell personal data, and we do not share it with data brokers.
- We do not use your channels, scans or packages to train machine-learning models.
- We do not run advertising trackers or third-party analytics profiling on the product.
- We do not send marketing email you did not ask for.
4. Third parties
Delivering the service involves a small number of external services. What leaves our systems, and to whom, is limited to the following:
- News sources. Scans request publicly available RSS and news feeds. Those requests come from our servers and carry no information about you.
- Your AI provider. If you add a key for Gemini, Claude, OpenAI or OpenRouter, story text and your channel’s niche description are sent to that provider to produce rankings and packaging. That request happens under your own provider account and is governed by that provider’s terms and privacy policy.
- YouTube Data API. If you enable competition checks, story search terms are sent to Google using the key you supply.
- Hosting and payments. Infrastructure and payment providers process data strictly on our instructions in order to run and bill the service.
5. How long we keep it
- Cached scans: automatically expire 24 hours after they are saved.
- Saved packages and channels: until you delete them or close your account.
- Account data: for as long as the account exists, then deleted within 30 days of closure except where we must keep records for legal or accounting reasons.
- Server logs: a short rolling window, typically no more than 30 days.
6. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to processing, receive it in a portable format, and complain to a supervisory authority. Most of these you can exercise directly in the product — channels, packages and settings are editable and deletable at any time.
For anything you cannot do yourself, email hello@vidiscoop.com and we will respond within 30 days.
7. Cookies
We use one cookie: the session cookie that keeps you signed in. It is HttpOnly, SameSite=Lax, marked Secure in production, and expires after 30 days or when you log out. There are no advertising or analytics cookies, which is why you are not being asked to accept anything.
8. Security
Passwords are hashed with scrypt and a per-user salt, sessions are random 256-bit tokens in HttpOnly cookies, ownership is verified on every protected request, and provider API keys are stored and used server-side only. The security page describes the mechanisms in detail.
9. International transfers
Our infrastructure providers and any AI provider you choose may process data outside your country. Where that happens we rely on the safeguards those providers offer, such as standard contractual clauses. You control which AI provider is used, and you can use the service with no AI provider at all.
10. Children
The service is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will remove it.
11. Changes to this policy
If we make a material change we will update the date at the top and notify account holders by email before it takes effect. Continuing to use the service after that means the updated policy applies.
12. Contact
Privacy questions and requests: hello@vidiscoop.com. See also the terms of service.