Privacy Policy

Privacy Policy โ€” How we collect, use, store, and protect your data

Last Updated: August 13, 2026

VideoHuz ("we", "us", or "our platform") is an integrated global content workflow and creator intelligence SaaS platform operated by VideoHuz Global Operations, purposefully built for international video creators and cross-border brands. We offer cross-platform operations data aggregation, AI-assisted content creation, and multi-platform publishing management. We value your privacy and are committed to handling your personal data in a transparent and compliant manner.

This Privacy Policy applies to the VideoHuz website (videohuz.com) and all related services. By accessing or using our services, you confirm that you have read and understood this Policy. If you do not agree with any terms herein, please immediately discontinue use of our services.

01

Information We Collect

1.1 Information You Directly Provide

  • Account Registration๏ผšEmail address, password (stored via salted cryptographic hash), and display name.
  • Team Information๏ผšTeam name and email addresses provided when inviting team members.
  • Content Creation Data๏ผšScripts, manuscripts, and storyboard drafts created in the VideoHuz Editor.
  • Payment Information๏ผšTransaction records processed via Stripe (we do not store full credit card numbers; all payment data is securely managed by Stripe).
  • Customer Communications๏ผšIssue descriptions and correspondence submitted through support tickets.

1.2 Information from Third-Party Platform Authorizations

When you link third-party social media accounts in VideoHuz "Matrix Config", we obtain data strictly within your explicit scope of authorization:

TikTok Platform

  • Basic user profile (Display Name, Avatar, OpenID) โ€” authorized via user.info.basic Scope
  • Public video list and metadata (Title, Description, Views, Likes, Comments, Shares) โ€” authorized via video.list Scope
  • Video publishing permissions and account capability status โ€” authorized via video.publish Scope

YouTube Platform (Google LLC)

  • Basic channel profile and identity (Channel Title, Custom URL, Avatar, Channel ID) โ€” authorized via .../auth/youtube.readonly Scope
  • Public video and Shorts list and metrics (Views, Likes, Comments) โ€” authorized via .../auth/youtube.readonly Scope
  • Video and Shorts upload and metadata management permissions โ€” authorized via .../auth/youtube.upload Scope
VideoHuz uses YouTube API Services. By using these features, you agree to be bound by the Google Privacy Policy (http://www.google.com/policies/privacy). VideoHuz's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. You can revoke VideoHuz's access to your data at any time via the Google Security Settings Page (https://myaccount.google.com/permissions). Unrefreshed API cache data is retained for no more than 30 days.

Other Platforms (Instagram, etc.)

  • Basic account information (Username, Avatar)
  • Public video analytics metrics (obtained compliantly via respective official APIs)

1.3 Automatically Collected Information

  • Device & Browser Info๏ผšIP address, browser type and version, operating system, and unique device identifiers.
  • Usage Logs๏ผšAccess timestamps, page navigation paths, feature usage frequency, and AI invocation logs.
  • Security Fingerprint๏ผšAnonymized fingerprint identifier used for edge rate limiting (ai_guest_fingerprint), not linked to personal identity.
02

How We Use Your Information

Service Delivery

Provide core functions including account management, content editing, AI writing assistance, and video rendering/publishing.

Data Aggregation & Analytics

Aggregate metrics across authorized platforms on the Global Dashboard to generate cross-platform reports.

Content Publishing

Publish video or photo content to authorized accounts on TikTok and other platforms on your behalf via Publish Hub.

Intel & Trend Discovery

Analyze publicly available industry trends via VideoHuz Intel Radar engine to provide creative inspiration.

AI Features

Invoke LLMs (Gemini, DeepSeek) to process your text for continuation, polishing, and score prediction without using data for model training.

Security Protection

Utilize IP and anonymous fingerprints for edge rate limiting against DDoS/Spam attacks.

Billing & Quota Management

Track compute credit consumption and handle subscription or credit purchase records.

Service Improvement

Analyze anonymized telemetry to optimize product usability, performance, and stability.

03

Data Storage and Security Measures

3.1 Storage Location

  • Primary Database๏ผšAccount records and project data are stored in managed PostgreSQL databases on Supabase (hosted on AWS cloud infrastructure).
  • Object Storage๏ผšVideo thumbnails and media assets are stored in secure Supabase Storage Buckets.
  • Caching Layer๏ผšUpstash Redis is utilized for distributed rate limiting and transient data caching.
  • Payment Records๏ผšIndependently managed by Stripe under PCI-DSS Level 1 compliance.

3.2 Security Measures

  • Transit Encryption๏ผšStrict HTTPS (TLS 1.2+ / TLS 1.3) enforced across all endpoints and API communications.
  • Password Security๏ผšUser credentials are encrypted using salted bcrypt hashing; plaintext passwords cannot be recovered.
  • OAuth Token Vaulting๏ผšThird-party Access and Refresh Tokens are vaulted using AES-256-GCM symmetric encryption with KMS-managed keys.
  • Access Control (RBAC)๏ผšGranular role-based access controls ensure team members only access data within authorized privileges.
  • Edge Protection๏ผšDual IP + browser fingerprint rate limiting (30 req/min) protects endpoints against automated abuse.
  • Row Level Security (RLS)๏ผšDatabase-level Supabase RLS policies enforce strict tenant data isolation.

3.3 Third-Party Integration & Data Flow Architecture

Full-lifecycle illustration of data transfer, encryption, publishing, and automated purging between VideoHuz and TikTok / third-party platforms

AES-256-GCMOAuth 2.0GDPR Compliant
Phase 1

OAuth 2.0 Authorization & Encrypted Token Storage

01User Initiated

Triggering Account Connection

User clicks "Connect TikTok Account" in the console, redirecting to the official TikTok OAuth page with explicitly requested scopes.

User Browserโž”
02Secure Exchange

Callback & Token Exchange

Upon user approval, TikTok returns an authorization code. VideoHuz backend securely exchanges it for Access/Refresh Tokens over HTTPS.

HTTPS Token Exchangeโž”
03Vaulted Storage

AES-256-GCM Encryption at Rest

Tokens are encrypted via AES-256-GCM before DB insertion. Only ciphertexts and IVs are stored, with keys strictly managed in cloud KMS.

Encrypted DB๐Ÿ”’ Secured
Phase 2

Direct Video Publishing & Asynchronous Webhook Lifecycle

01Submit Job

Publish Parameters & Compliance

Creator sets title, privacy level (Public/Friends/Private), and AIGC disclosure markers in Publish Hub before dispatching.

Creator Actionโž”
02Verified Pull

PULL_FROM_URL Mechanism

Calls Content Posting API. TikTok servers directly stream video files from DNS-verified trusted origins, preventing MITM tampering.

TikTok Verified Pullโž”
03Async Webhook

Status Notification & Feedback

TikTok transcodes and verifies the video, dispatching an async Webhook callback to VideoHuz to update job status and share links.

Webhook Status Callbackโœ“ Done
Assurance

Authorization Revocation & GDPR Automated Data Purging

Users can disconnect accounts anytime via Matrix Config or revoke access in TikTok App Settings. Upon disconnection or receiving TikTok Deauthorization Webhook, our backend physically deletes all associated OAuth tokens, profile data, and video caches within 1 second without retaining expired sensitive data.

04

Data Retention Policies

Data TypeRetention PeriodDescription
Account ProfileActive account lifetimePermanently purged within 30 days of account deletion
Content ProjectsActive account lifetimeUsers can delete individual drafts anytime; purged within 30 days upon deletion
Third-Party OAuth TokensAuthorization lifetimeImmediately destroyed upon disconnection; cleaned up automatically on expiration
Platform Cached MetricsMax 90 daysUsed for dashboard trends; wiped immediately upon account disconnection
AI Invocation Logs30 daysRetained only for credit billing audits; prompt contents are never stored for model training
Security & Audit Logs90 daysRetained strictly for security auditing and anomaly detection
Payment RecordsStatutory requirementRetained strictly per applicable tax and commercial accounting laws
05

Your Rights (GDPR & CCPA)

Under applicable data privacy regulations (including GDPR and CCPA), you hold the following fundamental rights:

Right of Access

You can request a machine-readable copy of all personal data we hold about you, provided within 30 days.

Right to Rectification

You can update your personal details in Team Settings or request correction of inaccurate data.

Right to Erasure (To Be Forgotten)

You may request total deletion of your personal data and projects, fulfilled within 30 days.

Right to Restrict Processing

You may request temporary restriction on processing your data under specific circumstances.

Right to Data Portability

You can export your project assets and scripts in structured, machine-readable formats.

Right to Withdraw Consent

Disconnect third-party accounts anytime to revoke data permissions; cached data is purged within 24h.

Right to Object

You may object to the processing of your data for specific analytical or marketing purposes.

Right to Lodge a Complaint

You retain the right to submit a formal inquiry to your local data protection supervisory authority.

To exercise any of the rights listed above, please contact privacy@videohuz.com. We will respond within privacy@videohuz.comใ€‚ 7 business daysใ€‚

06

Data Deletion Procedures

We provide multiple accessible channels to ensure you maintain full control over your personal data:

Self-Service Deletion

Path: Dashboard โ†’ Pipeline Board โ†’ Select Project โ†’ Delete

Immediately removes the selected project and related data from our live systems

Disconnect Third-Party

Path: Dashboard โ†’ Matrix Config โ†’ Disconnect

Immediately revokes OAuth tokens and purges cached platform metrics

Account Deletion

Path: Dashboard โ†’ Team & Settings โ†’ Delete Account

Permanently deletes all personal data, projects, and account credentials within 30 days

Email Request

Path: Send request to privacy@videohuz.com

Submit a formal erasure request processed by our compliance team within 7 business days

07

Third-Party Data Sharing

We do not sell your personal data under any circumstances. We only share strictly necessary data with the following vetted service providers:

Service ProviderShared DataPurpose
Supabase (Database)Account records, project dataCore data persistence and real-time collaboration infrastructure
Stripe (Payments)Payment transaction metadataProcessing credit pack and subscription purchases securely
Google AI / DeepSeek (AI)User-submitted prompt textsAI co-pilot writing, polishing, and rubric scoring (not used for training)
Global AI Voice & ASR EngineEncrypted Audio StreamsAutomated audio transcription and speech processing hosted in global cloud regions
Upstash (Redis Cache)Anonymized client identifiersEdge rate limiting and security DDoS prevention
Vercel (Hosting)Access traffic logsApplication hosting and global CDN edge routing
TikTok / YouTube and other global platformsUser-authorized media packagesPublishing content or reading public metrics strictly per user authorization

All third-party vendors are bound by Data Processing Agreements (DPAs). We may disclose information only when legally mandated by court subpoenas or law enforcement.

08

Cookies and Tracking Technologies

VideoHuz uses minimal, strictly necessary cookies to ensure secure and reliable operation:

Cookie NameCategoryPurposeDuration
sb-*-auth-tokenEssentialSupabase user session authenticationSession
ai_guest_fingerprintSecurityEdge rate limiting and anti-abuse verification1 Year

do not use third-party advertising or cross-site tracking cookies (such as Google Analytics or Facebook Pixel). We do not track your behavior across other websites or share your data with ad networks.

09

Children's Privacy

VideoHuz services are strictly intended for users aged 16 and older (or the minimum legal age in your jurisdiction). We do not knowingly collect personal information from minors under 16. If you believe a minor has provided us with personal data, please notify us immediately at privacy@videohuz.com for prompt deletion.

10

International Data Transfers

Our cloud infrastructure spans multiple global regions. Your data may be transferred to and processed in servers outside your country of residence under strict safeguards:

  • Standard GDPR-compliant Data Processing Agreements (DPAs) executed with all cloud providers
  • Standard Contractual Clauses (SCCs) implemented to ensure adequate data protection levels
  • Strong cryptographic encryption applied in transit and at rest
11

Policy Updates and Notifications

We may update this Privacy Policy periodically to reflect service evolution or regulatory revisions. When significant updates occur, we will notify you through:

  • Prominent notification banners within the Dashboard
  • Email notifications sent to your registered account address
  • Updating the "Last Updated" timestamp at the top of this page

Your continued use of VideoHuz after updates constitutes acceptance of the revised Privacy Policy.

12

Contact Information

If you have questions, feedback, or complaints regarding this Privacy Policy or wish to exercise your data sovereignty rights, please contact us:

Operating EntityVideoHuz Global Operations
Response SLAWithin 7 business days of request receipt

ยฉ 2026 VideoHuz. All rights reserved.