1. Scope and controller
This notice covers the Viddle website and private-beta studio. “Viddle”, “we” and “us” refer to the operator of this beta.
The production version must identify the legal data controller, registered address and any required EU, UK or Türkiye representative. Until that information is published, the beta must not be described as a fully launched commercial service.
2. Data we process
Account and profile data may include email address, authentication identifiers, display name, avatar, language, role and account settings.
Creative data may include prompts, uploaded reference media, project briefs, research notes, shot plans, generated outputs, render manifests and user approvals.
Operational data may include run IDs, provider responses, credit transactions, timestamps, IP address, device/browser details, security events and error diagnostics. Payment providers process card details; Viddle should retain only the identifiers and records needed for billing and reconciliation.
Support data includes the message and run ID you choose to send. The current Contact form opens your own email application and does not transmit the form to a Viddle server.
3. Why we process it
We process data to authenticate users, save private projects, perform requested generations and renders, show job status, account for credits, provide support, prevent abuse and comply with law.
Where applicable, processing may rely on performance of a contract, legitimate interests in operating and securing the Service, legal obligations or separate consent. Consent is not bundled into this notice and can be withdrawn where it is the legal basis.
4. Providers and disclosures
Requested prompts and media are sent to the selected AI, rendering, storage or infrastructure provider only as needed to complete the operation. Supabase supports authentication, database, storage and Edge Functions; Shotstack may receive approved render inputs when server-side export is requested.
Payment, email and model providers may act as processors or independent controllers under their own terms. The production subprocessor list and provider data-use settings must be approved before launch. We do not sell personal data.
5. International transfers
Providers may process data outside your country. Before production, Viddle must document each processing location and put required transfer safeguards in place, including contractual clauses or other legally recognised mechanisms where applicable.
6. Retention and deletion
Account and project content is kept while needed to provide the Service or until a verified deletion request is completed. Security logs, backups and provider copies expire under documented schedules; billing and legal records may be kept for mandatory periods.
Viddle does not promise instant deletion from every backup. The operations team must track active systems, storage, providers and legally required exceptions through the data-request runbook.
7. Your choices and rights
Depending on applicable law, you may request access, correction, export, deletion, restriction or objection, and may complain to a competent supervisory authority.
Use the profile data controls when available or the Contact page. Viddle may verify identity and will respond within the applicable statutory deadline. Marketing consent, if introduced, must be separate and optional.
9. Security and incidents
Viddle uses HTTPS, access controls, Supabase row-level policies, server-side secret storage, audit records and restricted provider operations. No system is completely secure.
Report suspected compromise through the Contact page. Viddle's incident process includes assessment, containment, evidence preservation and required regulator/user notifications.
10. Age, changes and contact
Viddle V1 is intended for users aged 18 or older. If we learn that an ineligible child supplied personal data, we will investigate and delete it where required.
We will date material changes and provide additional notice where law requires it. Use the Contact page for privacy or data-protection questions.