Legal

Privacy Policy

Last updated
5 August 2026
Effective
5 August 2026

In short

We collect what we need to run the product and nothing else. Your audio is sent to a speech-to-text provider to work out word timings — that is the one place your files leave our systems, and it is listed below. We do not sell your data, we do not train models on your music, and you can delete everything at any time.

Who controls your data

Vidome is the data controller for personal data processed through vidome.app. For privacy questions contact privacy@vidome.app.

What we collect

Account data. Your email address, and your name and avatar if you sign in with Google or GitHub. We never receive your password from those providers.

Content you upload. Audio files, lyrics, background images and video, and the projects you build from them.

Usage data. Which renders you started, how many credits they cost, and errors encountered. We keep this to run credit accounting, to support you, and to find bugs.

Billing data. Handled by Stripe. We store a customer reference, your plan, and invoice history. We never see or store your card number.

Technical data. IP address, browser and device type, and rough location derived from IP. Used for security, fraud prevention, and abuse detection.

Worth knowing

We do not use your music, lyrics or videos to train machine-learning models, and we do not licence them to anyone who does.

Why we are allowed to process it

Under UK and EU data protection law, our lawful bases are:

  • Contract — to provide the service you signed up for: storing your projects, rendering your videos, taking payment.
  • Legitimate interests — to keep the service secure, prevent abuse of the free tier, and improve the product. We balance this against your rights.
  • Consent — for any non-essential cookies, and for marketing email. You can withdraw consent at any time.
  • Legal obligation — to keep financial records and respond to lawful requests.

Who we share it with

We do not sell your personal data. We share it only with the providers below, each of which is contractually bound to process it solely on our instructions.

ProviderWhat forWhat they receiveWhere
OpenAISpeech-to-text, to detect word timings in your trackThe audio file you upload, and the lyrics you paste (used to improve recognition)United States
Cloudflare (R2)Storage and delivery of uploads, renders and thumbnailsUploaded audio, images, video, and rendered outputGlobal edge network
StripePayment processing and subscription billingName, email, billing address, payment details (handled by Stripe, never stored by us)United States / Ireland

Worth knowing

Worth being explicit about: when you use automatic lyric detection, your audio file is uploaded to OpenAI to be transcribed, along with the lyrics you pasted (which measurably improve recognition of unusual words). If you would rather that did not happen, sync your lyrics manually in the timeline editor — the feature works entirely without it.

We may also disclose data where legally required, or to protect our rights, users, or the public.

International transfers

Some providers are based in the United States. Where personal data leaves the UK or EEA, transfers rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with additional safeguards where required.

How long we keep it

  • Projects and uploads — until you delete them or close your account.
  • Finished renders7 days on the free plan; for the life of the subscription on paid plans.
  • Transcripts — cached against the audio file so re-uploading the same track costs you nothing. Deleted with the audio.
  • Credit and billing records — kept for 7 years, as tax law requires.
  • Security and abuse logs — 12 months.
  • After account deletion — nothing is destroyed straight away. Your account keeps working and the request stays cancellable for 30 days; on that day your projects, uploads, renders and account details are deleted, from our storage and not merely hidden. Backup snapshots still holding a copy rotate out within a further 35 days. The credit, billing and security records above outlive the account, with the reference to you anonymised.

Your rights

You can ask us to:

  • give you a copy of your data, in a portable format
  • correct anything inaccurate
  • delete your data (“right to be forgotten”)
  • restrict or object to processing based on legitimate interests
  • withdraw consent you previously gave

Email privacy@vidome.app. We respond within 30 days and never charge for it.

If you are unhappy with how we have handled your data you can complain to your local supervisory authority — in the UK, the Information Commissioner’s Office.

Security

Data is encrypted in transit (TLS) and at rest. Uploaded files are stored in a private bucket that is not publicly addressable; only finished renders you choose to share are served from a public path. Access to production data is limited to staff who need it, and every privileged action taken by our staff is recorded in an audit log.

Support staff cannot silently browse your account. Accessing a customer account requires a time-limited, reason-logged session that is read-only by default.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator as the law requires.

Cookies

We use a small number of cookies, most of which are strictly necessary. See the Cookie Policy for the full list and to change your choices.

Children

VIDOME is not intended for children under 13, or under 16 in the EEA and UK. If we learn we have collected data from a child below that age we will delete it.

Changes

We will post any changes here and update the date at the top. For material changes we will email you before they take effect.

Questions

Anything unclear in this document, write to support@vidome.app and a person will answer it.