Privacy Policy

Last updated: January 2025

1. Introduction

AI Video Automation (“we”, “us”, or “our”) provides an automated video generation and publishing platform. This Privacy Policy explains how we collect, use, store, and protect your information when you use our service.

2. Information We Collect

  • Account information: Email address, display name, and password (hashed).
  • Third-party API credentials: API keys you provide for HeyGen and OpenAI, and OAuth tokens for Google Drive, YouTube, TikTok, Facebook, and Instagram.
  • Pipeline configuration: Your niche keywords, schedules, avatar preferences, and publishing settings.
  • Execution logs: Records of each pipeline run, including per-step statuses, generated script text, video links, and failure reasons.
  • Subscription and billing data: Managed by Stripe; we store only your subscription status.

3. Encrypted API Key Storage

All third-party API keys and OAuth tokens you provide are encrypted at rest using AES-256 encryption via Supabase Vault before being stored in our database. Raw key values are never written to application logs or persisted in memory beyond a single pipeline execution request. Only the last 4 characters of each API key are displayed in the dashboard for identification purposes.

4. Third-Party Services

We use the following third-party APIs to operate the service:

  • OpenAI API: Used to generate video scripts from fetched article content. If you provide your own OpenAI API key it is sent to OpenAI on your behalf; otherwise a platform-level key is used. Content sent to OpenAI is subject to OpenAI’s Privacy Policy.
  • HeyGen API: Used to generate AI avatar videos from your scripts. Your HeyGen API key and script text are transmitted to HeyGen to produce video files. Use of HeyGen is subject to HeyGen’s Privacy Policy.
  • Google Drive: Videos are uploaded to your connected Google Drive folder using OAuth tokens you authorise. We request only the drive.file scope.
  • Social platforms (YouTube, TikTok, Facebook, Instagram): Videos and captions are published using OAuth tokens you authorise. Each platform’s own privacy policy applies.
  • Stripe: Handles all payment processing. We do not store card details.

5. Data Retention

  • Execution logs: Automatically deleted after 90 days.
  • API credentials: Retained until you delete them or close your account.
  • Account data: Retained until account deletion is completed (within 30 days of a deletion request).

6. Your Rights and Data Deletion

You may request deletion of all your account data at any time by emailing us or by submitting a request via our data deletion form. We will remove all your data within 30 days of a confirmed request.

7. Security

We enforce HTTPS on all endpoints, use HTTP-only cookies for session management, apply Row Level Security (RLS) on all database tables to prevent cross-user data access, and follow OWASP secure coding practices.

8. Contact

For privacy-related enquiries please contact us at privacy@example.com.