1. Who we are
Synthvids ("Synthvids", "we", "us", "our") operates the website and service at https://synthvids.ai (the "Service"). Synthvids is an AI video production tool that helps creators research topics, generate scripts, synthesize voiceover, render video, and — at the creator's direction — publish the resulting videos to their own connected channels.
This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and the choices you have.
Controller / operator: JB Malcolm LLC
Mailing address: c/o Northwest Registered Agent, 2108 N St, Ste N, Sacramento, CA 95816
Contact: [email protected]
If you have questions or complaints about our privacy practices, contact us at [email protected]. We respond to privacy requests within 30 days.
2. Information we collect
We collect only what we need to run the Service, and we are direct about what happens to it. In short: your account is private, your content is yours, and we do not sell any of it. The detail follows, and Section 2.5 states plainly how we treat the material you create.
2.1 Information you give us
- Account information. Your name, email address, and profile image. If you sign in with Google, we receive this from your Google Account (see Section 3).
- Billing information. Subscription tier and billing status. Card details are collected and stored by Stripe, our payment processor — we never receive or store full card numbers.
- Content and configuration. Channel settings, topic sources, prompts, voice selections, uploaded reference images, and any other input you provide to configure a video.
- Third-party API keys you choose to provide. If you supply your own keys for optional providers (for example, a voice provider), we store them encrypted and use them only to make requests on your behalf. These encrypted values are never read by a human reviewer, and are decrypted only at the moment we make the specific request you authorized — never for any other purpose.
- A Reddit session cookie, if you choose to provide one. If you use the Reddit research source, you may optionally copy your own Reddit login session cookie from your browser and paste it into your channel settings. This lets Synthvids fetch Reddit content as your logged-in session instead of as an anonymous visitor, which Reddit blocks after a few requests. The cookie is stored encrypted, is never shown in logs, and is used only to fetch content on your behalf when that channel's Reddit source runs.
- Support communications. Messages you send us.
2.2 Information we generate
- Generated media. Scripts, voiceover audio, images, and rendered video files produced from your inputs, along with associated metadata (titles, descriptions, thumbnails).
- Usage and job records. Render jobs, timestamps, credit consumption, error and status logs, and diagnostic information about failed jobs.
2.3 Information collected automatically
- Technical data. IP address, browser and device type, referring pages, and pages viewed.
- Cookies and similar technologies. We use cookies that are strictly necessary to keep you signed in and to secure your session. We do not use cookies for advertising and we do not sell advertising on the Service.
2.4 Discover (research)
Synthvids includes a research feature called Discover. When you select a topic or a source, Discover retrieves publicly available material and analyses it to identify subjects, facts, and themes worth covering. That material is used as research input: it informs what a script is about and how it is structured. Scripts are then newly written by a language model rather than assembled from the retrieved text.
Retrieved material that becomes part of a script or a rendered video is held as part of your channel's research state for as long as that story, its channel, or your account exists, and is removed when you delete any of those.
Retrieved material that is never turned into a script or a render is deleted automatically 90 days after it was discovered, regardless of whether you take any action — unused research material does not accumulate indefinitely.
Retained material — used or unused, while it exists — helps the Service track what you have already covered and avoid suggesting the same subject twice. It is never published to your channel, is not shown to other users, and is not sold or shared with third parties.
Discover retrieves material; it does not grant you rights in it. Determining whether a given source may be used for your project remains your responsibility — see our Terms of Service.
2.5 How we treat what you create
The scripts, audio, images, and videos you generate are yours. We hold them to operate the Service for you, and we commit to the following:
- Your content is private to your account by default. Generated media is stored in access-controlled storage and is not listed publicly, indexed by search engines, or browsable by other users. Playback and download links issued by the Service are time-limited and specific to your session. Content becomes public only when you choose to publish it to a channel you have connected.
- We do not sell your content or your personal information. Not to advertisers, not to data brokers, not to anyone. We do not share it for cross-context behavioural advertising, and we have no advertising business.
- We do not use your content to train our own AI models, and we select model providers whose commercial terms exclude training on API inputs. This applies to your prompts, your source material, your generated Output, and your Google user data. The one exception outside our control is ElevenLabs — see Section 6.
- We do not showcase your work without asking. We will not feature your videos, thumbnails, or channel in marketing, demos, or public examples unless you give us separate, express permission.
- Staff access is limited and purposeful. Our personnel do not browse user content. Access happens only where necessary to investigate a fault you have reported, to respond to a legal obligation, or to investigate a credible report of abuse — and is limited to what that purpose requires.
- You can take it with you, and you can take it down. You may download your generated media at any time, and delete it from your account. Deletion removes the file from our storage; see Section 7 for backup retention.
The one thing we cannot do is reach into a platform you have already published to. Once a video is live on your YouTube channel, you control it there.
3. Google user data
This section describes how Synthvids accesses, uses, stores, and shares data from Google APIs, including YouTube API Services. It applies in addition to the rest of this policy.
3.1 Sign-in with Google
If you choose to sign in with Google, we request the following scopes:
openid,.../auth/userinfo.email,.../auth/userinfo.profile
We use this to create and authenticate your Synthvids account. We receive your Google account email address, name, and profile picture. We do not receive your Google password.
3.2 YouTube channel connection
Publishing to YouTube is optional. You are never required to connect a YouTube channel to use Synthvids. If you choose to connect one, we request the following scopes:
| Scope | Why we request it |
|---|---|
https://www.googleapis.com/auth/youtube.upload | To upload videos you have created in Synthvids to the YouTube channel you select. |
https://www.googleapis.com/auth/youtube | To display your available YouTube channels including Brand Accounts, so you can select which channel to publish to, and to confirm the status of videos we uploaded on your behalf. The full scope is required for reliable Brand Account discovery; we do not read, modify, or delete existing channel content, comments, or subscriber data. |
What we access and store. When you connect a channel, we store an OAuth access token and refresh token, your YouTube channel ID, and channel title. We store the refresh token so that scheduled uploads can run at the time you selected, without requiring you to be signed in at that moment.
How we use it. We use this data solely to (a) show you which channel you are publishing to, (b) upload videos at your explicit direction, including on a schedule you set, and (c) report back the status and link of an upload we performed. We do not read, download, analyze, or index your existing YouTube videos, comments, subscriber data, or analytics beyond what is described here.
How we share it. We do not sell, rent, or transfer Google user data to third parties. We do not share it with advertisers, data brokers, or analytics providers. Google user data is transmitted only between your browser, our infrastructure providers listed in Section 5, and Google's own APIs.
We do not use Google user data to train AI models. Google user data is never used to develop, improve, or train any machine learning or artificial intelligence model, whether ours or a third party's.
Limited Use. Synthvids' use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3.3 Your control and revocation
- You may disconnect a YouTube channel at any time from your Synthvids account settings. Doing so deletes the stored tokens for that channel from our systems.
- In addition to our normal deletion procedure, you may revoke Synthvids' access to your Google data at any time via the Google security settings page at https://security.google.com/settings/security/permissions.
- Revoking access does not delete videos already uploaded to your YouTube channel. You control those directly through YouTube Studio.
3.4 Google and YouTube terms
By connecting a YouTube channel, you are also agreeing to the YouTube Terms of Service. Data handled by Google and YouTube is governed by the Google Privacy Policy.
4. How we use information
We use the information described above to:
- provide, operate, and maintain the Service;
- authenticate you and secure your account;
- generate the scripts, audio, images, and video you request;
- publish videos to channels you have connected, at your direction;
- process payments, enforce usage limits, and prevent abuse;
- diagnose failures, monitor performance, and improve reliability;
- communicate with you about your account, billing, and service changes; and
- comply with legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5. Service providers
We use the following providers to operate the Service. Each receives only the data needed for its function.
| Provider | Function | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage | Account data, job records, generated media, encrypted tokens |
| Vercel | Website hosting | Technical/request data |
| Render.com | Backend API and job workers | Job data, request data |
| Upstash | Job queue | Job identifiers and parameters |
| RunPod | GPU compute for video rendering and voice synthesis | Scripts, prompts, and media for the duration of a render |
| Stripe | Payments and subscriptions | Name, email, billing details |
| Anthropic | Script and text generation | Prompts and topic material you supply |
| ElevenLabs | Optional voice synthesis | Script text |
| OpenAI | Thumbnail image generation | Prompt text |
| xAI / Grok | Optional image generation | Prompt text |
| Klaviyo | Signup notification and account email list | Email address, signup date, plan tier |
| Email delivery provider | Transactional email | Email address |
| Google / YouTube | Publishing to your channel | See Section 3 |
We may add or change providers; we will update this list when we do. No provider in this list receives Google user data except Google itself and the infrastructure providers that store or transmit it on our behalf (Supabase, Vercel, Render.com, Upstash).
We may also disclose information if required by law, subpoena, or valid legal process, or where necessary to protect our rights, users, or the public.
6. AI processing and your content
Content you create with Synthvids belongs to you, subject to our Terms of Service. We process it to render your videos and to operate the Service.
We do not use your content or your Google user data to train AI models. Our model providers process your prompts under their own commercial terms; we select providers whose terms exclude training on API inputs.
ElevenLabs is the one exception we cannot guarantee. Voice synthesis through ElevenLabs requires you to connect your own ElevenLabs account and API key — Synthvids does not operate a shared ElevenLabs account on your behalf, and your script text is sent to ElevenLabs under your account, not ours. Zero-retention (no training on submitted audio or text) is ElevenLabs' default account setting, but it is a setting the account holder controls and can change at any time. Because the account is yours, Synthvids has no way to verify or guarantee which retention or training setting is active on it. If this matters to you, check the setting directly in your ElevenLabs account.
7. Data storage, location, and retention
Our primary database and file storage are hosted in Canada. Rendering compute may be performed in the United States. If you are located outside these countries, your information will be transferred to and processed there.
We retain:
- Account data for as long as your account is active, and for 90 days after deletion to allow recovery and to meet legal and accounting obligations.
- Generated media for 90 days following the most recent sign-in. Where an account belongs to an organization with more than one member, the most recent sign-in by any member counts. Signing in renews that period; after 90 days with no sign-in, generated media may be deleted. An account with no recorded sign-in is not deleted on this schedule.
- Google OAuth tokens until you disconnect the channel, revoke access, or delete your account, whichever comes first.
- Render logs for 30 days. After that, the console log of a render that has finished, failed, or been cancelled is cleared. A short failure message is kept with the render's own record for as long as that record exists, so we can still tell you why a render did not succeed.
Billing records are retained as long as required by tax and accounting law.
8. Security
We protect information using encryption in transit (TLS), strict access controls limiting who and what can read sensitive data, and row-level security isolation so that one account cannot access another's data. Credentials and tokens are isolated to service-role database access only and are not readable by other users. Stored OAuth tokens and user-supplied API keys are additionally protected with column-level AES-256-GCM encryption, decrypted only in-process at the moment a request is made to the provider it belongs to. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete your information;
- obtain a portable copy of your information;
- object to or restrict certain processing; and
- withdraw consent at any time, without affecting prior processing.
California residents have the rights described above under the CCPA/CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined by the CCPA.
EEA/UK residents may also lodge a complaint with their local supervisory authority.
To exercise any of these rights, email [email protected] or use the account deletion option in your account settings. We may ask you to verify your identity before acting on a request.
10. Children
The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us information, contact [email protected] and we will delete it.
11. Changes to this policy
We may update this policy from time to time. If we make material changes to how we handle Google user data or other personal information, we will notify you by email or through the Service before the change takes effect. The "Last updated" date above reflects the most recent revision.
12. Contact
JB Malcolm LLC
c/o Northwest Registered Agent, 2108 N St, Ste N, Sacramento, CA 95816
