VIDENSE
Privacy

Vidense Privacy Policy

How personal data is processed on the website, web app and native apps.

Version 2026-09-14.3 · Updated

1. Controller and contact

The controller under the General Data Protection Regulation (GDPR) is Apptheism, Fischmarkt 17, 78462 Konstanz, Germany.

Send privacy requests to privacy@vidense.ai. A data protection officer will be named only if legally required; none is currently recorded as appointed.

2. Scope

This Policy applies to vidense.ai, the Vidense web app, native Vidense apps, support communications and related server-side processing. The App Privacy summary supplements but does not replace this Policy.

3. Categories of data

  • Account data: name or display name, email address, internal user ID, language and account status.
  • Authentication data: password hash at the authentication provider, session and verification information, identifiers for Sign in with Apple or Google, and acceptance records.
  • Content: video link, public metadata, uploaded video file, filename, size, duration, preview image, analysis request, result, timestamps and, where offered, transcript.
  • Contract and payment data: plan, purchased product, status, term, transaction/provider identifiers, credit ledger entries, invoice and refund status. We generally do not receive full card or bank details.
  • Usage and device data: IP address, time, requested URL, browser/app version, operating system, technical errors, security events, product interactions and, if enabled, push token.
  • Communications: optional name, email address, subject and content of support requests, and optional newsletter consent.
  • Cancellation data: name, contract email address, plan or contract description, type and requested date of cancellation, and an optional reason or the reason given for extraordinary cancellation.

4. Purposes and legal bases

PurposeLegal basis
Account, analysis, library, billing and supportArticle 6(1)(b) GDPR (contract and pre-contract steps)
Receipt, confirmation and handling of cancellationsArticle 6(1)(b) and (c) GDPR (contract handling and legal obligation)
Accounting, tax and evidence obligationsArticle 6(1)(c) GDPR (legal obligation)
Security, abuse/fraud prevention and error diagnosisArticle 6(1)(f) GDPR (legitimate interest in secure, reliable operation)
Newsletter and non-essential notificationsArticle 6(1)(a) GDPR (consent)
Strictly necessary device storageSection 25(2)(2) TDDDG; subsequent processing under the GDPR bases above

5. Website access and security

When the site is accessed, Vidense and its hosting/security provider Cloudflare process connection data such as IP address, time, destination, headers, device/browser details and security signals. This is used to deliver the service, defend against attacks, enforce regional availability and diagnose errors.

Cloudflare Turnstile may process security signals during registration, login, password recovery and use of the contact or cancellation form to detect automated abuse. Turnstile is loaded only in those security flows.

6. Contact form and support

When you use the contact or cancellation form, we process the contact, message and contract data entered there and technical security data to deliver, confirm and handle the declaration and prevent abuse. Resend transmits the message to support@vidense.ai and, for the cancellation form, sends a receipt to the contract email address provided. You can use support@vidense.ai directly instead.

Requests relating to a contract or pre-contract steps are processed under Article 6(1)(b) GDPR. Other requests and protection of the form rely on Article 6(1)(f) GDPR; our legitimate interests are accessible support and protection against automated abuse.

7. Account and sign-in

Supabase processes the account, email verification, sessions and password hash. With Sign in with Apple, Apple provides an Apple identifier and, depending on the user's choice, a name and either a real or private relay email address. With Sign in with Google, Google provides a Google identifier and the approved basic profile data, in particular name and email address. Vidense cannot access Apple or Google passwords.

We record the accepted Terms version, time and access channel to perform the contract and retain evidence of legal declarations.

8. Video links, uploads and AI analysis

For public video links, we process the URL or video ID and metadata retrieved through official APIs. The link and analysis request are sent to Google's Gemini service, which may retrieve the publicly accessible content directly depending on the source.

Uploads are temporarily stored in Cloudflare R2 and then transferred to Google Gemini for analysis. Vidense does not use source videos for advertising or model training. We use the AI service as a paid business/API service. Under the paid-service terms, Google may log prompts and responses for a limited period to detect abuse; those security logs are separate from the temporary provider file object deleted by Vidense.

Results may contain personal data visible or audible in the video. Do not upload special-category personal data or third-party recordings unless you have the required legal basis or consent.

9. Purchases, subscriptions and credits

RevenueCat orchestrates the product catalogue, purchases and entitlement status across platforms. Web payments use RevenueCat Billing with Stripe; Apple purchases use StoreKit and Apple. Vidense receives the product, status, term, transaction identifier and mapping to the internal user ID.

Credit lots and immutable credit ledger entries are stored to perform the contract, prevent abuse and maintain a traceable account. A client-side purchase message alone never grants credits.

10. Monitoring, sharing and push notifications

If you monitor a public channel, we store its identifier, limits, status and technical delivery information. Public metadata may be processed through the YouTube Data API and official notification interfaces.

If you activate a public result link, anyone who has the link can access the shared content. Disabling it blocks the link but does not delete copies already made by third parties.

Push notifications are enabled only after operating-system permission. We process a device-specific push token and send messages through Apple Push Notification service. Permission can be withdrawn in system settings.

11. Recipients and processors

We disclose data only where needed to provide and secure the service, process payments, comply with law, or with consent. Where a recipient acts as a processor, the required data-protection terms apply, including the subprocessors incorporated into them.

Recipient/serviceFunction and possible data
Cloudflare, Inc.Hosting, CDN, security, Turnstile, R2 and queues; connection, security and upload data
Plus Five Five, Inc. (Resend)Email delivery for contact and support; name, email address, subject, message and technical delivery data
Supabase, Inc.Authentication and database; account, contract, content and usage data
Google LLC / applicable Google contracting entityGoogle sign-in, Gemini video analysis and official video metadata APIs; basic profile data, links, uploads, prompts, results and technical data
RevenueCat, Inc.Purchase, subscription and entitlement management; user, product and transaction identifiers
Stripe Payments Europe, Ltd. and affiliatesWeb payment processing, customer portal and invoice data
Apple Distribution International Ltd. and affiliatesApp Store purchases, Sign in with Apple and push notifications

12. International transfers

Some recipients or subprocessors process data outside the EU/EEA. Where there is no adequacy decision, transfers rely on appropriate safeguards, particularly EU Standard Contractual Clauses and any necessary supplementary measures. EU-US Data Privacy Framework certification is relied on only where it is current and applies to the specific recipient and data flow.

Resend states that it stores customer data, including message content, delivery logs and account records, in the United States. According to Resend, selecting a sending region affects routing and delivery rather than the storage location.

13. Retention and deletion

  • Uploaded source files: as soon as possible after completion or final failure; technical maximum of 24 hours for the R2 object and the temporary AI-provider file object addressable by Vidense. Limited provider security logs follow the verified contract and are documented separately.
  • Incomplete upload sessions: until the upload window expires, generally no more than 24 hours.
  • Analysis results and transcripts: until deleted by the user, account deletion, or an overriding legal/contractual period.
  • Account data and push tokens: until account deletion, device deregistration or loss of purpose.
  • Public shares: until disabled or the related result is deleted.
  • Billing, tax and accounting records: for applicable statutory retention periods; personal linkage is pseudonymised where possible.
  • Security and error logs: only while necessary for protection, diagnosis and evidence; exact provider periods must be documented before publication.
  • Contact and support requests: until finally handled and afterwards only for as long as needed for evidence, legal-defence purposes or statutory retention duties.
  • Cancellation notices and receipts: for contract handling and afterwards only for as long as needed for evidence, legal-defence purposes or statutory retention duties.

14. Account deletion, subscription cancellation and consent

Account deletion can be started in the app or account settings. We remove the profile, authentication, analyses, sources, push tokens and RevenueCat customer mapping; Sign in with Apple tokens are revoked for Apple accounts. Legally retained financial records remain pseudonymised.

Account deletion does not automatically cancel a subscription billed through an app store. Cancel it separately in the relevant store. Newsletter consent can be withdrawn through the provided control or by email at any time.

15. Your rights

Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, portability and objection. Consent can be withdrawn prospectively at any time. Where processing relies on legitimate interests, you may object for reasons arising from your particular situation; you may always object to direct marketing.

Contact the privacy address above to exercise a right. You may also complain to a data-protection supervisory authority, particularly in your place of residence, place of work or the location of the alleged infringement.

16. Automated processing and security

Vidense automatically generates video analyses. This does not make a solely automated decision with legal or similarly significant effects within Article 22 GDPR.

We use role-based access, transport encryption, separated secrets, server-side purchase verification and purpose-bound deletion workflows. No system is risk-free; security incidents are handled under applicable notification and information duties.

17. Changes

We update this Policy when the product, data flows, recipients or law changes. The current version and date are shown on this page. Material changes will be communicated appropriately.