Legal
Privacy Policy
This Privacy Policy explains how Nexmoe, operating VidBee and VidBee Cloud, collects, uses, stores, and shares personal information, and the rights you have. Please read it before using the Service. Using the Service means you have read and agree to this policy.
Last updated: September 5, 2026
Privacy highlights
- The desktop app can download and organize media locally without an account. VidBee Cloud accounts use GitHub sign-in.
- Payment card data is processed exclusively by Waffo Pancake. We do not store full card numbers on VidBee servers.
- We do not sell your personal information.
- Optional app analytics can be turned off in Settings. You can request access, correction, or deletion at [email protected].
1. Data controller
The data controller for the Service is:
- Name: Nexmoe, an individual / sole trader operating the VidBee project
- Brand: VidBee / VidBee Cloud
- Website: https://vidbee.org
- Privacy contact: [email protected]
- Data Protection Officer (DPO): Not applicable
2. Scope
This policy covers the VidBee website (vidbee.org), the VidBee desktop app for Windows, macOS, and Linux, VidBee Cloud (including api.vidbee.org), and related services such as update checks, release downloads, accounts, and payments.
When you download or subscribe to content from third-party platforms, those providers handle your requests under their own privacy policies. This policy applies to information we collect directly.
We may update this policy from time to time. Material changes will be announced at least 15 days in advance by email or a notice on vidbee.org.
3. Personal information we collect
3.1 Information you provide
- Account information from GitHub OAuth: name, email address, and profile image. We do not store a VidBee password for GitHub sign-in.
- Payment information: transaction amount, currency, payment status, and identifiers needed to match a Waffo Pancake order to your account. We do not store full card numbers — card data is processed by Waffo Pancake (see Section 6).
- Communications: emails, GitHub issues, Discord messages, and other support or feedback you send us.
- Invitation codes you enter or share, and related reward records.
3.2 Information we collect automatically
- Device and network data: IP address, user agent, operating system, browser type, and timezone where needed to operate sessions and security.
- Usage data: page views, feature events, session duration, and Cloud credit usage.
- Logs: request times, error logs, and performance data.
- VidBee Cloud content you submit for processing: transcript or subtitle text, prompt text, video URLs, subtitle origin, and generated output needed to run transcription and prompts.
3.3 Information stored only on your device
The desktop app runs locally. Unless you send material to VidBee Cloud, we do not upload your downloads, RSS feeds, or media libraries.
- Download history and queue state.
- RSS subscriptions and rules.
- App settings and preferences, including whether analytics is enabled.
- Cached thumbnails and library metadata.
- Local transcripts, API keys you enter for your own providers, and related files.
4. How we use personal information
We may aggregate or de-identify data for statistics. That data cannot reasonably identify you.
| Purpose | Legal basis |
|---|---|
| Provide and maintain the website, desktop app, and VidBee Cloud | Contract |
| Create and authenticate accounts (GitHub OAuth) | Contract |
| Billing, invoices, and payment processing | Contract |
| Customer support | Contract / legitimate interests |
| Service notices (billing, security, policy updates) | Legitimate interests |
| Security, abuse prevention, and fraud control | Legitimate interests |
| Product improvement and analytics | Legitimate interests / consent for optional analytics |
| Legal compliance and tax or accounting records | Legal obligation |
| Optional product updates or research surveys | Consent |
7. Security
- Transport encryption with TLS / HTTPS.
- Access control on a least-privilege basis for systems that hold account or Cloud data.
- Session credentials and OAuth tokens stored with access restricted to the auth service.
- Regular review of access, logs, and dependency updates.
If a security incident affects your rights, we will notify you and relevant regulators within 72 hours of becoming aware of it, where legally required. Keep your GitHub credentials private and do not share them.
No method of transmission or storage is 100% secure.
8. Retention
| Data type | Retention | After expiry |
|---|---|---|
| Account profile | While the account is active; 90 days after cancellation or deletion request | Delete or anonymize |
| Transaction records | 7 years, or longer if tax or accounting law requires | Delete or archive as required |
| Support emails and tickets | 2 years | Secure deletion |
| Security and audit logs | 12 months | Secure deletion |
| Cloud generation and credit ledgers | While the account is active; 90 days after cancellation | Delete or anonymize |
| Public subtitle or prompt cache used to operate Cloud | As long as needed to provide the Service, then delete or de-identify | Delete or de-identify |
| Website analytics | Up to 14 months | Delete or aggregate |
| Local desktop data | On your device until you delete it or uninstall the app | You control deletion |
9. Your rights
To exercise the rights below, email [email protected]. We will respond within 30 calendar days. If you believe we have not handled your request properly, you may complain to your local data-protection authority.
| Right | What it means |
|---|---|
| To be informed | Learn what data we collect and how we use it |
| Access | Receive a copy of your personal information |
| Rectification | Correct inaccurate or incomplete information |
| Erasure | Ask us to delete data in the cases the law allows |
| Restriction | Ask us to pause processing in certain cases |
| Portability | Receive your data in a machine-readable format |
| Objection | Object to processing based on legitimate interests or marketing |
| Withdraw consent | Withdraw consent for optional analytics, surveys, or similar processing |
You can also disable optional app analytics in Settings, use browser controls to block cookies, and delete local desktop data yourself.
10. Marketing and service notices
We may send product updates or research surveys only with your consent, for example through a voluntary Formbricks survey or an email you opt into. You can unsubscribe from marketing by using the link in the message, declining a survey, or emailing us.
Unsubscribing does not stop service-necessary notices such as billing, security, or material policy changes.
11. International transfers
Our servers and subprocessors may process data in the United States, the European Economic Area, and other countries where Cloudflare, GitHub, Waffo Pancake, and AI model providers operate.
When we transfer personal information internationally, we use one or more of the following safeguards:
- Data-processing terms that incorporate the EU Standard Contractual Clauses (SCCs) where required.
- Transfers only to recipients that provide an adequate level of protection.
- Other lawful transfer mechanisms where they apply.
12. Children
The Service is for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided information to us, contact [email protected] and we will delete it.
13. Third-party links and services
The Service may contain links to third-party sites or integrate third-party services, including GitHub, Waffo Pancake, Cloudflare, Rybbit, Formbricks, Discord, and AI model providers. This policy applies only to information we collect directly. We are not responsible for third-party privacy practices. Review their policies before you use those services.
14. Changes to this policy
If we make material changes, we will give at least 15 days' notice by a site announcement or email to your account address, and we will update the "Last updated" date on this page. Continued use after the effective date constitutes acceptance.
15. Contact
If you have privacy questions or want to exercise your rights, contact the VidBee team. We monitor this inbox for privacy, support, billing, and security requests.