Privacy Policy
Auk Video Inc. is a Canadian company based in Toronto, Ontario. This policy explains what we collect when you use Auk, why we hold it, who processes it on our behalf, and how to get it back or get rid of it.
Effective · Auk Video Inc.
1. Who we are and what this covers
Auk turns a long video you own into short vertical clips: we download or receive your source video, transcribe it, pick highlights, crop and caption them, and, if you ask, publish the result to a social account you have connected. This policy covers auk.video and the Auk web application. It does not cover the platforms you publish to, which run under their own policies.
We are the controller of the personal information described here (under Quebec's Law 25 and the GDPR, the “controller”; under PIPEDA, the organisation accountable for it). Our Privacy Officer is accountable for how we handle it; contact details are in section 13.
2. Connected publishing accounts
You can connect a social account so that Auk can publish the clips you choose to it. We only connect an account when you start the connection yourself, and we only ask the platform for the permissions publishing needs. Whatever the platform, the same rules apply to what we get back:
- We store the account identity we need to show you where a clip will go (an account id, display name and avatar URL), the permissions the platform granted, and a refresh token. Refresh tokens are encrypted at rest with AES-GCM and are never shown to you, logged, or sent to your browser. We do not store access tokens: we exchange the refresh token for a short-lived access token at the moment of each upload and discard it.
- We publish only the clips you send, to the account you choose, when you tell us to.
- We do not read your analytics, followers, subscribers, messages, comments or any post we did not publish for you.
- We never sell platform data, never use it for advertising, never use it to train machine-learning models, and never share it with anyone except the subprocessors in section 5 that are needed to run the upload.
- Nobody at Auk reads it, unless you ask us to for support, it is needed to investigate abuse or a security incident, or the law requires it.
- Disconnecting the account in Auk asks the platform to revoke our access and then deletes the stored identity and token outright, rather than flagging them.
YouTube (YouTube API Services)
Auk uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google's handling of your information is governed by the Google Privacy Policy.
When you connect a channel, we ask Google for exactly two permissions:
- youtube.upload, to upload the clips you choose to publish to your channel. We never upload anything you have not explicitly sent from Auk.
- youtube.readonly, to read your channel's id, title and avatar, so the app can show you which channel you are about to publish to, and to read back the status of a video we uploaded. We do not read your analytics, your comments, your subscribers or videos we did not upload.
From YouTube we store only: your channel id, title and avatar, so you can see where a clip will go; and, for each video Auk uploaded for you, its video id, link, upload status and privacy setting, so you can find it again. We refresh all of this from YouTube at least once a day, and never keep any of it for more than 30 days without refreshing it. At each refresh we also check that you have not revoked our access; if you have, we delete all of it within 7 days. We store no other YouTube data, and nothing about videos Auk did not upload.
You can revoke our access at any time, from inside Auk by disconnecting the channel in Settings, or directly at Google's security settings permissions page. Revoking at Google stops all access immediately.
Google user data and Limited Use
Auk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That covers both YouTube data and the name, email address and profile picture Google gives us if you sign in with Google. We use Google user data only to provide the features you see in Auk, and we do not use Google user data to develop, improve or train generalised artificial intelligence or machine-learning models.
TikTok
TikTok publishing is rolling out; this part applies from the moment you can connect a TikTok account. Auk uses TikTok's Login Kit and Content Posting API, and asks TikTok for:
- user.info.basic, to read your TikTok open id, display name and avatar, so the app can show you which account you are about to publish to;
- video.publish, to post the clips you choose to your account, with the caption and the audience you pick.
TikTok's handling of your information is governed by the TikTok Privacy Policy. Before anything is sent to TikTok, you see the account it will go to, choose who can see it, and confirm; we do not choose a privacy setting for you. You can revoke our access by disconnecting the account in Auk, or in the TikTok app under Settings and privacy, Security and permissions, Apps and services permissions.
Instagram and Facebook (Meta)
Instagram publishing is rolling out; this part applies from the moment you can connect an Instagram account. Auk publishes to Instagram professional (Business or Creator) accounts through Meta's Instagram API, and asks Meta for:
- instagram_business_basic, to read your Instagram account id, username and profile picture, so the app can show you which account you are about to publish to;
- instagram_business_content_publish, to publish the clips you choose to that account as Reels.
Meta's handling of your information is governed by the Meta Privacy Policy. You can revoke our access by disconnecting the account in Auk, or at Meta as described in section 8.
3. What we collect and why
Account information
Your email address, and your name and profile picture if you sign in with Google. We use this to authenticate you, to send you transactional email about your own projects, and to answer support requests. Authentication is handled by Supabase; if you sign in with a password we never see it, only the hash Supabase stores.
Content you give us
The video you upload or the link you paste, and everything derived from it: the downloaded source file, the extracted audio, the transcript, the clip candidates our model selected, the cropped clips, and the rendered MP4s. We hold this because it is the product: without it there is nothing to edit or export. Your content is yours, and we do not use it to train models.
To crop a clip around whoever is speaking, our software detects where faces are in each frame and which face is talking, and records their positions over time. It does not recognise who anyone is: it creates no face print or other biometric template, and it does not compare faces across videos or against any database. The position data is stored with the project and deleted with it. People who appear in your video are not our users, so section 5 of our Terms requires you to have their permission.
Connected publishing accounts
The account identity, granted permissions and encrypted refresh token described in section 2, for each platform you connect, and a record of what we published there for you (the post id, link and status the platform returns, refreshed as described in section 2) so you can find it again.
Your agreement to our terms
When you accept our Terms of Service and confirm that you have read this Privacy Policy, we record which document you accepted, its version (its effective date), the language you read it in, whether you accepted at signup or in the app, the time our server recorded it, and the time your browser reported you ticked the box. If you later give or withdraw consent to marketing email, we record that the same way. We keep this record to show that you agreed, as the platforms we connect to and Canadian law (including Quebec's Charter of the French language and Canada's Anti-Spam Legislation) expect. Nobody edits it, you or us: a change is a new entry, never an overwrite. We do not store your IP address or device details with it.
Billing information
Payments run through Paddle as our merchant of record. Paddle, not Auk, collects and processes your card details; we never see or store a card number. We store the Paddle customer and subscription identifiers, your plan, your subscription status and period end, and your credit balance and its ledger.
Usage and device information
Standard server logs (IP address, browser user agent, request paths, timestamps) kept for security, debugging and abuse prevention, and Google Analytics measurement described in section 6.
4. How we use it
- To run the pipeline you asked for: ingest, transcribe, select highlights, crop, caption, render, publish.
- To authenticate you and keep your projects separate from everyone else's.
- To meter credits, bill you and issue receipts.
- To send transactional email: your video is ready, your export failed, a password reset.
- To send product news, only if you have agreed to receive it, as Canada's Anti-Spam Legislation requires. Every such email has a working unsubscribe link, and we act on an unsubscribe within 10 business days.
- To keep the service up and to investigate errors, abuse and fraud.
- To meet legal and tax obligations.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use your video or transcripts to train machine-learning models. We do not run automated decision-making that produces a legal or similarly significant effect on you.
Where the GDPR or UK GDPR applies, our lawful bases are: performance of a contract (running the service, billing it, and publishing to the accounts you connect), legitimate interests (security, abuse prevention, product reliability), consent (analytics cookies and marketing email), and legal obligation (tax and accounting records).
5. Who processes it, internally and externally
Internally, access is limited to the people at Auk Video Inc. who need it to operate and support the service. Externally, we use the subprocessors below and no others. Each one is bound by a contract to process data only on our instructions.
| Subprocessor | What it handles | Where |
|---|---|---|
| Cloudflare, Inc. | Web hosting and CDN, the API, the job queue, video and artifact storage (R2), CPU render containers, and speech-to-text transcription on Workers AI | United States and global edge |
| Supabase, Inc. | Authentication and the application database (account, project and billing records) | United States (us-east-2) |
| RunPod, Inc. | GPU compute for speaker detection and vertical cropping of your clips | United States |
| OpenRouter, Inc., and the language model provider it routes each request to | Receive the text of your transcript to select highlight candidates. Neither receives your video, audio or account details. | United States |
| Paddle.com Market Ltd, Paddle.com (Canada) Ltd and Paddle.com Inc. | Merchant of record: checkout, payment, tax and invoicing. Paddle is an independent controller of the payment information it collects, under its own privacy notice. | United Kingdom, Canada, United States and European Union |
| Resend | Transactional email delivery | United States |
| Google LLC | YouTube Data API when you publish to a connected channel, Google Analytics, and Google sign-in if you use it | United States |
When you publish, the clip and the title, description and privacy setting you gave it go to the platform you chose (YouTube, TikTok or Instagram). That platform receives it on your instruction, as an independent organisation under its own policy, not as our subprocessor.
We also disclose information when the law requires it (a valid court order, subpoena or legal process), to establish or defend a legal claim, or to protect the rights and safety of our users. If Auk is acquired or merged, your information may transfer with the business; we will tell you before it becomes subject to a different privacy policy.
No third party serves advertisements on Auk. Nobody other than the subprocessors above serves content on our pages.
6. Cookies and device-level collection
We use two kinds of browser storage, and no advertising cookies:
- Strictly necessary. Supabase stores your session token in your browser's local storage so you stay signed in. The app keeps your theme choice in a first-party cookie (
auk-theme) and local storage, and keeps small UI state there too, such as a link you pasted on the homepage before signing in. A first-party cookie (auk-consent) remembers your answer to the analytics question for a year. Without these, the app cannot work. - Analytics, only if you accept. Google Analytics is not loaded at all until you choose Accept on the cookie banner; if you choose Reject, or never answer, it never runs. Once accepted, Google Analytics 4 sets cookies to measure aggregate usage: which pages are visited, how long a session lasts, roughly where visitors are. Its handling of that data is governed by the Google Privacy Policy. You can withdraw consent at any time with the button below, which stops Google Analytics and deletes the cookies it set; the app keeps working.
We do not fingerprint devices and we set no advertising or cross-site tracking cookies.
7. How long we keep it
- Projects and media (source video, audio, transcripts, clips, renders): for as long as your account exists, until you delete the project.
- Account records: for as long as your account exists.
- Record of your agreement and email preferences: for as long as your account exists, deleted with it.
- Publishing credentials and account identity: re-read from the platform daily while connected. Deleted immediately when you disconnect the account in Auk, and within 7 days (in practice the next day) if you revoke access at the platform instead.
- Links to what we published for you (the platform's video id, link and privacy status): re-read daily, and removed within 7 days of the account being disconnected or revoked, or of the video being deleted on the platform. The record that a clip was published stays in your history, without the link.
- Billing and tax records: up to seven years after the transaction, because Canadian tax law requires it.
- Server logs: generally 30 days, longer only where an open security investigation needs them.
8. Deleting your data
You can delete an individual project at any time from the app, which removes its source video, audio, transcript, clips and renders. You can disconnect a publishing account from Settings, which deletes the stored credential.
If you connected Instagram or Facebook, you can also remove Auk at Meta: on Facebook, go to Settings and privacy, Settings, Apps and websites, select Auk and choose Remove; on Instagram, go to Settings, Website permissions, Apps and websites, select Auk and choose Remove. For TikTok, go to Settings and privacy, Security and permissions, Apps and services permissions, and remove Auk. For YouTube, use Google's permissions page (menu names may differ in your version of the app). Removing Auk at the platform stops our access at once. We check every connected account at least daily; when we find that access has been removed, we delete the identity, token and everything else we hold from that platform within 7 days, without you needing to do anything more.
Deleting data from Auk, whether one project, one connection or your whole account, deletes only the copies Auk holds. It does not delete or change anything on YouTube, TikTok or Instagram. A video Auk published for you stays on that platform until you delete it there, in the platform's own app or website.
To delete your whole account and everything in it, cancel any plan in Manage billing and then use Request account deletion in Settings, or email [email protected] from the address on the account with the subject “Delete my account”. Either way, we cancel your subscription and delete your account, projects, media and connected platform accounts within 7 days of your request, and confirm by email. Our database provider keeps encrypted backups on a rolling cycle of no more than 30 days; until then a deleted record may exist only in a backup that nobody uses to operate the service, and if we ever restore a backup we delete it again before the service goes back online. Two records survive deletion, because the law or security requires them: the payment notifications Paddle sent us (which include your billing email and what you paid), kept for as long as Canadian tax law requires; and our internal log of actions staff took on accounts, kept for security. Paddle, as merchant of record, also keeps its own records of your payments.
9. How we protect it
All traffic runs over TLS. Refresh tokens for connected accounts are encrypted at rest with AES-GCM under a key held outside the database, and are never returned by any API route. Access to production systems is limited to the people who operate them. Every API request is checked against the account that owns the record it touches, which is enforced by an automated test that fails the build if a route forgets, so one customer cannot read another's projects.
No system is perfectly secure. If a breach of our security involves your personal information and creates a real risk of significant harm to you, as Canada's PIPEDA puts it, or a risk of serious injury, as Quebec's law puts it, we will notify you and the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec, as the law requires, as soon as feasible. Where the GDPR or UK GDPR applies, we notify the competent authority within 72 hours of becoming aware of a breach unless it is unlikely to result in a risk to people, and we notify you without undue delay when the risk to you is high. Our notice will say what happened, what information was involved, what we have done, and what you can do to protect yourself. We keep a record of every breach and confidentiality incident, whether or not it had to be reported.
10. Where your information is stored
We are based in Canada, but our infrastructure providers store and process data in the United States, the United Kingdom and the European Union, as set out in section 5. This means your information may be accessible to courts, law enforcement and national security authorities in those countries under their laws. For personal information from the European Economic Area or the United Kingdom, we rely on the European Commission's adequacy decision for Canada, and for onward transfers to our providers, on the European Commission's Standard Contractual Clauses (and the UK Addendum) or the provider's certification under the EU-U.S. Data Privacy Framework. As Quebec law requires, before we send personal information outside Quebec we assess whether it will be adequately protected and put a written agreement in place. You can ask us for more detail about these safeguards.
11. Your rights
Wherever you live, you can ask us to give you a copy of your personal information, correct it, delete it, or stop a particular use. Email [email protected] and we will answer within 30 days. If the law allows us more time and we need it, for example because a request is complex, we will tell you within the first 30 days why, and when you will hear from us. We will not charge you or treat you differently for asking.
Canada. Under PIPEDA you have the right to access and correct your personal information, to withdraw your consent to a use of it (subject to legal and contractual limits, and we will tell you what withdrawing means for the service), and to challenge our handling of it. If our answer does not satisfy you, you may complain to the Office of the Privacy Commissioner of Canada. Quebec residents additionally have rights of portability and de-indexing under Law 25 and may complain to the Commission d'accès à l'information du Québec .
European Economic Area and United Kingdom. You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting processing already carried out. You may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office.
United States. Residents of California and other states with comprehensive privacy laws have the right to know, delete, correct and port their personal information, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of, and we do not discriminate against anyone who exercises a right.
12. Children
Auk is not for children. You must be at least 18 and have reached the age of majority where you live to hold an account, because holding one means agreeing to a paid contract. We do not knowingly collect personal information from anyone under 18, and if we learn that we have, we delete the account and its contents. Contact us if you believe a child has given us information.
13. Contacting us, and complaints
Privacy questions, requests and complaints go to our Privacy Officer, who is the person in charge of the protection of personal information at Auk Video Inc., at [email protected], or by post to: Privacy Officer, Auk Video Inc., [REGISTERED ADDRESS], Toronto, Ontario, Canada. Anything else reaches us at [email protected]. We answer privacy requests within 30 days and will tell you if we need longer and why.
14. Changes to this policy
If we change this policy we will update the effective date at the top, and for a change that materially affects how we handle your information we will email you or show a notice in the app before it takes effect. If a change would let us use your information for a new purpose, we will ask for your consent before doing so, and nothing changes for you until you give it.
Auk Video Inc., [REGISTERED ADDRESS], Toronto, Ontario, Canada.