Last updated: September 14, 2026
This notice explains what Vidmoat does with your information: what we collect, why, who else touches it, where it goes, how long we keep it, and what you can make us do about it. It is written to be read rather than skimmed past.
Vidmoat is operated by Buzz Innovations Ltd, a company registered in England and Wales, company number 17212684. For data protection law we are the controller of the information described here. You can reach a human at fred@vidmoat.com.
You sign in with Google. We receive and store your email address, display name and profile picture from that sign-in. We never see or store your Google password. Authentication is handled by Firebase Authentication, a Google service.
The video, audio, images and fonts you upload; the projects you build from them, including all text you place on screen; the exports you render; and anything you publish through Vidmoat. We also derive things from your media: speech transcripts, silence regions, shot and motion measurements, visual labels, and (on some plans and requests) a timestamped description of what happens on screen.
The instructions you type into the AI console, agent mode, the chat bots or a generation box, and what the AI did in response. We keep the full text of a run, its plan, its commands, its errors and its credit cost. We use this to fix failures, to price features honestly, and to decide what to build.
Your plan, billing cycle, renewal date, credit balance and a transaction ledger, plus the customer and subscription identifiers our payment providers give us. We do not receive or store your card number: that stays with the payment provider.
Which features you use and when, which limits you reach, which client you used (web, desktop, mobile) and its version, when you were last seen, plus server logs. Some administrative and security records include an IP address: admin actions, system events, and the last IP used with an API key. Public API calls are logged with the route, status and duration.
Support tickets and their attachments, product feedback, expert handoff briefs, and, if you use Vidmoat Social, your profile, posts, comments and reports. Moderators keep private notes on accounts they have actioned.
Under UK and EU data protection law we must have a lawful basis for each purpose, not one basis for everything. Ours are:
| Purpose | Basis |
|---|---|
| Running the editor, storing your projects, rendering exports, and carrying out the AI instructions you give | Performance of our contract with you |
| Taking payment, preventing chargeback fraud, issuing invoices | Contract, and legal obligation for tax records |
| Publishing to a social platform you connected | Contract, on your instruction |
| Keeping the service secure, stopping abuse, enforcing limits | Legitimate interests: running a service that is not overwhelmed by abuse |
| Understanding how features are used so we can fix and improve them | Legitimate interests: making a product that works |
| Product and marketing email | Consent, withdrawable at any time from any email or your settings |
| Reporting child sexual abuse material | Legal obligation, and substantial public interest |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time using the contact address above.
Providing your content is not a statutory requirement, but it is necessary to use the product: we cannot edit or render a video you have not given us.
We do not use your videos, audio, images, transcripts or projects to train generative AI models, and we do not permit anyone else to do so with content we send them on your behalf. We do not sell your personal data, and we do not use your content in our own advertising or marketing.
One thing we do that is adjacent, and that we would rather state plainly than bury. When an agent run succeeds, we may keep the sequence of editing commands it produced, with the instruction that prompted it, as an internal example that helps the agent plan better next time. This is a record of which editor operations were combined in which order. It is not your media, and your footage, transcripts and rendered frames are never part of it. Email us if you would rather your runs were excluded and we will exclude them.
Some analysis runs entirely on your own machine, and the media involved is never uploaded for it:
The model files for the in-browser work are downloaded from the jsDelivr CDN, which will see your IP address as it would for any other file your browser fetches.
Uploads are stored on our own server in Helsinki, Finland, and mirrored to an object store in Stockholm, Sweden. Both are in the European Union. Exports are stored alongside them.
Files you upload are private to your account unless you publish them. Sharing a render creates a link that anyone holding it can view; you can revoke it. Posting to Vidmoat Social makes that video public.
Exports carry an invisible identifier.Every MP4 we render has a short code woven into the pixels, and a signed tag in the file’s metadata. They survive re-encoding. We use them to tell where a file came from: to answer a copyright complaint, to investigate abuse, and to prove provenance if you ever need to show a video is yours. They identify the export, not you personally, and we do not scan the internet looking for them.
Vidmoat’s AI features are built on models run by other companies. To answer your instruction we have to send them something. This is what goes where.
| Provider | Where | What we send |
|---|---|---|
| Alibaba Cloud (Qwen) | Singapore | Your instruction, a description of your timeline, and sampled video frames when a request needs to know what is on screen |
| DeepSeek | China | Your instruction and a description of your timeline, when it is next in line |
| xAI (Grok) | United States | Your instruction; and for image, video or voice generation, your prompt |
| Google (Gemini) | United States | Sampled video frames, where configured for video understanding |
A “description of your timeline” means clip names, durations, settings and any text you placed on screen. It can also include your speech transcript where the request depends on what was said. Sampled frames are still images taken from your video, tiled into one picture with timestamps.
Speech-to-text is ours.Transcription runs on Vidmoat’s own server, or in your browser. Audio is not sent to a third-party transcription service.
If you connect your own AI provider key, your content goes to that provider under your account and their terms, and we store the key encrypted.
You can connect an outside AI assistant — ChatGPT, Claude, or any other client that speaks the Model Context Protocol — to your Vidmoat account, and let it edit on your behalf. This section is about that specific arrangement, because it is the one case where a company we have no contract with can read your work, and you are the one who decides that.
Who receives your data. The operator of the assistant you connect. If you connect ChatGPT, that is OpenAI; if you connect Claude, that is Anthropic. They receive whatever the tools return, they are a controller of it in their own right, and what they then do with it is governed by their privacy policy and not by ours. We do not choose the assistant, we cannot see inside it, and we cannot delete data on your behalf once it has been handed over. Connecting one is a decision to share, and it is worth reading their policy before you make it.
What the tools send and return. Nothing is sent until the assistant calls a tool, and every call is made under permissions you granted. The categories, in full:
| Permission | What the assistant can send in | What comes back to it |
|---|---|---|
| See your plan and credits | Nothing | Your plan name, remaining AI credits and export allowance |
| Read your projects | A project id | The edit document: clip names, timings, settings, every word of text you placed on screen, and the speech transcript where one has been made |
| Create, edit and delete projects | Editing commands, and any text or styling they carry | The updated document, and what each command did |
| List your media | Nothing | File names, sizes, durations and the URLs your media is served from |
| Upload and import media | A file, or a URL to fetch one from | The stored file’s URL and its measured dimensions, duration and codec |
| Check renders and fetch frames | A project id and a timecode | Render progress, and still images of your video at the times it asks for |
| Start renders | Output settings | A job id, and the finished file’s URL. This spends your monthly export allowance. |
| Transcribe, generate speech, images or video | Your prompt, and the media to work from | The words that were said, or the generated file’s URL. These spend your credits and run through the providers named in section 6. |
| Analyse footage | A project or media id | Scenes, faces, motion, speech activity and on-screen text found in your footage |
| Run the AI editing agent | Your instruction | The edits it made. The instruction and a description of your timeline also go to the AI providers in section 6. |
| Search stock media | Search terms | Stock results from our library provider |
| Manage webhook endpoints | A webhook URL and the events it requests | This permission is reserved in the connection vocabulary. The public MCP server does not currently expose webhook management; no endpoint or event is created unless that feature is enabled. |
| Call third-party plugins | Arguments for the plugin tool you chose | Whatever the plugin returns. Calling third-party plugins sends data to the plugin’s own server; the plugin operator receives the arguments there, and Vidmoat does not give it your credentials. |
The public MCP documentation lists the endpoint, connection flow, current tool groups and the data categories returned by each permission.
Why.Only to carry out the instruction you gave the assistant. We do not use anything an assistant reads or writes to train models — section 3 applies here without exception — and we do not profile you from it or sell it to anybody.
What you control, and how. When a client asks to connect, we show you exactly which of the permissions above it wants and you approve or refuse the whole request; nothing is granted silently, and an app can never be given more than the ceiling set for it. A grant that already exists cannot widen itself: a client asking for more comes back to you as a fresh decision. You can see every connected app, and revoke any of them, at vidmoat.com/oauth/connected. Revoking is immediate and takes every token issued under that grant with it. Deleting your account deletes the grants too.
How long we keep it.The connection itself — which app, which permissions, when you approved it — lasts until you revoke it or close your account. Access tokens issued now are stored only as a one-way hash; a small number of older ones, from before we made that change, are still stored directly and are replaced by hashes as those connections refresh. Calls an assistant makes appear in our API request logs, which are kept for 30 days, and in the agent run records described in section 10. Anything the assistant did to your projects is simply part of your projects, and follows the same retention as the rest of your work.
One thing we cannot promise. An assistant acts on instructions you give it in a conversation we cannot see. If you ask it to delete a project or start a render, it will, and that spends your allowance or removes your work exactly as if you had done it yourself. Grant only the permissions you want used, and revoke a connection you are no longer using.
Beyond the AI providers above, these companies process personal data for us. The current list is kept at vidmoat.com/subprocessors.
Your account records and your media stay in the European Union. AI processing does not: as section 6 sets out, instructions and sampled frames go to providers in Singapore, China and the United States. Support, email, analytics and payment providers are variously in the United States and the EU.
Neither Singapore nor China has a UK or EU adequacy decision. Where we transfer personal data to a country without one, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with an assessment of the risk in that country. You can ask us for details of the mechanism used for a particular provider.
If you would rather your content were not sent abroad for AI processing at all, do not use the AI features. Everything else in the editor works without them.
| What | How long |
|---|---|
| Your account, projects and media | Until you delete them or close your account |
| Uploaded files no project references any more | 72 hours, then deleted |
| Deleted media in the backup store | Up to 30 days, because the store keeps versions |
| Interface usage events | 90 days |
| Server events | 400 days |
| Public API request logs | 30 days |
| Notifications you have read | 60 days |
| Billing records and invoices | 7 years, to meet UK tax law |
| Evidence in a child-safety report | 1 year, and it cannot be deleted on request |
Speech transcripts and video descriptions are cached against the file they came from so we do not redo the work, and are removed when the file is. Agent run records are kept while the account exists, because they are how a disputed charge gets settled.
You can ask us to:
You can delete your account yourself from your dashboard, which removes your projects, your uploaded files and your exports. Or email fred@vidmoat.com and we will action any of the above within one month.
If you are unhappy with how we have handled your data you can complain to the UK Information Commissioner’s Office at ico.org.uk, or to your own country’s supervisory authority. We would rather you told us first.
California residents. We do not sell personal information and we do not share it for cross-context behavioural advertising. You have the right to know, delete and correct, and we will not treat you differently for exercising it. We honour Global Privacy Control signals.
Access tokens for social platforms and plugins, connected AI provider keys and any credentials you store for browser automation are encrypted at rest with AES-256-GCM, and the encryption fails closed: if the key is missing, nothing is stored rather than something being stored in the clear. API keys are held only as hashes and shown once. Support diagnostics are built from an allowlist that explicitly excludes secrets.
No service is perfectly secure. If we discover a breach affecting your rights we will tell you and the ICO as the law requires.
Vidmoat is not for children. You must be at least 16 to use it, or older if your country sets a higher age for agreeing to terms like these. We do not knowingly collect data from anyone under 16, and if we learn we have, we will delete it. If you believe a child is using Vidmoat, tell us at fred@vidmoat.com.
When this notice changes materially we will say so in the product and update the date at the top. If a change means we would be doing something with your content that this version does not allow, we will ask first.
Buzz Innovations Ltd, registered in England and Wales, company number 17212684.
Email: fred@vidmoat.com
See also our Terms of Service, our list of subprocessors, and, if you use the public feed, the Vidmoat Social privacy notice.
11. Publishing to social platforms
If you connect YouTube, TikTok, Instagram, Facebook, Threads, LinkedIn, X or Pinterest, we store an encrypted access token, the account name and its avatar so you can tell your channels apart. We use them only to do what you asked: post the video you chose, and read back that post’s public statistics.
Vidmoat’s use of information received from Google APIs, including YouTube, follows the Google API Services User Data Policy, including its Limited Use requirements. Data we obtain from YouTube is used only to provide the features you asked for and is not sold, transferred for advertising, or used for any other purpose. You can revoke our access at any time in your Google account permissions, and Google’s own Privacy Policy applies to what they hold.
Disconnecting a platform in Vidmoat deletes the token we hold for it. It does not delete anything already posted to that platform: only the platform can do that.