This Privacy Policy describes how Reelyr ("we") collects, uses, and shares information when you use the service.
1. Information we collect
Account data: email address and name (via Clerk authentication).
Usage data: the topics you submit, channels you create, jobs you run, and videos you generate.
Payment data: processed by Stripe. We receive confirmation of successful payments and limited metadata (amount, credits purchased); we do not store your card details.
Technical logs: IP address, user agent, request timestamps — used for debugging and abuse prevention.
Social account tokens (optional): if you connect YouTube, Facebook, Instagram, or TikTok, we store the OAuth tokens you authorize, encrypted at rest, and use them only to post to the account you connected.
2. How we use your information
- To operate and improve the service
- To process your payments and deliver credits
- To render and store your generated videos
- To post to your connected social accounts at your instruction
- To respond to support requests
- To detect, investigate, and prevent fraud or abuse
3. Third parties (sub-processors)
Your data may be processed by the following providers. Each is contractually obligated to appropriate data protection standards:
Where you supply a URL, we fetch that page and read its text and images so the video can be built from what is actually on it. Where you upload a document or brand asset, its contents are processed to build the video. Both are sent to the providers below in the same way as anything else you enter.
- Clerk — authentication and user identity management
- Stripe — payment processing
- Hostinger — API hosting (virtual server)
- OpenRouter — research (including live web search), script and on-screen copy generation, image generation, and motion clips. OpenRouter routes these requests to the underlying model providers.
- ElevenLabs — voiceover and sound generation
- fal.ai — image generation, used only when the primary provider fails
- Google (Gemini API) — cover images, and voiceover only where an account is explicitly configured to use it
- AWS Lambda + S3 — video rendering and intermediate asset storage (us-east-1)
- Cloudflare R2 — final video storage and delivery
- Turso (libSQL) — primary database
- Vercel — web application hosting
- Meta (Facebook, Instagram) and YouTube — only when you connect an account and instruct us to publish to it
4. Data we never sell
We do not sell your personal data. We do not share it with advertisers or data brokers.
5. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Delete your account and associated data
- Export your data in a portable format
- Withdraw consent at any time
To exercise any of these rights, contact us via the contact page.
6. Retention
We retain account data for as long as your account is active. Generated videos are retained in R2 for at least 90 days. On account deletion, we delete personal data within 30 days, except where retention is required by law.
7. Cookies
We use strictly necessary cookies for authentication (Clerk session cookie, JWT token cookie). We do not use advertising or analytics cookies at this time.
8. Children
The service is not directed at children under 13. We do not knowingly collect personal data from children under 13.
9. International transfers
Your data may be processed in the United States and other countries where our sub-processors operate. We rely on standard contractual clauses and provider compliance frameworks for cross-border transfers.
10. Changes
We may update this Privacy Policy. Material changes will be communicated via email or an in-app notice.
11. Contact
For privacy questions or to exercise your rights, reach us at the contact page.