Skip to content

Privacy policy

How VedoBox handles information.

This is a product-ready privacy policy draft for review before public launch. It describes the current VedoBox Web architecture and must be completed with the legal entity, jurisdiction, contact, and processor details before publication.

Last updated: Draft — August 2026

1. Scope

This policy applies to the VedoBox public website, access-request pages, and the authenticated video subtitle localization workspace operated through VedoBox Web. It does not replace a separate agreement between a customer and the legal entity that will operate the service.

2. Information we receive

We may receive contact details and workflow context that you choose to send by email. The workspace may process account, workspace, project, membership, media, task, glossary, usage, and integration information needed to provide the enabled product workflow.

The site does not ask for media, subtitles, access tokens, API keys, signed URLs, or provider responses in an access-request form. Do not send those materials by email.

3. How we use information

We use information to respond to requests, authenticate users, authorize workspace and project access, process enabled media and subtitle tasks, deliver results, provide support, protect the service, investigate abuse, and maintain security and reliability. We do not use service content for unrelated advertising.

4. Service boundaries

Browser requests pass through the Web backend-for-frontend boundary. Service identity tokens, provider credentials, object keys, signed URLs, media, transcript text, and provider responses are not intended for logs or analytics. Persistent authorization and membership decisions remain with the VedoBox API.

5. Retention and deletion

Service content is currently retained for 30 days by default, with a configurable maximum of 90 days. Deletion revokes access first and then removes media and related content asynchronously. Actual retention for a specific environment is governed by the service state and applicable agreement.

6. Cookies and similar storage

The current product uses necessary, HttpOnly session cookies for authenticated access and short-lived login state. No advertising or third-party analytics cookies are currently configured in this repository. See the Cookie policy for the current implementation summary.

7. Your choices and requests

Before publication, this section must identify the responsible legal entity, the applicable rights process, verification requirements, response timelines, and the correct privacy contact address. Use the general Contact us page for a pre-launch question; it is not yet a formal rights-request channel.

8. Legal review required

The operator must confirm controller or processor roles, lawful bases, subprocessors, international transfers, children’s data rules, breach notices, supervisory authority, governing law, and the effective date before this policy is presented as final.