VidRocket
PrivacyTerms

Privacy Policy

Last updated: April 28, 2026 · Effective: April 28, 2026

This Privacy Policy explains how Hireabble Inc. (“Hireabble,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with VidRocket (the “Service”), available at vidrocket.ai and related subdomains. By using the Service you agree to the practices described here. If you do not agree, please do not use the Service.

1. Who we are

VidRocket is operated by Hireabble Inc., a corporation incorporated in the Province of Alberta, Canada. For questions about this policy or your data, contact us at privacy@vidrocket.ai.

2. Information we collect

2.1 Information you provide

  • Account information: name, email address, and password (passwords are hashed by our authentication provider, Supabase — we never see them in plaintext).
  • Google sign-in: if you sign in with Google, we receive your name, email, and profile image from Google’s OAuth flow.
  • Billing information: when you purchase a subscription or credit pack, payment is processed by Stripe. We do not store full card numbers or CVV codes; we receive a Stripe customer ID, the last four digits of your card, your billing country, and the status of your subscription.
  • Content you submit: URLs of public social-media profiles you scan (YouTube, TikTok, Instagram), videos you upload, comparison files, prompts you type into the post-scan chat, board notes, favorites, and other content you generate inside the Service.
  • Support and communications: emails and messages you send us.

2.2 Information collected automatically

  • Usage data: pages visited, referrer, device type, browser, operating system, country and city derived from your IP, and an anonymous 30-minute session identifier stored in a first-party cookie (va_sid).
  • IP address: we receive your IP address with every request. We do not store it in plaintext — we store a salted SHA-256 hash of the IP for abuse prevention and aggregate analytics.
  • Cookies: we set a session cookie for authentication (issued by Supabase), a session-id cookie for traffic analytics, and Stripe sets cookies on its checkout pages. We do not use third-party advertising or cross-site tracking cookies.
  • Logs and diagnostics: standard server logs (timestamps, request paths, response codes, error stack traces) generated by our hosting provider.

2.3 Information about third-party creators

When you scan a public profile, we fetch publicly available metadata and video content (titles, view counts, thumbnails, transcripts, frames) from YouTube, TikTok, or Instagram. We do not collect private accounts, private posts, follower lists, or personal contact information of those creators. The fetched material is processed to produce the analysis you requested and is retained per Section 7 (Retention).

3. How we use information

  • To provide and operate the Service (authentication, scans, analyses, chat, billing).
  • To send AI providers (see Section 5) the inputs needed to generate your analysis.
  • To bill you, process refunds, and prevent payment fraud.
  • To debug, monitor performance, and detect abuse or attempted account compromise.
  • To improve the Service through aggregate, de-identified usage analytics.
  • To send transactional email (sign-up confirmation, password reset, billing receipts). We may also send occasional product announcements; you can opt out at any time.
  • To comply with our legal obligations and enforce our Terms of Service.

We do not sell or rent your personal information. We do notuse your private uploads, scan inputs, or chat prompts to train our own AI models.

4. Legal bases (EU/UK users)

If you are in the European Economic Area or United Kingdom, our legal bases are:

  • Contract: to deliver the Service you signed up for.
  • Legitimate interests: security, fraud prevention, analytics, and product improvement.
  • Consent: for optional marketing email; you can withdraw consent any time.
  • Legal obligation: tax, accounting, and lawful requests.

5. AI processing and subprocessors

VidRocket sends inputs to third-party AI and infrastructure providers to deliver the Service. By using VidRocket, you agree to the routing of your inputs to these providers under their respective terms.

ProviderPurposeWhat is sent
SupabaseAuthentication, database, file storageAccount data, uploads, analysis records
Anthropic (Claude)Vision and text analysisVideo frames, transcripts, your prompts
Google (Gemini)Video understanding for some scan pathsPublic videos fetched on your behalf, analysis prompts
StripePayment processingEmail, billing details, purchase amount
VercelWeb hosting and edge deliveryStandard request data
RailwayFFmpeg and worker queueVideo files for frame extraction

Anthropic and Google have committed in their enterprise terms not to use API inputs to train their public models. We do not enable any “training opt-in” flag on these APIs.

6. Sharing and disclosure

We share information only as follows:

  • With subprocessors listed in Section 5, under their data-protection terms.
  • Public analyses: if you (or an administrator) explicitly mark an analysis or board as public, the analysis content and the public-creator metadata become viewable by anyone with the link or via our public library. Your email address is never shown on public pages.
  • Compelled disclosure: in response to valid legal process, with notice to you where lawfully possible.
  • Corporate transactions: if Hireabble is acquired or merges with another company, your data may be transferred under equivalent protections.

7. Retention

  • Account data: kept for the life of your account, plus up to 30 days after deletion to complete backups and reverse mistaken deletions.
  • Uploaded videos and extracted frames: kept until you delete them or your account is deleted, whichever is earlier. Inactive accounts may have storage purged after 12 months with prior email notice.
  • Scan results and chat history: retained as long as your account is active so you can revisit past scans.
  • Billing records: retained for 7 years to satisfy tax and accounting obligations.
  • Server logs: 30 days.
  • Hashed-IP analytics: 13 months in aggregate form.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent for marketing email.
  • Lodge a complaint with your local data-protection authority.

Canadian residents have the rights described under PIPEDA and any applicable provincial privacy laws (including Alberta’s PIPA and Quebec’s Law 25). California residents have the rights described under the CCPA/CPRA. We do not sell or “share” personal information for cross-context behavioral advertising.

To exercise any of these rights, email privacy@vidrocket.aifrom the address on your account, or use the in-app account settings. We will respond within 30 days.

9. Security

We use TLS in transit, encryption at rest for stored uploads and database backups, hashed passwords, scoped access controls, and least-privilege service credentials. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

10. International transfers

VidRocket is operated from Canada. Several of our subprocessors (notably Anthropic, Stripe, and Vercel) are located in the United States, so your information will be transferred to and processed there as well as in any other jurisdiction where our subprocessors operate. Where required for transfers out of the EEA or UK, we rely on Standard Contractual Clauses or equivalent transfer mechanisms.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us and we will delete it.

12. Third-party content and links

The Service displays content fetched from YouTube, TikTok, and Instagram. We are not responsible for those platforms’ privacy practices. Embedded videos play under the respective platform’s terms and may set their own cookies.

13. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects the latest revision. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect.

14. Contact

Hireabble Inc.
Email: privacy@vidrocket.ai

© 2026 Hireabble Inc. All rights reserved.VidRocket is a product of Hireabble Inc.