VidRocket
PrivacyTermsAcceptable useSafetyCopyrightUploadsAccessibilitySupport

VidRocket Privacy Policy

Last updated: October 7, 2026 · Effective: August 2, 2026

This Privacy Policy explains how VidRocket (“VidRocket,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use VidRocket (the “Service”). The Service includes the VidRocket website at vidrocket.ai and its subdomains, the VidRocket iOS app, and the VidRocket Studio desktop app. By using VidRocket you agree to the practices described here. If you do not agree, please do not use VidRocket.

1. Who we are

VidRocket is owned and operated by Hireabble Inc., a corporation incorporated in the Province of Alberta, Canada, which is the company responsible for your information under this policy. For questions about this policy or your data, contact VidRocket at privacy@vidrocket.ai.

2. Information we collect

2.1 Information you provide

  • Account information: name, email address, and password (passwords are hashed by our authentication provider, Supabase — we never see them in plaintext).
  • Google sign-in: if you sign in with Google, we receive your name, email, and profile image from Google’s OAuth flow.
  • Sign in with Apple: if you sign in with Apple, we receive your email address (or Apple’s private relay address, if you chose to hide yours) and, on your first sign-in only, the name you choose to share.
  • Billing information: when you purchase a subscription or credit pack on the web, payment is processed by Stripe. We do not store full card numbers or CVV codes; we receive a Stripe customer ID, the last four digits of your card, your billing country, and the status of your subscription. Purchases made inside the iOS app are processed by Apple through In-App Purchase — we never see your payment details, only the purchase and subscription status Apple reports back to us, which we use to unlock features and grant credits.
  • Content you submit: URLs of public social-media profiles you scan (YouTube, TikTok, Instagram), videos and photos you upload, record in the app, or import from your photo library, comparison files, prompts you type into the chat and editor, caption and on-screen text you write, board notes, favorites, and other content you generate inside the Service.
  • Memory, Soul and Routines: short facts about you and your content that our AI keeps between chats (for example your niche, audience, platforms and goals) — added by you in Settings, by asking the chat to “remember” something, or learned from what you write in the chat while “Learn from my chats” is on; the personality and instructions you give the AI (its “Soul”); and any routines you set up, with their schedules and results. We do not keep health, religious, political, sexual-orientation, ethnic or financial details, exact locations, passwords or keys, or other people’s personal details in Memory. You can see, edit, switch off and delete all of it in Settings on the website or under Account in the iPhone app. With Memory switched off, nothing in it is used and nothing new is learned or kept.
  • Audio: the audio track of clips you edit (used to generate captions and transcripts), voiceover you record, and any voice recording you submit to create a cloned voice.
  • Support and communications: emails and messages you send us.

2.2 Information collected automatically

  • Usage data: pages visited, referrer, device type, browser, operating system, country and city derived from your IP, and an anonymous 30-minute session identifier stored in a first-party cookie (va_sid).
  • IP address: we receive your IP address with every request. We do not store it in plaintext — we store a salted SHA-256 hash of the IP for abuse prevention and aggregate analytics.
  • Cookies: we set a session cookie for authentication (issued by Supabase), a session-id cookie for traffic analytics, and Stripe sets cookies on its checkout pages. The Meta pixel sets advertising cookies on the website (see “Advertising measurement” below for what it collects and how to opt out).
  • Logs and diagnostics: standard server logs (timestamps, request paths, response codes, error stack traces) generated by our hosting provider.
  • Product analytics: we use PostHog to record a defined set of in-app events (for example: first launch, an export started, an export finished, a paywall shown) so we can see which features are used and where people get stuck. In the apps these events are associated with your account identifier. We do not use automatic capture of every tap or screen, and PostHog data is not used for advertising.
  • Session recordings: on the website we record how people move through a page — scrolling, clicks, the sections in view and, once you are signed in, the route you move to next — so we can see where the product is confusing and fix it. This covers the public marketing and course pages (such as the homepage, /ads, /ugc-ads, /analyze, /launchpad and /skool) and, since September 2026, the pages inside your account. No camera, microphone or screen capture is involved: what is recorded is the structure of the page your browser already drew, replayed later like a diagram.
  • What a recording never contains. Anything you type is masked in your browser before it leaves your device — we see that a field was used, never what was put in it. Passwords, card numbers and codes are never recorded. Some pages are excluded entirely and no recording runs on them at all: Settings, billing and checkout, your account page, the partner payout and tax forms, and every sign-in, sign-up and password-reset page. On those pages nothing is captured in the first place rather than captured and discarded.
  • How recordings are handled. They run only where our cookie notice allows analytics: off until you accept in opt-in regions, off if your browser sends a Global Privacy Control signal, and you can decline anywhere. A recording is tied to the same session identifier as our traffic analytics; when you are signed in, that session is linkable to your account, and we use it to understand where accounts get stuck rather than to watch a named person. Recordings are stored privately, are readable only by our own staff, are kept for 30 days and then deleted automatically, and are never sold, shared with advertisers or used to target ads. They may be summarised by an AI model to find the common points where people get stuck. To opt out, decline analytics in the cookie notice; to have existing recordings removed sooner, ask us at the address below.
  • Advertising measurement: on the website we load the Meta pixel so we can see which of our ads on Facebook and Instagram bring people to VidRocket. It reports the pages you view on our site, and the points at which you sign up or buy a plan, to Meta — together with an advertising identifier Meta reads from its own cookies, which lets Meta recognise you across sites and show you our ads. Where you complete a purchase we also send the same event from our servers so the record is complete when a browser blocks the pixel. It is not loaded in the desktop or iOS apps.
  • Where advertising cookies need your consent first: if you are in the European Economic Area, the United Kingdom, Switzerland, or Quebec, the pixel does not load at all until you accept it on the cookie banner — decline, or simply ignore the banner, and it never runs. Everywhere else it runs by default and the banner is how you turn it off. We determine which applies from the country your request comes from, and your choice is remembered in your browser. We also honour the Global Privacy Control signal wherever you are: if your browser or extension sends it, we treat that as declining advertising cookies unless you later accept them yourself. You can additionally use the off-Facebook activity and ad-preference controls in your Meta account.
  • Crash and error reporting: we use Sentry to receive error and crash reports (error message, stack trace, and the state of the app at the time of failure). Reports are associated with your account identifier so we can reproduce a failure you actually hit.
  • Push notification token: if you allow notifications on iOS, Apple issues a device token that we store against your account so we can tell you when a render is finished. It identifies your device installation, not you personally, and is deleted when it stops working or you delete your account.
  • Device permissions (iOS): the app asks for camera, microphone, and photo library access only when you use a feature that needs them. Media stays on your device until you choose to add it to a project, at which point it is uploaded as described above.

2.3 Information about third-party creators

When you scan a public profile, we fetch publicly available metadata and video content (titles, view counts, thumbnails, transcripts, frames) from YouTube, TikTok, or Instagram. We do not collect private accounts, private posts, follower lists, or personal contact information of those creators. The fetched material is processed to produce the analysis you requested and is retained per Section 8 (Retention).

2.4 Connected social accounts (TikTok, Instagram, YouTube)

You can connect a TikTok, Instagram, or YouTube account to VidRocket so you can send the videos you make in VidRocket to that account. Connecting is optional, it happens on the platform’s own sign-in page, and we never see your password for that platform.

  • TikTok. VidRocket connects to TikTok through TikTok Login Kit and the TikTok Content Posting API, and asks for two permissions: user.info.basic, which gives VidRocket your TikTok open ID, display name, and profile picture; and video.upload, which lets VidRocket upload a video you choose to your TikTok account as a draft. We also receive an access token and a refresh token from TikTok. We use your display name and profile picture only to show you which TikTok account is connected, and the tokens only to upload the videos you choose to send, when you send them (or at the time you scheduled). An uploaded video arrives in your TikTok inbox as a draft; you add the caption and publish it yourself inside TikTok. VidRocket does not read your TikTok videos, followers, likes, comments, or messages, does not post anything publicly on your behalf, and does not sell or share TikTok data, use it for advertising, or use it to train AI models.
  • Instagram and YouTube. We receive the account identifier and name we publish to, and access tokens. We use them to publish the videos you choose (with the caption and title you write) and to show you the view, like, and comment counts of your own recent posts.
  • Instagram auto-DM. If you turn on Auto-DM, you connect your Instagram professional account a second time, through Instagram’s own login, with three permissions: instagram_business_basic (your account’s ID, username, name and profile picture, and the username of a person who messages you), instagram_business_manage_comments (to receive the comments left on your posts, reply to them, and send the one private message Instagram allows in answer to a comment), and instagram_business_manage_messages (to receive the messages and button taps people send your account, and to answer them). Instagram then sends us, for your account only: the comments on your posts (the text, the commenter’s Instagram-scoped ID and username), and the messages and button taps people send you. We use them for one thing: to send the replies and messages you set up in your automations, to the people who commented or messaged. We store, per person who interacted with your account, their Instagram-scoped ID, username, when they last messaged you, whether they follow you (checked only when your automation asks for it), whether they asked never to be messaged again (replying STOP), and which of your automations answered them and whether they opened the link. We never message anyone who has not commented on your post or messaged your account, never message outside the window Instagram allows, and do not use this data for advertising, sell it, or use it to train AI models. Disconnecting the account under Auto-DM, or removing VidRocket from the apps in your Instagram settings, stops it immediately; disconnecting also deletes the automations and the history above.
  • Disconnecting. Choose Disconnect next to the account under Settings → Connected accounts on vidrocket.ai (or in the Publish panel of VidRocket Studio). This deletes the tokens and account details we hold for it immediately. You can also remove VidRocket from the app permissions in your TikTok, Instagram, or Google account settings. Deleting your VidRocket account deletes every connection. See Data deletion for the steps.

2.5 AI assistants you connect (Muse, Claude, ChatGPT)

You can connect VidRocket to an AI assistant you already use, such as Meta’s Muse, Claude, or ChatGPT, and ask it to make videos with your VidRocket account. Connecting is optional. It happens on a VidRocket sign-in and approval screen, so the assistant never sees your VidRocket password, and you can also create a personal access key in Settings for a tool of your own.

  • What we receive from the assistant. Only the requests it sends to VidRocket on your behalf: the instructions, product details, and scripts it passes on, links to photos and videos you shared with it (which we download into your VidRocket library so they can be used), and the name the assistant gives for itself and, where it identifies itself by one, its web address. We do not receive the rest of your conversation with the assistant.
  • What the assistant receives from us. The results of what it asked for: your credit balance, your saved products and creators, scripts, ad copy, scores, and links to the videos it made. A general connection can also read your Memory and Soul (Section 2) and your routines and their results, and add a line to your Memory — every line it adds is yours to see, edit and delete like any other; a Muse connection cannot. Some of those links, such as a finished ad’s video link, do not expire, so the assistant can return to an ad later; anyone who has such a link can watch that video. What the assistant then does with the results, including posting them, is governed by its provider’s own privacy policy (Meta for Muse, Anthropic for Claude, OpenAI for ChatGPT), not this one.
  • Spending and posting. Requests that make something spend your VidRocket credits. The ad tools show a price and will not start until it is approved, and every connection has a daily credit limit you can change in Settings. A connection made from Muse cannot post, schedule, or delete anything; Muse posts with Meta’s own tools. A general connection (for example from Claude or ChatGPT) can publish a video only to a social account you connected under Section 2.4.
  • What we store. For each connection: the assistant’s name, when you approved it and last used it, its daily credit limit, and a one-way hash of its access and refresh tokens (never the tokens themselves). Credits spent through a connection are marked as such in your credit history.
  • Disconnecting. Under Settings → Claude, ChatGPT & Muse on vidrocket.ai, press the remove button next to the connection. It stops working straight away. You can also remove VidRocket in the assistant’s own connector settings. Deleting your VidRocket account deletes every connection.

3. How we use information

  • To provide and operate the Service (authentication, video creation and editing, scans, analyses, chat, billing).
  • To send the videos you choose to the TikTok, Instagram, or YouTube account you connected (see Section 2.4).
  • To send AI providers (see Section 5) the inputs needed to generate your analysis.
  • To answer the requests an AI assistant you connected makes on your behalf (see Section 2.5).
  • To bill you, process refunds, and prevent payment fraud.
  • To debug, monitor performance, and detect abuse or attempted account compromise.
  • To improve the Service through product analytics and crash reporting (see Section 2.2).
  • To deliver notifications you have opted into, such as when a render finishes.
  • To send transactional email (sign-up confirmation, password reset, billing receipts).
  • To send marketing email (tips, new features, offers) only if you ticked the marketing box at sign-up or in Settings. We record when and where you agreed. Every marketing email carries an unsubscribe link, and Settings → Marketing email turns it off at any time.
  • To comply with our legal obligations and enforce our Terms of Service.

We do not sell or rent your personal information. We do notuse your private uploads, scan inputs, or chat prompts to train our own AI models.

4. Legal bases (EU/UK users)

If you are in the European Economic Area or United Kingdom, our legal bases are:

  • Contract: to deliver the Service you signed up for.
  • Legitimate interests: security, fraud prevention, analytics, and product improvement.
  • Consent: for optional marketing email; you can withdraw consent any time.
  • Legal obligation: tax, accounting, and lawful requests.

5. AI processing and subprocessors

VidRocket sends inputs to third-party AI and infrastructure providers to deliver the Service. By using VidRocket, you agree to the routing of your inputs to these providers under their respective terms.

ProviderPurposeWhat is sent
SupabaseAuthentication, database, file storageAccount data, uploads, analysis records
Anthropic (Claude)Vision and text analysisVideo frames, transcripts, your prompts
Google (Gemini, Veo)Video understanding, transcription, and generated videoYour clips and their audio, public videos fetched on your behalf, analysis prompts
OpenAIImage generation for the chat’s ChatGPT-style image codes, ChatGPT answers shown in course lessons, and speech-to-text when our main transcription service is unavailableThe photo and prompt you submit to those features; the audio of a clip being transcribed
ElevenLabsVoiceover, voice cloning, and generated musicScripts you write, voice recordings you submit
fal.aiImage and video generation, audio cleanup, lip-syncThe media and prompts you submit to those features
HiggsfieldImage and video generation, including animating a still imageThe photos, reference images, and prompts you submit to those features
HeyGenTalking-avatar videoThe portrait or avatar image and the script you submit
PexelsStock footage searchYour search terms
SociaVaultFetching the public Instagram profiles, posts, reels and comments you ask us to analyze or copy, and searching the public Facebook / Instagram Ad Library and TikTok’s top ads for a routine that reads the ads in your nicheThe public handle or link you submit; for an ad-reading routine, a few search words about your niche or product (never your name or account)
StripePayment processing (web)Email, billing details, purchase amount
AppleIn-App Purchase, sign-in, push notifications (iOS)Purchase and subscription status, sign-in identifier, device push token
PostHogProduct analyticsNamed in-app events and your account identifier
MetaAdvertising measurement on the websitePages you view on vidrocket.ai, signups and purchases, and Meta’s own advertising identifier
SentryCrash and error reportingError details and your account identifier
VercelWeb hosting and edge deliveryStandard request data
RailwayVideo rendering, FFmpeg, and worker queueYour clips and the media in a project you render
TikTok, Instagram (Meta), YouTube (Google)Publishing, only to an account you connect (see Section 2.4)The video you choose to send; for Instagram and YouTube, the caption and title you write
Instagram (Meta)Auto-DM, only for an Instagram account you connect to it (see Section 2.4)The public replies and private messages your automations send, to the people who commented on your posts or messaged your account

Our AI providers commit in their API terms not to use inputs submitted through those APIs to train their public models, and we do not enable any “training opt-in” flag. In the apps, AI features are gated behind an explicit consent prompt before anything of yours is sent for processing, and you can withdraw that consent at any time in your account settings.

Some generation providers route your request to an underlying model operated by a different company. In particular, fal.ai and Higgsfield offer models built by ByteDance (including the Seedance family) and Kuaishou (the Kling family). Where you choose one of those models, the media and prompt for that request are processed by that model’s operator, which may be located outside your country, including in China. If you would rather not have your media processed by a particular model operator, do not select that model.

6. Photos of people, faces, and voices

Several features accept a photo or recording and produce new media from it — animating a still image, generating a talking avatar, placing a subject into a new scene, or cloning a voice. When the image or recording you supply contains an identifiable person, that upload is personal information about that person, and in some places it is treated as a special or sensitive category.

  • What we do with it. We store the file you upload so the feature can run and so you can re-use it in your projects, and we transmit it to the provider that performs the generation (see the table above). We do not run face recognition, we do not attempt to identify who is in an image, and we do not build or store a faceprint, face template, or other biometric identifier from your uploads.
  • What we do not do with it. We do not sell it, we do not use it to train our own models, and we do not enable training on it at our providers.
  • Your responsibility. You may only upload a photo, video, or voice recording of a person if that person is you, or if you have that person’s permission. Uploading someone else’s face or voice without permission is prohibited by our Terms, and may also break the law where you or that person live. Never upload an image of a child.
  • Deletion. Delete an uploaded photo or recording, and any media generated from it, from your library at any time; deletion removes it from our storage on the schedule in the Retention section. Generation providers hold a short-lived copy for the duration of the request under their own terms. Deleting your account removes your uploads entirely — see Data deletion.
  • Legal basis (EU/UK). Where this processing involves special-category data, we rely on your explicit consent, given through the in-app prompt before the feature runs. You can withdraw it at any time in your account settings, which stops future processing.

Model operators run their own safety checks and may refuse a request that appears to depict a real person, a public figure, or a minor — including when the person is you. Those refusals come from the provider and are outside our control.

7. Sharing and disclosure

We share information only as follows:

  • With subprocessors listed in Section 5, under their data-protection terms.
  • With an AI assistant you connect: the results of the requests it makes on your behalf, as described in Section 2.5.
  • Public analyses: if you (or an administrator) explicitly mark an analysis or board as public, the analysis content and the public-creator metadata become viewable by anyone with the link or via our public library. Your email address is never shown on public pages.
  • Compelled disclosure: in response to valid legal process, with notice to you where lawfully possible.
  • Corporate transactions: if VidRocket or Hireabble Inc. is acquired or merges with another company, your data may be transferred under equivalent protections.

8. Retention

  • Account data: kept for the life of your account, plus up to 30 days after deletion to complete backups and reverse mistaken deletions.
  • Uploaded videos and extracted frames: kept until you delete them or your account is deleted, whichever is earlier. Inactive accounts may have storage purged after 12 months with prior email notice.
  • Scan results and chat history: retained as long as your account is active so you can revisit past scans.
  • Memory, Soul and Routines: kept until you delete them in Settings or on the Routines page, or delete your account. Deleting a memory removes it immediately; switching memory off stops it being used, and stops anything new being learned or kept, without deleting it.
  • Billing records: retained for 7 years to satisfy tax and accounting obligations.
  • Instagram auto-DM: the comments and messages Instagram sends us are kept for 30 days; the record of who your automations answered, and what was sent, for 90 days; the list of people who asked never to be messaged again for as long as the Instagram account stays connected, so they are never messaged again. All of it is deleted when you disconnect the account.
  • Server logs: 30 days.
  • Hashed-IP analytics: 13 months in aggregate form.
  • Product analytics and crash reports: retained by PostHog and Sentry for up to 12 months.
  • Advertising measurement: retained by Meta under its own data policy; we do not store pixel data ourselves.
  • Push notification tokens: until the token stops working, you turn notifications off, or you delete your account.
  • Connected AI assistants: the connection record and its token hashes are kept until you remove the connection or delete your VidRocket account, whichever is earlier.
  • Connected social accounts: tokens, account identifiers, display names, and profile pictures are kept until you disconnect the account or delete your VidRocket account, whichever is earlier.

9. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent for marketing email.
  • Lodge a complaint with your local data-protection authority.

Canadian residents have the rights described under PIPEDA and any applicable provincial privacy laws (including Alberta’s PIPA and Quebec’s Law 25). California residents have the rights described under the CCPA/CPRA. We do not sell or “share” personal information for cross-context behavioral advertising.

To exercise any of these rights, email privacy@vidrocket.aifrom the address on your account, or use your account settings. You can delete your account and its associated data directly in the iOS app (Profile → Delete account) and on the web, without contacting us. We will respond to emailed requests within 30 days.

10. Security

We use TLS in transit, encryption at rest for stored uploads and database backups, hashed passwords, scoped access controls, and least-privilege service credentials. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

11. International transfers

VidRocket is operated from Canada. Several of our subprocessors (notably Anthropic, Stripe, and Vercel) are located in the United States, so your information will be transferred to and processed there as well as in any other jurisdiction where our subprocessors operate. Where required for transfers out of the EEA or UK, we rely on Standard Contractual Clauses or equivalent transfer mechanisms.

12. Children

The Service is not directed to children, and we do not knowingly collect personal information from anyone under 16. The iOS app is rated for users 17 and older. If you believe a child has provided us data, contact us and we will delete it.

13. Third-party content and links

The Service displays content fetched from YouTube, TikTok, and Instagram. We are not responsible for those platforms’ privacy practices. Embedded videos play under the respective platform’s terms and may set their own cookies.

14. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects the latest revision. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect.

15. Contact

VidRocket (Hireabble Inc.)
Email: privacy@vidrocket.ai

© 2026 Hireabble Inc. All rights reserved.VidRocket is a product of Hireabble Inc.