VideoLens ← Back to videolens.io

Privacy Policy

Last updated: August 18, 2026 · Applies to videolens.io, VideoLens accounts and Pro, the hosted app, and the VideoLens Chrome extension.

The short version

VideoLens gives you two explicit extension modes. In Private / BYOK mode, analysis goes directly from your browser to OpenAI with your key; VideoLens does not receive the video content, prompt, key, or report. In Pro / Managed mode, the content required for the analysis passes through VideoLens and Vercel AI Gateway to the configured AI provider (currently OpenAI) so you do not need a key. VideoLens does not retain raw frames or audio in its database, and a completed report is stored only when you enable cloud saving. The extension contains no analytics.

Chrome extension

  • Private / BYOK analysis. The selected video's frames, audio or captions, page title, and your prompt go directly from the extension to OpenAI's API (api.openai.com) using your own API key. They are not sent to VideoLens.
  • Pro / Managed analysis. If you deliberately select Managed mode, the same analysis content is sent over HTTPS to videolens.io, which authenticates your subscription or starter allowance and sends it through Vercel AI Gateway to the configured AI provider (currently OpenAI). VideoLens does not write raw frames, audio chunks, captions, or prompts to its database or intentionally include them in application logs.
  • Your OpenAI API key. Stored in chrome.storage.local on your device only. It is not synced between browsers and is transmitted only to api.openai.com. Remove it any time in Settings.
  • Analysis results. In Private mode, reports, timelines, and Q&A history exist only in your browser. In Managed mode, the completed report is also stored in your account only if you enable “Save completed reports to my cloud library.” That option is off by default.
  • Account connection. The extension stores a VideoLens session token and account email in chrome.storage.local. The token expires after 30 days and can be removed with Disconnect. Website login and billing credentials are never copied into the extension.
  • Browsing data. The extension reads a page only when you invoke it on that page (Chrome's activeTab permission), solely to find the video element, captions, and page title. It does not track your browsing, run in the background, or inject anything into pages you haven't invoked it on.
  • Analytics. The extension contains no analytics, telemetry, or error reporting of any kind.

Chrome Web Store Limited Use. VideoLens's use and transfer of information received through Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. The extension uses this information only to provide the video-analysis features the user requests.

Accounts, Pro, and cloud reports

  • Account data. We store your email address, account ID, subscription status, managed-report usage, and the technical identifiers needed to connect your extension and Stripe customer. Passwordless sign-in is provided by Supabase Auth.
  • Pairing data. Extension pairing challenges are random, single-use, and expire after 10 minutes. They contain no video content.
  • Cloud reports. When cloud saving is enabled, we store the completed structured report, including its title, summary, findings, timeline text, mode, and timestamped evidence. We do not store the source video, sampled image files, or audio files.
  • Payments. Stripe processes payment-card and billing details. VideoLens stores Stripe customer, subscription, product, and price identifiers plus subscription status; it does not receive or store full card numbers.
  • Deletion. You can delete individual cloud reports from the account page. To delete your account and its stored VideoLens data, contact us at the address below. Stripe may retain transaction records as required for legal, tax, fraud-prevention, and accounting obligations.

Hosted app (app.videolens.io)

  • Your OpenAI API key is held in session memory only and is never written to a database. Closing the tab discards it.
  • Uploaded videos and generated artifacts live in an ephemeral per-session cache used to make re-runs cheap, and are not retained as a dataset or shared.
  • The hosted app writes privacy-safe product events to its operational logs so we can measure whether the workflow succeeds. These events contain a random session identifier, workflow and mode, upload-versus-URL source type, success or non-sensitive error category, export format, and coarse duration or performance buckets.
  • Hosted-app product events never include videos, filenames, source URLs, prompts, reports, transcript text, extracted images, API keys, email addresses, or persistent cross-session identifiers.

Marketing-site analytics (videolens.io)

  • The public marketing site uses Vercel Web Analytics and Speed Insights to measure aggregate page visits, referrers, device/browser categories, approximate country or region, Core Web Vitals, and clicks on key links such as Launch App and GitHub.
  • Vercel Web Analytics does not use third-party cookies and stores anonymized, aggregated data. Conversion events include only the destination category and public page path — never video content, prompts, reports, API keys, or email addresses.
  • The Chrome extension remains free of analytics and telemetry. The hosted app records only the limited operational product events described above; measurement never includes analyzed content or reports.

Third parties

  • OpenAI — currently provides the AI models that process the text, audio chunks, and frames you analyze. Private mode uses your OpenAI account; Managed mode reaches OpenAI through Vercel AI Gateway. Processing is subject to OpenAI's privacy policy.
  • Vercel — hosts videolens.io, routes Managed-mode AI requests through Vercel AI Gateway, and provides privacy-friendly aggregate Web Analytics and Speed Insights for the public marketing site. Gateway processing is subject to Vercel's privacy policy.
  • Supabase — provides passwordless authentication and the database for account, entitlement, extension-pairing, usage, and opt-in cloud-report data.
  • Stripe — processes subscriptions and provides the hosted checkout and billing-management portal.
  • Railway — hosts app.videolens.io and its operational logs, including the limited hosted-app product events described above.
  • There are no ad networks or data brokers. We do not sell personal information or use analyzed video content for advertising.

Your choices

  • Remove your API key or uninstall the extension at any time — all locally stored data (key and settings) is deleted with it.
  • Use Private / BYOK mode without an account, disable cloud saving while using Pro, delete saved reports from the account page, disconnect the extension, or cancel Pro from the Stripe customer portal.
  • For privacy questions or an account-deletion request, email astrawebdevservices@gmail.com.

Changes

If this policy changes materially, the "last updated" date above will change and the new version will be posted at this URL. The extension never gains new data collection silently — Chrome requires updated permissions to be re-approved.