VideoLens ← Back to videolens.io

Privacy Policy

Last updated: October 3, 2026 · Applies to videolens.io, VideoLens accounts and Pro, the hosted app, the ChatGPT plugin, and the VideoLens Chrome and Firefox extensions.

The short version

VideoLens gives you two explicit extension modes. In Private / BYOK mode, analysis goes directly from your browser to OpenAI with your key; VideoLens does not receive that analysis content unless you separately choose to upload completed reports to your cloud library. Your API key is never uploaded to VideoLens. In Pro / Managed mode, the content required for the analysis passes through VideoLens and Vercel AI Gateway to the configured AI provider (currently OpenAI) so you do not need a key. VideoLens does not retain raw frames or audio in its database. Completed reports and follow-up Q&A are saved automatically in your browser on your device; cloud storage remains optional and off by default. The extension contains no analytics.

Chrome and Firefox extensions

  • Private / BYOK analysis. The selected video's frames, audio or captions, page title, and your prompt go directly from the extension to OpenAI's API (api.openai.com) using your own API key. They are not sent to VideoLens.
  • Pro / Managed analysis. If you deliberately select Managed mode, the same analysis content is sent over HTTPS to videolens.io, which authenticates your subscription or starter allowance and sends it through Vercel AI Gateway to the configured AI provider (currently OpenAI). VideoLens does not write raw frames, audio chunks, captions, or prompts to its database or intentionally include them in application logs.
  • Your OpenAI API key. Stored in chrome.storage.local on your device only. It is not synced between browsers and is transmitted only to api.openai.com. Remove it any time in Settings.
  • Analysis results and local library. Completed reports, timelines, and Q&A history are saved automatically in local IndexedDB so you can continue or reopen them. This library stays in your browser profile, has no VideoLens-imposed report-count limit, and can be deleted report by report. You may explicitly upload existing reports and follow-up answers to your connected account, including reports made with your own API key. You may also enable cloud saving for new reports and follow-up answers. Cloud saving is off by default; local copies are retained. Turning cloud saving off stops future uploads and does not delete existing cloud copies.
  • Account connection. The extension stores a VideoLens session token and account email in chrome.storage.local. The token expires after 30 days and can be removed with Disconnect. Website login and billing credentials are never copied into the extension.
  • Browsing data. For YouTube, the extension asks once for optional access to youtube.com so capture works from the browser toolbar or sidebar; it reads the page only after you start an analysis, solely to find the selected video, captions, and page title. Other supported sites use the browser's temporary activeTab permission. VideoLens does not track your browsing or analyze pages in the background.
  • Analytics. The extension contains no analytics, telemetry, or error reporting of any kind.

Chrome Web Store Limited Use. VideoLens's use and transfer of information received through Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. The extension uses this information only to provide the video-analysis features the user requests.

Accounts, Pro, and cloud reports

  • Account data. We store your email address, account ID, subscription status, sign-in timestamps, managed-report usage, and the technical identifiers needed to connect your extension and Stripe customer. Supabase Auth handles email-link sign-in and any account password; VideoLens does not receive raw passwords.
  • Service administration. Authorized administrators can review membership, billing status, sign-in timestamps, and managed-report activity to operate and support VideoLens. Managed-report records include the title, source type, analysis mode, timestamps, and completion status supplied by the client, even when cloud report saving is off. We also retain operational AI diagnostics such as model names, HTTP status, duration, fallback use, and fixed error categories to diagnose failures. These diagnostics contain no prompts, media, raw error text, or AI response contents. The admin dashboard does not expose report contents, source videos, images, or audio. Private / BYOK scans stay on your device unless you choose to upload their reports to your cloud library; uploaded report titles and metadata are then included in administrative activity records.
  • Pairing data. Extension pairing challenges are random, single-use, and expire after 10 minutes. They contain no video content.
  • Cloud reports. When cloud saving is enabled, we store the completed structured report, including its title, source details, prompt, summary, findings, timeline text, mode, timestamped evidence, and follow-up questions and answers. Uploads do not consume managed AI report credits. We do not store the source video, sampled image files, or audio files.
  • Payments. Stripe processes payment-card and billing details. VideoLens stores Stripe customer, subscription, product, and price identifiers plus subscription status; it does not receive or store full card numbers.
  • Deletion. You can delete individual cloud reports from the account page. To delete your account and its stored VideoLens data, contact us at the address below. Stripe may retain transaction records as required for legal, tax, fraud-prevention, and accounting obligations.
  • Retention. Account records and cloud reports are kept while the account is active, until you delete a report or request account deletion. Connected-app grants remain until you revoke them or delete the account. Pairing challenges expire after 10 minutes, and extension connection tokens expire after 30 days. Billing records may be kept longer where law, tax, fraud-prevention, or accounting obligations require it.

Optional recipe lookup

Recipe mode can read the current YouTube video's creator description alongside its frames and captions. If you choose Look online for missing details, the video title, URL, creator description, and extracted recipe details are sent to OpenAI web search through your selected Private or Managed AI connection. Search queries may be shared with search providers. This option is off by default and does not send raw frames or audio to search. Recipe details, evidence labels, and cited source links are included in your saved report; cloud saving remains optional. Using your own OpenAI key may incur additional search charges.

ChatGPT plugin and connected apps

If you connect VideoLens to ChatGPT, VideoLens uses your account sign-in and asks you to approve access. The plugin can read your account email and reports you explicitly saved to your cloud library, including titles, summaries, findings, source links, transcript and visual timeline text, and timestamps. It does not access local-only reports or raw video files, and it cannot delete reports, change billing, or start a new analysis. Report data returned by a tool becomes available to the ChatGPT conversation you used to request it and is handled by OpenAI under your ChatGPT settings and OpenAI's terms. VideoLens does not create a separate persistent copy of MCP tool results or log report content in MCP request logs. You can revoke a connected app's access from your VideoLens account page; content already sent to ChatGPT remains subject to your ChatGPT settings.

Hosted app (app.videolens.io)

  • The hosted app processes selected videos on the VideoLens server and calls OpenAI with your key. Your key is held in server session memory only and is never written to a database. It is discarded when the server session expires.
  • Uploaded videos and generated artifacts live in an isolated temporary server-session directory used for re-runs and playback. Cleanup occurs when that session is released; closing a tab may not end it immediately. Download reports to keep them. Hosted reports are not automatically added to your account or cloud library.
  • The hosted app writes privacy-safe product events to its operational logs so we can measure whether the workflow succeeds. These events contain a random session identifier, workflow and mode, upload-versus-URL source type, success or non-sensitive error category, export format, and coarse duration or performance buckets.
  • Hosted-app product events never include videos, filenames, source URLs, prompts, reports, transcript text, extracted images, API keys, email addresses, or persistent cross-session identifiers.

Marketing-site analytics (videolens.io)

  • The public marketing site uses Vercel Web Analytics and Speed Insights to measure aggregate page visits, referrers, device/browser categories, approximate country or region, Core Web Vitals, and clicks on key links such as Launch App and GitHub.
  • Vercel Web Analytics does not use third-party cookies and stores anonymized, aggregated data. Conversion events include only the destination category and public page path — never video content, prompts, reports, API keys, or email addresses.
  • The Chrome and Firefox extensions remain free of analytics and telemetry. The hosted app records only the limited operational product events described above; measurement never includes analyzed content or reports.

Third parties

  • OpenAI — currently provides the AI models that process the text, audio chunks, and frames you analyze. Private mode uses your OpenAI account; Managed mode reaches OpenAI through Vercel AI Gateway. Processing is subject to OpenAI's privacy policy.
  • Vercel — hosts videolens.io, routes Managed-mode AI requests through Vercel AI Gateway, and provides privacy-friendly aggregate Web Analytics and Speed Insights for the public marketing site. Gateway processing is subject to Vercel's privacy policy.
  • Supabase — provides passwordless authentication and the database for account, entitlement, extension-pairing, usage, and opt-in cloud-report data.
  • Stripe — processes subscriptions and provides the hosted checkout and billing-management portal.
  • Railway — hosts app.videolens.io and its operational logs, including the limited hosted-app product events described above.
  • There are no ad networks or data brokers. We do not sell personal information or use analyzed video content for advertising.

Your choices

  • Remove your API key or uninstall the extension at any time — all locally stored data, including settings and saved reports, is deleted with it.
  • Use Private / BYOK mode without an account, delete local reports inside the extension, disable cloud saving while using Pro, delete cloud reports from the account page, disconnect the extension, or cancel Pro from the Stripe customer portal.
  • For privacy questions or an account-deletion request, email astrawebdevservices@gmail.com.

Changes

If this policy changes materially, the "last updated" date above will change and the new version will be posted at this URL. The extension never gains new data collection silently — additional permissions require your approval.

Managed service reliability and activation

For connected accounts, we retain account connection, managed report start/completion/failure, checkout start, and subscription activation milestones. These contain an account identifier, a fixed event name, an opaque deduplication key, and a timestamp. They do not contain video titles, URLs, filenames, prompts, report text, API keys, or payment details. Private/BYOK scans are not tracked. Only the administrator can view aggregate activation metrics.