LEGAL_DOC

Privacy Policy

Last updated: May 2026

1. Overview

VideoKavach ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights. It applies to all users of videokavach.com and the VideoKavach API.

2. Data We Collect

2a. Account Data

  • Name, email address, phone number (optional)
  • Billing information (processed by Stripe — we do not store card numbers)
  • Password (bcrypt-hashed, never stored in plaintext)

2b. Video Content Metadata

  • Video titles, durations, file sizes, upload timestamps
  • Transcoded variant information
  • Custom thumbnails and captions you upload

2c. Viewer Identity Data (passed by you)

When you embed a video, you pass viewer identity (viewer_id, viewer_email, viewer_phone) in the signed embed token. This data is used solely for watermarking and leak forensics on your behalf. We store it in playback session logs for up to 90 days.

2d. Usage & Technical Data

  • Storage bytes used, bandwidth delivered per month
  • API request logs (for rate limiting and abuse detection)
  • Webhook delivery logs
  • Server-side logs (IP addresses, user agents) retained for 30 days

3. How We Use Your Data

  • Service delivery: Transcoding, encrypting, and serving your videos.
  • Billing: Calculating usage-based quotas and processing Stripe payments.
  • Security: Detecting abuse, validating API keys, enforcing rate limits.
  • Watermarking: Embedding viewer identity overlays to enable leak tracing.
  • Communications: Sending transactional emails (video ready notifications, quota warnings, account alerts). We do not send marketing emails without opt-in.
  • Product improvement: Anonymised, aggregated usage analytics to improve the platform.

4. Data Sharing

We do not sell your data. We share it only with:

  • Cloudflare R2 / S3-compatible storage: Encrypted video segments stored at rest.
  • Stripe: Payment processing. Governed by Stripe's Privacy Policy.
  • ZeptoMail (Zoho): Transactional email delivery.
  • Modal / serverless compute: FFmpeg transcoding jobs. No video content is retained after processing.
  • Law enforcement: Only when legally required under Indian law (IT Act, DPDPA 2023).

5. Data Retention

  • Video content is retained until you delete it or your account is terminated.
  • Playback session logs: 90 days.
  • Server access logs: 30 days.
  • Billing records: 7 years (as required by Indian tax law).
  • Account data: Deleted within 30 days of account termination on request.

6. Your Rights

Under the Digital Personal Data Protection Act 2023 (DPDPA) and applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data (right to erasure).
  • Withdraw consent for processing where consent is the legal basis.
  • File a grievance with us (see Contact below).

To exercise these rights, email [email protected]. We will respond within 30 days.

7. Security

All video segments are encrypted with AES-128 at rest. All data in transit uses TLS 1.2+. API keys are stored hashed. Encryption keys are stored encrypted with a master key. We conduct regular security reviews.

8. Cookies

We use a single session cookie for authentication (HttpOnly, Secure, SameSite=Lax). We do not use tracking cookies, analytics cookies, or third-party advertising cookies.

9. Children

The Service is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us immediately.

10. Changes to this Policy

We may update this policy. We will notify registered users by email before material changes take effect. The current version is always available at videokavach.com/legal/privacy.

11. Contact & Grievance Officer

For privacy questions, data requests, or to file a grievance:

VideoKavach

[email protected]

Response time: within 30 days