XYZ Youtube

BlogPricingAboutContact
Sign InSign Up

Privacy Policy

Last updated: March 13, 2026

1. Introduction

Welcome to [COMPANY NAME] ("[COMPANY NAME]", "we", "us", or "our"). We operate the website [DOMAIN NAME] and provide AI-powered video analysis, translation, and summarization services (collectively, the "Service").

This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information when you access or use our Service. Please read it carefully. If you do not agree with any part of this policy, you must discontinue use of the Service.

This Privacy Policy is designed to comply with applicable data protection and privacy laws, including:

  • The General Data Protection Regulation (EU) 2016/679 ("GDPR") — for users in the European Economic Area (EEA)
  • The UK General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR") — for users in the United Kingdom
  • The California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA") — for California residents
  • Law No. 6698 on the Protection of Personal Data ("KVKK") — for users in the Republic of Turkey
  • Other applicable national, state, or territorial data protection laws

2. Data Controller and Contact Information

The data controller responsible for your personal information is:

Company Name: [COMPANY NAME]

Website: [DOMAIN NAME]

Registered Address: [COMPANY ADDRESS]

Privacy Contact: [PRIVACY EMAIL]

For users in the EU or UK who wish to exercise their rights or contact our Data Protection Officer (DPO), please write to [PRIVACY EMAIL]. We will acknowledge your inquiry within 72 hours and respond substantively within 30 calendar days.

For Turkish users, our KVKK data controller representative can be reached at the same email address. We will respond within 30 days as prescribed by KVKK Article 13.

3. Information We Collect

3.1 Information You Provide Directly

  • Account Registration Data: Email address, chosen username or display name (optional), and a securely hashed password when you create an account.
  • Profile Information: Country of residence and language preferences you set in your account settings.
  • Payment and Billing Information: Cardholder name, billing address, and payment card details as required by our payment processor. We do not store full card numbers on our servers; all sensitive payment data is processed by PCI-DSS-compliant third-party processors.
  • Content Submissions: YouTube video URLs and any configuration preferences (e.g., target language, output format) you submit when creating a task.
  • Communications: Emails, support requests, feedback, or other messages you send to us, including metadata such as date, time, and your email address.

3.2 Information Collected Automatically

  • Log and Access Data: IP address, browser type and version, operating system, referring/exit URLs, pages visited, date and time of access, and HTTP status codes.
  • Device Information: Device type, screen resolution, device identifiers, and time zone.
  • Usage and Interaction Data: Features accessed, task types requested, task history, processing durations, error events, and click-stream data.
  • Cookies and Local Storage: Session identifiers, preference tokens, and analytics identifiers as described in our Cookie Policy.

3.3 Information from Third Parties

  • YouTube / Google: Publicly available video metadata (title, description, channel) and transcript data retrieved via the YouTube Transcript API. We do not access your personal Google account and do not store video content itself.
  • AI Processing Providers: When transcripts are sent to our AI API partners for translation or summarization, only the transcript text and processing instructions are transmitted. No personal account information is included.
  • Payment Processors: Transaction confirmation, payment status, and risk-scoring signals from our payment service providers.
  • Analytics Providers: Aggregated and, where consented, pseudonymized usage statistics from services such as Google Analytics.

4. Legal Bases for Processing Personal Data (EU / UK GDPR)

Where we process personal data of individuals in the EEA or UK, we rely on the following legal bases under Article 6 of the GDPR / UK GDPR:

  • Performance of a Contract (Art. 6(1)(b)): Processing necessary to create and manage your account, authenticate your session, process AI tasks you request, manage your subscription, and handle payments.
  • Legitimate Interests (Art. 6(1)(f)): Detecting and preventing fraud, abuse, and security threats; improving Service quality and reliability; conducting aggregated analytics; sending service-related announcements. We have assessed that our legitimate interests do not override your fundamental rights and freedoms.
  • Consent (Art. 6(1)(a)): Where you have given freely given, specific, and informed consent — for example, for optional analytics cookies or email marketing. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
  • Compliance with Legal Obligations (Art. 6(1)(c)): Processing required to meet applicable legal requirements such as tax record-keeping, financial reporting, or responding to lawful regulatory requests.

We do not intentionally collect or process special categories of personal data (Art. 9 GDPR), such as health data, racial or ethnic origin, political opinions, religious beliefs, or biometric data. If such data is inadvertently submitted (e.g., within a video transcript), we will delete it promptly upon discovery.

5. How We Use Your Information

We use personal data for the following specific purposes:

  • Account Management and Authentication: Creating and maintaining your account, verifying your identity, managing session tokens, and enabling password recovery.
  • Service Delivery: Processing your AI task requests (translation, summarization, analysis), delivering results to your account, and storing task history.
  • Subscription and Billing Management: Processing payments, issuing receipts and invoices, managing plan upgrades and downgrades, and handling refund requests.
  • Technical Operations: Monitoring system performance, diagnosing bugs and errors, conducting load balancing, and maintaining data backups.
  • Security and Fraud Prevention: Detecting unusual access patterns, investigating potential security incidents, enforcing rate limits, and protecting against misuse.
  • Personalization and Preferences: Remembering your language, theme (dark/light mode), and task configuration preferences across sessions.
  • Communications: Sending transactional emails (account verification, password resets, billing confirmations, service outage notices) and, where you have consented, marketing emails or product updates.
  • Legal and Regulatory Compliance: Retaining records as required by tax, accounting, or other regulatory obligations; responding to court orders or lawful regulatory inquiries.
  • Analytics and Service Improvement: Using aggregated, pseudonymized data to understand feature adoption, identify usability issues, and improve AI output quality.

We will not use your personal data for automated decision-making that produces legal or similarly significant effects without your explicit consent or a lawful basis.

6. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data to third parties. We may share your information only in the following circumstances:

6.1 Authorized Service Providers (Data Processors)

We engage trusted third-party service providers who act as data processors on our behalf, bound by written Data Processing Agreements (DPAs) that restrict their use of your data to only what is necessary for the contracted service:

  • Cloud Infrastructure and Hosting: Providers hosting our application servers, databases, and storage systems.
  • AI / Large Language Model (LLM) Providers: API services (e.g., OpenRouter) that process video transcript text for AI-powered tasks. Only transcript content and task configuration are shared — no personally identifiable account data.
  • Payment Processors: Services such as Stripe for secure, PCI-DSS compliant payment processing.
  • Email Infrastructure Providers: Services used to deliver transactional and account emails.
  • Analytics Services: Providers such as Google Analytics for aggregated, anonymized usage statistics. These operate under their own privacy policies and, where applicable, Google Analytics Data Processing Addendum.
  • Error Monitoring and Logging Services: Tools used to capture application errors and performance metrics for debugging.
  • Content Delivery Networks (CDN): Networks that cache static assets to improve load times globally.

6.2 Legal and Regulatory Disclosures

We may disclose personal data if required by applicable law, court order, government regulation, or legal process (including subpoenas, warrants, or official requests from law enforcement). We will, where legally permissible, notify you of such requests before complying.

6.3 Protection of Rights

We may disclose information when we believe in good faith that disclosure is necessary to protect [COMPANY NAME]'s legal rights, enforce our Terms of Service, prevent fraud, protect the safety of any individual, or address security threats.

6.4 Corporate Transactions

In the event of a merger, acquisition, asset sale, reorganization, or insolvency proceeding involving [COMPANY NAME], your personal data may be transferred to a successor entity. We will notify you via email and a prominent Service notice at least 30 days before any such transfer and before your data becomes subject to a materially different privacy policy.

6.5 With Your Consent

We may share your data with specific third parties when you have provided clear, explicit consent for a defined purpose.

7. International Data Transfers

Your personal data may be transferred to, stored in, or processed in countries outside your country of residence. We are committed to ensuring that all such international transfers comply with applicable data protection law.

  • EU / EEA to Third Countries: We use the European Commission-approved Standard Contractual Clauses (SCCs) as the primary transfer mechanism for transfers from the EEA to countries without an adequacy decision. Where an adequacy decision exists, we rely on that decision.
  • UK to Third Countries: For transfers from the UK, we use the UK Information Commissioner's Office (ICO) International Data Transfer Agreement (IDTA) or Addendum to the EU SCCs, as appropriate.
  • Turkey (KVKK): For transfers of personal data belonging to Turkish residents abroad, we comply with the requirements of KVKK Articles 8 and 9, relying on either the explicit consent of the data subject, or adequate protection measures approved by the Personal Data Protection Board (Kurul).
  • US Transfers: Where personal data of US residents is transferred internationally, we ensure that service providers maintain equivalent security standards and contractual data protection obligations.

You may request a copy of the applicable transfer safeguards by contacting us at [PRIVACY EMAIL].

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, or as required by law. Our standard retention schedules are:

  • Account and Profile Data: Retained for the duration of your active account and for up to 3 years following account deletion, unless a longer period is required by applicable law or litigation holds.
  • Video Transcripts (Processing Data): Transcript text sent to AI providers for processing is deleted within 24 hours of task completion. We do not store copies of video content.
  • Task Results (Translations, Summaries, Analyses): Retained in your account for 12 months from creation, or until you manually delete them, whichever comes first.
  • Payment and Financial Records: Retained for a minimum of 7 years to comply with tax authority requirements (applicable in the US, UK, EU, and Turkey).
  • Server and Access Logs: Retained for up to 90 days for security, debugging, and operational monitoring purposes, then permanently deleted or anonymized.
  • Email and Support Communications: Retained for up to 3 years from the date of last interaction.
  • Cookie Data: Session cookies are deleted when you close your browser; persistent cookies for up to 24 months. See our Cookie Policy for details.

Upon expiry of applicable retention periods, data is securely deleted, anonymized, or pseudonymized in accordance with our internal data disposal procedures.

9. Your Rights and How to Exercise Them

9.1 Rights Under EU / UK GDPR

If you are located in the EEA or the United Kingdom, you have the following rights under the GDPR / UK GDPR:

  • Right of Access (Art. 15 GDPR): Obtain a copy of the personal data we hold about you and information about how it is processed.
  • Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data without undue delay.
  • Right to Erasure — "Right to be Forgotten" (Art. 17 GDPR): Request deletion of your personal data where it is no longer necessary for the purpose it was collected, you have withdrawn consent, or you object to processing and there are no overriding legitimate grounds.
  • Right to Restriction of Processing (Art. 18 GDPR): Request that we restrict processing of your data in certain circumstances (e.g., while you contest the accuracy of the data).
  • Right to Data Portability (Art. 20 GDPR): Receive a structured, commonly used, machine-readable copy of your personal data and, where technically feasible, have it transmitted to another controller.
  • Right to Object (Art. 21 GDPR): Object at any time to processing of your data based on legitimate interests, including profiling, or for direct marketing purposes.
  • Right to Withdraw Consent: Withdraw any previously given consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • Right Not to Be Subject to Automated Decision-Making: Not be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects.
  • Right to Lodge a Complaint: File a complaint with your national supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In Germany, it is the relevant Landesbeauftragter. You may find your national DPA at edpb.europa.eu.

9.2 Rights Under California Law (CCPA / CPRA)

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

  • Right to Know / Access: Request that we disclose the categories and specific pieces of personal information collected about you in the preceding 12 months, the sources and purposes of collection, and categories of third parties with whom we share it.
  • Right to Delete: Request deletion of personal information we collected, subject to lawful exceptions (e.g., completing transactions, detecting security incidents, complying with legal obligations).
  • Right to Correct: Request that we correct inaccurate personal information we maintain about you.
  • Right to Opt Out of Sale or Sharing: We do not sell personal information to third parties for monetary consideration, nor do we share it for cross-context behavioral advertising. You may contact us to confirm this at any time.
  • Right to Limit Use of Sensitive Personal Information: We do not use or disclose sensitive personal information beyond what is reasonably necessary to provide the Service.
  • Right to Non-Discrimination: We will not deny you goods or services, charge different prices, provide a different quality of service, or retaliate against you for exercising your CCPA/CPRA rights.

To submit a verifiable consumer request, contact us at [PRIVACY EMAIL] or via your account settings. We will verify your identity before processing requests. Authorized agents may submit requests on your behalf with appropriate written authorization.

9.3 Rights Under Turkish Law (KVKK)

If you are a Turkish resident, under KVKK Article 11 you have the right to:

  • Learn whether your personal data has been processed (işlenip işlenmediğini öğrenme).
  • Request information about the processing if your data has been processed (işlenmişse buna ilişkin bilgi talep etme).
  • Learn the purpose of processing and whether data is used consistent with that purpose (işlenme amacını ve bunların amacına uygun kullanılıp kullanılmadığını öğrenme).
  • Know the third parties to whom your data has been transferred, domestically or internationally (yurt içinde veya yurt dışında kişisel verilerin aktarıldığı üçüncü kişileri bilme).
  • Request correction of incomplete or inaccurate data (eksik veya yanlış işlenmiş olması hâlinde bunların düzeltilmesini isteme).
  • Request deletion or destruction when the conditions requiring processing no longer apply (silinmesini veya yok edilmesini isteme).
  • Request notification to third parties to whom data was transferred regarding any corrections or deletions (düzeltme ve silme işlemlerinin üçüncü kişilere bildirilmesini isteme).
  • Object to results arising from automated analysis of personal data that are adverse to you (münhasıran otomatik sistemler vasıtasıyla işlenen verilerinizin aleyhinize bir sonucun ortaya çıkmasına itiraz etme).
  • Claim compensation for damages resulting from unlawful processing (kişisel verilerin kanuna aykırı olarak işlenmesi sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme).

KVKK requests must be submitted in writing by post to [COMPANY ADDRESS] or by email to [PRIVACY EMAIL]. We will respond within 30 days. If your request is denied or unsatisfactorily handled, you may lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK) at kvkk.gov.tr.

10. Children's Privacy

Our Service is not directed to children under the age of 16 years (or the minimum digital age of consent in your jurisdiction, if higher). We do not knowingly collect, process, or store personal information from individuals under 16 without verified parental or guardian consent.

If you are a parent or legal guardian and believe your child has created an account or submitted personal information to us without your consent, please contact us immediately at [PRIVACY EMAIL]. Upon verification, we will promptly delete the child's personal data and, where applicable, the associated account.

For US residents, we comply with the Children's Online Privacy Protection Act (COPPA), which requires verifiable parental consent before collecting personal information from children under 13. For EU/EEA users, we comply with Article 8 of the GDPR regarding the age of consent for information society services, which may be set by individual member states between 13 and 16.

11. Cookies and Similar Technologies

We use cookies, browser local storage, and similar tracking technologies to operate and improve our Service. These technologies allow us to authenticate users, preserve preferences, analyse Service usage, and deliver a consistent experience.

Where required by applicable law — including the EU ePrivacy Directive ("Cookie Directive"), the UK Privacy and Electronic Communications Regulations (PECR), and KVKK — we will obtain your prior informed consent before placing non-essential cookies or similar technologies on your device.

For full details on the categories of cookies we use, the specific cookies set, their purposes, retention periods, and instructions for managing your preferences, please review our dedicated Cookie Policy.

12. Data Security

We implement appropriate technical and organizational security measures designed to protect your personal data against unauthorized access, accidental loss, destruction, alteration, and unlawful processing. Our security practices include:

  • Encryption of all data in transit using TLS 1.2 or higher (HTTPS).
  • Encryption of sensitive data at rest using AES-256 or equivalent standards.
  • Secure password storage using adaptive hashing algorithms (e.g., bcrypt).
  • Strict role-based access controls limiting data access to authorized personnel with a legitimate need.
  • Regular security assessments, vulnerability scans, and periodic penetration testing.
  • Automated monitoring and alerting for suspicious access patterns and anomalies.
  • Documented incident response procedures aligned with GDPR's 72-hour breach notification obligation and UK GDPR / KVKK equivalent requirements.
  • Employee training on data protection obligations and information security best practices.

Despite our efforts, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security of your data, and you accept this inherent risk when using the Service. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately at [PRIVACY EMAIL].

13. Third-Party Links and Embedded Services

Our Service may contain links to or embed content from third-party websites and services (e.g., YouTube). These third parties operate independently under their own privacy policies, over which we have no control. We are not responsible for the privacy practices or content of third-party sites. We encourage you to review the privacy policies of any third-party services you access through our platform.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our data practices, legal requirements, or the features of our Service. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Send an email notification to all registered account holders at least 30 days before the changes take effect.
  • Display a prominent notice on the Service.

Your continued use of the Service after the effective date constitutes your acceptance of the revised Privacy Policy. If you do not agree with the updated terms, you must stop using the Service and may request account deletion by contacting us. We will retain certain data post-deletion as required by law and described in Section 8.

15. Contact Us and Supervisory Authorities

To exercise any of your rights described in this policy, ask questions about our data practices, or raise a concern, please contact:

Email (preferred): [PRIVACY EMAIL]

Postal Address: [COMPANY NAME] — Data Protection Team, [COMPANY ADDRESS]

Response Time: We will acknowledge receipt within 72 hours and provide a full response within 30 calendar days. For complex GDPR requests, we may extend this by a further 60 days and will notify you accordingly.

You also have the right to contact or lodge a complaint with the relevant supervisory authority in your jurisdiction:

  • EU: Your national Data Protection Authority (DPA). A full list is available at edpb.europa.eu/about-edpb/board/members.
  • UK: Information Commissioner's Office (ICO) — ico.org.uk
  • USA (California): California Privacy Protection Agency (CPPA) — cppa.ca.gov
  • Turkey: Kişisel Verileri Koruma Kurumu (KVKK) — kvkk.gov.tr

Company

BlogAbout UsCareersComing SoonChangelogComing Soon

Legal

Privacy PolicyTerms of ServiceCookie Policy

Support

Contact UsHelp CenterFAQRSS Feed

Follow Us

XYZ Youtube © 2026

Made with ❤️ in Ankara

We use cookies

We use cookies to enhance your browsing experience, provide personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. You can manage your preferences or learn more in our Cookie Policy.