Effective Date: July 6, 2026 Last Updated: September 7, 2026
This Privacy Policy explains how POVSync ("POVSync," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with the POVSync service (the "Service"). POVSync ingests a content creator's own livestream video-on-demand ("VOD") from supported platforms (e.g., Twitch, Kick), transcribes, segments, and classifies it using artificial intelligence, and renders an edited recap video.
Please read this Policy together with our [Terms of Service](/terms) and [Data Processing Agreement (DPA)](/dpa).
POVSync handles two distinct categories of data, and our role under privacy law differs for each. This distinction determines who is responsible for your data and how requests are handled.
| Layer | What it is | Our role | Who is responsible |
|---|---|---|---|
| (a) Account Data | Data about POVSync's own users — creators and the editors they invite (email, password hash, channel identity, billing, usage). | Controller | POVSync decides why and how this data is processed. Direct your requests to us. |
| (b) Content Data | Personal data contained *inside* a submitted VOD — faces, voices, spoken words/transcripts, on-screen chat usernames and messages — of the creator and of third parties who appear in the stream. | Processor | The creator who submits the VOD is the controller. POVSync processes this data only on the creator's instructions. Content-subject requests are routed to that creator. |
If you appear in, or are referenced in, a stream that a creator uploaded to POVSync and you wish to exercise rights over that content, see Section 8 (Content-Subject Requests) — your request generally must be directed to the creator who controls that content.
| Data | Examples | Source | Purpose | GDPR Lawful Basis |
|---|---|---|---|---|
| Identity & credentials | Email address, password hash, display name | You, at sign-up | Create and secure your account; authenticate you | Performance of a contract (Art. 6(1)(b)) |
| Channel identity | OAuth-verified Twitch/Kick channel handle and ID | OAuth provider, with your authorization | Verify you control the channel whose VODs you submit; prevent abuse | Performance of a contract; legitimate interests in preventing fraud (Art. 6(1)(f)) |
| Billing information | Subscription tier, transaction records, partial card data | You and Stripe (our payment processor) | Process payments and manage subscriptions | Performance of a contract; legal obligation for tax/accounting records (Art. 6(1)(c)) |
| Invited-editor data | Editor email and role/permissions | The inviting creator, or the editor | Enable collaborative editing of recaps | Performance of a contract; legitimate interests in providing collaboration features |
| Usage & device data | Log data, IP address, browser type, feature usage, render history | Automatically, as you use the Service | Operate, secure, debug, and improve the Service | Legitimate interests in maintaining and improving the Service (Art. 6(1)(f)) |
| Communications | Support tickets, emails | You | Respond to inquiries and provide support | Legitimate interests; performance of a contract |
We do not require or intentionally collect special-category data as Account Data. We do not store full payment card numbers; card processing is handled by Stripe.
When a creator submits a VOD, the file may contain personal data about the creator and about third parties — for example, guests, co-streamers, callers, and chat participants. This can include:
Our role. For Content Data, POVSync acts as a data processor acting on the documented instructions of the creator, who is the controller. We process Content Data only to provide the Service the creator requested — namely, to transcribe, segment, classify, and render a recap — and for no independent purpose of our own.
Lawful basis. As processor, we rely on the creator's instructions and our processing agreement with the creator (see Section 8 and our [DPA](/dpa)). The creator is responsible for establishing a lawful basis for the underlying content and for ensuring it has the rights and any necessary notices or consents to upload footage that may contain third parties.
Creator responsibility. The creator represents that it has the right to submit each VOD and to have it processed, and that doing so complies with applicable law and the source platform's terms. Content-subject requests are routed to the controlling creator (Section 8).
POVSync uses AI to turn a raw VOD into an edited recap. Specifically:
1. Transcription — the audio track is converted to a text transcript. 2. Segmentation & classification — the transcript and video are analyzed to identify and label notable moments (highlights, topic changes, etc.). 3. Rendering — selected segments are assembled into the produced recap.
Sub-processor for classification. To perform transcript classification, transcript text may be sent to Anthropic as a sub-processor. We configure this processing under a zero-data-retention arrangement, meaning the transcript text submitted for classification is not retained by the sub-processor after the request is completed and is not used to train its models. We do not use Content Data to train any POVSync model.
We do not use AI to make decisions that produce legal or similarly significant effects about individuals.
We practice data minimization — we keep data only as long as needed for the purpose it was collected.
| Data | Retention |
|---|---|
| Source VOD (uploaded video file) | Deleted within 24 hours of ingestion/processing. The original source video is not retained beyond this window. |
| Transcript text sent for classification | Not retained by the AI classification sub-processor (zero-retention); working copies are deleted as part of the source-deletion cycle. |
| Produced recap | Retained under the creator's control — stored so the creator can access, download, or delete it, and deleted when the creator deletes it or closes the account (subject to short backup-expiry windows). |
| Account Data | Retained while your account is active and for a reasonable period afterward, then deleted or anonymized, except where longer retention is required (e.g., tax, accounting, fraud-prevention, or legal-hold obligations). |
| Connected-platform OAuth tokens (YouTube, TikTok) | Revoked with the platform and deleted immediately when you disconnect the account. See Section 13. |
| Billing records | Retained as required by tax and accounting law. |
| Logs / usage data | Retained for a limited period for security, debugging, and abuse prevention, then deleted or aggregated. |
When data is deleted, residual copies in encrypted backups are purged on the normal backup-expiry cycle.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We disclose data only to the service providers / sub-processors needed to run the Service, each bound by contract to process data only on our instructions and to protect it:
| Sub-processor / Provider | Function | Data involved |
|---|---|---|
| Anthropic | AI transcript classification (zero-retention) | Transcript text (Content Data) |
| Modal | GPU compute for AI inference / video processing | VOD-derived Content Data during processing |
| Cloudflare R2 | Storage of recaps and transient working files | Recaps; transient source/working files |
| Supabase | Managed Postgres database (account records) | Account Data |
| Stripe | Payment and subscription processing | Billing Account Data |
| Render and Vercel | Application hosting and infrastructure | Account Data; transient Content Data |
A current list of sub-processors is available on request by emailing contact@povsync.com. We may also disclose data to comply with law, enforce our terms, protect rights and safety, or in connection with a corporate transaction (e.g., merger or acquisition), with notice where required.
We may process and store data in countries other than your own, including the United States. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum, together with supplementary measures where appropriate. To request a copy of the relevant transfer mechanism, contact us at contact@povsync.com.
Because POVSync is a processor for Content Data, we generally cannot independently grant access to, correct, or delete personal data embedded in a creator's VOD or recap, as we do not control the purpose of that processing.
For your own Account Data (where POVSync is the controller), see Section 9.
If you are in the EEA, UK, or Switzerland, you have the right to:
Timeline: We will respond within 30 days, extendable by up to 60 additional days for complex requests, with notice to you.
If you are a California resident, you have the right to:
Timeline: We will acknowledge your request within 10 business days and respond substantively within 45 calendar days, extendable by an additional 45 days with notice.
Submit a request to contact@povsync.com. We will take reasonable steps to verify your identity before responding, proportionate to the sensitivity of the data, and will not require excessive documentation. You may use an authorized agent where the law permits; we may require proof of authorization.
These rights apply to Account Data that POVSync controls. For Content Data embedded in a creator's VOD or recap, see Section 8.
We use cookies and similar technologies to operate the Service, remember your preferences, maintain sessions, and understand usage. We use Google Analytics 4 to measure and improve the Service. You can control cookies through your browser settings. Where required by law, we obtain consent for non-essential cookies before they are set.
We maintain technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, the prompt deletion of source VODs, and the zero-retention configuration for transcript classification. No system is perfectly secure; we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify affected parties and authorities as required by applicable law (e.g., supervisory authorities within 72 hours under GDPR, where applicable).
The Service is not directed to children, and we do not knowingly collect personal information from children under 16 (or under 13 where that is the applicable threshold). If you believe a child has provided us personal information as Account Data, contact us at contact@povsync.com and we will take appropriate steps to delete it. Creators are responsible for the content they submit, including any content involving minors.
Certain optional features — collectively, "Autopilot" — let a creator connect their own social accounts (currently YouTube and TikTok) so that POVSync can publish short-form clips of the creator's own stream to those accounts on the creator's instruction. Connecting an account is entirely optional and is always initiated by the creator.
How the connection works. When a creator chooses to connect an account, they authenticate directly on the platform's own sign-in page (Google/YouTube or TikTok) using OAuth. POVSync never receives or stores the creator's platform password. The platform returns a scoped access token that authorizes only the specific actions described below.
What we access, and why.
| Platform | Scope requested | What it permits | What POVSync does with it |
|---|---|---|---|
| YouTube (Google) | `youtube.upload` | Upload videos to the connected channel | Publish the creator's own clips as Shorts to their channel, at the creator's direction. We also read the connected channel's basic identity (channel id and name) solely to show which account is connected. |
| TikTok | `video.upload` (and, where enabled, `video.publish`) | Add a video to the account's drafts, or publish it | Publish the creator's own clips to their TikTok account, or place them in the account's drafts, at the creator's direction. |
We request the minimum scopes needed to post clips. We do not request or use access to read your videos, watch history, analytics, subscribers, comments, direct messages, or any other account data.
What we store. For a connected account we store the OAuth access and refresh tokens (used to post on your behalf), the connected account's external id and display name, and a record of the clips posted. Tokens are stored as secrets, are never displayed back to you, and are never sold or shared.
Revoking access. You can disconnect a platform at any time inside POVSync (Autopilot settings). Disconnecting revokes POVSync's authorization with the platform itself (Google's revocation endpoint for YouTube, TikTok's for TikTok), so the grant stops working at the source, and then deletes the stored tokens from our database. You can also revoke POVSync's access directly with the platform at any time:
What we delete, and when.
| Data | When it is deleted |
|---|---|
| OAuth access and refresh tokens | Revoked with the platform and deleted from our database immediately when you disconnect the account, and when we close your account at your request. |
| Connected-account identity (channel or account id, display name) | Deleted immediately when you disconnect that account. |
| Records of clips we posted for you (our clip and its title/caption, plus the resulting post id and URL) | Deleted when you delete the clip in POVSync, when we close your account at your request, or within 30 days of a deletion request to contact@povsync.com. |
| Any other data received from YouTube API Services | We do not download, store, or process YouTube audiovisual content, and we request no scope that would let us read your videos, analytics, subscribers, comments, or messages. Anything we did receive would be deleted within 30 days. |
To delete everything associated with your account, email contact@povsync.com. We complete verified deletion requests within 30 days.
Use of YouTube API Services. POVSync's Autopilot YouTube integration uses YouTube API Services. By connecting a YouTube account you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms). Google's handling of data is described in the Google Privacy Policy (https://policies.google.com/privacy). POVSync's use of information received from YouTube API Services complies with these terms.
Limited Use. POVSync's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We use Google user data only to provide and improve the user-facing Autopilot feature described above; we do not transfer or sell it, do not use it for advertising, and do not use it to train generalized or standalone AI/ML models.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and, where required, provide additional notice (e.g., by email or in-app notice). Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of the changes, to the extent permitted by law.
POVSync Email: contact@povsync.com
Data Protection Officer: Not appointed (not required for POVSync's current scale). Direct privacy questions to the email above.
EU / UK Representative (per GDPR Art. 27 / UK GDPR): Not appointed.
Terms · Privacy · DPA · Acceptable Use