1. Privacy at a glance
The following notes give a simple overview of what happens to your personal data when you visit this website.
2. Responsible party
The party responsible for data processing on this website is:
Benjamin Roul
Wächterstraße 51
72074 Tübingen
Germany
Email: benjamin.roul.26@gmail.com
The responsible party is the natural or legal person who, alone or together with others, decides on the purposes and means of the processing of personal data.
3. Data collection on this website
Server log files
When the pages are accessed, our hosting provider automatically collects information that your browser transmits: browser type and version, the operating system used, the referrer URL, the time of the request and the IP address. The legal basis is Art. 6 (1) lit. f GDPR — operating a technically error-free website is not possible without this data. It is not merged with other data sources.
User account
For sign-up we store your email address and, if you sign in with Google, your name and profile picture. The legal basis is Art. 6 (1) lit. b GDPR (performance of the usage contract). If you delete your account, this data is deleted.
Cookies
We use exclusively technically necessary cookies: a signed session cookie that keeps you logged in, and a short-lived cookie that secures the sign-in process against unauthorized access. Both are required for operation (Art. 6 (1) lit. f GDPR, § 25 (2) no. 2 TDDDG) and therefore do not require consent. We do not use tracking or advertising cookies.
Your videos and clips
To provide the service we download the videos you specify, analyze them, generate clips from them and store these until you delete them.
Two things leave our server in the process: first, the audio track of the video goes to a transcription service that turns it into text. Then this text goes to a language model that evaluates it so that your clips can be created from it. Both providers are processors under Art. 28 GDPR (see section 4).
If someone is speaking in your video, the voice and the content of what is said are part of this transmission — including of people other than yourself. Please make sure you only process material for which you hold the necessary rights and consents. Data from your account and your Google tokens are not sent along.
4. Service providers and processing
We use the following service providers for operation. Data processing agreements under Art. 28 GDPR exist with all of them; transfers to the USA are safeguarded by standard contractual clauses or the EU-US Data Privacy Framework.
- Vercel — hosting and delivery of the website.
- Supabase — database for account, channel and clip data.
- Resend — sending sign-in and notification emails.
- Hostman — server on which the videos are analyzed and the clips are rendered. The server is located in Germany; for this step your videos do not leave the EU.
- Speech-recognition provider — converts the audio track of your video into text. Processing in the USA.
- Language-model provider — automated evaluation of this text to create your clips. Processing in the USA.
We list the last two providers as a category rather than by name — Art. 13 (1) lit. e GDPR expressly permits categories as well for naming recipients. On request we will tell you the specific providers at any time; write to the address in section 8. Neither of them uses your content to train their own models.
5. Analytics tools and advertising
This website currently does not use any analytics tools or ad networks. Future implementations will be announced separately.
6. YouTube API Services
Voql uses the YouTube API Services to upload clips to the YouTube channel you have linked with your account. By using this feature you agree to the YouTube Terms of Service. The Google Privacy Policy additionally applies.
What data we receive from Google
When you link a channel, we receive an access and a refresh token from Google, as well as your channel's name and ID. We show you the channel name in the dashboard so it is clear where a clip is being published. We need the tokens because scheduled uploads run hours to days after you approve them. We do not read any comments, subscriber lists or statistics.
We do not pass on this data received from Google to anyone — not to processors, not to ad networks, not to data brokers, and we do not sell it. It leaves our servers exclusively toward Google itself, to carry out the upload you initiated.
We also do not use this data to develop, improve or train AI or machine-learning models — neither our own nor those of others. The language models that Voql uses to create your clips never see any data from Google APIs; they work exclusively with the video material you specified yourself.
How we protect this data
Your Google tokens are the most sensitive data we hold — whoever has them can publish in your name. This is why the following applies to them:
- Stored encrypted — access and refresh tokens are stored in the database encrypted with AES-256-GCM, each value with its own initialization vector. The key is not in the database but kept separately in the server environment. Anyone who got hold of the database would still not have usable tokens.
- Transmitted encrypted — access to clipaxt.com and all calls to the Google APIs run exclusively over TLS.
- Never in the browser — tokens do not leave the server. The interface only receives the information whether an authorization is valid, not the authorization itself.
- Scoped to your account — every database access is bound to your user ID, additionally secured by Row Level Security. Before every upload we check that the token still belongs to the channel you intended the clip for, and abort otherwise.
- Sessions secured — sign-in runs via a signed, httpOnly cookie that is not readable by scripts in the browser.
- No human access — nobody sees your tokens in plain text. Access to the production environment is held solely by the responsible party named in section 2, and only as far as it is necessary for operation and troubleshooting.
- Deleted immediately — if you disconnect a channel, the record with both tokens is deleted, not just hidden.
How long we store them
As long as the link exists. If you disconnect the channel in the dashboard or delete your account, the tokens and the channel data are deleted.
Revoke access
You can revoke Voql's access to your Google account at any time — independently of us, via the security settings of your Google account. After that Voql can no longer upload anything in your name.
Limited Use
Voql's use of information received from Google APIs, and its transfer to any other app, adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms: we use this data exclusively to provide the features you see in Voql's interface — to show the channel being published to, and to upload the clip there. We do not pass it on to third parties, do not use it for advertising and do not use it to train AI models. Humans do not read this data, unless you expressly ask us to, we have to investigate an abuse or security incident, or the law requires it.
7. Your rights
You have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of the data processing, as well as a right to have this data corrected or deleted. You may also request the restriction of processing, object to processing and have your data transferred in a common format (Art. 15 to 20 GDPR).
You can revoke any consent you have given at any time with effect for the future. Independently of this, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your place of residence or of the alleged infringement (Art. 77 GDPR).
8. Contact
If you have any questions about data protection, contact:
benjamin.roul.26@gmail.com
This privacy policy was created with the privacy policy generator by e-recht24.