VideoCentral Privacy Policy
Effective August 2, 2026. Last updated August 2, 2026.
This Privacy Policy explains how VideoCentral LLC ("VideoCentral", "we", or "us") collects, uses, and shares information when you use our website at videocentral.io, our web application, and our iOS and Android apps (together, the "Services").
VideoCentral is a private video platform for business teams. Most of the content in it — video, titles, labels, annotations — belongs to the organization that created it rather than to an individual user. If your employer or another organization gave you a VideoCentral account, that organization decides who may access its content and how long to keep it. We process that content on the organization's behalf. If you want organization content corrected or removed, contact your account administrator first.
1. Information you provide to us
- Account information. Your email address and password, and optionally your first name, last name, and display name. Passwords are stored only as a bcrypt hash — we do not keep or log them in readable form.
- Organization information. Your organization name, your role, and the channels and groups you belong to.
- Video and related content. The video you record or upload, along with titles, descriptions, labels, saved Collections, MarkUp annotations you draw on a clip, and any subtitle files you upload.
- Sharing details. When you share a clip outside your organization, the recipient email address you enter, an optional passcode, and the expiration date you choose.
- Client Capture requests. When you ask someone outside your organization to send you video, the email address and phone number you provide for them, plus the title and instructions you write. When they respond, we collect the name, email address, and note they submit with their video.
- Invitations. The email address and role of anyone you invite to your organization.
- Correspondence. The content of messages you send to our support, billing, or sales addresses.
2. Information we collect automatically
- Log data. Our servers record the IP address, request path and method, response status, timing, and browser user agent for requests to the Services. For signed-in requests we also record your user and organization identifiers so we can trace errors to their source.
- Session records. Each time you sign in we store the browser user agent and an expiration time for that session. You can hold up to five active sessions; the oldest is removed when you exceed that.
- Shared link activity. For each shared clip we record how many times it was opened, when it was first and last viewed, and the IP address of the most recent viewer. This lets the person who shared it confirm the recipient received it, and lets us investigate misuse of a link.
- Client Capture submissions. We record the IP address and browser user agent of anyone who uploads video through a Client Capture link.
- Storage and bandwidth. We record how many bytes are delivered for each clip so we can measure your organization’s usage against its plan.
- Rate limiting. We keep short-lived counters keyed to an IP address, email address, or user ID to block brute-force attempts and abuse. These expire within one hour.
4. How we use information
- Providing the Services. Creating and maintaining your account, storing and playing back your video, applying the permissions your administrators configure, and delivering shared links.
- Processing video. Converting uploads into streaming formats, generating still thumbnails, and segmenting subtitle files you provide. This is automated processing by our own software — see "How we handle your video" below.
- Sending email. Address verification, password resets, team invitations, shared clip notifications, Client Capture requests, and billing reminders.
- Billing. Measuring storage and bandwidth against your plan and reporting usage totals to our payment provider.
- Security and abuse prevention. Rate limiting, protecting accounts against brute-force attempts, and investigating misuse of shared or Client Capture links.
- Support and legal compliance. Answering your questions and meeting obligations under applicable law.
6. How we handle your video
Your recordings are the most sensitive thing you trust us with, so we want to be specific about what we do and do not do with them.
- We do not analyse the content of your video. We run no speech-to-text, no transcription, no facial recognition, no object detection, and no other machine-learning analysis on your recordings.
- If we add features that do analyse video — searchable transcripts or automatic captions, for example — they will be optional. Nothing will be analysed unless you turn the feature on and choose the recordings to use it with, and we will update this policy to describe how the feature works before you can use it.
- We do not use your video or any other content you store in VideoCentral to train machine-learning models, and we do not supply it to anyone else for that purpose. This applies to any analysis features we may add later.
- We do not scan your content to target advertising, and we do not serve advertising.
- Today, automated processing is limited to converting video into streaming formats, generating still thumbnails, and segmenting subtitle files that you upload.
- Our staff do not access the contents of your video except when you ask us to as part of a support request, or where we reasonably believe access is necessary to investigate abuse, comply with the law, or protect someone’s safety.
7. How long we keep information
- Video and content. Kept until you or an administrator in your organization deletes it, or until the organization’s account is closed and we remove its data.
- Account information. Kept while your account is active. See "Your rights and choices" for how to have it deleted.
- Sessions. Expire after 30 days at the latest, and expired sessions are removed the next time you sign in or your session refreshes.
- Shared links. Expire on the date set when the link was created. Expired share records, including the recorded viewer IP address, are deleted automatically.
- Client Capture requests. Expire on the date set when the request was created.
- Incomplete uploads. Upload sessions expire 24 hours after they begin.
- Verification, password reset, and invitation links. Time-limited and single-use.
- Background job records. Records of processing such as transcoding and email delivery, which can include a recipient address, are marked for deletion 30 days after they succeed or 90 days after they fail, and are permanently removed a year later.
- Server logs. Kept for a limited period for security, debugging, and compliance.
- Suppressed email addresses. Addresses that hard bounce or report our mail as spam are kept on a suppression list so we do not email them again.
8. Your rights and choices
- Access and correction. You can update your name and email address in your profile settings. For anything else, write to support@videocentral.io.
- Deletion. Email support@videocentral.io to request deletion of your account. Because video and other work product belong to the organization rather than to you individually, deleting your account does not delete your organization’s content — if you are a member rather than an administrator, ask your administrator. Administrators can remove users and delete content directly in the dashboard.
- Marketing. We only send email that is necessary to operate your account, such as verification, password resets, invitations, share notifications, and billing notices.
- Do Not Track. We do not track you across other websites, so a Do Not Track signal does not change what we collect.
If you are a California resident, the CCPA and CPRA give you the right to know what personal information we have collected, where it came from, why we collected it, and who we shared it with; to request correction or deletion; and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no opt-out to offer. Residents of other US states with comprehensive privacy laws have comparable rights.
To exercise any of these rights, write to support@videocentral.io. We will verify your identity against the information already on your account before acting, and we will respond within 45 days. If we need longer — up to 90 days in total — we will tell you why within the first 45.
If you are in the European Economic Area or the United Kingdom, you may also have the right to object to or restrict processing and to receive your information in a portable form. Where your organization controls the content, we act on its instructions and will refer your request to it.
9. How we protect information
- All traffic to the Services is encrypted with TLS, and plain HTTP requests are redirected to HTTPS.
- Passwords are stored as bcrypt hashes and are never held in readable form.
- Access tokens expire after 15 minutes, and refresh tokens live in an HttpOnly cookie that page scripts cannot read.
- Video is delivered through expiring signed URLs rather than publicly readable files.
- Shared links can be protected with a passcode, and lock after five failed attempts.
- Our database is not reachable from the public internet.
- Role-based permissions govern who in your organization can view, upload, or manage each channel.
No system is perfectly secure. If you believe your account has been compromised, or you have found a vulnerability, write to us immediately at the address below. Where a breach affects your personal information, we will notify you as required by applicable law.
10. Children's privacy
VideoCentral is built for business use. The Services are not directed to children under 13, and we do not knowingly collect personal information from them. If we learn that we have, we will delete it promptly. If you believe a child under 13 has given us personal information, contact us at the address below.
11. Where your information is processed
We operate the Services from the United States, and our infrastructure runs in Amazon Web Services regions in the United States. Video is delivered through a global content delivery network, which means copies may be cached at edge locations closer to a viewer. If you use the Services from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
12. Changes to this policy
We may update this policy as the product changes. When a change is material, we will notify account administrators by email or in the application before it takes effect, and we will update the "last updated" date above. Continuing to use the Services after a revised policy takes effect means you accept it.
Contact us
If you have questions about this policy, or want to exercise any of the rights described above, email us. We handle privacy requests by email rather than post:
- Privacy and general questions: support@videocentral.io
- Billing questions: billing@videocentral.io
VideoCentral LLC