Last updated: June 2026 · Effective: June 2026
8 Second Reels is the Data Fiduciary for personal data collected through this Platform. We are operated by an individual proprietor based in New Delhi, India.
Grievance Officer (as required under DPDP Act, 2023 and IT Rules, 2021):
Name: Neha Gupta
Email: support@8secondreels.com
Acknowledgment: Within 24 hours of receiving any complaint (as required under IT Intermediary Guidelines Rules, 2021).
Resolution: Within 15 working days of receipt.
Privacy-specific response: Within 72 hours for data protection and privacy-related complaints (as required under DPDP Act, 2023).
Your Google Cloud Service Account JSON key and GCS bucket name. These are classified as sensitive data and are handled under special protections described in Section 4.
We store only your Razorpay subscription ID, payment ID, amount, and payment status. We do not store any card numbers, UPI IDs, bank account details, or other payment instrument data — these remain exclusively with Razorpay.
| Data | Purpose | Legal Basis |
|---|---|---|
| Email, name | Account creation, login, billing notifications | Contract performance |
| GCP credentials | Authenticate with Google APIs to generate videos on your behalf | Contract performance |
| IP address, device info | Security monitoring, suspicious login detection | Legitimate interest (security) |
| Prompt text | Prompt history feature, safety monitoring | Contract performance |
| Activity logs | Security audit, fraud prevention, admin oversight | Legitimate interest (security) |
| Device fingerprint, signup IP | Fraud prevention (duplicate-account / abuse detection) | Legitimate interest (security) |
| Payment metadata | Subscription management, billing records | Contract performance, legal obligation |
Because your Google Cloud Service Account JSON key grants access to your GCP project (and potentially significant financial resources), we apply the following protections beyond standard personal data:
Encryption at rest
Your credentials are encrypted using industry-standard symmetric encryption before being written to the database. The encryption key is stored as a server-side environment variable, never in source code or the database itself.
Never in logs
Your credentials are explicitly excluded from all application logging, error reporting, and monitoring tools. Even in the event of an application error, credential data is never written to logs.
Never in API responses
No API endpoint returns your credentials — not even partially. The only information returned is a 'Configured: Yes/No' status.
Decryption only in memory
Credentials are decrypted temporarily in server memory only at the moment a generation request is made, to pass the authentication token to Google's APIs. The decrypted value is not cached, stored, or logged.
Admin cannot see your keys
Even our admin accounts can only see whether you have credentials configured, not what they contain. This is enforced at the API level, not just the UI.
We use only the cookies and storage necessary to provide the service:
We do not use advertising cookies, third-party tracking pixels, or any analytics tools that transmit data to external parties.
We share limited data with the following processors only as necessary to deliver the service:
Railway (database & API hosting)
All backend data (database, application server) is hosted on Railway's infrastructure, located in servers primarily in the United States.
Vercel (frontend hosting)
The frontend application is hosted on Vercel's global CDN. Vercel processes request metadata (IP address, user agent) for CDN delivery.
Google (OAuth authentication)
If you sign in with Google, Google provides your email address and profile information. We do not share your Platform data with Google beyond the OAuth handshake.
Razorpay (payment processing)
Your email and subscription details are shared with Razorpay to process payments. Razorpay handles all payment instrument data independently.
Google Cloud / Vertex AI (video generation)
Your text prompts are transmitted to Google's Vertex AI service to generate video content on your behalf, using your own GCP credentials. Google processes this data under their Cloud Data Processing Addendum. Google does not receive any other personal data from us beyond the prompt text required for generation.
Resend (transactional email)
Your email address is shared with Resend solely to deliver transactional emails (welcome, billing, renewal notifications).
Ollama Cloud (AI-powered features)
Your text prompts are transmitted to Ollama Cloud to power optional AI helper features — Prompt Coach, Auto-Enhance, Prompt Review for Veo, Caption & Hashtag Generation, Engagement Score, Prompt Variations, Series Script Generation, and Voice Suggestions. These features run on the Ollama Cloud API key you provide and connect yourself (encrypted at rest the same way your GCP credentials are — see Section 4); you are responsible for any usage on your own Ollama Cloud account, and these features are unavailable until you add your own key. A small number of platform-wide features (e.g. trending-content tooling, admin diagnostics) instead use the operator's own Ollama Cloud key and are not user-facing. In all cases, only prompt text is transmitted to Ollama; no other personal account data is shared. Processing is governed by Ollama's Privacy Policy.
We do not sell, rent, or share your personal data with any other third party for marketing or commercial purposes.
Trending content: The “India Today” and “Coming Up” sections display content derived from publicly available search trend data. This data is aggregated and informational only; your personal information is not transmitted to trend-data sources.
Your data is stored on Railway servers and Vercel infrastructure, and your prompts are processed by Google Cloud / Vertex AI — all of which may operate on servers located outside India (primarily in the United States). You provide explicit consent to this international transfer at account registration. We rely on the service providers listed in Section 6, each of whom maintains data protection standards equivalent to those required under Indian law and international best practices.
| Data type | Retention period |
|---|---|
| Account data (email, name) | Until account deletion, then deleted within 30 days |
| GCP credentials | Until you remove them or delete your account; deleted within 30 days of account deletion |
| Video metadata | Until you discard the video or delete your account |
| Prompt history | Rolling last 5 prompts; deleted on account deletion |
| Login session records | 90 days, then automatically purged |
| Activity logs | 180 days for security purposes, then purged |
| Payment metadata | 7 years as required by Indian accounting laws (GST compliance) |
| AI feature preferences | Until changed or account deleted; deleted within 30 days of account deletion |
| Video series data (theme, scripts, status) | Until you delete the series or your account; deleted within 30 days of account deletion |
| Uploaded images (starting frames) | Stored in your GCS bucket only; we retain no independent copy; deleted when you discard the associated video or delete your account |
| Uploaded audio files (background music) | Processed temporarily during series generation; not retained on our servers beyond successful processing completion |
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:
Right to Access
You may request a summary of the personal data we hold about you and how it is being processed.
Right to Correction
You may request that inaccurate or incomplete personal data be corrected.
Right to Erasure
You may request deletion of your personal data. We will process the request within 30 days, subject to data we are required to retain by law (e.g., payment records for 7 years).
Right to Grievance Redressal
You may raise a complaint with our Grievance Officer (see Section 1). If unsatisfied with our response, you have the right to escalate to the Data Protection Board of India once it becomes operational.
Right to Withdraw Consent
Where we process data on the basis of consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Right to Nominate
You may nominate another individual to exercise your rights in the event of your death or incapacity, as provided under Section 14 of the DPDP Act.
To exercise any of these rights, email our Grievance Officer at support@8secondreels.com. We will respond within 72 hours.
We implement the following technical and organisational security measures:
Despite our efforts, no internet transmission or storage system is 100% secure. In the event of a data breach affecting your personal data, we will notify you within 72 hours of becoming aware, as required under applicable law.
This Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at support@8secondreels.com and we will delete it promptly.
We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 30 days before they take effect. The updated policy will be posted on this page with a new effective date.
Grievance Officer: Neha Gupta
Privacy & data requests: support@8secondreels.com
General support: support@8secondreels.com
We aim to respond to all privacy-related requests within 72 hours. If you are dissatisfied with our response, you may escalate to the Data Protection Board of India (once operational) or approach the appropriate consumer forum under the Consumer Protection Act, 2019.