← Back to Home

Privacy Policy

Last updated: June 2026 · Effective: June 2026

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have under the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law. We are a Data Fiduciary as defined under the DPDP Act.

1. Who We Are (Data Fiduciary)

8 Second Reels is the Data Fiduciary for personal data collected through this Platform. We are operated by an individual proprietor based in New Delhi, India.

Grievance Officer (as required under DPDP Act, 2023 and IT Rules, 2021):

Name: Neha Gupta

Email: support@8secondreels.com

Acknowledgment: Within 24 hours of receiving any complaint (as required under IT Intermediary Guidelines Rules, 2021).

Resolution: Within 15 working days of receipt.

Privacy-specific response: Within 72 hours for data protection and privacy-related complaints (as required under DPDP Act, 2023).

2. What Data We Collect

2.1 Account Data

  • Email address — required for account creation, login, and notifications.
  • Name — optional, collected if you provide it during registration.
  • Profile photo / avatar — only if you sign in via Google OAuth and Google provides it.
  • Authentication method — whether you signed up via email/password or Google OAuth.

2.2 GCP Credentials

Your Google Cloud Service Account JSON key and GCS bucket name. These are classified as sensitive data and are handled under special protections described in Section 4.

2.3 Usage & Technical Data

  • Login metadata: IP address, browser type, operating system, and device type — recorded per login session for security purposes.
  • Prompt text: The text prompts you enter for video generation. We store your last 5 prompts to provide prompt history functionality.
  • Video metadata: Video ID, generation status, GCS URI (path to your video file), creation timestamp. We do not store the video files themselves.
  • Activity logs: Timestamped records of significant actions (e.g., login, key configuration, video generation) for security auditing. Activity logs are visible to authorised platform administrators on an ongoing basis for platform oversight, security monitoring, and fraud prevention. Prompt text within those logs may be reviewed in the event of a reported Terms violation or a specific security incident investigation.
  • AI Feature Preferences: Your settings for AI-powered features — including prompt coaching, auto-enhance, caption generation, Hinglish mode persona, and template preferences — stored to personalise your experience on the Platform.
  • Device fingerprint & signup IP: A device fingerprint and the IP address used at registration, retained for fraud prevention (e.g. detecting abuse of free signups).

2.4 Payment Data

We store only your Razorpay subscription ID, payment ID, amount, and payment status. We do not store any card numbers, UPI IDs, bank account details, or other payment instrument data — these remain exclusively with Razorpay.

2.5 What We Do NOT Collect

  • We do not collect browsing history outside our Platform.
  • We do not use advertising cookies or tracking pixels.
  • We do not collect sensitive personal data (Aadhaar, PAN, biometrics, health data, financial account details) beyond what is described above.

3. Why We Collect This Data (Purpose & Legal Basis)

DataPurposeLegal Basis
Email, nameAccount creation, login, billing notificationsContract performance
GCP credentialsAuthenticate with Google APIs to generate videos on your behalfContract performance
IP address, device infoSecurity monitoring, suspicious login detectionLegitimate interest (security)
Prompt textPrompt history feature, safety monitoringContract performance
Activity logsSecurity audit, fraud prevention, admin oversightLegitimate interest (security)
Device fingerprint, signup IPFraud prevention (duplicate-account / abuse detection)Legitimate interest (security)
Payment metadataSubscription management, billing recordsContract performance, legal obligation

4. Your GCP Credentials — Special Protections

Because your Google Cloud Service Account JSON key grants access to your GCP project (and potentially significant financial resources), we apply the following protections beyond standard personal data:

Encryption at rest

Your credentials are encrypted using industry-standard symmetric encryption before being written to the database. The encryption key is stored as a server-side environment variable, never in source code or the database itself.

Never in logs

Your credentials are explicitly excluded from all application logging, error reporting, and monitoring tools. Even in the event of an application error, credential data is never written to logs.

Never in API responses

No API endpoint returns your credentials — not even partially. The only information returned is a 'Configured: Yes/No' status.

Decryption only in memory

Credentials are decrypted temporarily in server memory only at the moment a generation request is made, to pass the authentication token to Google's APIs. The decrypted value is not cached, stored, or logged.

Admin cannot see your keys

Even our admin accounts can only see whether you have credentials configured, not what they contain. This is enforced at the API level, not just the UI.

5. Cookies & Local Storage

We use only the cookies and storage necessary to provide the service:

  • Session cookie (NextAuth): An encrypted, HTTP-only session cookie is set when you log in. This cookie is used solely to maintain your login session and expires after 7 days or when you log out. It cannot be read by JavaScript on the page.
  • Theme preference: Your dark/light mode preference is stored in your browser's local storage. This is purely a UI preference, stored on your device only, and is not transmitted to us.

We do not use advertising cookies, third-party tracking pixels, or any analytics tools that transmit data to external parties.

6. Third-Party Service Providers

We share limited data with the following processors only as necessary to deliver the service:

Railway (database & API hosting)

All backend data (database, application server) is hosted on Railway's infrastructure, located in servers primarily in the United States.

Vercel (frontend hosting)

The frontend application is hosted on Vercel's global CDN. Vercel processes request metadata (IP address, user agent) for CDN delivery.

Google (OAuth authentication)

If you sign in with Google, Google provides your email address and profile information. We do not share your Platform data with Google beyond the OAuth handshake.

Razorpay (payment processing)

Your email and subscription details are shared with Razorpay to process payments. Razorpay handles all payment instrument data independently.

Google Cloud / Vertex AI (video generation)

Your text prompts are transmitted to Google's Vertex AI service to generate video content on your behalf, using your own GCP credentials. Google processes this data under their Cloud Data Processing Addendum. Google does not receive any other personal data from us beyond the prompt text required for generation.

Resend (transactional email)

Your email address is shared with Resend solely to deliver transactional emails (welcome, billing, renewal notifications).

Ollama Cloud (AI-powered features)

Your text prompts are transmitted to Ollama Cloud to power optional AI helper features — Prompt Coach, Auto-Enhance, Prompt Review for Veo, Caption & Hashtag Generation, Engagement Score, Prompt Variations, Series Script Generation, and Voice Suggestions. These features run on the Ollama Cloud API key you provide and connect yourself (encrypted at rest the same way your GCP credentials are — see Section 4); you are responsible for any usage on your own Ollama Cloud account, and these features are unavailable until you add your own key. A small number of platform-wide features (e.g. trending-content tooling, admin diagnostics) instead use the operator's own Ollama Cloud key and are not user-facing. In all cases, only prompt text is transmitted to Ollama; no other personal account data is shared. Processing is governed by Ollama's Privacy Policy.

We do not sell, rent, or share your personal data with any other third party for marketing or commercial purposes.

Trending content: The “India Today” and “Coming Up” sections display content derived from publicly available search trend data. This data is aggregated and informational only; your personal information is not transmitted to trend-data sources.

7. International Data Transfers

Your data is stored on Railway servers and Vercel infrastructure, and your prompts are processed by Google Cloud / Vertex AI — all of which may operate on servers located outside India (primarily in the United States). You provide explicit consent to this international transfer at account registration. We rely on the service providers listed in Section 6, each of whom maintains data protection standards equivalent to those required under Indian law and international best practices.

8. Data Retention

Data typeRetention period
Account data (email, name)Until account deletion, then deleted within 30 days
GCP credentialsUntil you remove them or delete your account; deleted within 30 days of account deletion
Video metadataUntil you discard the video or delete your account
Prompt historyRolling last 5 prompts; deleted on account deletion
Login session records90 days, then automatically purged
Activity logs180 days for security purposes, then purged
Payment metadata7 years as required by Indian accounting laws (GST compliance)
AI feature preferencesUntil changed or account deleted; deleted within 30 days of account deletion
Video series data (theme, scripts, status)Until you delete the series or your account; deleted within 30 days of account deletion
Uploaded images (starting frames)Stored in your GCS bucket only; we retain no independent copy; deleted when you discard the associated video or delete your account
Uploaded audio files (background music)Processed temporarily during series generation; not retained on our servers beyond successful processing completion

9. Your Rights Under the DPDP Act, 2023

As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:

Right to Access

You may request a summary of the personal data we hold about you and how it is being processed.

Right to Correction

You may request that inaccurate or incomplete personal data be corrected.

Right to Erasure

You may request deletion of your personal data. We will process the request within 30 days, subject to data we are required to retain by law (e.g., payment records for 7 years).

Right to Grievance Redressal

You may raise a complaint with our Grievance Officer (see Section 1). If unsatisfied with our response, you have the right to escalate to the Data Protection Board of India once it becomes operational.

Right to Withdraw Consent

Where we process data on the basis of consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

Right to Nominate

You may nominate another individual to exercise your rights in the event of your death or incapacity, as provided under Section 14 of the DPDP Act.

To exercise any of these rights, email our Grievance Officer at support@8secondreels.com. We will respond within 72 hours.

10. Data Security

We implement the following technical and organisational security measures:

  • All data is transmitted over HTTPS/TLS.
  • GCP credentials are encrypted at rest using industry-standard symmetric encryption.
  • Passwords are hashed using a strong adaptive hashing algorithm and never stored in plaintext.
  • Session tokens have short expiry windows; refresh tokens are rotated on each use.
  • Repeated failed login attempts trigger automatic rate limiting and a temporary lockout.
  • Security headers (HSTS, X-Frame-Options, X-Content-Type-Options) are applied on all responses.
  • Admin accounts require TOTP two-factor authentication.

Despite our efforts, no internet transmission or storage system is 100% secure. In the event of a data breach affecting your personal data, we will notify you within 72 hours of becoming aware, as required under applicable law.

11. Children's Privacy

This Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at support@8secondreels.com and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 30 days before they take effect. The updated policy will be posted on this page with a new effective date.

Contact & Grievance Redressal

Grievance Officer: Neha Gupta

Privacy & data requests: support@8secondreels.com

General support: support@8secondreels.com

We aim to respond to all privacy-related requests within 72 hours. If you are dissatisfied with our response, you may escalate to the Data Protection Board of India (once operational) or approach the appropriate consumer forum under the Consumer Protection Act, 2019.