Legal & Policies

Privacy Policy

Effective:
[ADMIN REVIEW REQUIRED]
Last updated:
[ADMIN REVIEW REQUIRED]

This document describes how MediaMorph AI actually works today. It is a production-ready draft, not legal advice, and has not been reviewed for a specific jurisdiction. Anything marked [ADMIN REVIEW REQUIRED] must be completed by the business owner before public launch.

This policy explains what MediaMorph AI — operated by [ADMIN REVIEW REQUIRED] — collects when you use the website, dashboard and Telegram bot, how that information is used, and which providers process it with us. It describes the product as it actually works today.

Related documents: Terms of Service and Cookie Policy.

1. Information we collect

Account

  • First name (collected at sign-up) and email address.
  • Authentication data held by our authentication provider. Passwords are stored hashed by that provider; we never see or store your password in plain text. Signing in with Google shares only your basic profile and email with us.
  • Profile picture, if you upload one, stored in our private file storage.
  • Preferences: timezone, default output language, publishing mode and notification settings.
  • Telegram user id, username and chat id — only if you link the bot.

Subscription & usage

  • Plan, plan status, billing period dates, and pending plan changes; Paddle customer, subscription and price identifiers; manual payment submissions (method, sender number, transaction reference, amount) where the operator enables them.
  • Credit balance, credit ledger entries, trial status and trial credit counters, and per-run usage records: video duration, credits charged, plan at the time, and outcome.

Content you submit

  • The video links you submit, plus detected video title and duration.
  • Transcripts produced from those videos, including timed segments.
  • Generated newsletter drafts and social posts, their queue/schedule state, publishing results and timestamps.

Technical

Like any hosted web application, our hosting and database platform processes standard request data such as IP address, user agent and timestamps in server logs for security and debugging, and we record application error diagnostics. We do not run analytics or advertising trackers, and we do not build advertising profiles. See the Cookie Policy for the short list of browser storage we set.

2. How we use it

  • Create and secure your account and keep you signed in.
  • Transcribe the videos you submit and generate newsletter and social drafts.
  • Queue, schedule and publish drafts to the accounts you have connected.
  • Meter usage: enforce video-length limits, count videos, charge and reconcile credits.
  • Manage subscriptions, upgrades, downgrades and trial status from verified billing events.
  • Send service email: sign-in and password flows, processing notifications, billing notices.
  • Provide support, investigate issues, prevent abuse and enforce plan limits and these policies.
  • Meet legal, tax and accounting obligations.

We do not sell your personal information, and we do not use your videos, transcripts or drafts to train our own models.

3. Video links & processing

When you submit a link, this is what happens:

  1. We validate the link and read the video's duration to check it against your plan limit.
  2. We request a transcript — first from our transcript provider (Supadata), then from the video's own captions, then, if needed, by transcribing the audio with a speech-to-text model (Whisper via Groq or OpenAI). Long videos may be transcribed in segments.
  3. The transcript is sent to a language model to produce your newsletter and social drafts.
  4. The video URL, title, duration, transcript and generated drafts are stored in your account so you can review, edit, copy, re-publish and audit usage.

We process the link and the resulting text. We do not host or redistribute the source video. You are responsible for having the rights to the videos you submit.

4. AI processing

Transcription and generation happen through third-party AI providers over API calls. On plans that support your own keys, requests run on the key you supply; otherwise they run on the operator's keys. We send only what is needed — the audio or transcript text and the generation prompt — and we do not authorise these providers to use your content to train their models. Each provider's own retention and security practices apply to the API call itself; the providers are listed below.

5. Connected accounts & keys

When you connect beehiiv, Buffer, Facebook, LinkedIn or Telegram, we store the credentials and metadata needed to publish for you — access tokens (and refresh tokens where provided), account/page identifiers, granted scopes and expiry. On plans that allow it, we store the model API keys you enter. These secrets are encrypted before being written to our database and are used only to perform the actions you ask for. You can disconnect an integration or remove a key at any time from settings, and revoke access at the provider.

6. Payments

Subscriptions are processed by Paddle as merchant of record. We never receive or store your full card details. We store the identifiers and status Paddle sends us — customer id, subscription id, price id, plan, status and period dates — so your plan and credits stay in sync. Where the operator enables manual bank/mobile payment submissions, we store the reference details you enter so an administrator can verify the transfer.

7. Service providers

These are the providers actually used to run the Service. Each receives only the data needed for its function, and each is governed by its own privacy policy.

ProviderPurpose
PaddleSubscription checkout, billing, invoices and payment processing (Merchant of Record).
SupadataPrimary transcript extraction from the video links you submit.
GroqWhisper speech-to-text fallback and Llama content generation.
OpenAIContent generation and Whisper transcription when configured or when you supply your own key.
AnthropicContent generation when configured or when you supply your own key.
Google (Gemini)Content generation and natural-language parsing of Telegram requests.
DeepSeekContent generation fallback when configured.
beehiivPublishing newsletter drafts to the publication you connect.
BufferQueueing and publishing social posts to the channels you connect.
Meta (Facebook) and LinkedInPublishing posts to the pages and profiles you authorise.
TelegramOptional bot interface for submitting links and approving drafts.
ResendTransactional email such as sign-in, billing and processing notifications.
Managed cloud platform (hosting, database, authentication, file storage)Runs the application, stores your account data and hosts uploaded avatars.

Some providers operate outside your country, so your data may be processed abroad. We may also disclose information where required by law, or to protect our rights, users and systems.

8. Security

  • Traffic between your browser, our servers and provider APIs uses HTTPS/TLS.
  • Integration tokens and model API keys are encrypted by the application before storage; secrets are never returned to the browser in full.
  • Row-level security policies and role checks isolate your rows from other accounts. Administrative operations run server-side behind explicit role checks.
  • Strong-password rules are enforced at sign-up and password change.

No system is perfectly secure. We do not claim any specific certification or formal compliance audit — any such claim would need to be verified before it appears here.

9. Retention

We keep your account data, transcripts, drafts and usage records while your account exists, because the dashboard, usage history and billing records depend on them. Usage and credit ledger entries are kept as business records even after a plan ends.

Defined retention periods: [ADMIN REVIEW REQUIRED] — the business has not published fixed retention windows yet, so we do not state one here. On a deletion request we remove or anonymise data as described below.

10. Your rights

Depending on where you live, you may have rights to access, correct, export, delete or restrict the processing of your personal data, to object to certain processing, and to complain to a data-protection authority. Email us and we will action valid requests. We do not claim certification under any specific privacy framework; the law that applies to you may grant you more rights than are listed here, and the governing law recorded for the Service is [ADMIN REVIEW REQUIRED].

11. Deletion & account closure

There is no self-service delete-account button today. To close your account and delete your data, email support@mediamorph.io from your account address and we will process it. In the meantime you can delete individual runs and drafts, disconnect integrations, and remove stored keys yourself from the dashboard. Cancel any paid subscription before requesting deletion so billing stops. Some records — invoices, credit ledger entries and other legally required data — may be retained where the law requires it.

12. Children

The Service is not intended for children. Do not create an account if you are under the minimum age required to consent to online services where you live. If we learn a child's account exists, we will remove it.

13. Changes

We will update this page when the product or its providers change, and revise the effective and last-updated dates at the top. Continuing to use the Service after an update means you accept the revised policy.

14. Contact

Privacy questions and data requests: support@mediamorph.io. Product support: support@mediamorph.io. Business details, including registered address, are on the contact page.

Questions about this document? Email support@mediamorph.io.