Privacy policy

Last updated: 28 May 2026

1. Who we are

Our products include Vyrol Studio (video processing) and Vyrol Share (hosted customer pages). This policy explains what we process, why, and your choices. For privacy requests contact privacy@vyrol.io.

2. Data we process

  • Account & auth: Clerk handles sign-up (email or Google). We store your Clerk user id, credits, plans, and billing references — not your login password.
  • Vyrol Studio: Uploaded media, render settings, job status, usage metering, and filenames. Job files are removed automatically after a retention period (see Terms); job history may remain in your account.
  • Vyrol Share: Hosted video copies, thumbnails, logos, page copy, and contact details you choose to show visitors. Viewer analytics (page views, CTA clicks, anonymous visitor ids, referrer, device class).
  • Payments: Stripe processes cards; we store Stripe customer ids and purchase events, not full card numbers.

3. Sub-processors

We use trusted providers: Clerk (authentication), Stripe (payments), and infrastructure hosts where the app runs. Their privacy policies apply to data they process on our behalf.

4. Why we use data

To provide the service, bill correctly, prevent abuse, improve reliability, support you, and (only if you opt in) send product news and offers.

Support troubleshooting: If you contact us about a render or Share Page issue, authorised staff may access your upload and outputs for that job or page only, to diagnose the problem (for example when you provide a job id or support code). Access is limited to what is needed to help you; staff accounts are restricted and we do not use your content for marketing or unrelated purposes.

5. Retention

  • Completed Studio job files: typically removed after about 7 days (configurable on our side).
  • Share hosted files: kept until each page's keep-live date — Solo up to 30 days, Growth up to 90 days, Business 12 months by default (up to 24 months if you set a later date in settings before expiry). When you upgrade Share, we extend keep-live on active pages to your new plan maximum; when you downgrade, we shorten keep-live to the new tier maximum, with at least 7 days after the change when the tier cap from publish has already passed. When that date passes, public links stop serving and we delete the hosted copy from our storage. We do not keep a separate recovery copy after deletion. Account and page metadata (e.g. analytics) may remain for billing and support.
  • Account and analytics records may be kept longer where needed for billing, legal, or support.

6. Your responsibilities (Share Pages)

Contact details on a Share Page are your business information shown to the public. Ensure you have a lawful basis to display them and to use viewer analytics. Do not upload unlawful content.

7. Marketing email

We only send promotional email if you opt in at sign-up (or later in account settings when available). You can unsubscribe at any time. Transactional messages (billing, security) may still be sent as needed.

8. Your rights

Depending on where you live (e.g. UK/EU GDPR), you may have rights to access, correct, delete, restrict, or port your data, and to object to certain processing. Contact privacy@vyrol.io. You may also complain to your local data protection authority.

9. Security

We apply technical and organisational measures appropriate to the service. No online system is 100% secure.

10. Changes

We may update this policy; the date above will change. Continued use after notice constitutes acceptance where permitted by law.

Terms & conditions