Legal
Privacy Policy
Last updated: August 7, 2026
1. Controller and scope
ViewMade, available at viewmade.com, is operated by FAST AI LABS LTD (“we”). We are the controller of account and service data described here. This policy covers our website, dashboard, billing, YouTube connection, AI tools, video production and connected-assistant features.
2. Data we collect
Account and profile data. Name, email, Google profile image when supplied, a one-way password hash for password accounts, account identifiers, legal acceptance records, security fingerprints and session records. Plain-text passwords are never stored.
Service and production data. Topics, prompts, scripts, reports, settings, generated output, source attributions, private media, queue state, credit entries, support data, feature usage, timestamps, error and incident records.
Billing data. Stripe processes card and payment details. We do not receive full card numbers. We retain Stripe customer, subscription, price, invoice, payment status, tax and cancellation references needed to provide access, reconcile credits, prevent duplicate grants and resolve billing disputes.
Connected assistants. Connection name, approved scopes, key prefix, expiry, revocation, last-use time and tool activity. API keys and OAuth access tokens are stored as one-way hashes; plaintext keys are shown only when first issued.
Website and referral data. If you opt in to analytics, we record an anonymous first-party identifier, page path, referrer host, campaign labels, locale and coarse device class. We do not store an IP address, full user-agent, account ID, email or page query text in analytics. Partner-link clicks use short-lived, one-way network and browser hashes to prevent duplicate commission claims. Partner attribution is stored in your browser only after marketing consent.
3. Google and YouTube data
Authorized channel import. Connecting YouTube requests only youtube.readonly. We use it to prove channel ownership and import the channel profile, uploads playlist and up to 25 recent videos, including titles, descriptions, tags, thumbnails, publication dates and available performance counts. ViewMade cannot upload, edit or delete YouTube content.
The Google access token exists only during that import request. We request no refresh token and do not store the access token. Imported data is visible only in the authorizing workspace and is used for the channel research, recommendations and production features the user requested. We do not sell Google user data, use it for advertising, or use it to train generalized AI models.
Public discovery data.Research uses a server-side API key to search public YouTube videos and channels without accessing a viewer’s Google Account. We temporarily store public video and channel IDs, titles, descriptions, tags, thumbnails, publication times, channel country and public counts for views, likes, comments, subscribers and uploads. This shared niche cache supplies the Research feed and is not used to identify or profile viewers.
ViewMade-derived metrics. Breakout multiples, views-per-hour, keyword-pattern scores, ranks, summaries and recommendations are calculated independently by ViewMade from public YouTube API data. They are estimates, are not supplied or endorsed by YouTube, and are labelled as ViewMade calculations in the Service.
Active discovery clusters refresh at least every 24 hours. Public API data and derived metrics are refreshed or deleted no later than 28 days after their last retrieval, leaving a safety margin below YouTube’s 30-day limit. We do not retain a private shadow copy beyond that period. Historical storage will not be extended unless YouTube separately approves that use through its compliance process.
Remove the channel in Dashboard → Channel to delete the stored channel connection and associated imported YouTube API data. You can also revoke Google access from Google account permissions. Because no reusable token is stored, revocation immediately prevents any new authorized import. Deletion requests are completed promptly and no later than 30 calendar days where YouTube policy sets that limit.
Use of YouTube API Services is also governed by the YouTube Terms of Service and Google’s Privacy Policy.
4. Purposes and lawful bases
We process data to form and perform the contract; authenticate users; provide requested research and production; collect payment and tax information; enforce limits; protect the Service; investigate abuse; maintain records; answer requests; and meet legal obligations. The principal lawful bases are contract, legal obligation and our legitimate interests in security, fraud prevention and reliable operation. We use consent only where the law specifically requires it; optional consent can be withdrawn without affecting earlier lawful processing.
5. Processors and transfers
We disclose only what is necessary to providers acting for the following purposes:
- Stripe for checkout, subscriptions, invoices, tax and fraud prevention;
- Google and YouTube for login and the read-only channel connection you initiate;
- AI, voice, media and public-data providers to create the exact output you request;
- hosting, storage, email, monitoring and security providers to operate the Service.
Providers may process data outside your country. Where required, we use recognized transfer safeguards and limit transfers to the service purpose. We do not sell personal data.
6. Retention
Account, production and workspace data is kept while the account remains active and for a reasonable closure period. OAuth attempts expire automatically. Security, consent, transaction, invoice, tax, chargeback and fraud records may be retained longer where required for legal claims or accounting. Consented anonymous website analytics is retained for 13 months; its browser identifier expires after six months. Cookie-consent evidence is retained only as long as reasonably required to demonstrate the choice presented and made. Provider credentials and YouTube data are retained only as described above. Backups expire on their normal protected rotation and are not restored for ordinary use after a valid deletion.
7. Security
We use encrypted transport, restricted server access, one-way credential hashes, signed sessions, tenant-scoped database queries, rate limits, audit records, payment-signature verification, backups and least-privilege service access. No system is risk-free; contact us immediately if you believe an account or credential is compromised.
8. Your choices and rights
Depending on location, you may request access, correction, portability, deletion, restriction or an objection, and complain to a data-protection authority. Disconnect channels and assistants from the dashboard. Submit an export or deletion request from account settings or email support. We verify the requester and may retain limited records required by law, payment disputes, security or fraud prevention.
9. Cookies
Strictly necessary cookies keep you signed in, preserve secure OAuth state and protect requests. The authenticated Service does not work without them. Anonymous analytics and partner-attribution cookies are off until you opt in. Rejecting them does not block signup, payment or the product. Change or withdraw the choice at any time using Cookie settings in the footer. The Cookie Policy lists every cookie, purpose and duration.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect their data.
11. Changes
We update this policy when processing changes. Material changes are dated and, where required, presented for renewed acceptance before the new processing begins.
12. Contact
Privacy questions and requests: support@viewmade.com