Privacy Policy
Last updated: June 9, 2026
This Policy describes how VideoHub (https://videohub.pro) collects, uses, and protects your personal data when you use our video transcription service.
1. Who we are
VideoHub is operated by Ricardo Reis ([email protected]). It is a personal project, not a registered company.
2. Data we collect
- Email: to create and identify your account.
- Display name (optional): when you sign up or arrive via Google/GitHub.
- OAuth provider identifier: when you sign in with Google or GitHub, we store the public user ID from that provider (we never receive your password).
- Transcription history: videos you have transcribed through our interface, including URL, title, and resulting text.
- Technical logs: IP address, user agent, and request timestamps, kept for up to 30 days for diagnostics and abuse prevention.
3. How we use your data
- Authenticate you (5-year session cookie).
- Save and display your transcription history.
- Send essential transactional emails (password reset only). We do not send marketing.
- Enforce anti-abuse rate limits.
4. Sharing with third parties
We use the following processors to operate the service:
- Google OAuth / GitHub OAuth: when you click "Continue with Google/GitHub", we authenticate your email via these providers.
- Resend (https://resend.com): transactional email delivery (password reset).
- Groq (https://groq.com): transcription processing (audio → text via Whisper).
- DigitalOcean: server hosting.
We never sell your data. We never share it with advertisers.
5. Social login (Google / GitHub)
When you use "Continue with Google", we receive only: your email, your name, and an anonymous Google identifier. We do not receive your password or access to other parts of your Google account (Gmail, Drive, contacts, etc.). The same applies to GitHub.
6. Cookies
We use only one strictly necessary cookie (session) to keep you signed in. No marketing or tracking cookies.
7. Your rights
You may at any time:
- Access your data (via the app interface).
- Request a data export.
- Request permanent deletion of your account and history.
To exercise any right, email [email protected]. We reply within 7 business days.
8. Retention
We retain your data while your account is active. After deletion we remove everything within 30 days (except where retention is legally required).
9. Security
Passwords are bcrypt-hashed. Connections use HTTPS (TLS 1.3). Password reset tokens are single-use and expire in 1 hour.
10. Children
The service is not intended for children under 13. If we discover we have collected data from a child, we delete it immediately.
11. Changes to this Policy
We may update this Policy. The date at the top reflects the latest revision. Material changes will be announced via email or an in-app banner.
12. Contact
Questions? [email protected]