Legal
Privacy
Last updated 2026-08-03. This describes what Playhead collects, who else processes it, how long it is kept and how to have it removed. It is written to be checkable: every retention period below is enforced by the software, not by a promise.
What we collect
Your account. An email address and a password hash, both held by Supabase — we never see a password. An organization name, which you choose. Nothing else about you is asked for.
What your agent did. Every call is recorded: which video, which window, which detail level, what it cost, and whether it succeeded. This is the audit trail behind every credit charged, and it is what makes a billing dispute answerable in one query.
The videos themselves. A link is fetched from the platform hosting it. A file you pass by path is uploaded so it can be decoded — decoding is the service. Both produce contact sheets and, if asked, a transcript.
Billing.Name, billing address and tax id go to Stripe. Card details are entered on Stripe's own form and never reach our servers.
Measurement, only if you agree.Page views and conversion events go to Google Analytics and Google Ads. Every consent signal starts denied; nothing is sent until the cookie banner is answered with “Accept all”. Choosing “Only essential” leaves everything working.
What we do not do
- We do not train models on your videos, your transcripts or your prompts. Nothing you analyse is used to improve anything.
- We do not sell data, and we do not share it with anyone not listed below.
- We do not read your content. Sheets are generated by a program and served over signed, short-lived URLs; nobody looks at them.
- We do not track you across other websites. There is no advertising pixel on this site beyond Google's own tag, and that is gated on consent.
Who else processes it
Each of these receives only what its purpose requires. Adding one is a change to this page.
| Who | For what | What they get |
|---|---|---|
| Supabase | Authentication and the database holding accounts, credits and job history | Email address, hashed password, organization membership, usage recordsEU or US, depending on the project's region |
| Stripe | Subscriptions, invoices and payment | Name, billing address, tax id, card details (handled entirely by Stripe — they never reach us)US, with EU processing under their standard terms |
| Groq | Speech-to-text, when transcription is requested and no uploader captions exist | The audio track of the video being analysedUS |
| Cloudflare | Content delivery, rate limiting and bot protection | IP address and request metadataGlobal edge |
| Analytics and advertising measurement — only after consent is given | Page views, referrer, consent state, conversion eventsGlobal |
How long it is kept
| What | How long | Why |
|---|---|---|
| Contact sheets and transcripts | 1 to 90 days depending on plan, then deleted from object storage | They are derived data and can be rebuilt from the source at any time |
| The record that a call happened | For the life of the account | It is the audit trail behind every credit charged, and a billing dispute is one query |
| Source video files | At most 24 hours in a working cache | One download serves every later window; nothing is archived |
| Account, credit ledger and invoices | For the life of the account, then as tax law requires | Financial records have a statutory retention period we do not get to choose |
Your rights
Under the GDPR, the UK GDPR and the US state privacy laws, you can ask for a copy of your data, ask for it to be corrected, and ask for it to be deleted. Two of those are buttons rather than requests:
- Delete a single video's results.
DELETE /v1/videos/{id}removes its sheets and transcripts immediately, ahead of their retention window. - Delete everything. Settings → Delete account removes the organization, its keys, its history and its ledger, and then the login itself. It runs in one transaction and cannot be undone.
- Anything else — a copy, a correction, an objection — goes to privacy@playhead.dev. We answer within 30 days, which is the statutory limit rather than our target.
Where it is processed
The database is a Supabase project in the region it was created in. The engine runs in a container that can be moved between providers without changing anything a customer sees. Transcription is either Groq (US) or a local model in our own deployment, and the fallback direction is recorded on every transcript so you can tell which handled a given video.
For customers under data-residency rules, the Enterprise deployment runs the whole engine — including transcription — inside your own network, so no video, audio or frame leaves it.
Cookies
Two kinds. The ones that sign you in and keep you signed in are essential and cannot be switched off without breaking login. The ones that measure which pages people find useful are optional and start switched off. The banner asks once; refusing is one click, and it is the same size as accepting.
A referral link also sets a cookie recording which link brought you here, for 90 days. It contains a public code from a public link and grants nothing.
Changes and contact
A material change to this page is announced by email to account holders before it takes effect. Everything else is a correction, and the date at the top moves.
Playhead — privacy@playhead.dev
See also the terms of service.