Privacy Policy

Last updated: July 31, 2026

Videoable stores files and hands out links to them. That means we hold your media and a small amount of information about you and the people who open your links. This page explains exactly what that is, in plain terms.

1. What we store

Your account:

  • your email address, and your name if you give one;
  • a bcrypt hash of your password — we never see or store the password itself;
  • your plan, subscription status and a Stripe customer reference if you pay us;
  • how many bytes you are using, so we can enforce your storage allowance.

Your media:

  • the file you uploaded and the renditions, thumbnails and previews we generate from it;
  • technical metadata read from the file — size, duration, dimensions, format — plus the title and description you set;
  • the short link, its visibility setting and, for password-protected links, a hash of the password.

Viewers of your links:

  • a salted, one-way hash of the IP address and browser user agent. The raw IP address is never written to our database; the hash exists only to avoid counting the same person twice;
  • coarse signals about the view — approximate country, device type, referring site, seconds watched and whether it was an embed.

We do not run advertising networks, third-party analytics scripts or cross-site trackers on the pages that play your media.

2. How long we keep it

  • Media. On the free plan, 90 days from upload. On paid plans, until you delete it or close your account.
  • View events. Twelve months, after which they are aggregated into counts you can still see and the individual rows are deleted.
  • Account data. Until you delete your account, plus the billing records tax law obliges us to keep.
  • Backups. Encrypted and rotated on a short cycle, so deleted material disappears from them within weeks.

3. Cookies

We set cookies only where the product cannot work without them:

  • a signed, httpOnly session cookie that keeps you logged in for 30 days and is cleared when you sign out;
  • a short-lived unlock cookie for each password-protected link you open, so you do not have to retype the password on every visit;
  • a preference cookie for things like your theme.

No advertising cookies, and nothing that follows you to other sites.

4. Who else sees your data

We share the minimum needed to run the service:

  • Stripe processes payments. Card details go straight to Stripe and never touch our servers.
  • Our hosting and storage provider runs the machines your files sit on.
  • Email delivery sends account and billing messages.
  • Law enforcement, when a valid legal order requires it.

We do not sell personal data, and we do not trade it for services.

5. Your choices

You can edit or delete any upload at any time, change the visibility of a link, and export your originals with the download button. You can update your email and password in settings.

Deleting your account removes your profile and every file you have uploaded, including renditions and thumbnails. Links stop working immediately and the action cannot be undone.

Depending on where you live you may also have the right to access, correct, port or object to the processing of your data. Email us and we will action it within 30 days.

6. Security

Passwords are hashed with bcrypt, sessions are signed tokens in httpOnly cookies, and traffic runs over TLS. Storage keys are validated so one account can never read another account's files. Changing your password invalidates every session that was already open.

No system is perfect. If we ever discover a breach that affects you, we will tell you and the relevant regulator without unnecessary delay.

7. Children

Videoable is not intended for children under 13, and we do not knowingly create accounts for them. If you believe a child has an account, email us and we will remove it.

8. Changes and contact

If this policy changes in a way that matters, we will email account holders before it takes effect. The date at the top always reflects the current version.

Privacy questions go to privacy@videoable.app. The rules for using the service are in the terms.