Skip to main content
Privacy & Security

Privacy Notice

How VidPal collects, uses, shares, and protects personal data when you visit our sites, create an account, or watch videos shared by our users.

Last updated: April 2, 2026

1. Who This Notice Covers

This Privacy Notice explains how PepoCloud LLC (“PepoCloud LLC,” “we,” “us,” or “our”) handles personal data for our VidPal websites (vidpal.ai), applications, Chrome extension, and video services (collectively, the “Services”). It applies to:

  • Users: account owners and team members who record, upload, edit, and share videos through the Services.
  • Viewers: people who watch shared videos, visit video landing pages, or interact with video content created through the Services.
  • Visitors: anyone who browses our marketing sites, support pages, or interacts with our promotional materials.

By using the Services, you consent to the practices described here. If you do not agree, please discontinue use of the Services.

2. Personal Data We Collect

Data you provide to us

We collect the personal data you choose to share, including:

  • Account and profile details such as name, email address, password, and profile photo.
  • Video content you upload, record, or create through the Services, including screen recordings, camera recordings, and edited video projects.
  • Campaign recipient data, including names, email addresses, and custom personalization tokens you provide for video campaigns.
  • Payment and billing information (e.g., billing contact details, billing address). Payment card data is processed by Dodo Payments and not stored by VidPal.
  • Support requests, feedback, and any other information you provide when you contact us.

Data we collect automatically

When you use the Services, we automatically collect certain information, including:

  • Usage and log data such as the pages you view, features you use, actions you take, timestamps, referring/exit pages, and session IDs.
  • Device and browser information including IP address, browser type, operating system, device identifiers, language settings, and approximate geolocation derived from your IP address.
  • Cookies and similar technologies used to operate and improve the Services.
  • Video engagement data such as views, watch time, percentage watched, click-through actions, and viewer interaction metrics.

Chrome Extension

Our Chrome extension enables screen recording, tab recording, and camera recording directly from your browser. When you use the extension:

  • Screen and tab recordings are captured locally in your browser using browser APIs (getDisplayMedia, tabCapture, desktopCapture). Recordings are uploaded to our servers (Cloudflare R2) for storage and playback only after you complete a recording.
  • Camera and microphone access is requested only when you choose to record with camera or microphone enabled. This data is not accessed unless you initiate a recording.
  • Authentication tokens are stored locally in your browser (chrome.storage) to keep you signed in. These tokens are sent to our servers to authenticate API requests.
  • Google Drive integration (optional): If you choose to save recordings to Google Drive, the extension requests access to the Google Drive API with the drive.file scope, which only allows access to files created by the extension. No other files in your Google Drive are accessed or read.
  • Tab and display information (such as active tab URL and display dimensions) is accessed locally to facilitate recording and is not transmitted to our servers.

The extension does not collect browsing history, read page content, or track your activity outside of the recording features you initiate.

3. How We Use Personal Data

We use personal data for the following purposes:

  • Provide, operate, and maintain the Services, including video recording, editing, hosting, sharing, and analytics.
  • Process video recordings and deliver AI-powered features such as automatic captions, dubbing, voice change, summarization, and chat-with-video.
  • Create and manage accounts, authenticate users, and process payments or subscription charges.
  • Send notifications, service announcements, video-ready alerts, and support responses.
  • Personalize experiences, recommend configurations, and remember your preferences.
  • Monitor and analyze usage, trends, and activities to improve the Services and develop new features.
  • Detect, investigate, and prevent fraud, abuse, security incidents, and other harmful activity.
  • Comply with legal obligations, enforce our agreements, and protect our rights, users, and the public.

Where required by law, we will obtain your consent before using personal data for certain purposes, and you may withdraw consent at any time.

4. Legal Bases for EEA/UK/Swiss Personal Data

When the GDPR, UK GDPR, or Swiss data protection laws apply, we process personal data under these legal bases:

  • Contract: To provide the Services and fulfill our agreements with you.
  • Legitimate interests: To secure and improve the Services, respond to inquiries, deliver video analytics, and prevent misuse, provided these interests are not overridden by your rights.
  • Consent: For certain marketing, analytics, or optional integrations; you may withdraw consent at any time.
  • Legal obligations: To comply with applicable laws, regulations, and lawful requests.

5. How We Share Personal Data

We do not sell personal data. We may share personal data in these circumstances:

Service providers

Vendors and subprocessors that help us deliver the Services access personal data only to perform work on our behalf. Key service providers include:

ProviderPurpose
AWS (S3/CloudFront)Video storage & CDN
Cloudflare R2Video & asset storage
AssemblyAITranscription & caption generation
ElevenLabsAI dubbing & voice change
OpenAIAI features (summaries, chat, personalization)
Dodo PaymentsPayment & billing processing
InngestBackground job processing
ResendTransactional email delivery
Google APIs (Drive)Optional: save recordings to Google Drive (drive.file scope only)
TallyFeedback forms & bug reports

User-directed sharing

When you share videos publicly, publish video landing pages, or distribute campaign links, your video content and associated metadata become accessible to viewers. You control who can access your videos through sharing settings and password protection.

Legal compliance and protection

We may disclose information if required by law, subpoena, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, the safety of others, investigate fraud, or respond to a government request.

Business transfers

If we engage in a merger, acquisition, financing, or sale of all or part of our business, personal data may be transferred as part of that transaction, subject to appropriate confidentiality protections.

6. Cookies and Similar Technologies

We use cookies, pixel tags, local storage, and similar technologies to operate and improve the Services. These technologies help us remember preferences, keep you signed in, understand usage, and deliver relevant content.

Types of cookies we use

  • Essential: Required for core functionality, authentication, and security.
  • Performance and analytics: Help us understand how the Services are used to improve performance and user experience.
  • Functional: Enable enhanced features, such as remembering your recording preferences or editor settings.
  • Marketing: Used to deliver relevant marketing and measure campaign effectiveness, where permitted.

Managing preferences

You can manage cookies through your browser settings or our cookie banner (where available). Blocking some cookies may affect how the Services function.

7. Data Retention

We keep personal data only as long as needed for the purposes described in this Notice. Specific retention practices include:

  • Video content: Retained while your account is active and you choose to keep the content. Deleted videos are removed from our storage systems.
  • Engagement analytics: Video view data, watch time metrics, and CTA click data are retained for reporting and analytics purposes while your account is active.
  • Account data: Deleted upon account closure, subject to any legal or regulatory retention requirements.

When data is no longer needed, we will delete or de-identify it in accordance with our retention policies, unless we need to keep it to comply with legal or regulatory requirements.

8. Data Security

We implement technical, administrative, and organizational measures designed to protect personal data, including:

  • Encryption in transit (TLS) and at rest for stored data.
  • AES-256-GCM encryption for integration credentials and OAuth tokens.
  • Regular security audits and vulnerability assessments.
  • Access controls and least-privilege principles for internal systems.

Despite these efforts, no security controls are infallible, and we cannot guarantee absolute security. If you have reason to believe your account or interaction with us is no longer secure, please contact us immediately using the details in Section 34.

9. International Data Transfers

VidPal is operated by PepoCloud LLC. Your personal data may be transferred to and processed in countries other than where you live, including the United States. These countries may have data protection laws that differ from those in your jurisdiction.

When transferring personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses, reliance on adequacy decisions, or other lawful transfer mechanisms, and we take additional measures as needed to protect personal data.

10. Your Privacy Rights and Choices

Depending on where you live, you may have rights regarding your personal data, including:

  • Access and portability: Request a copy of your personal data in a structured, machine-readable format.
  • Correction and deletion: Request correction of inaccurate data or deletion of your personal data, subject to legal exceptions.
  • Opt-out: Object to certain processing activities or withdraw consent where processing is based on consent.

You can exercise these rights by contacting us at privacy@vidpal.ai or using in-product settings where available. We may request information to verify your identity before fulfilling your request.

11. Marketing and Communication Preferences

You can opt out of promotional emails at any time by clicking the unsubscribe link in the email or contacting us. Even if you opt out, we may still send you non-promotional messages about your account, transactions, or service updates.

Transactional emails — such as video-ready notifications, account confirmations, and security alerts — will continue regardless of your marketing preferences.

12. Third-Party Services and Integrations

The Services may contain links to or integrations with third-party sites, tools, or services. Your use of those services is subject to their terms and privacy policies, which we do not control. We encourage you to review those policies to understand how they handle your data.

VidPal offers integrations with CRM platforms, automation tools, messaging services, and tracking pixels. Detailed per-integration disclosures are provided in Sections 13 through 27 below. If you connect a third-party integration, data may flow between VidPal and that provider as directed by you. Disconnecting an integration will stop new data sharing but may not delete data already shared with that provider.

13. Use of HubSpot CRM Data

When you connect your HubSpot account via OAuth, VidPal accesses and processes certain data through HubSpot APIs.

Data we access

  • Contact data including names, email addresses, and associated contact records.

How we use HubSpot data

  • Sync video engagement data with your HubSpot contacts.
  • Create or update contacts when campaign recipients view your videos.
  • Log video engagement events (views, watch time, CTA clicks) as activities and notes on contact records.
  • We do not use HubSpot data for advertising or analytics unrelated to video engagement synchronization.

Sharing, storage, and control

OAuth tokens are encrypted with AES-256-GCM and stored securely. You can disconnect the HubSpot integration at any time from your VidPal settings, which will revoke access and stop data synchronization.

14. Use of Salesforce CRM Data

When you connect your Salesforce account via OAuth, VidPal accesses and processes certain data through Salesforce APIs.

Data we access

  • Lead and contact data including names, email addresses, and associated records.

How we use Salesforce data

  • Sync video engagement data with your Salesforce leads and contacts.
  • Create leads for unknown email addresses when campaign recipients engage with videos.
  • Log video engagement activities as tasks on lead and contact records.

Sharing, storage, and control

OAuth tokens are encrypted with AES-256-GCM and stored securely. You can disconnect the Salesforce integration at any time from your VidPal settings.

15. Use of Zoho CRM Data

When you connect your Zoho CRM account via OAuth, VidPal accesses and processes certain data through Zoho APIs.

Data we access

  • Lead and contact data including names, email addresses, and associated records.

How we use Zoho data

  • Create leads for new email addresses when campaign recipients engage with videos.
  • Log video engagement events as notes on lead and contact records.

Sharing, storage, and control

OAuth tokens are encrypted with AES-256-GCM and stored securely. You can disconnect the Zoho integration at any time from your VidPal settings.

16. Use of Copper CRM Data

When you connect your Copper CRM account using an API key and email address, VidPal accesses and processes certain data through Copper APIs.

Data we access

  • People data including names, email addresses, and associated records.

How we use Copper data

  • Create or update people records when campaign recipients engage with videos.
  • Log video engagement events as activities on people records.
  • We do not access data unrelated to video engagement synchronization.

Sharing, storage, and control

API keys are encrypted with AES-256-GCM and stored securely. You can disconnect the Copper integration at any time from your VidPal settings.

17. Use of ActiveCampaign Data

When you connect your ActiveCampaign account using an API key and account URL, VidPal accesses and processes certain data through ActiveCampaign APIs.

Data we access

  • Contact data including names and email addresses.

How we use ActiveCampaign data

  • Create or update contacts via the sync endpoint when campaign recipients engage with videos.
  • Log video engagement events as notes on contact records.

Sharing, storage, and control

API credentials are encrypted with AES-256-GCM and stored securely. You can disconnect the ActiveCampaign integration at any time from your VidPal settings.

18. Use of Close CRM Data

When you connect your Close CRM account using an API key, VidPal accesses and processes certain data through Close APIs.

Data we access

  • Lead and contact data including names, email addresses, and associated records.

How we use Close data

  • Create or update leads when campaign recipients engage with videos.
  • Log video engagement events as notes on lead records.

Sharing, storage, and control

API keys are encrypted with AES-256-GCM and stored securely. You can disconnect the Close integration at any time from your VidPal settings.

19. Use of Freshsales CRM Data

When you connect your Freshsales account using an API key and domain, VidPal accesses and processes certain data through Freshsales APIs.

Data we access

  • Contact data including names, email addresses, and associated records.

How we use Freshsales data

  • Create or update contacts when campaign recipients engage with videos.
  • Log video engagement events as notes on contact records.

Sharing, storage, and control

API keys are encrypted with AES-256-GCM and stored securely. You can disconnect the Freshsales integration at any time from your VidPal settings.

20. Use of Monday.com Data

When you connect your Monday.com account using an API token, VidPal accesses and processes certain data through Monday.com's GraphQL API.

Data we access

  • Board and item data, including item names and column values.

How we use Monday.com data

  • Search items by email address to find matching records.
  • Post video engagement data as updates on matching items.

Sharing, storage, and control

API tokens are encrypted with AES-256-GCM and stored securely. You can disconnect the Monday.com integration at any time from your VidPal settings.

21. Use of Zapier Data

When you authorize the VidPal integration on Zapier via OAuth, VidPal sends event data to your configured Zapier triggers.

Data we access

  • Zapier receives event payloads from VidPal; we do not access your Zapier account data.

How we use Zapier data

  • We send event data to Zapier triggers including: video views, CTA clicks, campaign launches, engagement thresholds, and new video events.
  • Event payloads include video metadata and viewer information but not video content itself.
  • You control which Zaps process this data and what downstream actions are taken.

Sharing, storage, and control

OAuth authorization is managed through Zapier's platform. You can revoke access at any time from your Zapier or VidPal settings.

22. Use of Make.com Data

When you configure a Make.com (formerly Integromat) webhook integration, VidPal sends event data to your specified webhook URL.

Data we access

  • We do not access your Make.com account data. We only send outbound event payloads to your webhook URL.

How we use Make.com data

  • We send the same event types as Zapier (video views, CTA clicks, campaign launches, engagement thresholds, new videos) to your configured webhook URL.
  • You are responsible for the security of your webhook endpoint and the processing of received data.

Sharing, storage, and control

Webhook URLs are stored securely in our database. You can remove or update your webhook configuration at any time from your VidPal settings.

23. Use of Slack Data

When you connect your Slack workspace via OAuth, VidPal sends notification messages to your selected Slack channel.

Data we access

  • We access only the permissions needed to post messages to your selected channel. We do not read Slack messages or access data beyond posting notifications.

How we use Slack data

  • Send notification messages about video views, CTA clicks, and engagement summaries to your chosen channel.

Sharing, storage, and control

OAuth tokens are encrypted with AES-256-GCM and stored securely. You can disconnect the Slack integration at any time from your VidPal settings, which will stop notifications and revoke access.

24. Use of Tracking Pixel Data

VidPal allows you to embed third-party tracking pixels and tags on your video share pages. Supported platforms include Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, Twitter/X Pixel, TikTok Pixel, and Pinterest Tag.

How tracking pixels work

  • When you enable a tracking pixel, the corresponding third-party script is embedded on your video share pages.
  • These scripts may collect viewer data (such as page views, interactions, and device information) according to their respective privacy policies.
  • We store only the pixel or tag IDs you provide. We do not receive, process, or store any data collected by these third-party scripts.

Your responsibilities

You are responsible for complying with each platform's policies (including obtaining viewer consent where required) when you enable tracking pixels on your video pages.

25. Use of AssemblyAI Data

Data we share

  • We send video audio to AssemblyAI for transcription and automatic caption generation.

How AssemblyAI processes data

  • Audio is processed for transcription and is not stored by AssemblyAI after processing is complete.
  • The resulting transcripts are stored in our database and associated with your video.

26. Use of ElevenLabs Data

Data we share

  • We send video audio to ElevenLabs for AI dubbing and voice change features.

How ElevenLabs processes data

  • Audio is processed in accordance with ElevenLabs' privacy policy.
  • The resulting audio files are stored in our systems and associated with your video.

27. Use of Dodo Payments Data

Data we share

  • We share billing information (name, email, billing address) with Dodo Payments for payment processing.

How Dodo Payments processes data

  • Payment card data is processed directly by Dodo Payments and is never stored by VidPal.
  • Dodo Payments handles payment data in accordance with their privacy policy and applicable payment card industry standards.

28. California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides specific rights regarding your personal information.

Your California rights

  • Request to know the categories or specific pieces of personal information we collect, use, disclose, or share.
  • Request deletion of personal information, subject to legal exceptions.
  • Opt out of the “sale” or “sharing” of personal information for cross-context behavioral advertising. We do not sell personal information.
  • Be free from discrimination for exercising your rights.

To exercise your rights, contact us at privacy@vidpal.ai. We will verify your request and respond as required by law. You may use an authorized agent to submit a request; we may require proof of authorization and confirmation of your identity.

29. U.S. State Privacy Rights (Virginia, Colorado, Connecticut, and Similar Laws)

Residents of certain U.S. states have rights such as confirming whether we process personal data, accessing and obtaining a copy of personal data, requesting deletion, correcting inaccuracies, and opting out of targeted advertising, the sale of personal data, or certain profiling.

You can exercise these rights by contacting privacy@vidpal.ai and specifying your state of residence. If we decline to act on a request, you may appeal by replying to our decision with “Appeal” in the subject line. We will respond to appeals within the timeframe required by applicable law.

To opt out of targeted advertising via cookies, adjust your browser settings or use our cookie banner (where available).

30. EEA, UK, and Swiss Residents

If you are located in the EEA, UK, or Switzerland, PepoCloud LLC is the controller of your personal data unless we process it on behalf of a customer as their processor. You may contact our Data Protection Officer at dpo@vidpal.ai.

Under the GDPR, you have the right to access, rectification, erasure, restriction of processing, data portability, and objection. You also have the right to lodge a complaint with your local data protection authority and may request information about cross-border transfer safeguards (see Section 9).

If we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

31. Children's Privacy

The Services are not directed to children under 13 (or under 16 in the EEA), and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can take appropriate steps to delete it.

If we learn that we have collected personal data from a child without appropriate consent, we will delete that information promptly.

32. Changes to This Privacy Notice

We may update this Notice to reflect changes in our practices, technologies, legal requirements, or other factors. When we do, we will update the “Last updated” date at the top of the Notice. In some cases, we may provide additional notice (such as a banner or email).

Your continued use of the Services after an update means you acknowledge the revised Notice.

33. Sub-Processors

We use the following third-party service providers (sub-processors) to process data on our behalf. We ensure all sub-processors maintain appropriate security and privacy standards.

Sub-ProcessorPurposeLocation
AWS (S3/CloudFront)Video storage & CDNUS/Global
Cloudflare R2Video & asset storageGlobal
AssemblyAITranscription & captionsUS
ElevenLabsAI dubbing & voiceUS/EU
OpenAIAI features (summaries, chat)US
Dodo PaymentsPayment processingUS
InngestBackground job processingUS
ResendTransactional emailUS
VercelApplication hostingUS/Global
Google APIsGoogle Drive integration (optional, drive.file scope)US/Global
TallyFeedback forms & bug reportsEU

This list may be updated from time to time. We recommend checking this section periodically for any changes.

34. Contact Us

If you have questions about this Privacy Notice or our privacy practices, please contact us:

Email: privacy@vidpal.ai

Data Protection Officer: dpo@vidpal.ai

Support: support@vidpal.ai

Address: Trinitar Solutions LLP, 99 A/3, South Street, Chatrapatti, Virudhunagar, Tamil Nadu 626102, India

Your Privacy Matters

We value your trust and are committed to transparency. If you have questions about your data or need to exercise your privacy rights, reach out and our team will respond promptly.