Privacy Policy
Last updated: July 30, 2026
This Privacy Policy explains how Riocut ("Riocut", "we", "us") collects, uses, and protects your information when you use our website and the Riocut application (together, the "Service"). By using the Service you agree to this policy. If you have any questions, contact us at support@khareedlow.com.
1. Information we collect
- Account information. Your name, email address, and password hash when you sign up, or your basic profile (name, email) when you sign in with Google or Discord.
- Content you provide. Videos, images, and audio you upload; video links you submit for processing; prompts, titles, and captions you write; and the projects, timelines, and clips the Service creates from them at your request.
- Connected social accounts. If you choose to connect a social account (YouTube, TikTok, Instagram, Facebook, X, or LinkedIn), we store the account's display name, avatar, platform user ID, and the OAuth access tokens the platform issues. We never see or store your social media passwords.
- Usage and billing data. Credit balance and usage records (which features consumed credits), plan information, and basic technical logs (IP address, browser type, timestamps) needed to operate and secure the Service.
- Cookies and local storage. We use them to keep you signed in and to remember preferences such as drafts and templates. We do not use third-party advertising cookies.
2. How we use your information
- To provide the Service: storing your media, generating and editing videos, transcribing audio, and creating clips.
- To process your content with AI: audio may be transcribed and transcripts may be sent to third-party AI model providers (for example via OpenRouter, Google, OpenAI, or Replicate) solely to perform the feature you requested, such as selecting clip highlights or generating captions. Your content is not used by us to train AI models.
- To publish on your behalf: when you explicitly click publish (or schedule a post), we upload the selected clip and caption to the social platform you chose, using the tokens from your connected account. We never post without an action you initiated.
- To manage credits, prevent abuse, provide support, and improve the Service.
3. Connected platforms
Publishing uses each platform's official API, and your use of those platforms remains governed by their own terms and privacy policies:
- YouTube. Riocut uses YouTube API Services. By connecting a YouTube account you also agree to the YouTube Terms of Service, and Google's Privacy Policy applies. Riocut's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use the YouTube upload permission only to upload videos you explicitly ask us to publish, and the read permission only to display your channel name and avatar. You can revoke Riocut's access at any time via Google security settings.
- Meta (Instagram and Facebook). We use the tokens only to list your pages/accounts and to publish the posts you request. Revoke access any time in your Facebook or Instagram settings.
- TikTok, X, LinkedIn. Same principle: identity display and user-initiated publishing only. Access can be revoked in each platform's app/security settings.
Disconnecting an account in Riocut deletes its stored tokens immediately. See also our data deletion instructions.
4. How we share information
We do not sell your personal information. We share data only with:
- Service providers that host our infrastructure (cloud compute, storage, databases) and process payments, under agreements that limit their use of your data to providing those services.
- AI model providers, limited to the content needed to fulfil the specific request you made (for example a transcript sent for highlight selection).
- Social platforms you connected, when you publish or schedule a post.
- Authorities, if required by law, or to protect the rights, safety, and security of Riocut and its users.
5. Data retention and deletion
- Your content and projects are kept while your account is active so you can keep working with them.
- Social account tokens are kept until you disconnect the account or delete your Riocut account.
- You can request deletion of your account and all associated data at any time by emailing support@khareedlow.com — see data deletion for details. We complete deletion within 30 days, except where a longer retention is legally required (for example billing records).
6. Security
Data is encrypted in transit (TLS). Access tokens and credentials are stored server-side and never exposed to other users or third parties. Access to production systems is restricted. No method of storage is 100% secure, but we work to protect your data with industry-standard measures and will notify affected users of any breach as required by law.
7. Your rights
Depending on where you live (including under GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise any of these rights, email support@khareedlow.com.
8. Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.
9. Changes to this policy
We may update this policy as the Service evolves. We will post the new version here and update the date above; material changes will be announced in the app or by email. Continued use of the Service after changes take effect means you accept the updated policy.
10. Contact
Questions or requests about privacy: support@khareedlow.com.