Reelory← Back

Privacy Policy

Last updated: 31 July 2026

This Privacy Policy explains how personal data is collected, used, stored and protected when you use Reelory (the “Service”), available at reelory.ai.

Reelory is a software product. The platform automatically analyses short-form videos (such as Reels, TikTok and Shorts) and returns an AI-generated report covering the hook, structure, virality triggers and pacing of the video. Processing is fully automated and typically completes in about a minute. The Service involves no human review of your videos: every report is produced by software.

Please read this Policy together with our Terms of Service and Refund Policy.

1. Who is responsible for your data (Controller)

The data controller is:

Irina Iscenco, acting as an individual (sole trader). There is no separate legal entity.

ControllerIrina Iscenco (individual / sole trader)
Place of establishmentThailand — the controller is an individual established outside the EEA and the UK
Emailsupport@reelory.ai
Telegram@reelory_support

For any privacy question, request or complaint, write to support@reelory.ai. We aim to reply within 5 business days and, for formal data subject requests, within the statutory deadlines set out in Section 10.

A data protection officer (DPO) has not been appointed, as the Service does not meet the criteria in Article 37 GDPR. Privacy matters are handled directly by the controller via the contact channels above.

2. Scope of this Policy

This Policy applies to personal data processed when you:

  • visit reelory.ai;
  • create and use a Reelory account;
  • submit video links for automated analysis;
  • purchase credit packages;
  • contact support.

It does not apply to third-party websites or platforms you may reach through links from the Service, or to the platforms hosting the videos you submit. Those services have their own privacy policies.

3. What data we collect

3.1 Account data

  • Email address
  • Password, stored only as a salted one-way hash (we never store or see your plaintext password)
  • Account creation date, language/locale preference
  • Current credit balance and credit transaction history

3.2 Content data

  • URLs of the videos you submit for analysis
  • The video and audio content downloaded from those URLs for the purpose of running the analysis
  • Speech transcripts generated from that audio
  • The AI-generated analysis reports, account audits and content plans produced for you

3.3 Transaction data

  • Purchase history: package purchased (Starter / Standard / Pro), amount, currency, date, order and receipt identifiers
  • Refund records where a refund has been requested

We do not collect, process or store your card number, CVV, expiry date or bank account details. All payment data is collected and processed directly by Paddle, which acts as merchant of record for purchases made through the Service (see Section 6).

3.4 Technical data

  • IP address
  • Browser type and version, device and operating system, user agent
  • Timestamps, pages viewed, referring URL
  • Session and authentication identifiers
  • Diagnostic data attached to application errors (error type, stack trace, request context)

3.5 Communications data

  • The content of emails and Telegram messages you send to support, and our replies
  • Delivery events for transactional emails (sent, delivered, bounced, opened where technically recorded)

3.6 Cookie and consent data

  • Your cookie choices (see Section 9)

3.7 Data we do not want to receive

The Service is not designed for special categories of personal data (Article 9 GDPR) — such as health, biometric, political, religious or sexual-life data — or for criminal offence data. Please do not submit videos or text containing such data.

Videos you submit may contain personal data of other people (for example, the person appearing in the video). You are responsible for ensuring that you are entitled to submit the link, and that doing so does not infringe the rights of others. We process that content solely to generate your report; the retention of the underlying media is described in Section 8.

4. Why we process your data and on what legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Create and maintain your account, authenticate youAccount dataPerformance of a contract — Art. 6(1)(b)
Run the automated video analysis and deliver reports, audits and content plansContent data, account dataPerformance of a contract — Art. 6(1)(b)
Process purchases, allocate credits, issue receipts, handle refundsTransaction data, account dataPerformance of a contract — Art. 6(1)(b)
Keep accounting and tax records of transactionsTransaction dataLegal obligation — Art. 6(1)(c)
Send transactional emails (confirmations, receipts, password resets, service notices)Account data, transaction dataPerformance of a contract — Art. 6(1)(b)
Provide customer supportCommunications data, account dataPerformance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f)
Keep the Service secure: prevent abuse, fraud, credential stuffing, scraping and rate-limit violationsTechnical data, account dataLegitimate interests — Art. 6(1)(f)
Monitor errors, diagnose faults and maintain reliabilityTechnical dataLegitimate interests — Art. 6(1)(f)
Aggregate, non-identifying statistics about product usage to improve the platformTechnical data, aggregated usage countsLegitimate interests — Art. 6(1)(f)
Marketing or product-update emails, where offeredEmail addressConsent — Art. 6(1)(a)
Establish, exercise or defend legal claimsAny of the above, as strictly necessaryLegitimate interests — Art. 6(1)(f); legal claims — Art. 9(2)(f) where applicable

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. Our interests are in operating a secure, functioning, financially sustainable software service. You may object to this processing at any time (see Section 10).

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Providing an email address and a password is a contractual requirement: without them we cannot create an account or deliver the reports you purchase. Providing a video URL is necessary to run an analysis. You are not required to provide any other personal data, and not providing it does not affect your access to the Service.

We do not sell personal data. We do not share personal data with advertising networks or data brokers, and we do not build advertising profiles.

5. Automated processing and AI

The analysis produced by Reelory is generated automatically by software, including large language models and speech-to-text models operated by our AI and speech-to-text subprocessors (see Section 6). This is the core function of the product.

This automated processing is applied to the video content you submit, not to you as a person. We do not use automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Your reports are informational output; acting on them is entirely your decision.

Content sent to our AI subprocessor for analysis is submitted through its commercial API. Under the commercial API terms of our AI provider in force at the date of this Policy, inputs and outputs sent through the API are not used to train its models. We will update this Policy if that changes.

6. Who we share data with (processors and recipients)

Most of these providers act as our processors and are bound by a written data processing agreement requiring them to process personal data only on our documented instructions, to apply appropriate security measures, and to assist us with data subject rights and breach notification. Paddle is an exception: for payment, tax and fraud-prevention data it acts as an independent controller under its own privacy policy.

ProviderRoleWhat they processLocation of processing
PaddlePayments; merchant of record for all purchases. Paddle acts as an independent controller for payment, tax and fraud-prevention data under its own privacy policyEmail, billing country, card and payment data, transaction records, refund recordsEU / UK / USA
VultrApplication hosting (compute servers running the platform)All data handled by the application, including account, content and technical dataUSA (New Jersey)
SupabaseManaged database and object storage (running on AWS)Account data, content data (video URLs, transcripts, reports), credit and transaction recordsUSA (AWS us-east)
SentryError monitoring and diagnosticsTechnical data and error context; may incidentally include an account identifier or IP addressUSA / EU
ResendDelivery of transactional emails (confirmations, receipts, password resets, service notices)Email address, message content, delivery eventsUSA / EU
Anthropic (Claude API)AI processing: generating the analysis, audits and content plansVideo transcripts and derived text submitted for analysisUSA
DeepgramAutomated speech transcriptionThe audio track extracted from the video you submitted, and the resulting transcriptUSA

An up-to-date list of our subprocessors is available on request at support@reelory.ai. We will update this Policy when we add or replace a subprocessor.

We do not see or store your card details at any point. Card data is captured and held by Paddle.

Other recipients. We may also disclose personal data:

  • to professional advisers (accountants, lawyers) where necessary and under a duty of confidentiality;
  • to public authorities or courts where required by applicable law, and only to the extent legally required;
  • to a successor in the event of a transfer of the business, in which case you will be informed in advance and this Policy will continue to apply until replaced.

7. International transfers — data is stored and processed in the United States

Your personal data is stored and processed in the United States. Our application servers are located in New Jersey, USA, our database is hosted in the AWS us-east region in the USA, and our AI and speech-to-text processing providers operate in the USA. Some providers may additionally process data in the EU, the UK or other locations, as indicated in the table in Section 6.

If you are located in the European Economic Area, the United Kingdom or Switzerland, this means your personal data is transferred outside your home jurisdiction to a country that has not received an adequacy decision.

The controller is established outside the EEA and the UK. Where a representative under Article 27 GDPR or UK GDPR is required, it is [EU/UK REPRESENTATIVE].

Transfer mechanism. These transfers are made on the basis of:

  • the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (Module Two, controller-to-processor), incorporated into our agreements with each processor;
  • for UK data, the UK International Data Transfer Addendum to those Clauses (or the UK IDTA, where the provider uses that form), issued under section 119A of the Data Protection Act 2018;
  • for Swiss data, the Swiss adaptations recognised by the Swiss Federal Data Protection and Information Commissioner.

Supplementary measures.In addition to the contractual safeguards, we apply: encryption of data in transit (TLS 1.2 or higher), encryption at rest at the storage layer, one-way hashing of passwords, strict access controls and least-privilege credentials, and data minimisation — we download and store only the media needed to produce and re-display your report (see Section 8).

You may request a copy of the relevant transfer safeguards by writing to support@reelory.ai. Commercially confidential terms may be redacted.

8. How long we keep data (retention)

We keep personal data only as long as necessary for the purposes described above. Specific periods:

Data categoryRetention period
Account data (email, hashed password, settings, credit balance)For the life of your account. Deleted within 30 days of account deletion
Downloaded video and audio filesStored with the corresponding analysis so that the video can be replayed in your account, and deleted together with that analysis. Deleted within 30 days of account deletion
Transcripts and generated reports, audits and content plansStored in your account until you delete them, or until 24 months after creation, whichever comes first. Deleted within 30 days of account deletion
Video URLs you submittedStored with the corresponding report and deleted with it
Transaction and refund records7 years from the transaction date, in line with the accounting and tax record-keeping rules applicable to the controller and to Paddle as merchant of record. Retained even after account deletion, in the minimum form required by law
Server and application access logs (including IP address)30 days
Security and abuse-prevention records (blocked attempts, rate-limit events)90 days, or longer where needed to investigate an active incident
Error monitoring data (Sentry)Up to 90 days, in line with the retention configured in our monitoring plan
Transactional email delivery logsUp to 12 months, in line with the retention configured by our email provider
Support correspondence (email, Telegram)24 months from the last message in the thread
Cookie choicesStored locally in your browser until you clear your browser data. We do not keep a server-side record of your cookie choices
Encrypted system backupsRolling backups, overwritten in line with the backup retention window configured by our database provider; deleted data disappears from backups within that window

Where data must be retained for a legal obligation or to defend a legal claim, we restrict it from active use and keep only what is necessary for that purpose.

9. Cookies and similar technologies

We distinguish two kinds of cookies:

Essential cookies— required for the Service to function. These handle authentication and session state, security (including CSRF protection and abuse prevention), load balancing, and remembering that you have seen our cookie notice. They cannot be switched off, and are set on the basis of our legitimate interest in delivering a functioning, secure service (and, where applicable, the “strictly necessary” exemption under the ePrivacy Directive).

Non-essential cookies— analytics and product-usage measurement. We currently set only essential cookies. We set strictly necessary cookies only — no analytics, no advertising and no cross-site tracking — so there is no consent banner to interact with. If optional cookies are ever introduced, they will be off until you accept them, and this policy and our Cookie Policy will be updated first.

Most browsers also let you block or delete cookies directly; blocking essential cookies may prevent you from logging in.

We do not use cookies for advertising, cross-site tracking or profiling.

10. Your rights

We apply the core rights below — access, correction, export and deletion — to all users, wherever they are located. If you are in the EEA, the UK or Switzerland, you additionally have the following rights under the GDPR (and equivalent rights under the UK GDPR):

  • Access— obtain confirmation of whether we process your data and receive a copy of it, together with information about the processing.
  • Rectification— have inaccurate data corrected and incomplete data completed.
  • Erasure (“right to be forgotten”)— have your data deleted where one of the grounds in Article 17 applies.
  • Restriction— require us to limit processing in the circumstances set out in Article 18.
  • Portability— receive the data you provided to us in a structured, commonly used, machine-readable format, and transmit it to another controller.
  • Objection— object at any time to processing based on legitimate interests, on grounds relating to your particular situation; and object at any time, without needing a reason, to processing for direct marketing.
  • Withdraw consent— where processing is based on consent, withdraw it at any time.
  • Lodge a complaint— with the supervisory authority in your country of residence, place of work, or place of the alleged infringement. In the UK, this is the Information Commissioner’s Office (ico.org.uk).

How to exercise your rights.

  • Export your data — email support@reelory.ai from the address registered to your account and we will send you a machine-readable copy of your account data, your analysis history and your reports within one month.
  • Delete your account— use the account deletion function in your account settings. Deletion removes your account data, your reports and your submitted URLs on the schedule set out in Section 8. Transaction records required by tax law are retained as described there.
  • Any other request — email support@reelory.ai from the email address registered to your account, or contact us on Telegram at @reelory_support.

We will respond within one month of receiving your request. This period may be extended by up to two further months where the request is complex or where several requests have been received; we will tell you within the first month if this applies, and why.

Exercising your rights is free of charge. Where a request is manifestly unfounded or excessive — in particular because it is repetitive — we may charge a reasonable fee or refuse to act, and will explain our reasoning.

Identity verification. To protect your data, we may need to verify your identity before acting on a request. Normally, sending the request from the email address on your account is sufficient. We will not ask you for a copy of an identity document unless we have a genuine and documented doubt about your identity.

11. Security

We apply technical and organisational measures appropriate to the risk, including:

  • TLS 1.2 or higher for all data in transit;
  • encryption at rest at the storage layer;
  • passwords stored only as salted one-way hashes — never in plaintext or reversible form;
  • row-level access controls in the database so that account data is isolated per user;
  • least-privilege access to production systems, restricted to the controller and limited to what is necessary;
  • secrets held in environment configuration, never in source code, and never written to logs;
  • error and security monitoring with alerting;
  • encrypted backups with a limited retention window;
  • no storage of payment card data at any point.

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and within 72 hours of becoming aware of it, in accordance with Article 33 GDPR, and we will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR).

You are responsible for keeping your account credentials confidential. Please use a unique, strong password and notify us at support@reelory.ai if you suspect unauthorised access to your account.

12. Children

The Service is not intended for, and is not directed to, anyone under the age of 16. We do not knowingly collect personal data from children under 16. By creating an account you confirm that you are at least 16 years old.

If you believe that a child under 16 has provided us with personal data, contact support@reelory.ai. We will verify the situation and delete the data and the associated account without undue delay.

Some EEA member states set the digital consent age under Article 8 GDPR anywhere between 13 and 16. Whatever the local age, our own minimum age for using the Service is 16.

13. Changes to this Policy

We may update this Policy from time to time — for example, if we add a service provider, change a retention period, or if the law changes.

The date at the top of this page always shows when the current version took effect. If we make a material change — such as introducing a new purpose of processing, a new category of recipient, or a change affecting your rights — we will notify registered users by email at least 14 days before the change takes effect, and will display a notice in the Service.

If a change requires your consent under applicable law, we will ask for it separately. Continuing to use the Service after a change takes effect means you accept the updated Policy, except where consent is legally required.

Previous versions are available on request at support@reelory.ai.

14. Contact

For any question about this Privacy Policy or about how your data is handled:

  • Email: support@reelory.ai
  • Telegram: @reelory_support
  • Controller: Irina Iscenco (individual / sole trader), established in Thailand

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.