Privacy Policy

Effective date: To be set at launch · Version 1.2 (draft)

This document describes how Viqu handles personal data. It is not a substitute for legal advice.

This Privacy Policy explains what information we collect, how we use it, and the choices you have when you use Viqu — our website at videoquery.site, our web application, and related APIs and services (together, the “Service”). Viqu lets you submit a video (by pasting a YouTube or web link, or uploading a file) so we can build a searchable, chat-ready index of that video and answer your questions about it with timestamped citations.

By using the Service you agree to this Privacy Policy and to our Terms of Service. If you do not agree, please do not use the Service.

The Service is operated by Proxima Core Technologies, based in Pakistan. We offer the Service to a global audience; see the section on International transfers below.

1. Information we collect

Account and identity data

We use Clerk to authenticate users. When you sign up or sign in, we receive and store the identifiers Clerk provides, which may include your user ID, email address, and (if you provide them) name and profile image, along with authentication metadata such as sign-in timestamps and the sign-in method you used.

We also store account attributes we manage ourselves, such as your role (for example, standard user or administrator) and account status.

Content you submit

When you use the Service, you provide content and we generate derived data from it:

  • Source references — the YouTube or web URLs you paste, or media files you upload for analysis.
  • Derived analysis artifacts — transcripts and subtitle text, scene and frame metadata, on-screen text (OCR), visual descriptions, and numerical embeddings used for search.
  • Chat data — the questions you ask, the answers generated, and the transcript/context snippets retrieved to produce those answers.
  • Job and processing metadata — processing status, stages, timing, and error information.

During processing we may temporarily hold media or audio files needed to run the pipeline; we do not retain full copies of source videos longer than necessary to provide the Service (see Data retention).

Billing and credits

If you purchase a subscription or credit pack, the sale is processed by our Merchant of Record, Paddle (the applicable Paddle contracting entity for your location). Paddle acts as an independent data controller for buyer payment, invoicing, fraud-prevention, and tax processing. We do not receive or store your full card number — Paddle handles it. We store the customer, subscription, transaction, and invoice or receipt references Paddle returns to us, your plan tier, your credit-wallet balance, and an immutable ledger of credit transactions.

Support data

If you submit a bug report or feedback, we collect the information you provide (for example, a title, description, steps to reproduce, a star rating, an optional comment, and optional page/client context). Some of this may be emailed to our administrators for handling.

Technical, product-analytics, and error-monitoring data

  • IP address and user-agent, and related request metadata, used for security, abuse prevention, and rate limiting.
  • Correlation/request identifiers recorded in our server logs.
  • A theme preference stored locally in your browser (localStorage), which is not sent to our servers.
  • Essential cookies and similar technologies used by us and by our authentication and payment providers to keep you signed in and operate the Service.
  • When product analytics is enabled in a given environment, PostHog may receive device and browser information, page views, coarse approximate location derived by the analytics provider, your account email (used as an analytics person identifier), selected product event names (for example, ingest or checkout funnel steps), and — for a sampled subset of sessions — masked session replay. We design events so they do not include full chat message text, transcripts, JWTs, or signed media URLs.
  • When error monitoring is enabled, Sentry may receive application error reports (stack traces, environment tags, and limited request metadata) from the web app, API, and GPU workers. We scrub authentication headers and avoid sending payment or auth request bodies. Sentry does not receive full chat content by design.

What we do not do

  • We do not sell your personal information.
  • We do not use third-party advertising or cross-site advertising trackers.
  • We do not intentionally collect more data than we need to run the Service.
  • We do not send full chat transcripts or raw video content to PostHog or Sentry.

2. How we use information

We use the information above to:

  • Provide and operate the Service — authenticate you, ingest and index videos, run chat, display your library, and meter and bill credits.
  • Secure and maintain the Service — prevent abuse and fraud, enforce rate limits, and diagnose and fix problems (including via error monitoring).
  • Understand product usage and improve the Service — using product analytics events and (where enabled) sampled, masked session replay.
  • Communicate with you — about your account, purchases, security, and material changes to our policies.
  • Comply with law and enforce our Terms — including responding to valid legal requests and copyright notices.

4. How we share information

We share personal data only as needed to run the Service, with providers acting on our behalf under contract, with Paddle as the independent controller and Merchant of Record for purchases, and where required by law. We do not sell personal data.

CategoryProvider(s)Purpose
AuthenticationClerkSign-up, sign-in, identity
PaymentsPaddle (Merchant of Record)Purchases, subscription billing, invoicing, fraud prevention, refunds, and tax
AI / machine learningOpenAIGenerate embeddings, chat answers, and speech-to-text in our cloud environments
GPU computeRunPod (when enabled/entitled)Run media-processing stages of the pipeline
Product analyticsPostHog (when enabled for that environment)Product usage events and sampled session replay (inputs masked; not full chat content)
Error monitoringSentry (when enabled for that environment)Application error reports from the web app, API, and GPU workers
Transactional emailResendDeliver support/administrative email notifications
Hosting and storageOur cloud infrastructure providersApplication database, cache/queue, and vector search to run the Service

When you submit a YouTube or web link, we access that third-party source to retrieve the content you asked us to analyze. Your use of YouTube content is also subject to Google/YouTube’s terms and privacy policies; we are not responsible for third-party sites.

We may also disclose information if we reasonably believe it is required to comply with law, enforce our Terms, or protect the rights, safety, or property of our users or others. If we are ever involved in a merger, acquisition, or sale of assets, we will provide notice before personal data becomes subject to a different privacy policy.

5. AI processing

Viqu uses AI models to index and answer questions about the content you submit. Speech-to-text and vision media stages run on entitled GPU infrastructure (local or RunPod). In our cloud environments, chat and embeddings are performed via OpenAI. We send providers only the content and prompts needed to produce your results. AI-generated answers, transcripts, and visual descriptions can be inaccurate or incomplete; you are responsible for how you use them (see the Terms of Service).

6. Data retention

We keep personal data only for as long as needed for the purposes described here:

DataRetention
Account dataUntil you delete your account or ask us to delete it (see Your rights)
Videos, indexes, and chat historyWhile your account is active, or until you delete the video or your account
Temporary media/audio files used for processingNo longer than necessary to complete processing
Credit ledger and billing recordsRetained longer where required for financial, accounting, or tax purposes
Server logsKept for a rolling period for security and troubleshooting, then deleted, unless needed for an investigation
Product analytics and error reports (PostHog / Sentry)Retained according to each provider’s retention settings for our projects, typically for a limited rolling period needed for debugging and product improvement
Support ticketsUntil resolved and for a reasonable archival period

7. Security

We use reasonable technical and organizational measures to protect personal data, including encryption in transit (TLS), access controls, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. You may also have the right to lodge a complaint with your local data-protection authority.

To exercise these rights, email uranus.app.ai@gmail.com. We will respond as required by applicable law.

Account deletion. When you delete your account (or it is deleted through our authentication provider), we mark the account as deleted and disable access. Associated content and index data are removed or scheduled for deletion; some records (for example, billing/credit-ledger entries) may be retained where the law requires. You can request full deletion of remaining personal data by contacting us, subject to those legal retention limits.

9. Children

The Service is not directed to, and we do not knowingly collect personal data from, anyone under 16 years of age (or a higher age if required by the laws that apply to you). If you believe a child has provided us personal data, contact uranus.app.ai@gmail.com and we will delete it.

10. Cookies and similar technologies

We use cookies and similar technologies that are essential to operate the Service — primarily to keep you signed in (via our authentication provider) and to support core functionality and security. Your theme preference is stored in your browser’s localStorage and is not transmitted to us. We do not use advertising or cross-site advertising cookies.

When product analytics is enabled, PostHog may set first-party analytics cookies (or use localStorage) to distinguish sessions and deliver sampled session replay. We treat this as product analytics rather than advertising. If we expand non-essential cookies for EU/UK users in a way that requires a consent banner under applicable law, we will update this policy and implement the required choices before relying on those cookies.

11. International transfers

We operate globally and rely on providers (such as Clerk, OpenAI, Paddle, Resend, PostHog, and Sentry) that may process data in the United States, Canada, the United Kingdom, the European Economic Area, and other countries. This means your personal data may be transferred to and processed in countries whose data-protection laws differ from those in your country. Where required, we and our providers rely on appropriate safeguards (such as standard contractual clauses and equivalent mechanisms) for these transfers.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Effective date” above and, where appropriate, provide additional notice on the Service or by email. Your continued use of the Service after an update takes effect means you accept the revised policy.

13. Contact us

Proxima Core Technologies — email uranus.app.ai@gmail.com.

For privacy questions, data-access or deletion requests, or complaints, contact us at the address above.

This Privacy Policy describes Viqu’s practices. It is not legal advice to you and does not create warranties beyond those in our Terms of Service.