Privacy Policy
Last updated: August 23, 2026
This Privacy Policy explains what information Reeloop (“Reeloop”, “we”, “us”) collects when you use our website and faceless-video generation service (the “Service”), how we use it, and the choices you have. For users in the EEA/UK, this includes the disclosures required by GDPR Art. 13.
Data controller
The data controller is APP STUDIO, a SASU (société par actions simplifiée unipersonnelle) registered with the Marseille RCS under number 917 474 207, whose registered office is at BT B, 18 Boulevard Reynaud de Trets, 13010 Marseille, France (EU VAT: FR06917474207), trading as Reeloop (contact: support@reeloop.ai). The controller determines how and why your personal data is processed.
When Reeloop acts as processor
The section above describes when APP STUDIO is the controller - which is the case for an individual using Reeloop for themselves, and for our own account, billing, fraud-prevention, security and consent-gated analytics purposes. It is different when a business customer determines the purposes and means of processing content through the Service (prompts, scripts, uploaded media, voice and likeness assets, social-publishing tokens and schedules, API requests). For that Customer Data, APP STUDIO processes it on the business customer's behalf as processor, under the Data Processing Addendum. The business customer is then responsible for its own legal basis, notices and instructions. Where an agency uses Reeloop for its own client, that agency is the controller (or its client's processor) and Reeloop is its sub-processor.
Information we collect
Account data. When you sign up we collect your email address and, optionally, your name - either the display name your Google or Microsoft account gives us, or one you type into the optional field on the sign-up form or when we ask "what should I call you?" during onboarding. The name is used to address you in the product and in our email; it is never required, and you can change or clear it at any time. Authentication is handled by Supabase; we do not store passwords.
Content you submit. The topics, scripts, URLs, and settings you provide to generate videos, and the resulting scripts, scenes, voiceover, and caption data.
Billing data. If you subscribe, payments are processed by Stripe. We receive a customer and subscription identifier and your plan status. We never receive or store your full card number.
Usage data. Basic technical information (such as credits used and request timestamps) needed to operate the Service.
Device & anti-abuse signals. Free video generations cost us real money, so we process technical signals about the device and network used to sign up in order to protect the free tier from automated and repeat abuse: a device identifier derived by Fingerprint from browser and device characteristics, indicators such as automated-browser, virtual-machine and proxy/VPN detection, your IP address, and how many recent signups came from it. We use these only to decide whether a new account qualifies for free promotional credits and to detect abuse - never for advertising, profiling, or to identify you outside your Reeloop account. A signup that doesn't qualify still gets a working account; only the free credits are withheld. Fingerprint's agent runs as an essential anti-abuse measure and is not controlled by the cookie banner (see Cookies below); we rely on our legitimate interest in preventing fraud, and you can object under Your rights below.
Biometric-adjacent media (only if you use these features). If you create a voice clone, a video avatar, or an actor/character from your own reference photo or video, you submit a voice sample, portrait image, or short video of a person. We process this only to produce the feature you asked for and only after an explicit in-app confirmation that you have the right (and, where the person is not you, that person's consent) to use it. We never use it to identify anyone, train a general model, or for advertising.
Connected social accounts. If you connect TikTok, YouTube, or Instagram, we receive an OAuth access token (stored encrypted), your account id/handle on that platform, and - when you publish or view analytics - the resulting post ids and view/like/comment/share counts.
How we use your information
We use your information to provide and operate the Service, generate the content you request, manage your credits and subscription, respond to support requests, prevent abuse, and comply with legal obligations.
Legal bases (EEA/UK)
We process personal data on these bases: performance of our contract with you (operating the Service, generating your content, billing, transactional email such as welcome / video-ready / payment notices); your consent (analytics, advertising and session-replay cookies, the support chat, voice cloning, video avatars, and actor/character replicas - you can withdraw consent at any time via the cookie settings or by deleting the feature); our legitimate interests (keeping the Service secure and preventing abuse - including the Turnstile bot check, Fingerprint's device-identification agent, and the server-side risk scoring that decides whether a new account receives free promotional credits - error tracking, and improving the product in ways that don't override your rights); and legal obligation (retaining limited billing records for tax and accounting). Marketing email is sent only with your consent or as permitted by applicable soft-opt-in rules, and every message carries an unsubscribe link.
Third-party processors
To deliver the Service we share the minimum necessary data with:
Infrastructure: Supabase (authentication, database & file storage), Vercel (hosting), Stripe (payments - we never receive or store your full card number), and Sentry (error tracking, to diagnose bugs and outages).
Security & anti-abuse: Cloudflare (Turnstile - a bot check on the sign-up and sign-in pages) and Fingerprint (device intelligence used to detect automated and repeat signups claiming free credits; receives browser/device characteristics and your IP address, not your content). If you sign up with an email address and password rather than with Google or Microsoft, Castle also scores that sign-up for automated abuse and receives the email address you signed up with, your IP address and your browser headers. These run as essential security measures and are not consent-gated.
AI model & media providers used to generate your content - the topic, script, reference images/voice samples, and product URLs you submit are sent to whichever of these produce your output: Anthropic (script writing), ByteDance / BytePlus (Seedance) and Kling (AI video scenes), kie.ai (routing for the premium video models offered on paid plans) and, through it, Google (Veo 3.1 video scenes), OpenAI (catalog-voice text-to-speech, Whisper transcription/captions, and content moderation), ElevenLabs (voice cloning and cloned-voice text-to-speech), Tavus (video-avatar face replicas, when you create one), fal.ai (image generation and lip-sync), json2video (assembling scenes/audio/captions into the final video), and Pexels and Pixabay (real stock-footage clips, when enabled - only a search query derived from your topic is sent; note that if a personal name appears in your topic, it can be included in that query).
Communications & analytics: Resend (transactional email - welcome, video-ready, billing, and reconnect notices) and Loops (contact records and lifecycle email - Loops receives your email address, your name if we have one, and your plan, so its sequences can address you and branch on what you're paying for; the contact is deleted when you delete your account); and, only with your cookie consent, PostHog (product analytics), Meta (advertising pixel/conversions API), Microsoft Clarity (session replay and heatmaps) and Crisp (in-app support chat). Google Tag Manager loads on every page but is configured with consent mode defaulting to denied, so its measurement tags only fire once you accept.
Not sub-processors for your content. Stripe (payments), PostHog (product analytics), Meta (advertising measurement), Microsoft Clarity (session replay), Google Tag Manager, Crisp (support chat), Loops (contact records and lifecycle email), Cloudflare (Turnstile bot check) and Fingerprint (anti-abuse device intelligence) and Castle (sign-up abuse scoring) act for our own controller-side purposes - billing records, security, support and consent-gated analytics. They do not process the content you submit on a business customer's behalf, so they are covered here rather than in the Data Processing Addendum's sub-processor list.
Publishing & analytics recipients. When you connect and publish to a social platform, your video, caption, and post settings are sent to that platform as the recipient: TikTok (Content Posting API), Google / YouTube (Data API), and Meta (Instagram Graph API). When you view analytics we read back the post metrics from those same APIs. Publishing is your instruction: once posted, the content is public on that platform and governed by its own terms and privacy policy.
International transfers. Some processors are located outside the EEA/UK (notably in the United States). Where data is transferred internationally it is protected by an approved safeguard - the EU-U.S. Data Privacy Framework or Standard Contractual Clauses - as provided by each processor.
Cookies
We use essential cookies required to keep you signed in - these are always on and can't be declined without breaking the app. Cloudflare Turnstile also runs on the sign-up and sign-in pages as an essential bot check, and Fingerprint's device-identification agent runs on every page as an essential anti-abuse measure - it reads browser and device characteristics to derive a device identifier used to detect repeat and automated signups claiming free credits. Neither is consent-gated. With your consent (see the cookie banner), we additionally use analytics cookies (PostHog), session replay (Microsoft Clarity), an advertising cookie/pixel (Meta), and the in-app support chat (Crisp). Google Tag Manager loads on every page with consent mode set to denied by default, and only activates measurement tags once you accept. Declining keeps only the essential cookies, the Turnstile bot check, and Fingerprint; we do not sell your data.
Data retention
We keep your account and generated content while your account is active, and remove data on a fixed schedule enforced by an automated daily job. The concrete windows:
- Studio tool outputs (intermediate images a Studio tool produces) are automatically deleted after 30 days.
- Source voiceover and transcript for a finished video are deleted 7 days after the final video is rendered (the audio is baked into the MP4).
- Failed generations (refunded, no output) are purged after 14 days.
- Connected-account OAuth tokens are kept until you disconnect that account or delete your account.
- Voice-clone samples and avatar/actor reference media are kept until you delete that feature or your account.
- Finished videos are kept until you delete them or your account; they are your content — except on a free plan, where the video, thumbnail, and voiceover audio files (not the record of what you made) are removed after 6 months of account inactivity, with a 14-day warning email first. This does not apply to paid plans.
You can delete your account and all associated data at any time from Settings → Account, or follow our data deletion instructions. After deletion we remove your personal data except where we are required to retain limited records (for example, billing records kept for the statutory tax/accounting period).
One limit worth stating plainly. Account deletion removes your data from our own systems and issues erasure requests to the providers we hold an identifier for. It does not automatically reach the two anti-abuse providers described above: we never store a Fingerprint visitor identifier or a Castle record id, so we have no handle to delete by. What they hold is the device and network signals (and, for Castle, the email address) captured at sign-up, under their own retention schedules - not your content, scripts, videos or connected accounts, none of which are ever sent to them. If you want that data erased too, email us at the address below and we will pass the request on.
Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, to restrict or object to certain processing, to data portability, and to withdraw consent at any time (without affecting processing already carried out). To exercise any of these rights, email us at the address below. If you are in the EEA/UK you also have the right to lodge a complaint with your local data-protection supervisory authority.
Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.
Changes
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about privacy? Email support@reeloop.ai.