Privacy Policy
This Privacy Policy explains how First Media Network Pvt Ltd collects, uses, stores, shares, transfers, and deletes personal data when you visit or use Pixeloop Studio, including clip.pixeloop.app, Pixeloop accounts and workspaces, video-processing and editing features, support services, payments, and connected-platform features.
1. Who we are
Pixeloop Studio (“Pixeloop”, “we”, “us”, or “our”) is operated by First Media Network Pvt Ltd, Chowki Number 2, Rewari, Haryana 123401, India.
For privacy questions, requests, or grievances, contact hello@pixeloop.app with the subject “Privacy request.”
For personal data used to administer Pixeloop accounts, billing, our website, product security, and our own service analytics, First Media Network Pvt Ltd generally acts as the data controller or data fiduciary.
When an organisation uses Pixeloop to process videos or other content containing personal data on its behalf, that organisation generally determines the purpose of the processing and acts as the controller or data fiduciary. Pixeloop processes that customer content on the organisation’s documented instructions as its processor or data processor, except where applicable law requires otherwise. If your data appears in content uploaded by a Pixeloop customer, please contact that customer first. We will assist the customer where required.
2. Scope
This policy applies to:
- clip.pixeloop.app and other Pixeloop Studio pages that link to this policy;
- Pixeloop accounts, workspaces, projects, editing, and rendering features;
- uploaded, linked, generated, and exported content;
- connected Google, YouTube, and other supported platform accounts;
- payments, customer support, security, and service communications; and
- visitors to the Pixeloop Studio website.
This policy does not govern a third-party service before information is provided to Pixeloop or after you direct Pixeloop to publish or transfer content to that service. Those services apply their own terms and privacy policies.
3. Personal data we collect
Depending on how you use Pixeloop, we may collect:
- Account and workspace data: name, email address, profile details, authentication identifiers, account preferences, workspace membership, role, and settings.
- Customer content and project data: uploaded or linked video, audio, images, logos, prompts, transcripts, captions, project settings, timestamps, editing decisions, brand presets, generated assets, rendered outputs, and related metadata. Customer content may incidentally contain personal data about people appearing or speaking in it.
- Connected-platform data: when you authorise a connection, channel or account identifiers, profile and channel information, video metadata, thumbnails, upload or publishing status, permitted analytics such as views, watch time, and audience retention, OAuth tokens, granted permissions, and token status.
- Billing and transaction data: billing contact details, country, plan, source-minute balance, transaction and payment identifiers, amount, currency, invoices, and payment or refund status. Razorpay and other authorised payment providers process payment credentials. Pixeloop does not receive or store full card numbers, CVV codes, banking passwords, or payment one-time passwords.
- Usage, device, security, and diagnostic data: IP address, browser and device information, operating system, language, timestamps, pages or features used, referral information, cookie or session identifiers, application events, rendering and processing diagnostics, error reports, fraud signals, and security logs.
- Communications: support messages, feedback, survey responses, and other information you choose to provide when contacting us.
4. How we obtain personal data
We obtain personal data:
- directly from you when you register, upload content, configure a project, make a purchase, or contact us;
- from the organisation that provides or administers your Pixeloop workspace;
- from connected services when you authorise Pixeloop to access them;
- automatically from your browser, device, and use of the service; and
- from service providers that help us process payments, prevent abuse, deliver communications, or operate Pixeloop.
If you provide content or personal data concerning another person, you are responsible for having the rights, permissions, notices, and lawful basis required to provide it to Pixeloop and instruct us to process it.
5. How and why we use personal data
We use personal data to:
- create, authenticate, and secure accounts;
- administer workspaces, permissions, plans, and source-minute balances;
- import media, transcribe speech, identify candidate clips, generate or transform creative material, render outputs, and deliver previews or downloads;
- apply captions, layouts, reframing, branding, editing instructions, and export settings;
- connect authorised accounts and upload or publish content at your direction;
- display authorised channel, video, publishing, or performance information;
- process purchases, issue invoices or refunds, and maintain financial records;
- send transactional, security, support, and service communications;
- diagnose failures, monitor reliability, prevent fraud and abuse, and protect Pixeloop and its users;
- enforce our Terms of Service and other agreements;
- comply with legal obligations and respond to valid legal requests; and
- understand and improve product performance using information appropriate for that purpose.
We do not use customer content or Google or YouTube user data to train general-purpose artificial-intelligence or machine-learning models. If we introduce an optional programme that uses private customer content for model improvement, we will provide a separate explanation and obtain any consent required before that use begins.
6. Legal bases for EEA and UK users
Where the EU GDPR or UK GDPR applies, we rely on one or more of the following legal bases:
- Contract: creating accounts and providing product features you request, including steps requested before entering a contract.
- Customer instructions: processing customer content for an organisational customer under our agreement; the customer determines its own lawful basis.
- Contract and legal obligation: billing, invoices, tax records, and legally required disclosures.
- Legitimate interests: security, fraud prevention, service reliability, support, and product improvement, balanced against the rights of affected individuals.
- Contract or consent: optional connected accounts and permissions, depending on the feature and applicable law.
- Consent: non-essential cookies, optional analytics, or marketing where applicable law requires it.
- Legal obligation or legitimate interests: establishing or defending legal claims and responding to lawful authorities.
You may withdraw consent at any time where processing relies on consent. Withdrawal does not affect processing already carried out lawfully. You may object to processing based on legitimate interests; we will consider the objection and stop processing where required by law.
Pixeloop does not make decisions producing legal or similarly significant effects about individuals solely through automated processing. Clip scores and AI-generated suggestions assist creative editing and can be reviewed or changed by the user.
7. Google and YouTube data
When you connect Google or YouTube, Pixeloop requests only the permissions needed for the feature you select. Depending on the permissions granted, Pixeloop may identify your channel, upload or manage videos at your direction, read video and channel information, and retrieve YouTube Analytics data for your own channel and content.
Pixeloop uses Google and YouTube data only to provide and secure user-facing features that you request. We do not sell that data, use it for advertising or surveillance, or use it to train general-purpose AI or machine-learning models. We do not permit humans to read Google user data except where necessary for security, legal compliance, or support that you affirmatively request and where applicable Google policies permit it.
Pixeloop’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Your use of YouTube features is also subject to the YouTube Terms of Service and Google Privacy Policy.
You can disconnect a connected account through Pixeloop where that control is available or email hello@pixeloop.app. You can also revoke Pixeloop’s access from your Google Account permissions. Removing data stored by Pixeloop does not automatically delete videos or other data held by YouTube; manage that content through YouTube.
8. AI and infrastructure processing
To perform a feature you request, Pixeloop may send the necessary content, transcript, prompt, project settings, and technical metadata to contracted infrastructure, transcription, rendering, storage, and AI providers. Providers may process that information only to provide contracted services, maintain security, and comply with law, subject to their agreements with us.
AI outputs and clip scores may be inaccurate. They are creative recommendations, not decisions about a person’s legal rights, employment, credit, insurance, healthcare, education, or access to essential services.
9. How we disclose personal data
We may disclose personal data to:
- authentication and identity providers;
- hosting, database, storage, content-delivery, transcription, AI-processing, and rendering providers;
- payment, invoicing, and fraud-prevention providers;
- email, monitoring, analytics, and customer-support providers;
- connected platforms when you instruct Pixeloop to access, upload, or publish content;
- professional advisers, auditors, insurers, and prospective transaction counterparties under appropriate confidentiality obligations;
- government authorities, courts, or other parties when required by law or reasonably necessary to protect rights, safety, and service integrity; and
- an acquirer or successor in connection with a merger, financing, reorganisation, acquisition, or sale of assets, subject to applicable notice and confidentiality requirements.
We require service providers to process personal data only for contracted purposes and to apply appropriate safeguards.
Pixeloop does not sell or rent personal data. Pixeloop does not share personal data for cross-context behavioural advertising or targeted advertising as those terms are defined by applicable US state privacy laws.
10. Cookies and similar technologies
Pixeloop uses cookies, local storage, and similar technologies where needed for authentication, security, fraud prevention, preferences, session continuity, and core product operation. We may use limited analytics to understand reliability and product usage.
Where applicable law requires consent, non-essential analytics or advertising technologies will be used only after consent. You may withdraw that consent through the cookie-preference control when available or through your browser settings. Blocking essential storage may prevent sign-in or other core features from working.
Pixeloop does not currently use third-party advertising cookies to build advertising profiles from your use of Pixeloop Studio.
11. International processing and transfers
Pixeloop is operated from India. Our providers may process personal data in India, the United States, or other countries where they operate. Privacy laws in those countries may differ from the laws where you live.
Where the EU GDPR or UK GDPR applies to a restricted international transfer, we use a lawful transfer mechanism where required, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another legally recognised safeguard. We may also rely on a permitted derogation for a specific transfer where applicable. We assess and apply supplementary technical or organisational safeguards when required.
You may contact hello@pixeloop.app to request further information about the transfer safeguards relevant to your personal data. Commercially sensitive or security-related portions may be redacted where law permits.
12. Retention and deletion
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including to provide and secure the service, complete requested processing, resolve disputes, enforce agreements, and meet legal, accounting, and tax obligations.
Our normal retention approach is:
- Account and workspace data: while the account or workspace is active and for a limited period after closure where needed for recovery, security, disputes, or legal compliance.
- Source media, projects, transcripts, settings, and generated outputs: while the related project or account remains active, until you delete them, or until an applicable product retention period expires.
- Temporary processing files: removed after processing or after a limited troubleshooting and recovery period.
- OAuth tokens: while the connection remains authorised and needed for the requested feature.
- Google or YouTube authorised data after disconnection or a deletion request: relevant tokens are revoked and authorised data is deleted as soon as possible and, where the Google API Services User Data Policy requires, within seven calendar days. Data associated with an externally revoked or unrefreshable authorisation is deleted as soon as possible and within 30 calendar days.
- Security and diagnostic logs: for a limited period appropriate to security, fraud prevention, and reliability needs.
- Support communications: for as long as needed to resolve the request, maintain support history, and protect legal rights.
- Billing, invoice, tax, and accounting records: for the period required by applicable financial and tax law.
When you delete data or close an account, we remove or de-identify it from active systems within a reasonable period unless continued retention is required or permitted by law. Residual copies may remain temporarily in encrypted backups and are removed or rendered inaccessible through the normal backup lifecycle. We may retain limited evidence of transactions, consent, requests, security incidents, or disputes where required by law or necessary to establish, exercise, or defend legal claims.
An organisation administering your workspace may be able to access, export, or delete workspace information in accordance with its agreement and applicable law.
13. Security
We use reasonable administrative, technical, and organisational measures designed to protect personal data. These include access controls, encryption in transit, credential separation, least-privilege practices, monitoring, backups, and incident-response procedures appropriate to the nature of the service.
No internet service is completely secure. You are responsible for protecting your credentials, limiting who can access your workspace, and ensuring that content and connected-platform permissions are appropriate for your use.
If we become aware of a personal-data breach, we will investigate and provide notices to affected customers, individuals, or authorities when applicable law requires it.
14. Your privacy rights
Depending on where you live and subject to applicable exceptions, you may have the right to:
- obtain information about how we process your personal data;
- request access to or a copy of your personal data;
- correct, complete, or update inaccurate personal data;
- request deletion or erasure;
- restrict or object to certain processing;
- withdraw consent where processing relies on consent;
- receive certain personal data in a portable format;
- opt out of certain sales, sharing, targeted advertising, or profiling where applicable;
- appeal a refusal of a request where applicable law provides an appeal right;
- nominate another person to exercise rights where Indian law provides that right; and
- complain to an applicable privacy or data-protection authority.
Pixeloop will not discriminate against you for exercising an applicable privacy right.
To exercise a right, email hello@pixeloop.app with the subject “Privacy request.” Describe the request and the account or workspace concerned. To protect users, we may verify your identity and authority before completing a request. An authorised agent may submit a request where permitted by law, but we may require proof of authority and identity.
We respond within the period required by applicable law. For EEA and UK requests, this is normally within one month, subject to lawful extensions for complex or numerous requests. If we cannot fulfil a request, we will explain the reason and any available complaint or appeal route where required.
EEA users
You may lodge a complaint with the data-protection authority in the EEA country where you live or work, or where you believe an infringement occurred. A list of authorities is available through the European Data Protection Board.
UK users
You may complain to the UK Information Commissioner’s Office. We encourage you to contact us first so we can try to resolve the concern.
United States residents
Where a US state privacy law applies to Pixeloop, residents may request access, correction, deletion, and portability and may exercise applicable rights to opt out of sale, sharing, targeted advertising, or certain profiling. Pixeloop does not sell personal data or use it for cross-context behavioural advertising. Because these laws apply only when statutory conditions are met, particular rights may not apply in every case.
India
Users in India may request access to information about processing, correction, completion, updating, or erasure, withdraw consent where applicable, nominate another person where the law permits, and use our grievance-redressal process. If a grievance is not resolved, you may have the right to approach the Data Protection Board of India when and to the extent the relevant provisions are in force.
15. Business customers and people appearing in customer content
Business customers are responsible for:
- providing required privacy notices to employees, contractors, customers, guests, speakers, and other people whose data they upload or connect;
- establishing a lawful basis and obtaining required permissions or releases;
- limiting content and account access to authorised users;
- configuring retention and deleting content when no longer needed; and
- responding to requests from individuals where the business customer acts as controller or data fiduciary.
If you appear in content processed by a Pixeloop customer and want to exercise a privacy right, contact the customer that uploaded the content. If you cannot identify or reach that customer, contact us and provide enough information to locate the content. We will assess the request and, where appropriate, forward it to or coordinate with the responsible customer.
16. Children
Pixeloop is intended for users aged 18 or older and is not directed to children. We do not knowingly create accounts for or collect personal data directly from children. If you believe a child has provided personal data to Pixeloop, contact us so we can investigate and take appropriate action.
Customers must not upload content concerning children unless they have all rights, permissions, consents, and safeguards required by applicable law.
17. Changes to this policy
We may update this policy when our service, providers, legal obligations, or data practices change. We will post the revised policy with a new “Last updated” date. Where a change materially affects your rights or requires consent, we will provide additional notice or obtain consent as required before the change takes effect.
18. Contact and grievance redressal
First Media Network Pvt Ltd
Chowki Number 2
Rewari, Haryana 123401
India
Email: hello@pixeloop.app. Please use the subject “Privacy request” or “Privacy grievance” and do not send passwords, API keys, full payment-card numbers, banking passwords, or one-time passwords.