Privacy Policy

Last updated: December 12, 2025

1. Introduction

At Videoath, we take your privacy seriously. This policy explains what information we collect, how we use it, and your rights regarding your data.

We've written this policy to be clear and straightforward. If you have questions, contact us at support@videoath.com.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Profile photo (optional)
  • Authentication data (managed by Clerk)

Profile & Preferences

During onboarding and in your profile, you may provide:

  • Your role (pre-med student, applicant, etc.)
  • Test type you're preparing for (CASPer, MMI)
  • Target test date
  • Schools you're applying to
  • Email preferences

Video & Audio Recordings

When you practice, we store your video and audio recordings. This is core to how Videoath works — you record responses to practice scenarios, and we help you review and improve.

Your recordings include:

  • Video/audio files of your practice responses
  • Transcriptions (generated automatically)
  • AI-generated feedback and scores
  • Your written reflections

Usage Data

We automatically collect:

  • Pages you visit and features you use
  • Practice completion and progress data
  • Device type, browser, and operating system
  • IP address and general location (country/region)
  • Referral source (how you found us)

Payment Information

When you make a purchase, payment is processed by Stripe. We receive confirmation of your purchase but never see or store your full credit card number. Stripe handles all payment security.

3. How We Use Your Information

We use your information to:

  • Provide the service: Store your recordings, generate transcriptions, deliver mentor insights, track your progress
  • Enable practice groups: Show your responses to group members, facilitate peer feedback
  • Personalize your experience: Recommend content based on your test type, progress, and goals
  • Send communications: Practice reminders, progress updates, and important account notifications
  • Improve Videoath: Analyze usage patterns to make the product better (we use aggregated, anonymized data for this)
  • Prevent abuse: Detect and prevent fraud, spam, and terms violations

4. Video Recordings — How We Handle Them

Your video recordings are sensitive data. Here's exactly how we handle them:

Storage

Recordings are stored securely on Convex cloud infrastructure with encryption at rest and in transit.

Who Can See Your Recordings

By default, only you can see your recordings. They become visible to others when:

  • Practice groups: If you join a practice group, other group members can view responses you submit to that group
  • Community sharing: If you choose to share a response publicly, other Videoath users can view it
  • Shareable links: If you generate a share link, anyone with that link can view the recording

AI Processing

Your recordings are processed by AI to generate transcriptions and feedback. This processing happens automatically when you complete a recording. The AI provider (OpenAI) processes your content but does not retain it for training their models.

Deletion

You can delete any recording at any time from your dashboard. Deleted recordings are permanently removed from our systems within 30 days.

5. Practice Groups & Peer Review

Practice groups are designed for collaborative learning. When you participate:

  • Other group members can see responses you submit to the group
  • You can see other members' responses and provide feedback
  • Feedback ratings (1-5 stars) are visible to the response owner
  • Written or video feedback you provide is visible to the recipient
  • Group admins can view all content within the group

You can leave a practice group at any time. Your past submissions to that group remain visible to other members unless you delete them.

6. Third-Party Services

We use trusted third-party services to operate Videoath:

ServicePurposeData Shared
ClerkAuthenticationEmail, name, profile photo
Stripe (via Autumn)PaymentsPayment details, purchase history
ConvexDatabase & file storageAll app data and recordings
OpenAIAI feedback generationTranscripts for analysis
PostHogProduct analyticsUsage events (anonymized)
MailerSendEmail deliveryEmail address, name

These services have their own privacy policies and are contractually obligated to protect your data.

7. Data Retention

We keep your data for as long as you have an account, plus:

  • Account data: Retained until you delete your account
  • Recordings: Retained until you delete them (or your account)
  • Purchase history: Retained for 7 years for tax/legal compliance
  • Analytics data: Retained for 2 years, then anonymized
  • Email logs: Retained for 1 year

8. Your Rights

You have the right to:

Access Your Data

View all data we have about you. Most of this is accessible directly in your dashboard. For a full export, contact us.

Delete Your Data

Delete your recordings anytime from your dashboard. To delete your entire account and all associated data, contact us at support@videoath.com.

Export Your Data

Download your recordings and profile data. Contact us if you need help with a data export.

Opt Out of Marketing

Unsubscribe from marketing emails using the link in any email, or update your preferences in your profile settings. You'll still receive essential transactional emails (receipts, security alerts).

Correct Your Data

Update your profile information anytime in your account settings.

9. Security

We protect your data with:

  • Encryption in transit (HTTPS/TLS) and at rest
  • Secure authentication via Clerk
  • Access controls limiting who can access production data
  • Regular security reviews of our infrastructure
  • Secure cloud hosting with Convex and Vercel

No system is 100% secure. If you discover a security vulnerability, please report it to support@videoath.com.

10. Children's Privacy

Videoath is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us and we'll delete it.

11. International Users

Videoath is operated from Canada. If you're accessing from outside Canada, your data will be transferred to and processed in Canada and the United States (where our service providers operate).

For users in the European Economic Area (EEA) or UK, we process your data under legitimate interests for providing the service you've signed up for. You have additional rights under GDPR — contact us to exercise them.

12. Changes to This Policy

We may update this privacy policy from time to time. If we make significant changes, we'll notify you via email or a notice on the platform before the changes take effect.

13. Contact Us

Questions about your privacy? We're here to help.