1. Introduction
At Videoath, we take your privacy seriously. This policy explains what information we collect, how we use it, and your rights regarding your data.
We've written this policy to be clear and straightforward. If you have questions, contact us at support@videoath.com.
2. Information We Collect
Account Information
When you create an account, we collect:
- Name and email address
- Profile photo (optional)
- Authentication data (managed by Clerk)
Profile & Preferences
During onboarding and in your profile, you may provide:
- Your role (pre-med student, applicant, etc.)
- Test type you're preparing for (CASPer, MMI)
- Target test date
- Schools you're applying to
- Email preferences
Video & Audio Recordings
When you practice, we store your video and audio recordings. This is core to how Videoath works — you record responses to practice scenarios, and we help you review and improve.
Your recordings include:
- Video/audio files of your practice responses
- Transcriptions (generated automatically)
- AI-generated feedback and scores
- Your written reflections
Usage Data
We automatically collect:
- Pages you visit and features you use
- Practice completion and progress data
- Device type, browser, and operating system
- IP address and general location (country/region)
- Referral source (how you found us)
Payment Information
When you make a purchase, payment is processed by Stripe. We receive confirmation of your purchase but never see or store your full credit card number. Stripe handles all payment security.
3. How We Use Your Information
We use your information to:
- Provide the service: Store your recordings, generate transcriptions, deliver mentor insights, track your progress
- Enable practice groups: Show your responses to group members, facilitate peer feedback
- Personalize your experience: Recommend content based on your test type, progress, and goals
- Send communications: Practice reminders, progress updates, and important account notifications
- Improve Videoath: Analyze usage patterns to make the product better (we use aggregated, anonymized data for this)
- Prevent abuse: Detect and prevent fraud, spam, and terms violations
4. Video Recordings — How We Handle Them
Your video recordings are sensitive data. Here's exactly how we handle them:
Storage
Recordings are stored securely on Convex cloud infrastructure with encryption at rest and in transit.
Who Can See Your Recordings
By default, only you can see your recordings. They become visible to others when:
- Practice groups: If you join a practice group, other group members can view responses you submit to that group
- Community sharing: If you choose to share a response publicly, other Videoath users can view it
- Shareable links: If you generate a share link, anyone with that link can view the recording
AI Processing
Your recordings are processed by AI to generate transcriptions and feedback. This processing happens automatically when you complete a recording. The AI provider (OpenAI) processes your content but does not retain it for training their models.
Deletion
You can delete any recording at any time from your dashboard. Deleted recordings are permanently removed from our systems within 30 days.
5. Practice Groups & Peer Review
Practice groups are designed for collaborative learning. When you participate:
- Other group members can see responses you submit to the group
- You can see other members' responses and provide feedback
- Feedback ratings (1-5 stars) are visible to the response owner
- Written or video feedback you provide is visible to the recipient
- Group admins can view all content within the group
You can leave a practice group at any time. Your past submissions to that group remain visible to other members unless you delete them.
6. Third-Party Services
We use trusted third-party services to operate Videoath:
| Service | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication | Email, name, profile photo |
| Stripe (via Autumn) | Payments | Payment details, purchase history |
| Convex | Database & file storage | All app data and recordings |
| OpenAI | AI feedback generation | Transcripts for analysis |
| PostHog | Product analytics | Usage events (anonymized) |
| MailerSend | Email delivery | Email address, name |
These services have their own privacy policies and are contractually obligated to protect your data.
7. Data Retention
We keep your data for as long as you have an account, plus:
- Account data: Retained until you delete your account
- Recordings: Retained until you delete them (or your account)
- Purchase history: Retained for 7 years for tax/legal compliance
- Analytics data: Retained for 2 years, then anonymized
- Email logs: Retained for 1 year
8. Your Rights
You have the right to:
Access Your Data
View all data we have about you. Most of this is accessible directly in your dashboard. For a full export, contact us.
Delete Your Data
Delete your recordings anytime from your dashboard. To delete your entire account and all associated data, contact us at support@videoath.com.
Export Your Data
Download your recordings and profile data. Contact us if you need help with a data export.
Opt Out of Marketing
Unsubscribe from marketing emails using the link in any email, or update your preferences in your profile settings. You'll still receive essential transactional emails (receipts, security alerts).
Correct Your Data
Update your profile information anytime in your account settings.
9. Security
We protect your data with:
- Encryption in transit (HTTPS/TLS) and at rest
- Secure authentication via Clerk
- Access controls limiting who can access production data
- Regular security reviews of our infrastructure
- Secure cloud hosting with Convex and Vercel
No system is 100% secure. If you discover a security vulnerability, please report it to support@videoath.com.
10. Children's Privacy
Videoath is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us and we'll delete it.
11. International Users
Videoath is operated from Canada. If you're accessing from outside Canada, your data will be transferred to and processed in Canada and the United States (where our service providers operate).
For users in the European Economic Area (EEA) or UK, we process your data under legitimate interests for providing the service you've signed up for. You have additional rights under GDPR — contact us to exercise them.
12. Changes to This Policy
We may update this privacy policy from time to time. If we make significant changes, we'll notify you via email or a notice on the platform before the changes take effect.
13. Contact Us
Questions about your privacy? We're here to help.
- Privacy inquiries: support@videoath.com
- General questions: support@videoath.com
- Security issues: support@videoath.com