Skip to main content
← Legal

Privacy Policy

Effective date: July 19, 2026  ·  v1.5  ·  VidScore LLC

Previous versions available upon request.

Download PDF ↓

1.What We Collect

VidScore™ collects data in three categories: account data, video analysis data, and usage analytics. The following sections explain exactly what each includes.


2.Account Data

If you create a VidScore account, we collect:

  • Your email address
  • A generated user ID (UUID) assigned by our auth system
  • Subscription status and tier (3-day access, Pro, or Premium)
  • Account creation and last-login timestamps
  • A randomly generated device identifier (UUID) stored in your Chrome extension for fraud prevention

We do not collect your name, phone number, or physical address unless you provide it voluntarily through a contact form.

Email addresses are normalized before storage (converted to lowercase, whitespace trimmed, and common alias patterns removed) to maintain account integrity and prevent duplicate accounts.

Enterprise Team Member Data

If your organization subscribes to VidScore Enterprise Data, we additionally collect membership data for every person your administrators invite to your team portal. For each team member we store:

  • Work email address (used as the canonical identity within your organization)
  • Display name (optional, as entered by the inviting admin)
  • Role assignment ("admin" or "member")
  • Membership timestamps: invited_at, joined_at, and last_login_at
  • A one-time invite token that expires 72 hours after an invite is sent

Team member data is scoped to your organization via row-level security. Members of one enterprise organization cannot see members of another. Administrators of your organization act as controllers of this data for their own team; VidScore processes it on their instructions under our Data Processing Agreement.

Every portal action (sign-in, download, invite, role change, settings change) is recorded in an append-only activity log scoped to your organization. Log entries contain the actor's user ID, the action name, a target identifier, the request IP address and user agent, and a JSON metadata blob for the action. See Sections 11 and 13 for retention and your rights.

Single Sign-On (SSO) Configuration Data (Scale tier)

If your organization is on the Scale tier and requests SAML SSO, we store the following SSO configuration metadata for each email domain you register:

  • Your company email domain (for example, nike.com)
  • The identity provider you selected from the request form (Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud, or other SAML 2.0)
  • An optional display name for the connection
  • The email address of the administrator who submitted the request
  • Request, activation, and removal timestamps
  • The Supabase SAML provider identifier (a non-secret internal UUID, populated after our team completes the manual IdP registration)

When a team member from a configured domain signs in, we receive their work email address and a user identifier from your identity provider via the SAML assertion. We do not store the SAML assertion itself or any additional claims issued by your IdP. The identifier is stored only as the Supabase Auth user ID on your enterprise_members row. Sign-in via SSO is recorded in the activity log as an auth.sso_login event.


3.Video Analysis Data

When you trigger an analysis, the extension collects publicly available information from the YouTube page, including video metadata (title, description, view count, duration, publish date), the video captions, and channel information (name, subscriber count, description). This data is used solely for generating your analysis and is not used for advertising or sold to third parties.

We analyze what creators say publicly. We do not access private videos, direct messages, or any content not visible to the public.

4.AI-Powered Analysis

VidScore uses Google Cloud Vertex AI (Gemini models) to analyze video content. When you trigger an analysis, the video captions and metadata described in Section 3 are sent to Google Cloud Vertex AI to produce your scores and analysis. Requests are routed to regional Vertex AI endpoints (us-east5, us-west1, europe-west4, asia-northeast1) for failover and latency. VidScore uses the paid Vertex AI service, which does not use your data for model training.

Analysis is processed on Google Cloud infrastructure, which may be located outside your country of residence. See Section 10 (International Data Transfers) for details.

5.Usage Analytics

We log usage events to understand how VidScore is being used and to diagnose errors. Events may include the video ID, content type, page URL, browser user agent, and a timestamp. We use this data to improve the product and fix issues.

Security & Fraud Prevention

To prevent subscription fraud and trial abuse, VidScore generates a random device identifier (UUID) that is stored in your Chrome extension storage. This identifier is sent to our servers when you start a trial or subscription to detect whether the same device has previously been used to create an account. It is not used for advertising, cross-site tracking, or any purpose other than fraud prevention. You can reset this identifier by reinstalling the extension.

We do not track you across websites. The extension only activates on YouTube domains. Device identifiers are processed under our legitimate interest in preventing fraud (see Section 9).


6.Chrome Extension Specifics

The VidScore extension analyzes videos on YouTube pages and communicates with vidscore.ai to enable features like people profiles. The side panel can remain open as you browse, but the extension does not monitor your browsing history or track activity on other sites.

  • Analysis is triggered per video, not passively
  • No cross-site tracking
  • The side panel can stay open across pages but only collects data on YouTube
  • Only connects to the domains declared in our Chrome Web Store manifest: YouTube (video data, captions, thumbnails, and channel avatars), our own vidscore.ai and Supabase backend, and public Wikimedia sources (Wikidata, Wikipedia, and Wikimedia Commons) for public-figure profiles and portrait images

To fetch captions, the extension uses your active YouTube session to retrieve them on your behalf. Session credentials used for this purpose are not stored on VidScore's servers.

We do not store your YouTube login credentials or any YouTube account identity. Your session is used only to retrieve captions and is not retained.

7.Payment Data

VidScore does not store credit card numbers, bank account details, or other payment credentials. All payment processing is handled by Stripe.

We receive confirmation of your subscription status and billing events from Stripe. We store those status records (e.g., "Pro active") but not your raw payment data.


8.Third-Party Services

VidScore uses the following third-party services to operate. Each may process data as part of our service delivery:

  • Google Cloud Vertex AI (Gemini models): AI-powered analysis of video captions and metadata to produce scores and findings
  • Supabase: database, authentication, and backend functions
  • Stripe: payment processing and subscription management
  • Google and YouTube APIs: video metadata and caption retrieval
  • Google Knowledge Graph API: public identity verification for people identified in videos
  • Wikimedia projects (Wikidata, Wikipedia, and Wikimedia Commons): public identity enrichment and public-figure portrait images (open databases; queries and images are public)
  • Cloudflare: network security, DDoS protection, and edge delivery
  • Redis: caching layer for analysis results and performance optimization
  • Vercel: website hosting

We do not sell your data to any third party. These services are processors, not buyers.



10.International Data Transfers

VidScore LLC is based in the United States. If you are located outside the US, your data is transferred to and processed in the US and other countries where our service providers operate.

  • Supabase: US-based infrastructure
  • Google Cloud Vertex AI: processed on Google Cloud infrastructure across multiple regions (us-east5, us-west1, europe-west4, asia-northeast1)
  • Stripe: US-based with global processing
  • Cloudflare: edge locations worldwide
  • Vercel: US-based hosting with global CDN

For transfers from the EU/EEA, we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission, and where applicable, adequacy decisions. Our service providers maintain their own data protection agreements that include appropriate safeguards for international transfers.


11.Data Retention

We retain data for as long as it is needed to operate the service.

  • Account data: retained until you delete your account
  • Video captions: retained temporarily for processing (up to 7 days), then automatically deleted
  • Video analysis results (scores and findings): retained indefinitely to provide consistent scores and power historical insights
  • Public figure profiles: retained as part of the VidScore index; subject to correction and removal requests
  • Usage and diagnostic logs: retained for up to 12 months, then anonymized or deleted
  • Enterprise team member data: retained while the membership is active. When a member is removed from their organization, their identity is detached from the membership row and purged from the active team list
  • Enterprise activity log: retained for up to 365 days per organization, then automatically pruned. Administrators may export their log to CSV at any time for longer retention in their own storage
  • Payment records: retained as required for accounting and tax compliance (typically 7 years)
  • Device identifiers: retained for the lifetime of the associated account for fraud prevention; deleted when the account is deleted

You may request deletion of your account data and associated personal information at any time. See the Data Deletion section below.


12.California Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you specific rights:

  • Right to know what personal information we have collected about you
  • Right to request deletion of your personal information
  • Right to opt out of the sale of your personal information. We do not sell your data.
  • Right to non-discrimination for exercising these rights

To exercise these rights, email [email protected]. We will respond within 45 days.


13.EU and EEA Residents (GDPR)

If you are in the European Union or European Economic Area, GDPR gives you additional rights:

  • Right to access the personal data we hold about you
  • Right to rectification if your data is inaccurate
  • Right to erasure (right to be forgotten)
  • Right to restrict processing in certain circumstances
  • Right to data portability
  • Right to object to processing based on legitimate interests
  • Right to lodge a complaint with your local supervisory authority

VidScore LLC (258 Harvard St, #355, Brookline, MA 02446) is the data controller for personal data collected through this service. To exercise your rights, email [email protected]. We will respond within 30 days.


14.Automated Decision-Making

VidScore uses automated processing to generate scores and findings from video content. This includes AI-powered analysis of captions and metadata.

These scores are analytical outputs about public video content, not decisions about individuals. They do not determine access to services, creditworthiness, employment, or any legal outcome affecting you.

If you are the subject of a VidScore profile and believe a score is inaccurate, you may request a human review through our correction process.


15.Children and Minors

VidScore is intended for users aged 13 and older, consistent with YouTube's own minimum age requirement. We do not knowingly collect personal information from children under 13.

If you are under 13, please do not use VidScore or submit any personal information. If you are a parent or guardian and believe your child under 13 has registered an account or submitted data, contact us and we will delete it promptly.

For users between 13 and 17, the data we collect is limited to what is described in this policy. We do not create public profiles of minor viewers. We do not use data from minor users for advertising.

VidScore analyzes video content, not viewer identity. We do not build or publish profiles of viewers regardless of age. The minor protection in our Public Figure Disclaimer applies to people who appear in videos, not to VidScore users.

16.Cookies and Local Storage

VidScore uses minimal browser storage and does not use tracking cookies. For full details, see our Cookie Policy.

  • The website uses session storage only (cleared when you close your browser)
  • The Chrome extension uses chrome.storage APIs (not HTTP cookies)
  • No third-party tracking cookies or advertising pixels
  • No analytics cookies (we do not use Google Analytics or similar services on the website)

17.Data Deletion and Contact

You can delete your account and all associated data directly from the extension. Open the VidScore side panel, go to Settings, and select "Delete Account." Deletion is immediate and permanent. You can also request deletion by emailing us with the subject line "Data Deletion Request." We will confirm and complete deletion within 30 days.

For all privacy questions: [email protected]

VidScore LLC
258 Harvard St, #355
Brookline, MA 02446

We may update this Privacy Policy as the product evolves. Material changes will be communicated via email. Continued use after the effective date constitutes acceptance.

© 2026 VidScore LLC  ·  Privacy Policy  ·  v1.5