1. Introduction
At Intellush, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using Intellush, you consent to the data practices described in this policy.
If you do not agree with this Privacy Policy, please do not access or use the Service.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide when using the Service:
- Account Information: Email address, name, and authentication credentials when you create an account
- Subscription Data: YouTube channel URLs, topic preferences, and custom channel names
- Payment Information: Processed securely through Paddle.com (we do not store your payment card details)
- Communications: Messages, feedback, or support requests you send to us
2.2 Information Collected Automatically
We automatically collect certain information when you use the Service:
- Usage Data: Pages visited, features used, time spent on the Service, and interaction patterns
- Device Information: Browser type, operating system, IP address, and device identifiers
- Cookies and Tracking: We use cookies and similar technologies to enhance your experience (see Section 8)
- Log Data: Server logs including timestamps, errors, and system events for debugging and security
2.3 Information from Third Parties
We may receive information from third-party services:
- Authentication: Firebase Authentication for account management
- Payment Processing: Paddle.com for subscription billing and payment status
- YouTube Data: Public metadata from YouTube channels you subscribe to (titles, descriptions, thumbnails)
3. How We Use Your Information
We use the collected information for the following purposes:
- Provide the Service: Process videos, generate summaries, classify content, and deliver personalized news feeds
- Account Management: Create and maintain your account, authenticate access, and manage subscriptions
- Payment Processing: Process payments, manage billing, and handle refunds through Paddle.com
- Communication: Send service updates, subscription confirmations, and respond to support requests
- Improvement: Analyze usage patterns to improve features, fix bugs, and optimize performance
- Security: Monitor for suspicious activity, prevent fraud, and protect user accounts
- Compliance: Meet legal obligations and enforce our Terms & Conditions
4. Data Storage and Security
4.1 Where We Store Your Data
Your data is stored using secure cloud infrastructure providers:
- Database: PostgreSQL hosted on secure cloud infrastructure
- Authentication: Firebase (Google Cloud Platform) with global data centers
- Storage: Google Cloud Storage (GCS) for processing records and transcripts
- Hosting: Railway with automatic SSL encryption
4.2 Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: All data in transit is encrypted using TLS/SSL (HTTPS)
- Access Control: Strict authentication and authorization mechanisms
- Regular Audits: Periodic security reviews and vulnerability assessments
- Data Minimization: We only collect data necessary for the Service
- Third-Party Security: Our partners (Firebase, Paddle, Google Cloud) maintain SOC 2 Type II compliance
4.3 Data Retention
We retain your personal data only as long as necessary to provide the Service and fulfill legal obligations. Account data is deleted within 90 days of account deletion unless we are required to retain it for legal or compliance reasons.
5. Sharing Your Information
We do not sell, rent, or trade your personal information. We only share your data in the following circumstances:
- Service Providers: Third-party vendors who assist in providing the Service (Firebase, Paddle, Google Cloud, AI providers). These providers are contractually obligated to protect your data.
- Legal Requirements: When required by law, court order, or government request, or to protect our rights and safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity
- With Your Consent: When you explicitly authorize us to share your information
6. Your Privacy Rights
6.1 Access and Portability
You have the right to access your personal data and request a copy in a structured, commonly used format. Contact us at support@intellush.com to request your data.
6.2 Correction and Update
You can update your account information and preferences through your account settings at any time.
6.3 Deletion
You have the right to request deletion of your personal data. You can delete your account through account settings or by contacting us. Note that some information may be retained for legal or compliance purposes.
6.4 Opt-Out
You can opt out of non-essential emails by clicking the "unsubscribe" link in any marketing email. Service-related emails (billing, security) cannot be opted out of while your account is active.
6.5 GDPR Rights (EU Users)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR, including the right to object to processing, restrict processing, and lodge a complaint with a supervisory authority.
7. Children's Privacy
The Service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child, please contact us immediately, and we will take steps to delete that information.
9. Third-Party Services
We use the following third-party services to provide and improve the Service:
- Firebase (Google): Authentication and user management - Privacy Policy
- Paddle: Payment processing and subscription billing - Privacy Policy
- Google Cloud Platform: Infrastructure and storage - Privacy Policy
- YouTube API: Channel data retrieval - Privacy Policy
These third-party services have their own privacy policies, and we encourage you to review them.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure that appropriate safeguards are in place for international data transfers in compliance with GDPR and other applicable regulations.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on the Service at least 30 days before the changes take effect. Continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us: