This policy explains what veedeeoh. ("veedeeoh", "we", "us") stores when you use the veedeeoh cloud service at veedeeoh.com, why, who processes it on our behalf, and what you can do about it. It covers the hosted cloud service only. If you self-host veedeeoh from the open-source repository, your installation talks to no veedeeoh servers and this policy does not apply to it.
The data controller for the personal data described in this policy is veedeeoh, the operator of this service, established in Texas, United States, and referred to throughout as "veedeeoh", "we" or "us". You can reach us at support@veedeeoh.com.
[REVIEW: legal entity] The data controller trades as veedeeoh and is established in Texas, United States. Still outstanding: a postal address, which several privacy laws expect and which the operator does not currently have, and the legal form once the operator incorporates.
This section lists the actual records the service keeps, rather than a general description. Every table below lives in our Supabase Postgres database unless stated otherwise.
| Record | What is in it |
|---|---|
auth.users(managed by Supabase) | Your email address, a salted hash of your password if you set one (we never receive the password itself), your Google account identifier if you sign in with Google, and any passkeys you enrol, stored as a public key credential with the nickname you gave it. Also your email confirmation state and active sessions. |
profiles | One row per account: your email, plan tier and expiry, seat count, Stripe customer and subscription references, watch party credit balances and lifetime counters, and a marker recording which trial reminder email you were last sent. |
| Record | What is in it |
|---|---|
household_profiles | Each "who is watching" profile: its name, avatar colour or avatar image URL, whether it is a kids profile, the set of content ratings it is allowed to see, and, if you set a parental PIN, a salted SHA-256 hash of that PIN. The PIN itself is never stored or transmitted in the clear. |
household_members, household_invites | Who else is on your account, and the email address and token for invitations you have sent that have not yet been accepted. |
| Record | What is in it |
|---|---|
watch_progress | Per profile: the title identifier, its name, your playback position in seconds, the runtime, and whether you finished it. This is what powers Continue Watching across your devices. |
favorites | Per profile: the titles you added to My List, with their names and poster URLs. |
collections, collection_items | Lists you build yourself, plus the platform-curated lists everyone sees. Your own lists are visible only to your household. |
profile_exclusions | Titles you have hidden from a particular profile. |
| Record | What is in it |
|---|---|
parties, party_joins | The parties you host or join: the join code, what was being watched, the seat limit, when it started and ended, and which accounts joined and when. |
| Sync service (Cloudflare Durable Object) | While a party is live, a small state blob is relayed between participants: the title identifier, the stream index, the playback position in seconds, whether it is paused, and a timestamp. Each connected participant is tagged with their account identifier and the display name they are joining under. There is no chat, no voice, no video and no media of any kind passing through this service. Party state is discarded when the party ends. |
party_credit_ledger, free_month_grants | Every credit granted, purchased or spent, and any free month a milestone earned you. |
| Record | What is in it |
|---|---|
referral_codes, referrals | Your referral code, and, if you arrived through someone else's code, a permanent record of who referred you, through which route (a link, a watch party, a household invite or a partner), and the commission rate agreed at that moment. |
referral_earnings | For each payment made by someone you referred: the Stripe invoice reference, the gross amount, the rate, the commission owed, and whether it has been paid out. |
| Record | What is in it |
|---|---|
feedback | When you use "Report a problem": the description you write, your account identifier and email, which profile was active and whether it was a kids profile, the page URL and view you were on, the app version, your browser user agent string, your window size, and a short tail of recent browser console messages. The console tail is filtered in your browser before it is sent, to strip anything that looks like an access token or API key, and each line is truncated. It can still contain incidental technical detail, so treat a report the way you would treat sending a screenshot. |
beta_invites, waitlist | Email addresses submitted for the waitlist or issued a beta invite, and what the invite granted. |
The app keeps working state in your browser's local storage: your signed-in session and access token, your Supabase session, which profile is active, a cached copy of your household profiles, your region, subtitle and quality preferences, and small flags such as whether you dismissed the install prompt or acknowledged a ratings notice. Your session is also written to a first-party cookie so that a reload keeps you signed in. None of these are advertising cookies and none of them are read by anyone but veedeeoh.
Our hosting providers process the ordinary technical information any web request carries: your IP address, the approximate country it maps to, and your browser type. We use the country to decide which regional catalogue to show you. We do not keep our own server access logs beyond what Vercel and Cloudflare retain as part of running the platform.
Our hosting providers keep short-lived request logs that include IP addresses, under their own retention schedules rather than ours. We do not build our own analytics from them and we do not keep a copy.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and there is no advertising SDK, analytics script or session recorder in the app.
If you are in the UK or EU, the lawful bases we rely on are: performance of a contract, for everything needed to give you what you signed up for, meaning your account, profiles, syncing, watch parties and taking payment; legitimate interests, for keeping the service secure and working, preventing abuse of seats, credits and referrals, and understanding usage in aggregate, where we use the least identifying data that answers the question and you can object; legal obligation, for financial and tax records; and consent, for anything optional, which today is nothing beyond the account itself. There is no advertising, no behavioural profiling and no tracking to consent to.
| Provider | What they handle |
|---|---|
| Supabase | Authentication and the Postgres database holding every table listed above. |
| Stripe | Payment, subscriptions, credit top-ups and invoices. Stripe collects and holds your card details directly. We never receive them. |
| Vercel | Hosting for the web app and its server endpoints. |
| Cloudflare | The watch party sync service, and a relay for stream manifests that some providers do not allow a browser to fetch directly. |
| Resend | Delivery of transactional email. Resend sees your email address and the message content. |
| Only if you choose to sign in with Google, in which case Google confirms your identity to us. |
Our database and hosting are in the United States. If you are in the UK or EU, that is an international transfer, and it relies on the Standard Contractual Clauses that Supabase, Vercel, Cloudflare, Stripe and Resend each incorporate into their terms as our processors.
We serve our own web fonts from this domain. Loading a veedeeoh page makes no request to Google, or to any other third party, for anything needed to render it.
[REVIEW: transfers and DPAs] Best effort without counsel. Each processor's data processing agreement should be signed and filed rather than merely relied on. The Google Fonts transfer that used to happen on every page load has been removed by self-hosting the fonts.
veedeeoh is an interface over free, ad-supported and public-domain catalogues. When you press play, your browser fetches the video from Pluto TV, Tubi or the Internet Archive. Those requests come from your device and network, so those providers can see your IP address, device type and what you played, exactly as they would if you used their own apps. Their handling of that information is governed by their own privacy policies, not this one. We do not pass them your veedeeoh account, your email address or your profile names.
Account data, profiles, watch history, favourites and lists are kept for as long as your account exists. Deleting your account removes them, as described below. Watch party sync state is discarded when the party ends, although the record that a party happened stays in your account until the account is deleted. Billing records are retained by Stripe under its own retention rules and we may need to keep invoice and commission records for tax and accounting purposes after your account is gone.
How long we keep things. Your account and everything in it, including profiles, viewing history and My List, until you delete your account, at which point it goes immediately and permanently. Financial records, meaning invoices, payments and referral earnings, for seven years from the transaction because tax law requires it; those survive account deletion with the link to you removed. Problem reports for two years. Waitlist entries until the waitlist closes or you ask us to remove yours. Watch party state only for the life of the party, since the relay holds it in memory and it is gone when the party ends.
The export includes everything we hold that is linked to your account: profiles, viewing history, My List, collections and their contents, hidden titles, household members and invitations, parties you hosted and joined, your credit ledger, your referral records and earnings, problem reports you have filed, follows, suggestions and blocks. Anything our own security rules stop even you from reading is listed by name in the file rather than left out silently.
Depending on where you live you may also have rights to access, correct, delete, restrict or object to processing, to data portability, and to complain to a supervisory authority. Email support@veedeeoh.com and we will action requests we cannot serve through the buttons above. We will not treat you differently for exercising a right.
You can access, correct, export or delete your data, object to processing based on legitimate interests, and ask us to pause processing while a question is resolved. Most of it you can do yourself in Settings, since export and deletion are both buttons. If you write to us instead we will respond within 30 days, and we verify a request by requiring it to come from the email address on the account rather than asking for more identification than that. If you are in the UK or EU and think we have got something wrong you can complain to your national data protection authority; if you are in a US state whose privacy law gives you an appeal, say so and we will look at the decision again.
veedeeoh accounts are for adults. Kids profiles are created and controlled by the adult account holder, who chooses which ratings each profile may see and may set a PIN on adult profiles. A kids profile is a viewing mode inside your account, not a separate account: it has no email address, no login and no sign-up flow, and a child never provides us information directly. Unrated content is treated as adult content by default rather than being shown to a kids profile.
We do not knowingly collect personal information directly from children under 13. If you believe a child has provided us information, email us and we will remove it.
veedeeoh accounts are for adults. We do not knowingly let anyone under 13 create one, and we never ask a child for anything: a kids profile is made by the adult who holds the account, and contains a name, an avatar and a rating limit that the adult chose. There is no signup, no email address and no login for a child. If you believe a child has created an account, write to us and we will delete it.
[REVIEW: children's privacy law] Written best effort without counsel. The position taken is that no child is a user. Whether COPPA, the UK Age Appropriate Design Code or state minor-protection laws attach anyway to a household product with kids profiles is a legal determination and has not been made.
Data is encrypted in transit. Passwords are hashed by our authentication provider and never reach us. Parental PINs are stored only as a salted hash. Database access is governed by row-level security policies, so one account cannot read another's rows even through a crafted request, and endpoints that touch your data act with your own credentials rather than an administrative key. A parental PIN is a "keep honest kids out" control on a shared device, not cryptographic protection, and should not be relied on as one.
No system is perfectly secure.
If personal data is breached in a way likely to put you at risk, we will tell you without undue delay, and notify the relevant regulator within 72 hours of becoming aware where the law requires it. We will say what happened, what it affects and what to do about it.
We may update this policy. The "last updated" date at the top always reflects the current version, and we will tell you about material changes through the app or by email before they take effect.
Questions about this policy or your data: support@veedeeoh.com. [REVIEW: contact and DPO] The controller is established in Texas, United States, and has no fixed postal address at present; contact is by email. Counsel should confirm whether email alone satisfies the controller contact-details requirement in each jurisdiction served, and assess whether a Data Protection Officer, or an EU or UK representative under Article 27, must be appointed.
See also the Terms of Service.