Privacy Policy

Last updated: 22 August 2026

The short version

This policy explains what veedeeoh. ("veedeeoh", "we", "us") stores when you use the veedeeoh cloud service at veedeeoh.com, why, who processes it on our behalf, and what you can do about it. It covers the hosted cloud service only. If you self-host veedeeoh from the open-source repository, your installation talks to no veedeeoh servers and this policy does not apply to it.

The data controller for the personal data described in this policy is veedeeoh, the operator of this service, established in Texas, United States, and referred to throughout as "veedeeoh", "we" or "us". You can reach us at support@veedeeoh.com.

[REVIEW: legal entity] The data controller trades as veedeeoh and is established in Texas, United States. Still outstanding: a postal address, which several privacy laws expect and which the operator does not currently have, and the legal form once the operator incorporates.

1. What we store, table by table

This section lists the actual records the service keeps, rather than a general description. Every table below lives in our Supabase Postgres database unless stated otherwise.

Your account and sign-in

RecordWhat is in it
auth.users
(managed by Supabase)
Your email address, a salted hash of your password if you set one (we never receive the password itself), your Google account identifier if you sign in with Google, and any passkeys you enrol, stored as a public key credential with the nickname you gave it. Also your email confirmation state and active sessions.
profilesOne row per account: your email, plan tier and expiry, seat count, Stripe customer and subscription references, watch party credit balances and lifetime counters, and a marker recording which trial reminder email you were last sent.

Your household

RecordWhat is in it
household_profilesEach "who is watching" profile: its name, avatar colour or avatar image URL, whether it is a kids profile, the set of content ratings it is allowed to see, and, if you set a parental PIN, a salted SHA-256 hash of that PIN. The PIN itself is never stored or transmitted in the clear.
household_members, household_invitesWho else is on your account, and the email address and token for invitations you have sent that have not yet been accepted.

What you watch

RecordWhat is in it
watch_progressPer profile: the title identifier, its name, your playback position in seconds, the runtime, and whether you finished it. This is what powers Continue Watching across your devices.
favoritesPer profile: the titles you added to My List, with their names and poster URLs.
collections, collection_itemsLists you build yourself, plus the platform-curated lists everyone sees. Your own lists are visible only to your household.
profile_exclusionsTitles you have hidden from a particular profile.

Watch parties

RecordWhat is in it
parties, party_joinsThe parties you host or join: the join code, what was being watched, the seat limit, when it started and ended, and which accounts joined and when.
Sync service
(Cloudflare Durable Object)
While a party is live, a small state blob is relayed between participants: the title identifier, the stream index, the playback position in seconds, whether it is paused, and a timestamp. Each connected participant is tagged with their account identifier and the display name they are joining under. There is no chat, no voice, no video and no media of any kind passing through this service. Party state is discarded when the party ends.
party_credit_ledger, free_month_grantsEvery credit granted, purchased or spent, and any free month a milestone earned you.

Referrals

RecordWhat is in it
referral_codes, referralsYour referral code, and, if you arrived through someone else's code, a permanent record of who referred you, through which route (a link, a watch party, a household invite or a partner), and the commission rate agreed at that moment.
referral_earningsFor each payment made by someone you referred: the Stripe invoice reference, the gross amount, the rate, the commission owed, and whether it has been paid out.

Support and problem reports

RecordWhat is in it
feedbackWhen you use "Report a problem": the description you write, your account identifier and email, which profile was active and whether it was a kids profile, the page URL and view you were on, the app version, your browser user agent string, your window size, and a short tail of recent browser console messages. The console tail is filtered in your browser before it is sent, to strip anything that looks like an access token or API key, and each line is truncated. It can still contain incidental technical detail, so treat a report the way you would treat sending a screenshot.
beta_invites, waitlistEmail addresses submitted for the waitlist or issued a beta invite, and what the invite granted.

Stored in your browser, not on our servers

The app keeps working state in your browser's local storage: your signed-in session and access token, your Supabase session, which profile is active, a cached copy of your household profiles, your region, subtitle and quality preferences, and small flags such as whether you dismissed the install prompt or acknowledged a ratings notice. Your session is also written to a first-party cookie so that a reload keeps you signed in. None of these are advertising cookies and none of them are read by anyone but veedeeoh.

Technical information we necessarily see

Our hosting providers process the ordinary technical information any web request carries: your IP address, the approximate country it maps to, and your browser type. We use the country to decide which regional catalogue to show you. We do not keep our own server access logs beyond what Vercel and Cloudflare retain as part of running the platform.

Our hosting providers keep short-lived request logs that include IP addresses, under their own retention schedules rather than ours. We do not build our own analytics from them and we do not keep a copy.

2. Why we process it

We do not sell personal information, we do not share it for cross-context behavioural advertising, and there is no advertising SDK, analytics script or session recorder in the app.

If you are in the UK or EU, the lawful bases we rely on are: performance of a contract, for everything needed to give you what you signed up for, meaning your account, profiles, syncing, watch parties and taking payment; legitimate interests, for keeping the service secure and working, preventing abuse of seats, credits and referrals, and understanding usage in aggregate, where we use the least identifying data that answers the question and you can object; legal obligation, for financial and tax records; and consent, for anything optional, which today is nothing beyond the account itself. There is no advertising, no behavioural profiling and no tracking to consent to.

3. Who processes data on our behalf

ProviderWhat they handle
SupabaseAuthentication and the Postgres database holding every table listed above.
StripePayment, subscriptions, credit top-ups and invoices. Stripe collects and holds your card details directly. We never receive them.
VercelHosting for the web app and its server endpoints.
CloudflareThe watch party sync service, and a relay for stream manifests that some providers do not allow a browser to fetch directly.
ResendDelivery of transactional email. Resend sees your email address and the message content.
GoogleOnly if you choose to sign in with Google, in which case Google confirms your identity to us.

Our database and hosting are in the United States. If you are in the UK or EU, that is an international transfer, and it relies on the Standard Contractual Clauses that Supabase, Vercel, Cloudflare, Stripe and Resend each incorporate into their terms as our processors.

We serve our own web fonts from this domain. Loading a veedeeoh page makes no request to Google, or to any other third party, for anything needed to render it.

[REVIEW: transfers and DPAs] Best effort without counsel. Each processor's data processing agreement should be signed and filed rather than merely relied on. The Google Fonts transfer that used to happen on every page load has been removed by self-hosting the fonts.

4. Third-party content providers

veedeeoh is an interface over free, ad-supported and public-domain catalogues. When you press play, your browser fetches the video from Pluto TV, Tubi or the Internet Archive. Those requests come from your device and network, so those providers can see your IP address, device type and what you played, exactly as they would if you used their own apps. Their handling of that information is governed by their own privacy policies, not this one. We do not pass them your veedeeoh account, your email address or your profile names.

5. How long we keep it

Account data, profiles, watch history, favourites and lists are kept for as long as your account exists. Deleting your account removes them, as described below. Watch party sync state is discarded when the party ends, although the record that a party happened stays in your account until the account is deleted. Billing records are retained by Stripe under its own retention rules and we may need to keep invoice and commission records for tax and accounting purposes after your account is gone.

How long we keep things. Your account and everything in it, including profiles, viewing history and My List, until you delete your account, at which point it goes immediately and permanently. Financial records, meaning invoices, payments and referral earnings, for seven years from the transaction because tax law requires it; those survive account deletion with the link to you removed. Problem reports for two years. Waitlist entries until the waitlist closes or you ask us to remove yours. Watch party state only for the life of the party, since the relay holds it in memory and it is gone when the party ends.

6. Your controls

Depending on where you live you may also have rights to access, correct, delete, restrict or object to processing, to data portability, and to complain to a supervisory authority. Email support@veedeeoh.com and we will action requests we cannot serve through the buttons above. We will not treat you differently for exercising a right.

You can access, correct, export or delete your data, object to processing based on legitimate interests, and ask us to pause processing while a question is resolved. Most of it you can do yourself in Settings, since export and deletion are both buttons. If you write to us instead we will respond within 30 days, and we verify a request by requiring it to come from the email address on the account rather than asking for more identification than that. If you are in the UK or EU and think we have got something wrong you can complain to your national data protection authority; if you are in a US state whose privacy law gives you an appeal, say so and we will look at the decision again.

7. Children

veedeeoh accounts are for adults. Kids profiles are created and controlled by the adult account holder, who chooses which ratings each profile may see and may set a PIN on adult profiles. A kids profile is a viewing mode inside your account, not a separate account: it has no email address, no login and no sign-up flow, and a child never provides us information directly. Unrated content is treated as adult content by default rather than being shown to a kids profile.

We do not knowingly collect personal information directly from children under 13. If you believe a child has provided us information, email us and we will remove it.

veedeeoh accounts are for adults. We do not knowingly let anyone under 13 create one, and we never ask a child for anything: a kids profile is made by the adult who holds the account, and contains a name, an avatar and a rating limit that the adult chose. There is no signup, no email address and no login for a child. If you believe a child has created an account, write to us and we will delete it.

[REVIEW: children's privacy law] Written best effort without counsel. The position taken is that no child is a user. Whether COPPA, the UK Age Appropriate Design Code or state minor-protection laws attach anyway to a household product with kids profiles is a legal determination and has not been made.

8. Security

Data is encrypted in transit. Passwords are hashed by our authentication provider and never reach us. Parental PINs are stored only as a salted hash. Database access is governed by row-level security policies, so one account cannot read another's rows even through a crafted request, and endpoints that touch your data act with your own credentials rather than an administrative key. A parental PIN is a "keep honest kids out" control on a shared device, not cryptographic protection, and should not be relied on as one.

No system is perfectly secure.

If personal data is breached in a way likely to put you at risk, we will tell you without undue delay, and notify the relevant regulator within 72 hours of becoming aware where the law requires it. We will say what happened, what it affects and what to do about it.

9. Changes

We may update this policy. The "last updated" date at the top always reflects the current version, and we will tell you about material changes through the app or by email before they take effect.

10. Contact

Questions about this policy or your data: support@veedeeoh.com. [REVIEW: contact and DPO] The controller is established in Texas, United States, and has no fixed postal address at present; contact is by email. Counsel should confirm whether email alone satisfies the controller contact-details requirement in each jurisdiction served, and assess whether a Data Protection Officer, or an EU or UK representative under Article 27, must be appointed.

See also the Terms of Service.