Summary
This summary is provided for convenience. The numbered sections that follow are the operative text.
- We do not operate a server that receives your content. Your topics, scripts, voiceovers, footage, rendered videos and publishing history exist only on your own computer.
- You supply your own API keys. VidForge AI does not resell access to any AI or stock media provider. Requests go directly from your machine to the provider you configured, under your own account with that provider.
- You create your own platform credentials. To publish, you register your own developer application with YouTube, TikTok or Facebook. Authorisation happens on that platform's own consent screen.
- Access tokens never leave your machine. They are encrypted at rest with a key stored only on your computer, and we have no technical means to read them.
- Nothing is published without your action. A publishing job stays stopped until you start it. On TikTok, videos are delivered to your inbox as drafts for you to review and post yourself.
- This website collects very little. No advertising trackers, no cross-site profiling, and no account to create.
Who we are
VidForge AI develops and distributes VidForge AI, a video generation and publishing application for Windows 10 / 11 (64-bit). For the purposes of data protection law, VidForge AI is the controller of the limited personal data described in the website section of this policy.
For data that the application processes on your own computer — your scripts, media, credentials and publishing history — you are the controller. We do not receive that data and cannot access it. Where you send prompts to an AI provider or a video to a publishing platform using your own credentials, you are the controller of that transfer and the provider's own terms and privacy policy apply to it.
You can reach us at support@vidforgeai.online for any question about this policy or any request under it.
How the software is built
Understanding one architectural fact makes the rest of this policy straightforward: VidForge AI is a local application, not a hosted service. There is no sign-up, no login to VidForge AI itself, no synchronisation and no server-side storage.
When you generate a video, the following happens entirely on your computer:
- Your topic and settings are written to a local SQLite database on your disk.
- Prompts are sent from your computer directly to the AI provider whose API key you configured. The response is stored locally.
- Stock media is downloaded from Pexels or Pixabay directly to your local cache using your own API key.
- Narration is generated either by a cloud provider you configured, or by a model running locally on your own CPU or GPU.
- Subtitles are transcribed locally by OpenAI Whisper. The audio does not leave your machine for this step.
- The video is composited and encoded locally by FFmpeg, using your GPU where one is available.
- If you start a publishing job, the finished file is uploaded from your computer directly to the platform, using the access token held on your computer.
At no point in that sequence does a request pass through infrastructure operated by VidForge AI. This is not a policy commitment that could be quietly reversed — it is a property of how the software is built. There is no server to send your data to.
Information we collect
4.1 Data stored on your computer by the application
The following is stored locally, under the application's data directory. We do not receive it. It is listed here so you know what exists on your disk and what deleting it removes.
| Category | What it contains | Where it lives |
|---|---|---|
| Project data | Topics, niches, generated scripts, storyboards, scene plans and job settings. | Local SQLite database |
| Generated media | Voiceover audio, downloaded stock footage and images, subtitle files, thumbnails and rendered videos. | Local data and exports folders |
| Provider credentials | The API keys you entered for AI, voice and stock media providers. | Local configuration file on your disk |
| Platform credentials | The OAuth client ID and secret of the developer application you registered. | Local configuration file on your disk |
| Access tokens | The access and refresh tokens a platform issued after you authorised it, plus the token's expiry and granted scopes. | Encrypted in a local SQLite database |
| Connected account labels | The display name, channel or page name, avatar URL and account identifier a platform returned, used only to label accounts in the interface. | Local SQLite database |
| Publishing history | Which file was uploaded to which account, when, whether it succeeded, and the platform's error message if it did not. | Local SQLite database |
| Application logs | Diagnostic messages about pipeline stages, encoder selection and upload attempts. | Local log files |
4.2 Data we receive
We receive personal data in only two situations:
- When you contact us. If you email support@vidforgeai.online, we receive your email address, your message and anything you choose to attach — which may include log excerpts or screenshots. We use it to answer you and for nothing else.
- When you visit this website. Described in the website section below.
4.3 Data we do not collect
We want to be specific rather than merely reassuring. We do not collect, and have no mechanism to collect: your scripts or generated videos; your API keys; your OAuth tokens; your publishing history; your social media follower counts, viewer data or audience analytics; your contacts, direct messages or comments on any platform; telemetry or usage analytics from inside the application; or your machine's hardware fingerprint.
The application contains no analytics or telemetry SDK. It does not phone home, and it does not report which features you use.
OAuth login and platform access
VidForge AI never asks for and never stores a password for any third-party platform. Connecting an account uses that platform's official OAuth 2.0 authorisation flow for installed desktop applications.
5.1 How authorisation works
- You first register your own developer application in the platform's developer console — Google Cloud Console for YouTube, the TikTok for Developers portal for TikTok, or Meta for Developers for Facebook — and paste its client ID and secret into the application's Settings. The credentials are yours, not ours; no keys are embedded in the installer.
- When you choose to connect an account, VidForge AI starts a temporary HTTP server bound to the loopback address on your own computer and opens the platform's own consent screen in your browser.
- You review the requested permissions and approve or decline on the platform's page. We never see this page and never receive your credentials for it.
- If you approve, the platform redirects to the loopback address on your machine with an authorisation code. The local server receives it, exchanges it with the platform for an access token, and shuts down.
- The token is encrypted and written to a local database. It is refreshed in the background as it approaches expiry, and re-authorisation is requested if refresh fails.
The redirect goes to your own computer. It does not pass through a VidForge AI domain. TikTok's and Meta's consoles require the exact loopback port to be registered, which is why the application shows you the port it is using.
5.2 TikTok login
Authorisation uses TikTok's OAuth v2 endpoint with PKCE, and requests only the video.upload and user.info.basic scopes.
With these scopes, VidForge AI cannot post publicly to your TikTok profile. A video sent to TikTok arrives in your TikTok inbox as a draft. You review it inside the TikTok app and decide whether to publish it. Direct posting requires TikTok's video.publish scope, which VidForge AI does not request.
From user.info.basic the application reads three fields — your open ID, display name and avatar URL — for the sole purpose of labelling the connected account in the interface so you can tell several TikTok accounts apart. TikTok does not provide an email address through this scope and the application does not request one. VidForge AI does not read your videos, your followers, your analytics, your comments or your direct messages, and the granted scopes do not permit it to.
5.3 Google and YouTube login
Authorisation uses Google's OAuth 2.0 endpoint and requests the youtube.upload, youtube.readonly and userinfo.email scopes. Upload permits publishing a video to a channel you control. Read-only is used to retrieve the channel name and avatar so accounts can be labelled. The email scope returns the address of the Google account, shown in the interface for the same reason.
VidForge AI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. That data is used only to provide the publishing features you invoke, is never transferred to anyone except at your direction, is never used for advertising, and is never read by a human except with your explicit consent to investigate a support issue you raised.
5.4 Facebook login
Authorisation uses Meta's OAuth flow and requests pages_show_list, pages_manage_posts and pages_read_engagement. These allow the application to list the Pages you manage so you can choose a destination, publish a video to the Page you selected, and confirm that the post succeeded. It does not request access to your personal profile, your friends or your private messages.
What each platform grants
The table below is a plain restatement of the permissions the application requests. It is generated from the same values the software actually sends, so it cannot drift out of date relative to the product.
| Platform | Scopes requested | Fields read | How a video is delivered |
|---|---|---|---|
| YouTube | https://www.googleapis.com/auth/youtube.upload, https://www.googleapis.com/auth/youtube.readonly, https://www.googleapis.com/auth/userinfo.email | Channel ID, Channel title, Avatar URL, Email address | Uploaded straight to your channel with the visibility you choose. |
| TikTok | video.upload, user.info.basic | Open ID, Display name, Avatar URL | Delivered to your TikTok inbox as a draft. You review it inside the TikTok app and post it yourself — VidForge AI never posts publicly on your behalf. |
| pages_show_list, pages_manage_posts, pages_read_engagement | Page ID, Page name, Page avatar | Published to the Facebook Page you select. |
Instagram and X publishing are in development and are not present in VidForge AI 2.2.1. The application requests no permissions from either platform.
Website, cookies and analytics
This website is a static marketing and documentation site. It has no login, no shopping cart and no comment system.
7.1 Cookies
We set no advertising cookies and no cross-site tracking cookies. The only client-side storage we use is a single entry that remembers whether you chose the light or dark theme, so your choice survives a page reload. It contains no identifier and is not sent to us. Clearing your browser storage removes it.
7.2 Server logs
Like any website, ours is served by a hosting provider that records standard request logs — IP address, timestamp, requested URL, referrer, user agent and response status. These are used to keep the site available and to investigate abuse or errors, and are retained for a short period before deletion.
7.3 Analytics
If we use analytics on this website, we use only a privacy-preserving, cookieless service that reports aggregate page views and referrers and does not build a profile of you across sites. We do not use Google Analytics, advertising pixels, session recording or fingerprinting. Full detail is in our Cookie Policy.
How information is used
The limited data we receive is used only for these purposes:
- Answering your support, sales or legal enquiries.
- Diagnosing a defect you have reported to us, using the logs you chose to send.
- Keeping this website available, secure and free of abuse.
- Understanding in aggregate which pages of this website are useful.
- Complying with a legal obligation, or establishing and defending legal claims.
We do not sell personal data. We do not share it with data brokers. We do not use it for advertising, profiling or automated decision-making, and we do not use your content to train any model.
Legal bases for processing
Where the UK GDPR, the EU GDPR or a comparable law applies, we rely on the following legal bases:
| Processing | Legal basis |
|---|---|
| Replying to your enquiry | Legitimate interests, and performance of a contract where your enquiry concerns a licence you hold. |
| Website server logs and security | Legitimate interests in keeping the service available and secure. |
| Cookieless aggregate analytics | Legitimate interests in improving the website. |
| Retaining correspondence for a legal claim | Legitimate interests, and compliance with a legal obligation where one applies. |
Where we rely on legitimate interests, we have considered whether the processing is necessary and proportionate and whether it overrides your interests. You may object to processing based on legitimate interests at any time.
Third-party services
VidForge AI is designed around services you choose and configure. Each entry below is optional unless marked otherwise, and a service receives data only if you have supplied a key for it and enabled the feature that uses it. When data goes to one of these providers, it goes directly from your computer under your own account with that provider, and that provider's privacy policy governs it.
| Service | What it does | What it receives |
|---|---|---|
| OpenAI | Script writing, research, storyboard and scene planning; optional text-to-speech. | The topic and prompts you supply, plus generated script text. |
| Anthropic | Script writing, research and SEO metadata generation (default text provider). | The topic and prompts you supply, plus generated script text. |
| ElevenLabs | Cloud voice generation. | Script text to be spoken and the voice ID you selected. |
| VoxCPM2 | Local voice generation and voice cloning.Runs on your device | Nothing. The model runs on your own CPU or GPU. |
| Kokoro | Local, lightweight voice generation.Runs on your device | Nothing. The model runs on your own CPU. |
| OpenAI Whisper | Subtitle transcription and word-level timing.Runs on your device | Nothing. Whisper runs locally on your machine. |
| Pexels | Stock video and image search. | Search keywords derived from your script. |
| Pixabay | Fallback stock video and image search. | Search keywords derived from your script. |
| Google / YouTube | Publishing to a YouTube channel you own. | The video file, its title, description, tags and thumbnail, sent with your OAuth token. |
| TikTok | Delivering a video draft to your TikTok inbox. | The video file and its caption, sent with your OAuth token. |
| Meta / Facebook | Publishing to a Facebook Page you manage. | The video file, its title and description, sent with your OAuth token. |
Beyond these, we use a hosting provider to serve this website and an email provider to receive messages sent to our support address. Both act as processors on our behalf under written terms.
Because you contract directly with these providers, their terms — including any data retention or model-training policy — apply to what you send them. We recommend reviewing the privacy policy of each provider you enable, particularly for prompts containing confidential business information.
Data retention
| Data | Retained | Who controls deletion |
|---|---|---|
| Everything the application stores locally | Until you delete it. There is no automatic expiry and no cloud copy. | You |
| Access tokens on your machine | Until you disconnect the account, delete the local database, or the platform revokes them. | You, or the platform |
| Support correspondence | Up to 24 months after your enquiry is resolved, then deleted. | Us, or you on request |
| Website server logs | Typically 30 days, then deleted or aggregated beyond identifiability. | Us |
| Aggregate website analytics | Retained in aggregate form only, containing no personal data. | Us |
Security
12.1 On your machine
- OAuth access and refresh tokens are encrypted at rest using Fernet — AES-128 in CBC mode with an HMAC-SHA256 authentication tag.
- The encryption key is generated on first run and stored only on your computer, with owner-only file permissions where the operating system supports them. We do not hold a copy and cannot recover it. If it is lost, the tokens are unrecoverable and accounts must be reconnected — this is deliberate.
- Publishing uses a separate database from the render pipeline, so a failure in one cannot corrupt the other.
- All communication with AI providers and publishing platforms uses HTTPS.
- No password for any third-party service is ever requested or stored.
12.2 Your responsibilities
Because your data lives on your computer, its security depends substantially on your own practices: keep your operating system and the application updated, use full-disk encryption, protect your account with a strong password, and treat your API keys and token encryption key as secrets. Anyone with access to your unlocked machine has access to your projects and connected accounts.
12.3 Reporting a vulnerability
If you believe you have found a security vulnerability, please report it privately to support@vidforgeai.online rather than disclosing it publicly. Tell us what you found and how to reproduce it. We will acknowledge your report, keep you informed, and will not pursue action against good-faith research that avoids privacy violations and service disruption.
12.4 Breach notification
If a breach affecting personal data we hold occurs and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware where required, and will inform affected individuals without undue delay.
Your rights
Subject to the law that applies to you, you have the right to request access to the personal data we hold about you; correction of inaccurate data; erasure; restriction of processing; portability in a machine-readable format; objection to processing based on legitimate interests; and withdrawal of any consent you gave.
If you are in California, you additionally have the right to know what personal information is collected, to delete it, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA and CPRA, and we will not discriminate against you for exercising any right.
To exercise any right, email support@vidforgeai.online. We will respond within 30 days and will ask for enough information to verify your identity — but no more than necessary. There is no charge for a reasonable request.
One practical point: because your projects, media and tokens are stored only on your own computer, we cannot fulfil an access or erasure request for them — we have no copy to produce or delete. You already have direct and complete control over that data. Our data deletion page explains exactly how to remove it.
If you are unhappy with how we handled your request, you may complain to your local data protection authority. In the United Kingdom this is the Information Commissioner's Office; in the European Union it is the supervisory authority of your member state. We would appreciate the chance to resolve it with you first.
Rights under UK and EU GDPR
Where the UK GDPR or the EU GDPR applies to you, the table below states each right, the article that grants it, and — specifically — what exercising it against us actually produces. For a locally-installed application the honest answer differs from the usual boilerplate, because you already hold the only copy of most of your data.
| Right | Article | What it means | What we do |
|---|---|---|---|
| Access | Article 15 | Obtain confirmation of whether we process your data, and a copy of it. | We will provide everything we hold, which in practice is your support correspondence. Your projects and credentials are on your own disk and already fully accessible to you. |
| Rectification | Article 16 | Have inaccurate data corrected and incomplete data completed. | Tell us what is wrong in our records and we will correct it. |
| Erasure | Article 17 | Have your data deleted where there is no overriding reason to keep it. | We delete correspondence on request. We cannot delete your local data because we do not have it — the data deletion page shows how to remove it yourself. |
| Restriction | Article 18 | Require that processing pauses while a dispute about it is resolved. | We will stop processing your data other than storing it until the matter is settled. |
| Portability | Article 20 | Receive your data in a structured, commonly used, machine-readable format. | We will export our records as JSON or plain text. Your project data is already in open formats — SQLite, MP4, SRT, WAV — on your own disk. |
| Objection | Article 21 | Object to processing based on legitimate interests. | Object and we will stop unless we have a compelling reason we can explain to you. |
| Withdraw consent | Article 7(3) | Withdraw consent at any time where consent is the basis for processing. | Withdrawal is honoured immediately and does not affect processing already carried out lawfully. |
| Automated decisions | Article 22 | Not be subject to solely automated decisions with legal or significant effects. | We make no automated decisions about you. There is no profiling, scoring or eligibility logic anywhere in the product or on this site. |
| Complain | Article 77 | Lodge a complaint with a data protection supervisory authority. | You may complain to your local authority at any time. We would appreciate the chance to resolve it first, but that is a preference, not a precondition. |
To exercise any of these, email support@vidforgeai.online. We respond within 30 days and ask only for what is needed to verify that the request is yours. There is no fee for a reasonable request, and we do not require you to create an account in order to make one.
We have not appointed a Data Protection Officer, because the scale and nature of our processing does not meet the Article 37 threshold — we process no special-category data, carry out no systematic monitoring, and hold little beyond support email. Requests go to the address above and are handled directly.
Rights under CCPA and CPRA
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the following rights. We extend the same treatment to residents of other states with comparable laws, including Virginia, Colorado, Connecticut, Utah and Texas, rather than gatekeeping by jurisdiction.
| Right | How we handle it |
|---|---|
| Right to know | We disclose the categories we collect — your email address and message content when you contact us, plus website server logs. Nothing else reaches us. |
| Right to delete | We delete correspondence on request, subject to any legal retention obligation. |
| Right to correct | We correct inaccurate records on request. |
| Right to opt out of sale or sharing | There is nothing to opt out of. We do not sell personal information and do not share it for cross-context behavioural advertising, so we display no “Do Not Sell” link. |
| Right to limit use of sensitive information | We do not collect sensitive personal information as the CPRA defines it. |
| Right to non-discrimination | Exercising any right changes nothing about your access to the software, which is free and requires no account. |
In the twelve months preceding the effective date of this policy we have not sold or shared personal information, and we have not disclosed personal information for a business purpose beyond our hosting and email providers acting under written terms.
You may use an authorised agent to submit a request on your behalf; we will ask for written proof of authorisation. Send requests to support@vidforgeai.online.
Deleting your data and accounts
There is no VidForge AI account to delete, because none is ever created. What can be deleted is the data on your computer, the authorisation you granted to a platform, and any correspondence we hold.
- Disconnect an account. Remove it in the Publishing Center's Accounts tab. This deletes the encrypted token from your local database immediately.
- Revoke access at the platform. Independently of the above, revoke VidForge AI's access in your Google, TikTok or Meta security settings. This invalidates the token at the source, regardless of what is stored locally.
- Delete local data. Uninstall the application and delete its data directory. This removes every script, render, token and history record, because that is the only place they exist.
- Ask us to delete correspondence. Email support@vidforgeai.online and we will delete our record of your enquiries.
Step-by-step instructions, including where each platform's revocation page lives, are on our data deletion page.
Children
VidForge AI is not directed at children. You must be at least 18 years old, or the age of majority where you live, to use it. This is partly a matter of contract and partly practical: the publishing platforms VidForge AI connects to set their own minimum ages for developer API access, and you must satisfy those too. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact support@vidforgeai.online and we will delete it.
International transfers
We are a small operation and the personal data we hold — support correspondence and website logs — may be processed by hosting and email providers located outside your country, including in the United States. Where such a transfer involves personal data protected by UK or EU law, we rely on an adequacy decision where one exists, or otherwise on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum.
Separately, when you use your own API keys, your prompts and media are transmitted directly from your computer to the provider you chose, which may be located in another country. That transfer is made by you under your own agreement with that provider, and its location and safeguards are described in that provider's own privacy policy.
Changes to this policy
We may update this policy to reflect changes in the software, our providers or the law. The effective date at the top of this page always reflects the current version. If a change materially reduces your rights or materially expands what we collect, we will say so clearly on this page and, where we have your address because you contacted us, by email. Continuing to use VidForge AI after a change takes effect means you accept the updated policy.
Contacting us
For any privacy question, request or complaint, write to support@vidforgeai.online. Please include enough detail for us to understand what you are asking for. We aim to acknowledge within 2 business days and to resolve substantive requests within 30 days.
This policy should be read together with our Terms of Service, Cookie Policy, Acceptable Use Policy and data deletion instructions.
Questions about this document
Write to us and a person will read it. We aim to reply within 2 business days.
support@vidforgeai.online