Legal
Privacy
Last updated 2026-09-16. This describes what Maximilian Moj collects, which models read it, who else processes it, how long it is kept and how to have it removed. It is written to be checkable: every retention period below is enforced by the software, not by a promise.
What we collect
Your account. An email address and a password hash, both held by Supabase. We never see a password. An organization name, which you choose. Nothing else about you is asked for.
If you sign in with Google. We receive your name, email address and profile picture from your Google Account, and use them for one thing: to create and identify your Playhead account. We do not read your Gmail, Drive, Contacts, Calendar or YouTube data, we ask for no permission to, and none of what Google sends us is sold, shared or used for advertising. Disconnect it at any time in your Google Account permissions, or delete the account here and it goes with it.
What your agent did. Every call is recorded: which video, which window, which detail level, what it cost, and whether it succeeded. This is the audit trail behind every credit charged, and it is what makes a billing dispute answerable in one query.
The videos themselves. A link is fetched from the platform hosting it. A file you pass by path is uploaded so it can be decoded, because decoding is the service. Both produce a reading of the video and, if asked, a transcript.
What is in the videos. A video can hold faces, voices, names, addresses and anything else the camera caught. The next two sections say what happens to that, and who is answerable for it.
Billing. Name, billing address and tax id go to Stripe. Card details are entered on Stripe's own form and never reach our servers.
Measurement, only if you agree. Page views and conversion events go to Google Analytics and Google Ads. Every consent signal starts denied. Nothing is sent until the cookie banner is answered with “Accept all”. Choosing “Only essential” leaves everything working.
How AI reads your video
Playhead is an AI product and this is the section that says what that means. It uses machine learning models to turn a video into words. Some of those models run on our own machines. Others belong to other companies, and using them means sending them part of your video.
What leaves our machines, and what does not. We fetch and decode the video ourselves, and our own code chooses which seconds are worth looking at. What goes to a model provider is built from those seconds. It is a contact sheet, which is a grid of small still pictures, or a short clip we assemble out of the same stills. Your question and the transcript text go with it. The recording you submitted is not sent to any model provider, and neither is the whole of it. The audio track is the one exception, and it goes to the transcription service only when you ask for a transcript.
Which models, and what each one gets. Every provider that sees a picture or hears audio is named here. This table is part of the longer list further down, and adding a row to either is a change to this page.
| Model provider | What it does | What it receives |
|---|---|---|
| Google (Gemini API) | The model that reads the contact sheets and writes the answer | Contact sheets, or a short clip built from the frames we chose, plus transcript text and your questionUS and EU |
| OpenRouter | A second route to the same models, used when the first one is rate limited or refuses | Contact sheets, or a short clip built from the frames we chose, plus transcript text and your questionUS |
| Groq | Speech-to-text, when transcription is requested and no uploader captions exist | The audio track of the video being analysedUS |
They do not train on it, and here is exactly what that means. Each provider above serves us under business API terms which say they do not use what is sent through the API to train their models, and which limit how long they may keep it. That is their commitment to us, and we choose providers that make it. It is not a promise we can make on their behalf, and we say so rather than write a sentence you cannot check.
We do not train on it either, unless you say so. Your account holds a separate switch under Team. It is off until you turn it on, the product works exactly the same either way, and it covers the annotations we write and the questions you ask. It never covers your media, and it never covers a video that is not yours.
A model can be wrong about you. A reading is a guess made by a program, and it is stored beside the measurements that are not guesses. If a reading says something incorrect about you, write to us and we will correct or delete it. That is the same right as any other correction, and it is section eight below.
No decision about you is made by a machine alone. We use automated checks to find unlawful material and abuse of the limits. No person reads your content as part of that. Nothing automated here decides anything with a legal effect on you. An account suspension is decided by a person, we say which rule it was, and you can ask us to look again.
People who appear in a video
A video usually holds people who never signed up here. This is how that is handled and who answers for it.
You decide, and we carry it out. For the content of a video you submit, you are the controller and we are your processor. We analyse what you send, for the purpose you asked for, and for nothing else. Making sure those people may be filmed and analysed is your job, and the terms say so in section 3.
We do not identify anybody. The engine finds where a face or a body is in the frame, because that is how it chooses which second to look at. It does not match a face against any database, it builds no face template, and it holds no record that connects a person in one video to a person in another. Using Playhead to identify, track or profile a person is forbidden by the terms.
If you are in a video somebody else submitted. Write to hello@tryplayhead.com. We will tell you what we hold, delete it where we may, and pass your request to the customer who submitted it, because they are the ones who decided to submit it.
What we do not do
- We do not train on anything you have not agreed to. The account settings hold two separate answers: one confirms that you may submit the material at all, and one says whether we may keep the work as training material. The second is voluntary, it is off until you turn it on, and the product works either way.
- We never train on a video that is not yours. A link you paste to somebody else's video is analysed for you and nothing about it is kept as training material, whatever you tick.
- We never publish your video or a frame of it. The second answer covers the annotations we write and the questions you ask, and it does not cover the media.
- We do not sell data, and we do not share it with anyone not listed below. We have never sold personal data and we do not share it for cross-context behavioural advertising, which are the two words that carry a meaning under US state law.
- We do not read your content. Sheets are generated by a program and served over signed, short-lived URLs. Nobody looks at them.
- We do not track you across other websites. There is no advertising pixel on this site beyond Google's own tag, and that is gated on consent.
Who else processes it
Each of these receives only what its purpose requires. Adding one is a change to this page. The first three rows are the model providers from the section above, repeated here so this list is complete on its own.
| Who | For what | What they get |
|---|---|---|
| Google (Gemini API) | The model that reads the contact sheets and writes the answer | Contact sheets, or a short clip built from the frames we chose, plus transcript text and your questionUS and EU |
| OpenRouter | A second route to the same models, used when the first one is rate limited or refuses | Contact sheets, or a short clip built from the frames we chose, plus transcript text and your questionUS |
| Groq | Speech-to-text, when transcription is requested and no uploader captions exist | The audio track of the video being analysedUS |
| Supabase | Authentication and the database holding accounts, credits and job history | Email address, hashed password, organization membership, usage recordsEU or US, depending on the project's region |
| Google Cloud | The machine that fetches, decodes and samples the video | The video file itself, while it is readEU (Frankfurt) |
| Cloudflare | Content delivery, rate limiting, bot protection, and the object store holding contact sheets and cached video | IP address, request metadata, contact sheets, transcripts, cached source videoGlobal edge, with the bucket in the EU |
| Stripe | Subscriptions, invoices and payment | Name, billing address, tax id, card details, which are handled entirely by Stripe and never reach usUS, with EU processing under their standard terms |
| Google Analytics and Google Ads | Measurement and advertising, only after consent is given | Page views, referrer, consent state, conversion eventsGlobal |
Why we are allowed to
The GDPR asks for one reason per purpose. These are ours, and each row is a thing the software actually does.
| What for | On what basis | Note |
|---|---|---|
| Making an account work, reading a video, returning an answer | Performance of a contract | This is the service you asked for. Without it there is nothing to deliver. |
| Billing, invoicing and tax records | Legal obligation, and performance of a contract | Tax law sets the retention period, not us. |
| Rate limits, abuse detection and security logging | Legitimate interest | Our interest is a service that stays up for everybody who paid for it. |
| Analytics and advertising measurement | Consent | Denied until the banner is answered with Accept all. Withdraw it at any time. |
| Keeping your work as training material | Consent | A separate switch under Team, off until you turn it on, and off again in one click. |
| Answering a copyright notice and keeping the record of it | Legal obligation, and legitimate interest | We have to be able to show what we did and when. |
How long it is kept
| What | How long | Why |
|---|---|---|
| Contact sheets and transcripts | 1 to 90 days depending on plan, then deleted from object storage | They are derived data and can be rebuilt from the source at any time |
| The record that a call happened | For the life of the account | It is the audit trail behind every credit charged, and a billing dispute is one query |
| Source video files | At most 24 hours in a working cache | One download serves every later window; nothing is archived |
| What the model was sent and what it answered | 30 days, then the sweep empties the body and keeps the counts | It is how a wrong answer is explained, and after a month nobody asks |
| Account, credit ledger and invoices | For the life of the account, then as tax law requires | Financial records have a statutory retention period we do not get to choose |
| A copyright notice and what we did about it | 3 years from the day it is closed | It is the evidence that we acted, and a claim can arrive long after the video is gone |
Your rights
Under the GDPR, the UK GDPR and the US state privacy laws, you can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, ask us to restrict what we do with it, take it elsewhere, and object to processing we base on a legitimate interest. Two of those are buttons rather than requests:
- Delete a single video's results.
DELETE /v1/videos/{id}removes its sheets and transcripts immediately, ahead of their retention window. - Delete everything. Settings → Delete account removes the organization, its keys, its history and its ledger, and then the login itself. It runs in one transaction and cannot be undone.
- Withdraw a consent. The cookie banner can be answered again at any time. The training permission is a switch under Team. Withdrawing either changes nothing about the past and everything about the future.
- Anything else, such as a copy, a correction or an objection, goes to hello@tryplayhead.com. We answer within 30 days, which is the statutory limit rather than our target. We ask for nothing to prove who you are beyond the ability to read the account's email.
You can also complain to a supervisory authority. In the EU that is the data protection authority where you live. Doing so costs nothing and you do not have to ask us first.
Where it is processed
The database is a Supabase project in the region it was created in. The engine runs on a machine in the EU, in a container that can be moved between providers without changing anything a customer sees. Transcription is either Groq (US) or a local model in our own deployment, and the fallback direction is recorded on every transcript so you can tell which handled a given video.
Some of the companies in the table are in the United States, so some data goes there. Those transfers run on the European Commission's standard contractual clauses, and where a provider is certified under the EU-US Data Privacy Framework, on that as well.
For customers under data-residency rules, the Enterprise deployment runs the whole engine, including transcription, inside your own network. No video, audio or frame leaves it.
Cookies
Two kinds. The ones that sign you in and keep you signed in are essential and cannot be switched off without breaking login. The ones that measure which pages people find useful are optional and start switched off. The banner asks once. Refusing is one click, and it is the same size as accepting.
A referral link also sets a cookie recording which link brought you here, for 90 days. It contains a public code from a public link and grants nothing.
Children
Playhead is not for children. We do not knowingly collect anything from a person under 16. If you believe a child has an account here, write to hello@tryplayhead.com and we will delete it.
Changes and contact
A material change to this page is announced by email to account holders before it takes effect. Adding a model provider or any other subprocessor is a material change. Everything else is a correction, and the date at the top moves.
Maximilian Moj, Ackerhummelweg 15, 50999 Köln, Germany at hello@tryplayhead.com