←  Back to Vabrium

Privacy Policy

Version 1.1 · Effective 1 October 2026

VABRIUM PRIVACY POLICY

Version 1.1
Effective: 1 October 2026

This policy explains what Vabrium collects, why, and what you can do
about it. It covers the Vabrium desktop application and the vabrium.com
website.

The data controller is Vabrium LLC, a North Carolina limited liability
company. Its registered-agent address is 4030 Wake Forest Rd Ste 349,
Raleigh, NC 27609, United States. Contact [email protected] for
privacy questions and waitlist-removal requests.


THE SHORT VERSION

Vabrium performs core video editing and many AI operations on your
computer. Cloud backup and connected features can send information
outside your computer, as described below. We do not train our models on
your footage or your projects.

We do not sell personal information or disclose it for cross-context
behavioural advertising. Our website uses Cloudflare Web Analytics, as
described below.

The following sections explain the information we process and your
choices.


1. WHAT WE COLLECT

1.1 Account information. If you create an account: your email address,
an authentication credential, and account timestamps. Handled by our
authentication provider (Supabase).

1.2 Subscription information. If you subscribe to a paid plan: a
customer identifier, your plan, and its status and renewal dates.

Your card details go directly to Stripe. We never receive or store your
full card number, and we cannot charge a card outside Stripe.

1.3 Feature usage counts. The app records how many times you have used
metered features — for example variant generations, background removals,
and minutes of captions — and synchronises those counts with your
account so your monthly allowance is consistent across your devices.

These usage records do not themselves contain your clips or captions.
They can include event timestamps and feature information. Content may
be transmitted separately through the cloud or connected features
described below.

1.4 Support requests. If you send a support ticket: your message, the
category you chose, the email address you supply (optional), and the app
version. Our server also records the IP address the ticket came from, to
limit abuse.

You may optionally attach diagnostics. That attachment contains the app
version, the build type, your operating system version, and the tail of
the application log. The app displays the exact payload before it is
sent, and the attachment is off unless you turn it on. Application logs
can contain file paths and file names from your own machine, so read the
payload before attaching it.

1.5 Website, waitlist and downloads. Our website and download
infrastructure process connection and request information, such as IP
address, user agent and requested resource, to deliver and secure their
services. When you join the beta waitlist, we collect your email
address, signup source and signup time. We use this information to
maintain the waitlist and send beta-access updates. The waitlist does
not ask for payment information.

Cloudflare hosts and delivers the website. The website also uses
Cloudflare Web Analytics to measure page views and performance.
Cloudflare states that this analytics service does not use cookies or
localStorage to collect its metrics and does not fingerprint visitors
for analytics. This describes Cloudflare Web Analytics, rather than
every aspect of website infrastructure.

Supabase stores waitlist information. Our current Supabase project is
configured in its US West region. Providers may also process information
in other locations in which they operate.


1.6 Update checks. The app periodically requests an update manifest.
That request reveals your IP address and the fact that a Vabrium install
checked for updates. It carries no account identifier.

1.7 Entitlement, usage and device checks. While you are signed in and
the relevant services are configured, the app sends entitlement and
usage checks to help apply plan allowances and detect inconsistent
account or entitlement information. These include subscription tier and
status, relevant dates, usage information and app version. Usage records
can include timestamps. Signed-in presence heartbeats run approximately
every ten minutes and include app-version and last-seen information,
with a persistent randomly generated device identifier used for device
seats. These records are separate from media sent through cloud
features.

1.8 Cloud backup. Cloud backup can upload clip metadata, thumbnails and
exported video to Supabase. The cloud-backup preference is enabled by
default in the current application settings; raw-media backup is
controlled separately and is off by default. Whether an upload runs
depends on configuration, sign-in, feature availability and the action
or trigger that starts it. Turning backup off does not delete previously
uploaded copies. Keep your own copies of important files.

1.9 Crash reports. When the reporting backend is configured, the app
sends queued crash reports on a later launch. Reports include a
persistent randomly generated installation identifier, app version,
platform, error type, grouping signature, error message and bounded
traceback or fault detail. The app attempts to remove common home-
directory usernames, but reports may still contain personal information
or file paths. We use them to diagnose failures and improve reliability.
This automatic reporting is separate from the optional support
diagnostics in section 1.4.

1.10 Connected AI and platforms. Local AI processing is distinct from
optional hosted providers and other connected features. If you select
and configure a hosted language-model provider, requests can include
current and previous conversation messages. Application context is
enabled by default and can include timeline state, clip names,
preferences and personal memory. Turning application context off does
not necessarily remove conversation history. Supported routes include
Anthropic and a user-configured OpenAI-compatible endpoint, which is not
necessarily operated by OpenAI.

Assistant searches can send queries to DuckDuckGo and fallback providers
such as Wikipedia; optional configurations support Brave, Tavily or a
selected SearXNG server. Searches can be triggered when the assistant
determines they are needed. Weather queries can be sent to wttr.in using
a place mentioned in your request or a location inferred from the
request IP address. If you select and configure ElevenLabs for speech
generation, it receives the submitted text and voice request.

Connected publishing or streaming platforms receive the authorization,
content and other information needed for the actions you request. Your
platform choices determine the audience for anything you publish. Review
the selected provider's terms and privacy notice before sending private
information. Our commitment not to train our models on your footage or
projects does not describe an independent provider's own practices.


2. LOCAL AND CONNECTED PROCESSING

Vabrium stores working data on your computer, including projects,
caches, thumbnails, logs and learned preferences. Local storage does not
mean every feature is offline: the cloud, account, support, crash-
reporting and connected-service flows in section 1 can send information
outside your computer.

Uninstalling the app does not necessarily remove separate project
folders, cloud copies, platform uploads or separately installed model
runtimes. Deleting local files and requesting deletion of information
held by Vabrium are separate actions.


3. WHY WE USE IT, AND OUR LEGAL BASIS

If you are in the European Union or the United Kingdom, the UK GDPR and
GDPR require us to state a legal basis. Ours are:

  * To give you an account and provide the service you asked for —
    performance of a contract. (1.1, 1.2, 1.3, 1.8, 1.10)
  * To answer your support request — performance of a contract, and our
    legitimate interest in supporting our users. (1.4)
  * To attach diagnostics to a support ticket — your consent, given by
    ticking the box. You can decline and still get support. (1.4)
  * To send the beta-access updates you request when joining the
    waitlist — your consent. To withdraw, email [email protected]
    from the address you used to sign up. Withdrawal does not affect
    processing lawfully completed before withdrawal. (1.5)
  * To keep the service secure, prevent abuse, and prevent repeated
    misuse of free trials — our legitimate interests. (1.4, 1.5, 1.7)
  * To diagnose failures and maintain service reliability — our
    legitimate interests, subject to applicable privacy rights and
    any consent required by law. (1.9)
  * To keep tax and payment records — a legal obligation. (1.2)


4. WHO WE SHARE IT WITH

We do not sell your personal information. We do not share it for
advertising. We do not disclose it for cross-context behavioural
advertising.

We use a small number of service providers who process data on our
instructions:

  * Supabase — account authentication, databases, cloud storage,
    support records and the beta waitlist.
  * Cloudflare — website hosting, delivery, security and analytics.
  * Stripe, Inc. — payment processing and subscription management.
  * GitHub, Inc. — hosting the installer and its download payload.

Selected hosted AI, search, weather and connected-platform providers
receive information as described in section 1.10.

We may disclose information if the law requires it, or where it is
necessary to establish or defend a legal claim, or to protect someone's
safety. If we are ever required to hand over user data, we will tell you
unless we are legally prohibited from doing so.


5. INTERNATIONAL TRANSFERS

Vabrium is based in the United States. Our current Supabase project is
configured in its US West region. Providers may also process information
in other locations in which they operate. Information may therefore be
transferred outside your country, including outside the EU or UK.
Applicable data-protection law may require safeguards for these
transfers. For information about processing locations and whether a
particular transfer is covered by a safeguard, contact
[email protected].


6. HOW LONG WE KEEP IT

  * Account and subscription data: while your account exists, with
    deletion requests handled under section 7 and exceptions for
    records we must retain under applicable law.
  * Feature usage counts: for the current and previous billing period.
  * Support tickets: up to 24 months, so we can recognise a recurring
    problem.
  * Waitlist emails: until removal is requested, or until 12 months
    after launch, whichever comes first.
  * Server logs: up to 90 days.


7. YOUR RIGHTS

Wherever you live, you can email [email protected] to ask about
personal information we hold, request a correction, or request deletion.
We handle requests under applicable law, including applicable exceptions
and deadlines. Account deletion, subscription cancellation, deletion of
local files and removal from the waitlist are separate actions.

To leave the waitlist, email [email protected] from the address you
used to sign up. We handle waitlist-removal requests manually.

If you are in the European Union or the United Kingdom you have the
right to access, rectification, erasure, restriction, portability, and
objection, and the right to withdraw consent at any time without
affecting processing already carried out. You may also complain to your
national data protection authority.

If you are a California resident you have the right to know what we
collect, to delete it, to correct it, and to opt out of sale or sharing.
We do not sell personal information or disclose it for cross-context
behavioural advertising. We will not discriminate against you for
exercising any right.

We will respond within the deadlines required by applicable law.


8. CHILDREN

Vabrium is not for children under 13, and we do not knowingly collect
personal information from them. If you believe a child under 13 has
given us personal information, email [email protected] and we will
delete it.

If you are in the European Union or the United Kingdom and under 16, a
parent or guardian must consent before you create an account. If you are
under 18, the parent or guardian involvement required by our Terms also
applies.


9. SECURITY

Traffic between the app and our services uses HTTPS. Access to
production data is limited to the accounts that need it. Payment card
data is handled by Stripe and never reaches our systems.

No system is perfectly secure. If we become aware of a breach affecting
your personal information, we will notify you and the relevant authority
where the law requires it.


10. AUTOMATED DECISIONS

Vabrium uses AI for features such as editing suggestions, captions and
the assistant. Processing may be local or involve a connected provider
as described in section 1.10. AI output can be inaccurate; review it
before relying on or publishing it. Account and entitlement checks are
separate from these AI features and can affect access to plan features.


11. CHANGES

We may update this policy. If a change is material we will notify you in
the app or by email before it takes effect, and update the version and
date above. Older versions are available on request.


CONTACT

  Privacy and waitlist removal  [email protected]
  Legal    [email protected]
  Support  [email protected]

  Registered agent address
           Vabrium LLC, 4030 Wake Forest Rd Ste 349,
           Raleigh, NC 27609, United States

←  Back to Vabrium