Legal
Privacy Policy
idb takes long video you give it and makes short things out of it. That means your media, your words and — inside the video — faces and voices pass through our systems. This page says exactly what happens to all of it.
The short version
- We do not sell your data, and we do not use it for advertising.
- We do not train AI models on your videos, audio, transcripts, faces or voices.
- This marketing site sets no advertising or tracking cookies. It uses cookieless page analytics, which store nothing on your device.
- Your card number never reaches us — payment happens on Stripe's or AbacatePay's own page.
- Disconnect YouTube, delete a project, or delete your account whenever you want.
Who we are, and what this covers
idb (also written "idobetter") is a media production tool and a Pisoms product, operated from Brazil. It ingests long-form video you provide and produces short clips, transcripts, summaries and narrated videos, and can publish results to a channel you connect. idb is currently in private beta — access is by invitation.
We are the controller of the personal data described here. The providers listed in section 9 act as operators (processors) on our instructions.
This policy covers the marketing site idobetter.io and the application app.idobetter.io. It does not cover services you reach from idb — YouTube, Google, our payment providers — each of which has its own policy.
For anything here, including any request about your data, write to hello@idobetter.io. That address also reaches the person responsible for data protection questions (the encarregado under LGPD art. 41). We answer within 15 business days.
The words we use
Brazil's LGPD (Lei 13.709/2018) gives these terms specific meanings, and we use them as it does:
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person. |
| Sensitive data | Data on racial or ethnic origin, religious belief, political opinion, health, sex life, or genetic or biometric data used to identify a person. |
| Processing | Any operation on personal data — collecting, storing, analysing, transmitting, deleting. |
| Data subject | You — the person the data is about. |
| Controller | Who decides how and why data is processed. That is us. |
| Operator | Who processes data on the controller's instructions. Our providers, listed in section 9. |
| Legal basis | The specific ground in law that permits a given processing. Ours are in section 3. |
Why we are allowed to process your data
Every use of your data below rests on one of these grounds (LGPD art. 7; GDPR art. 6 for users in Europe):
| What we do | Legal basis |
|---|---|
| Create and run your account | Performance of a contract |
| Process the media you submit and store the results | Performance of a contract |
| Meter credits, take payment, keep order records | Performance of a contract; legal obligation (tax and accounting) |
| Publish to a channel you connected | Your consent, given when you connect it — revocable at any time |
| Keep the service working and secure; diagnose failures; prevent abuse | Legitimate interest |
| Aggregate product analytics inside the app | Legitimate interest |
| Answer your support messages | Performance of a contract; legitimate interest |
| Comply with the law, or defend a legal claim | Legal obligation; regular exercise of rights |
Where we rely on legitimate interest we have weighed it against your rights and freedoms, and you can object — see section 12.
What we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Email address, name, and the account identifier from your sign-in provider. | Google sign-in. We never receive your password. |
| Content you submit | Video links you paste and media files you upload. | You |
| Content we generate | Transcripts, clip boundaries, summaries, scripts, captions, thumbnails and rendered video. | Produced from your content |
| Derived analysis data | Face positions, speaker turns and similar working data used to frame and cut clips. See section 5. | Produced from your content |
| Credit and order data | Credit balance, the ledger of grants and consumptions, order records, plan period. No card data. | You and our payment providers |
| Connected channel data | Channel id, title and public @handle, plus an OAuth refresh token. See section 7. | YouTube, when you connect a channel |
| Technical and diagnostic data | IP address, browser and device type, timestamps, error traces, which features were used and where they failed. | Automatically, as you use the app |
| Support correspondence | What you write to us and what we write back. | You |
What we do not collect
- Card numbers, CVV or bank credentials. Those are entered on our payment provider's page and never reach our systems.
- Sensitive-category data. We do not ask for it and you should not put it in a support message. Note that a video may itself contain data of that kind — section 5 explains how video content is handled.
- Advertising identifiers, cross-site tracking, or anything bought from a data broker. We do none of it.
How your video is processed, and what "AI" means here
This is the section most people actually want. When you submit a video, it goes through a pipeline:
- Ingest. The file is uploaded, or downloaded from the link you gave.
- Speech to text. A speech-recognition model produces a timed transcript. This runs on GPU machines we operate or rent — it is not sent to a third-party transcription service.
- Looking at the picture and the voices. The engine works out which faces are on screen, which of them is speaking, and how the audio divides between speakers, so the crop follows the right person instead of the middle of the frame. This runs on the same GPU machines.
- Choosing the moments. The transcript text is sent to a third-party AI model provider, which selects which passages are worth clipping and drafts titles, descriptions and captions.
- Rendering. The clips are cut, framed, captioned and encoded.
Three commitments about that pipeline:
1. We do not train models on your content. Not on your video, your audio, your transcripts, your face or your voice. The models idb uses are pre-trained; your material passes through them and is never added to them.
2. Face and voice analysis is scoped and temporary. Face positions, tracking data and speaker turns exist only to frame and cut your clips. They are tied to your project, are never used to identify anyone, are never matched against any external database, are never shared, and are deleted with the project.
3. The model provider receives the transcript, not the video. Text is all that leaves for analysis. Your media files are never uploaded to it.
When idb publishes a generated video for you, it is labelled as AI-made in its description. AI output is not always correct — the Terms of Service covers what that means for you as the person publishing it.
YouTube API Services
idb uses YouTube API Services so you can connect your channel and publish to it. By connecting a channel you also agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
What we store when you connect
- Your channel's id, title and public @handle, so the app can show which channel is connected.
- An OAuth refresh token issued by Google, held server-side in our database (encrypted at rest by the database provider) and used only to mint short-lived access tokens when the app uploads a video, uploads captions, or reads your channel name. Tokens are never exposed to your browser or your device.
What we do and do not do with it
- Uploads happen only when you explicitly publish, or when you have switched on a scheduled or automatic publishing feature for a channel you connected.
- idb can act only on videos it published for you. We do not read your existing videos, your subscribers, your watch history or your channel analytics.
Revoking access
Disconnect a channel at any time inside the app (Profile → connected channels), which deletes the stored token. You can also revoke idb's access from Google directly at myaccount.google.com/permissions.
idb's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
TikTok and Instagram
idb suggests captions and hashtags written for those platforms. It does not connect to them, does not authenticate with them, cannot post to them, and holds no credentials for them. Nothing about your TikTok or Instagram accounts reaches us.
Payments
Credits and plan passes are sold through Stripe (card) and AbacatePay (PIX). Checkout takes place on their pages, under their terms.
- We store what you bought, when, how much, the status and the credits granted. We never see or store a card number, CVV or bank credential.
- A PIX payment requires the payer's CPF. It is entered on AbacatePay's checkout and handled by AbacatePay; idb does not ask you for it.
- We keep order and ledger records for as long as tax and accounting law requires — see section 11.
Their policies: stripe.com/privacy · abacatepay.com.
Who else touches your data
Running idb means entrusting parts of your data to service providers. Every one of them is bound by contract to process it only on our instructions and never for its own purposes.
| Category of recipient | What they do for idb |
|---|---|
| Cloud hosting and networking | Serve this site and the application, and run the API behind it |
| Object storage | Hold your source media and the files generated from it |
| Managed databases | Hold your account, project, credit and order records |
| GPU compute | Rented machines that transcribe, analyse and render your video — section 10 |
| AI model providers | Analyse transcript text — section 5 |
| Payment providers | Take payment and return refunds — section 8 |
| Authentication and publishing | Google sign-in, and the YouTube API when you connect a channel — section 7 |
| Product analytics | Aggregate usage measurement inside the app — section 6 |
Ask, and we will name them. We do not publish the individual vendors — which pieces we assemble, and how, is part of how idb is built. But LGPD art. 18, VII gives you the right to know the entities your data has been shared with, and we honour it in full: write to hello@idobetter.io and we will name the providers that hold your data, within the same 15 business days as any other request.
We also disclose data where the law requires it, or to establish or defend a legal claim. If idb were ever transferred to another owner, your data would move with it and we would tell you first.
We do not sell personal data, and we do not share it with advertising networks, ad-tech partners or data brokers. There is no "sale" or "sharing" of personal data here in the sense those words carry under US state privacy laws.
Providers change as the service changes. The categories above are kept current, and the effective date at the top of the page moves when they change.
Where your data is processed
idb is operated from Brazil, and most of the infrastructure it runs on is not. We would rather state that plainly than bury it.
- Account, project, credit and media data are stored and processed in the United States.
- Rented GPU capacity varies by country. idb rents GPU machines by the hour to transcribe, analyse and render. Those machines sit in data centres in several countries, and which one a given job lands on depends on what is available at that moment. Your media file is copied to that machine for the duration of the job and removed when the machine is released — hours, not days.
- Transcript text sent for AI analysis is processed on the model provider's infrastructure, outside Brazil.
These international transfers are made under LGPD art. 33 — they are necessary to perform the contract you entered into with us — and under contractual clauses with each provider requiring protection compatible with Brazilian law. We apply data minimisation, encryption in transit, access control and confidentiality obligations throughout.
You can ask us for more detail about any transfer at hello@idobetter.io, and you may petition Brazil's ANPD (Autoridade Nacional de Proteção de Dados) at any time.
How long we keep it
| Data | Kept |
|---|---|
| Account record | While your account exists. Deleted when you ask us to delete it. |
| Source media and generated results | While the project exists. Deleted when you delete the project, or with your account. |
| Working copies on rented GPU machines | For the length of the job only, then removed with the machine. |
| OAuth refresh token | Until you disconnect the channel or delete your account. |
| Credit ledger and order records | Retained after account deletion where tax and accounting law requires it — in Brazil, up to five years — reduced to the minimum the law asks for. |
| Technical and diagnostic logs | A short rolling window, then discarded. |
| Support correspondence | While needed to resolve the matter, then archived. |
Once a retention period ends, data is deleted or irreversibly anonymised.
Your rights
Under LGPD art. 18 you may at any time ask us for:
- Confirmation and access — whether we process your data, and a copy of it.
- Correction — of anything incomplete, inaccurate or out of date.
- Anonymisation, blocking or deletion — of data that is unnecessary, excessive, or processed contrary to the law.
- Portability — your data in a structured, machine-readable form.
- Deletion — of data processed on the basis of your consent.
- Information — about who we have shared your data with, and about the consequences of refusing consent.
- Withdrawal of consent — at any time, without affecting what was lawful before.
- Objection — to processing based on legitimate interest.
Write to hello@idobetter.io from the address on your account. Requests are free and answered within 15 business days. We may ask you to confirm your identity first — that protects you, not us. You may also petition the ANPD directly.
If you are outside Brazil, the equivalent rights under your own law — access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to your supervisory authority — are honoured the same way.
Deleting your account
Email hello@idobetter.io from your account address and we will remove your account, your projects, your uploaded media, the results generated from them, and any connected-channel token. Deletion is permanent and cannot be undone — back up anything you want to keep first. The only things that survive are the order records that tax law obliges us to hold, listed in section 11.
You do not need us for the narrower cases: delete a project in the app to remove its media and results, or disconnect a channel to delete its token.
Security
- Everything travels over TLS. Stored media and databases are encrypted at rest by the providers that hold them.
- Secrets, service keys and OAuth tokens live server-side and are never sent to the browser.
- Media is played back through short-lived signed URLs that expire, rather than public links.
- Access to production data is limited to those who need it, with individual accounts.
No system is perfectly secure, and we will not pretend otherwise. If a security incident occurs that is likely to create risk or relevant harm to you, we will notify you and the ANPD as LGPD art. 48 requires.
Children and adolescents
idb is not directed at children. You must be 18 or older to hold an account, or 16 or 17 with the assistance of a parent or guardian who accepts the terms with you. Nobody under 16 may use idb.
We do not knowingly collect data from anyone under 16. If we learn that we have, we delete it as quickly as we can — tell us at hello@idobetter.io.
Changes to this policy
When this policy changes, the new version is published at this address with a new effective date, and the date of the version it replaces is noted beneath it. Material changes are announced in the app before they take effect.
Contact
idb — a Pisoms product.
Everything, including data protection requests: hello@idobetter.io. For a request under the LGPD, put LGPD or Privacy in the subject line so it is routed straight through. We answer within 15 business days.
Supervisory authority in Brazil: ANPD — gov.br/anpd.