Privacy Policy

Effective Date: June 22, 2026

1. Introduction

This Privacy Policy explains how Vyra ("we," "us," or "our") collects, uses, and protects your information when you use our video editing platform. We built Vyra to be a place you can trust with your work - this policy spells out exactly what we do, and just as importantly, what we never do, with your data.

2. Your Videos & Content - Our Core Commitment

Your projects, uploads, and exports are yours. This is the part of the policy that matters most, so we'll be direct:

  • You own your content. We claim no ownership of the videos, images, audio, or projects you upload or create.
  • We use it only to run and improve Vyra. Your content is used to provide the editing, analysis, and rendering features you ask for, and to improve our service internally. That's it.
  • We never sell it. We never use it for advertising. We do not sell, rent, or trade your content or personal data, and we never use your content to serve you ads.
  • It is never shared outside Vyra except with the specific service providers we rely on to actually deliver the product - for example, the AI services that understand your video, transcribe your audio, and render your exports. Those providers act only on our behalf, only to deliver those features.
  • Our providers do not train on your content. Under the commercial terms of the plans we use, the third-party AI and infrastructure providers that process your content are not permitted to use it to train their own models or for any purpose other than providing services to Vyra.
  • It's encrypted and access-controlled. Your content is encrypted in transit and at rest, isolated per account, and protected by access controls.
  • You can delete it. Delete a file, a project, or your whole account, and the underlying data is removed (see Data Retention below).

3. Information We Collect

Account Information

  • Email address
  • Name
  • Authentication credentials (we store a securely hashed password - never your password in plain text - or rely on your Google Sign-In)

Content You Create

  • Projects and all project data
  • Uploaded files (videos, images, audio, documents)
  • Video editor compositions and exports

Usage Data

  • Feature usage and API requests
  • Performance and reliability metrics

Payment Information

  • Subscription and billing data is processed by Stripe. We do not store your payment card details.

4. How We Use Your Information

  • Provide and operate our service
  • Authenticate your account
  • Generate AI-powered scripts and analyze your videos
  • Process and render video exports
  • Track usage for billing
  • Improve our service internally (for example, diagnosing issues and making our features work better)
  • Send important service updates

5. Service Providers (Sub-Processors)

We use a small set of trusted providers to operate Vyra. They process your data only on our behalf and only to deliver the features below. Under the plans we use, they do not use your content to train their own models or for any unrelated purpose.

  • AI video understanding & scripting: Google (Gemini)
  • Audio transcription: ElevenLabs
  • Embeddings (semantic search): OpenAI
  • Authentication & database: Supabase, and Google for Google Sign-In
  • Storage & video processing: Cloudflare R2, Google Cloud, and Amazon Web Services
  • Hosting: Vercel and Railway
  • Payments: Stripe for subscription billing
  • Product analytics: Privacy-respecting analytics to understand feature usage and performance

We keep this list current. Each provider operates under its own privacy policy and contractual data-protection terms with Vyra.

6. Third-Party Agent Access (MCP)

Vyra supports the Model Context Protocol (MCP), which lets external AI agents you choose (such as Claude Code, Codex, or other MCP-compatible tools) interact with your editor on your behalf.

When you authorize a third-party agent:

  • The agent can view your project assets, timeline state, and editor settings
  • The agent can execute editing actions (adding media, editing properties, etc.) in your browser session
  • Access is scoped to the project open in your editor and requires your explicit OAuth consent
  • You can revoke access at any time from your account settings

In this MCP flow, the external agent is the AI you bring - Vyra does not route your MCP-session data through its own AI providers. The agent processes the data it accesses under its own provider's policy, which we do not control. Please review the privacy policy of any agent you authorize.

7. Data Sharing

We do not sell your personal information or your content. We share data only in these limited cases:

  • With the service providers (sub-processors) listed above, solely to operate Vyra
  • With legal authorities when required by law, or to protect the rights, safety, and security of Vyra and its users
  • In connection with a merger, acquisition, financing, or sale of assets - see below

Business transfers: If Vyra is involved in a merger, acquisition, financing, or sale of all or part of our business, your information may be transferred as part of that transaction. We will notify you of any such change, and any successor entity will be required to honor the commitments in this Privacy Policy, or to give you notice and a choice before your data is used under a materially different policy.

8. Data Security

We implement strong, layered security measures, including encryption of your content in transit (TLS) and at rest, securely hashed passwords, scoped authentication tokens, per-account data isolation, and access controls. No method of transmission or storage is 100% secure, but we work hard to protect your data and to limit who and what can access it.

9. International Data Transfers

Vyra is operated from the United States, and our infrastructure and service providers are primarily located in the United States. If you access Vyra from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our providers operate. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these transfers.

10. Cookies & Local Storage

We use cookies and browser storage to maintain your login session and cache preferences for faster loading. We do not use them for cross-site advertising.

11. Data Retention

We retain your content and account data while your account is active. You may delete individual files and projects at any time. When you delete your account, we remove your personal data and content from our active systems within 30 days, except where we are required to retain limited records to comply with legal, tax, or accounting obligations. Backups are purged on a rolling basis.

12. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate information
  • Delete your content and account
  • Export your data
  • Object to or restrict certain processing, and withdraw consent

If you are in the EEA/UK, these rights are provided under the GDPR. If you are a California resident, you have rights under the CCPA/CPRA - including the right to know, delete, and opt out of the "sale" or "sharing" of personal information. Vyra does not sell or share your personal information as those terms are defined under California law. To exercise any of these rights, contact us at caleb@usevyra.com.

13. Children's Privacy

Vyra is not intended for users under 13 (or the minimum age of digital consent in your country). We do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.

14. Changes to This Policy

We may update this policy at any time, and will update the effective date accordingly. Under certain circumstances (for example, with certain material changes or where required by applicable privacy laws) we will provide notice to you of these changes and, where required by applicable law, we will obtain your consent. Notice may be by email to you, by posting a notice on our Services, or by other means consistent with applicable law.

15. Contact Us

Questions about this Privacy Policy? Contact us at:

Email: caleb@usevyra.com

← Back to home