Privacy policy
Last updated 18 August 2026
ReelFlow is a video production studio: a web app, plus an optional desktop agent that runs on your own computer. This page says, in plain words, what we store, where it lives, what leaves your machine, and who else receives data. When the product changes, this page changes with it.
Who runs ReelFlow
ReelFlow is operated by its small founding team, based in the United States and Türkiye. For any question about this policy or your data, write to hello@thereelflow.com.
Your account
When you sign up we store your email address, your display name, and — if you choose one — a profile picture; if you sign in with Google, we show the picture from your Google profile. You can sign in with an email and password or with a Google account. Passwords and two-factor secrets are handled by our authentication provider, Supabase; we never see them.
If you invite teammates, we store the invited email address. If registration is closed and you join the waitlist, we store your email and a hashed form of your network address. Administrative actions on your studio are recorded in an audit log together with the network address they came from, so account changes can be traced.
Your studio and what it makes
Your projects, channels, ideas, scripts, storyboards, generated copy, and the record of every production job — including the prompts sent and the results returned — are stored in our database, so your work is there on every device you sign in from. We also meter usage per studio (model tokens, GPU seconds, storage bytes) to enforce plan limits.
Job logs are kept for 14 days. Job records are kept for about 90 days, and the most recent ones are always kept.
Where your media lives
The heavy files stay on your machine. Final rendered videos, the original full-quality images and audio, and the publish kit are produced on your own computer and are never uploaded.
What the cloud keeps is the light preview layer: small thumbnails, compressed narration clips, and a 720p preview copy of the finished video, so you can review work from a phone. These live in our storage (Supabase, or Cloudflare R2 when configured) and delete themselves — previews after 14 days, temporarily parked originals after 7. Channel artwork and cover images are kept as part of your studio.
Your AI keys, your calls
ReelFlow works with AI model keys you bring yourself (Google Gemini, OpenAI, Anthropic). Keys are stored encrypted, sealed per studio; the interface only ever shows you the last few characters.
Generation itself happens with your key, from your side: your prompts, images, and audio go directly from your browser or your computer to the AI provider you chose — the content of those calls does not pass through our servers. What the provider does with them is governed by that provider's own terms and privacy policy; the account and the bill are yours.
YouTube and your Google account
When you paste a YouTube link for analysis, we fetch that video's or channel's public metadata through the YouTube Data API, and public transcripts are fetched from your own browser or your own computer. Fetched metadata and transcripts are cached in our database.
Connecting a YouTube channel asks Google for three permissions. Two are narrow: reading the connected channel's basic identity — its name, handle and artwork — so ReelFlow can show which channel it is working with, and uploading the videos you asked ReelFlow to produce. The third is broader than what we actually use, because Google offers no narrower one: attaching a subtitle track to a video requires a permission that also covers other changes to the account. ReelFlow uses it for subtitles on the videos it uploaded for you and for nothing else. It does not read your comments, your subscribers, your analytics or anything private, and it makes no other change to your channel. The permission is stored encrypted, and you can withdraw it at any time — in your Google account's security settings (myaccount.google.com/permissions) or by disconnecting the channel inside ReelFlow. Either one ends our access immediately.
ReelFlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Cookies
We use cookies for one thing: keeping you signed in. There are no advertising cookies, no analytics cookies, and no third-party trackers — we run no analytics service at all. A short-lived cookie is set while you reset a password, and some interface preferences are kept in your browser's local storage.
Who else is involved
ReelFlow runs on a small set of services, and data reaches each one only for the purpose named here: Vercel (hosting the app), Supabase (database, sign-in, and storage), Cloudflare R2 (media previews), Resend (sending invitation and waitlist emails), YouTube's Data API (public video metadata), and Freesound (searching sound effects). The AI providers you bring keys for receive your generation calls directly, as described above.
Deletion
You can delete artifacts, channels, and styles yourself, and revoke devices, API keys, shares, and invitations — the effect is immediate. Media previews and temporary files delete themselves on the schedules above.
There is no self-serve account deletion yet. To close your account, write to hello@thereelflow.com: we anonymize your profile, revoke your studio's devices, and sign the account out everywhere.
When this page changes
As the product grows, this page is updated with it; the date at the top says when. Changes that matter to your data are announced in the product.