Privacy Policy
Last updated 31 July 2026
This policy explains what personal information Featurelab (“we”) collects when you use the service, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
1. Who we are
The person responsible for deciding how and why your personal information is used is Kyle Grattan, a sole trader trading as Featurelab, based in New Zealand.
For any question about this policy, or to exercise your rights, contact us at privacy@featurelab.video.
We are based in New Zealand and handle personal information in accordance with the Privacy Act 2020 and its information privacy principles. Where we offer the service to people in the United Kingdom or the European Economic Area, the UK GDPR and EU GDPR may also apply to that processing.
2. What we collect, and why
Everything below is information the product actually processes. We do not use third-party advertising or analytics trackers, and we do not sell personal information.
| Information | Why we process it | Legal basis (UK/EU) |
|---|---|---|
| Email, name, profile image | To create and secure your account. Provided by Google when you sign in. | Contract |
| Authentication and session identifiers | To keep you signed in and protect your account. | Contract |
| Images, screen recordings and audio you upload | They are the raw material of the videos you make. | Contract |
| Project settings, scene configuration and version history | To save, restore and let you edit your projects. | Contract |
| Text extracted from your screenshots | So you can search your own asset library. Extraction runs in your browser. | Contract |
| Narration scripts and AI prompts you write | To generate speech and power in-editor AI assistance. | Contract |
| Voice identifiers, voice settings and, where applicable, custom voice samples | To generate narration audio in the voice you select. | Contract; consent where a custom voice is involved |
| Videos you render | They are the product output, stored so you can download them. | Contract |
| IP address, browser, device and request information | Security, abuse prevention, debugging and operating the service. | Legitimate interests — see below |
| Error and diagnostic information | To detect and fix failures. | Legitimate interests — see below |
| Usage counters (renders, AI messages, narration characters) | To enforce fair-use limits and control the cost of metered services. | Legitimate interests — see below |
| Moderation check metadata (time, result, category) | Security and abuse prevention. The rejected file itself is not kept. | Legitimate interests — see below |
| Authorisations and tokens for integrations you connect | To let tools you authorise act on your behalf. Revocable at any time. | Contract |
| Support messages and correspondence | To answer questions and resolve problems. | Contract; legitimate interests |
| Billing and transaction records, once paid plans launch | Payments, refunds, accounting, tax and fraud prevention. | Contract; legal obligation |
| Project content, when we review it | Service operation and quality assurance: an authorised administrator may review projects to investigate failures, enforce our acceptable-use policy and assure output quality. Every such access is logged. | Legitimate interests — see below |
Our legitimate interests are: protecting Featurelab and its users from abuse, controlling the cost of metered third-party services, keeping the service secure and available, diagnosing faults, and presenting locally relevant options in the interface. We have assessed these against your rights and interests and keep a record of that assessment.
We derive an approximate country from your IP address to order the voice list sensibly. We do not add that derived country to your Featurelab profile, although our hosting and security providers process IP addresses in their operational logs. We do not knowingly collect information from anyone under 16; if you believe a child has given us information, contact us and we will delete it.
3. AI-generated content
Your prompts and narration text are sent to the AI providers listed in section 6 to generate speech, draft scripts and power in-editor assistance.
We do not use your content to train Featurelab models. We select and configure AI services with the intention that submitted content is not used to train their general-purpose models, subject to each provider’s applicable terms — which are identified on our subprocessor page. Provider terms differ and can change; where a provider’s terms do not support this, we will say so there.
4. Voices
Featurelab offers licensed synthetic voices supplied by our speech provider. Using one of these does not require you to hold any rights in a real person’s voice.
Separately, some voices in the shared library are derived from real, identifiable people. Before you use a voice of that kind — or upload, clone or contribute a voice associated with an identifiable person — we ask you to confirm that you are the speaker or hold the speaker’s documented permission. We record that confirmation, the voice it relates to and when you gave it, so that both you and we can evidence it later.
Voice recordings and voice models may be treated as biometric or otherwise sensitive information in some countries. Where you supply a custom voice sample, we rely on your explicit consent and handle it accordingly.
5. Automated checks on uploads
Before an uploaded image is added to your asset library, an automated safety service checks it for categories prohibited by our Acceptable Use Policy. An image that fails the check is not added to your account and is not stored. We keep limited metadata about the check — its time, result and category — for security and abuse prevention.
These checks decide whether an upload is accepted. They do not produce legal or similarly significant effects about you. You can ask us to review a rejection: a person will review the decision, though because the rejected file is not retained we may need you to describe it or supply it again through another channel. Contact support@featurelab.video.
6. Who we share information with
We use the service providers below to operate Featurelab. Where required, we put data-processing terms in place with them. We do not sell personal information or share it for advertising.
| Provider | What they receive | Purpose |
|---|---|---|
| Clerk | Account identity and session information | Authentication |
| Convex | Your account and project data | Application database |
| Vercel | Requests, logs, AI routing | Hosting and delivery |
| Amazon Web Services | Uploaded media, generated audio, rendered video | Storage, rendering and delivery |
| ElevenLabs | Narration text and voice selection | Speech synthesis |
| OpenAI (via Vercel AI Gateway) | Prompts and narration drafting text | AI assistance |
| GitHub | A GitHub username and publicly available contribution information, only when you use the contribution-graph feature | Public data lookup |
A current list, with each provider’s legal entity, role, hosting region and transfer mechanism, is maintained on our subprocessor page. Where our contractual or legal obligations require it, we will give notice of material changes to that list.
Where a feature obtains information about a person from a third party rather than from that person directly — such as GitHub contribution data — the source is that third party’s public API.
7. Sending information overseas
Our providers are located outside New Zealand, principally in the United States. Information sent overseas may be subject to the laws of those countries. Before disclosing personal information outside New Zealand we take steps to satisfy ourselves that comparable safeguards apply, as required by information privacy principle 12 of the Privacy Act 2020.
Where UK or EU data protection law applies, we use an appropriate transfer mechanism — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU–US Data Privacy Framework, or another legally recognised safeguard. The mechanism differs between providers and is identified on our subprocessor page. You can request further detail from privacy@featurelab.video.
8. How long we keep it
We keep your account and project information for as long as your account is open. Beyond that:
| Category | Retention |
|---|---|
| Projects, assets and rendered videos | Until you delete them, or your account is deleted |
| Assets no longer referenced by any project | Deleted automatically after 30 days |
| Request, security and error logs | 90 days |
| Moderation check metadata | 12 months |
| Rejected uploads | Not stored at all |
| Support correspondence | 12 months after the matter is closed |
| Integration authorisations | Until you revoke them, or account deletion |
| Account exports you generate | 30 days |
| Backups | Up to 35 days, then overwritten |
| Billing records, once paid plans launch | As required by New Zealand tax law, typically 7 years |
When you delete your account it is deactivated immediately and scheduled for permanent deletion after a 30-day recovery period, during which you can ask us to restore it. Deleted information may persist in encrypted backups for up to 35 days before being overwritten; it is not restored except for disaster recovery or security purposes. Limited records may be retained where the law requires it.
A limited number of legacy files created before July 2026 are stored outside the per-account structure described above and do not carry reliable account-attribution metadata. Because those locations were shared, we cannot establish which account a file belongs to, so they are not deleted automatically when an account is deleted — including as part of the account-deletion process, where they are recorded as retained. They remain isolated from the application, are not reassigned or made available to any account, and are not used to build a profile of anyone. If you believe such a file is yours, contact privacy@featurelab.video and we will remove it where ownership can be established.
9. Your rights
You can ask for access to the personal information we hold about you, ask us to correct it, and — where the relevant law provides them — ask us to delete it, export it, restrict how we use it, or object to our use of it. You can withdraw consent where our processing relies on consent. Some of these rights are subject to legal conditions and exceptions.
- Project export — download your projects and their configuration in a machine-readable format from your account settings.
- Delete your account — from your account settings, subject to the 30-day recovery period described above.
- Access request — for a copy of the personal information we hold about you, contact privacy@featurelab.video.
We respond within the time the applicable law allows — 20 working days under the New Zealand Privacy Act, and one month under the UK and EU GDPR.
If you are not satisfied with our response you can complain to a regulator. In New Zealand that is the Office of the Privacy Commissioner (privacy.org.nz). In the United Kingdom it is the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). In the EEA it is your national supervisory authority.
10. Security
Information is encrypted in transit and at rest. Each account’s files are stored under a separate namespace and access is checked on every request. We use least-privilege credentials, automated dependency and code checks, and error monitoring configured not to capture the content of your prompts or uploads. No system is perfectly secure; if a privacy breach is likely to cause serious harm we will notify affected people and the Privacy Commissioner as the Privacy Act requires, and any other regulator where that applies.
12. Changes
If we make a material change we will update the date at the top of this page and notify you by email or in the app before it takes effect.