← Back

Privacy Policy

Last updated 31 July 2026

This policy explains what personal information Featurelab (“we”) collects when you use the service, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

1. Who we are

The person responsible for deciding how and why your personal information is used is Kyle Grattan, a sole trader trading as Featurelab, based in New Zealand.

For any question about this policy, or to exercise your rights, contact us at privacy@featurelab.video.

We are based in New Zealand and handle personal information in accordance with the Privacy Act 2020 and its information privacy principles. Where we offer the service to people in the United Kingdom or the European Economic Area, the UK GDPR and EU GDPR may also apply to that processing.

2. What we collect, and why

Everything below is information the product actually processes. We do not use third-party advertising or analytics trackers, and we do not sell personal information.

InformationWhy we process itLegal basis (UK/EU)
Email, name, profile imageTo create and secure your account. Provided by Google when you sign in.Contract
Authentication and session identifiersTo keep you signed in and protect your account.Contract
Images, screen recordings and audio you uploadThey are the raw material of the videos you make.Contract
Project settings, scene configuration and version historyTo save, restore and let you edit your projects.Contract
Text extracted from your screenshotsSo you can search your own asset library. Extraction runs in your browser.Contract
Narration scripts and AI prompts you writeTo generate speech and power in-editor AI assistance.Contract
Voice identifiers, voice settings and, where applicable, custom voice samplesTo generate narration audio in the voice you select.Contract; consent where a custom voice is involved
Videos you renderThey are the product output, stored so you can download them.Contract
IP address, browser, device and request informationSecurity, abuse prevention, debugging and operating the service.Legitimate interests — see below
Error and diagnostic informationTo detect and fix failures.Legitimate interests — see below
Usage counters (renders, AI messages, narration characters)To enforce fair-use limits and control the cost of metered services.Legitimate interests — see below
Moderation check metadata (time, result, category)Security and abuse prevention. The rejected file itself is not kept.Legitimate interests — see below
Authorisations and tokens for integrations you connectTo let tools you authorise act on your behalf. Revocable at any time.Contract
Support messages and correspondenceTo answer questions and resolve problems.Contract; legitimate interests
Billing and transaction records, once paid plans launchPayments, refunds, accounting, tax and fraud prevention.Contract; legal obligation
Project content, when we review itService operation and quality assurance: an authorised administrator may review projects to investigate failures, enforce our acceptable-use policy and assure output quality. Every such access is logged.Legitimate interests — see below

Our legitimate interests are: protecting Featurelab and its users from abuse, controlling the cost of metered third-party services, keeping the service secure and available, diagnosing faults, and presenting locally relevant options in the interface. We have assessed these against your rights and interests and keep a record of that assessment.

We derive an approximate country from your IP address to order the voice list sensibly. We do not add that derived country to your Featurelab profile, although our hosting and security providers process IP addresses in their operational logs. We do not knowingly collect information from anyone under 16; if you believe a child has given us information, contact us and we will delete it.

3. AI-generated content

Your prompts and narration text are sent to the AI providers listed in section 6 to generate speech, draft scripts and power in-editor assistance.

We do not use your content to train Featurelab models. We select and configure AI services with the intention that submitted content is not used to train their general-purpose models, subject to each provider’s applicable terms — which are identified on our subprocessor page. Provider terms differ and can change; where a provider’s terms do not support this, we will say so there.

4. Voices

Featurelab offers licensed synthetic voices supplied by our speech provider. Using one of these does not require you to hold any rights in a real person’s voice.

Separately, some voices in the shared library are derived from real, identifiable people. Before you use a voice of that kind — or upload, clone or contribute a voice associated with an identifiable person — we ask you to confirm that you are the speaker or hold the speaker’s documented permission. We record that confirmation, the voice it relates to and when you gave it, so that both you and we can evidence it later.

Voice recordings and voice models may be treated as biometric or otherwise sensitive information in some countries. Where you supply a custom voice sample, we rely on your explicit consent and handle it accordingly.

5. Automated checks on uploads

Before an uploaded image is added to your asset library, an automated safety service checks it for categories prohibited by our Acceptable Use Policy. An image that fails the check is not added to your account and is not stored. We keep limited metadata about the check — its time, result and category — for security and abuse prevention.

These checks decide whether an upload is accepted. They do not produce legal or similarly significant effects about you. You can ask us to review a rejection: a person will review the decision, though because the rejected file is not retained we may need you to describe it or supply it again through another channel. Contact support@featurelab.video.

6. Who we share information with

We use the service providers below to operate Featurelab. Where required, we put data-processing terms in place with them. We do not sell personal information or share it for advertising.

ProviderWhat they receivePurpose
ClerkAccount identity and session informationAuthentication
ConvexYour account and project dataApplication database
VercelRequests, logs, AI routingHosting and delivery
Amazon Web ServicesUploaded media, generated audio, rendered videoStorage, rendering and delivery
ElevenLabsNarration text and voice selectionSpeech synthesis
OpenAI (via Vercel AI Gateway)Prompts and narration drafting textAI assistance
GitHubA GitHub username and publicly available contribution information, only when you use the contribution-graph featurePublic data lookup

A current list, with each provider’s legal entity, role, hosting region and transfer mechanism, is maintained on our subprocessor page. Where our contractual or legal obligations require it, we will give notice of material changes to that list.

Where a feature obtains information about a person from a third party rather than from that person directly — such as GitHub contribution data — the source is that third party’s public API.

7. Sending information overseas

Our providers are located outside New Zealand, principally in the United States. Information sent overseas may be subject to the laws of those countries. Before disclosing personal information outside New Zealand we take steps to satisfy ourselves that comparable safeguards apply, as required by information privacy principle 12 of the Privacy Act 2020.

Where UK or EU data protection law applies, we use an appropriate transfer mechanism — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU–US Data Privacy Framework, or another legally recognised safeguard. The mechanism differs between providers and is identified on our subprocessor page. You can request further detail from privacy@featurelab.video.

8. How long we keep it

We keep your account and project information for as long as your account is open. Beyond that:

CategoryRetention
Projects, assets and rendered videosUntil you delete them, or your account is deleted
Assets no longer referenced by any projectDeleted automatically after 30 days
Request, security and error logs90 days
Moderation check metadata12 months
Rejected uploadsNot stored at all
Support correspondence12 months after the matter is closed
Integration authorisationsUntil you revoke them, or account deletion
Account exports you generate30 days
BackupsUp to 35 days, then overwritten
Billing records, once paid plans launchAs required by New Zealand tax law, typically 7 years

When you delete your account it is deactivated immediately and scheduled for permanent deletion after a 30-day recovery period, during which you can ask us to restore it. Deleted information may persist in encrypted backups for up to 35 days before being overwritten; it is not restored except for disaster recovery or security purposes. Limited records may be retained where the law requires it.

A limited number of legacy files created before July 2026 are stored outside the per-account structure described above and do not carry reliable account-attribution metadata. Because those locations were shared, we cannot establish which account a file belongs to, so they are not deleted automatically when an account is deleted — including as part of the account-deletion process, where they are recorded as retained. They remain isolated from the application, are not reassigned or made available to any account, and are not used to build a profile of anyone. If you believe such a file is yours, contact privacy@featurelab.video and we will remove it where ownership can be established.

9. Your rights

You can ask for access to the personal information we hold about you, ask us to correct it, and — where the relevant law provides them — ask us to delete it, export it, restrict how we use it, or object to our use of it. You can withdraw consent where our processing relies on consent. Some of these rights are subject to legal conditions and exceptions.

  • Project export — download your projects and their configuration in a machine-readable format from your account settings.
  • Delete your account — from your account settings, subject to the 30-day recovery period described above.
  • Access request — for a copy of the personal information we hold about you, contact privacy@featurelab.video.

We respond within the time the applicable law allows — 20 working days under the New Zealand Privacy Act, and one month under the UK and EU GDPR.

If you are not satisfied with our response you can complain to a regulator. In New Zealand that is the Office of the Privacy Commissioner (privacy.org.nz). In the United Kingdom it is the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). In the EEA it is your national supervisory authority.

10. Security

Information is encrypted in transit and at rest. Each account’s files are stored under a separate namespace and access is checked on every request. We use least-privilege credentials, automated dependency and code checks, and error monitoring configured not to capture the content of your prompts or uploads. No system is perfectly secure; if a privacy breach is likely to cause serious harm we will notify affected people and the Privacy Commissioner as the Privacy Act requires, and any other regulator where that applies.

11. Cookies and similar technologies

We use a session cookie so you stay signed in, and preference storage that remembers your theme and sidebar layout. We do not use advertising or analytics cookies.

Based on the technologies currently in use, we do not consider a cookie-consent banner to be required. We will reassess this if we introduce analytics, advertising or other non-essential technologies, and will ask for consent where it is needed.

12. Changes

If we make a material change we will update the date at the top of this page and notify you by email or in the app before it takes effect.