Your data

Privacy Policy

How FeedReels collects, uses and protects your personal data — compliant with the Swiss nFADP and the EU GDPR.

Last updated: June 18, 2026

This policy describes how FeedReels collects, uses and protects your personal data, in line with the Swiss revised Federal Act on Data Protection (nFADP) effective since 1 September 2023, and the EU GDPR for users located in the European Union.

1. Data controller

The controller is Lenovia, operator of FeedReels, registered seat at 1201 Geneva, Switzerland. Contact for data protection matters: legal@feedreels.ai.

2. Data we collect

  • Account: email, hashed password, preferred language, timezone.
  • Content: RSS sources, imported articles, generated scripts and videos.
  • Social accounts: encrypted OAuth tokens for TikTok and Instagram.
  • Payment: billing details processed by Stripe; we never store card numbers.
  • Biometric data: voice samples only when you use voice cloning, with separate explicit consent (GDPR art. 9).
  • Technical usage: server logs, IP address, browser type.
  • Communications: messages sent to support and to the AI assistant.

3. Purposes and legal bases

PurposeLegal basis (nFADP / GDPR)
Provide the service (video generation and publishing)Contract performance
Billing and fraud preventionLegal obligation + legitimate interest
Security, access logs, monitoringLegitimate interest
User supportContract performance
Voice cloningExplicit consent (GDPR art. 9)
Aggregated anonymous usage statisticsLegitimate interest

4. Sub-processors (exhaustive list)

Your data may be transmitted to the following sub-processors, strictly for the purposes above:

Sub-processorPurposeCountryDataLegal basis
Lovable Cloud (Supabase)Application hosting, database, authentication, file storageUE (Irlande / Allemagne)Email, mot de passe haché, contenus utilisateur, jetons OAuth (chiffrés), logsContract performance
CloudflareServerless edge runtime, CDN, DDoS protectionUS (DPF) + edge mondialAdresse IP, en-têtes HTTP, métadonnées de requêteLegitimate interest (security, availability)
StripePayments, billing, fraud preventionUS (DPF) + IEEmail, identité de facturation, métadonnées de transaction. Aucun numéro de carte stocké chez nous.Contract performance + legal obligation (accounting)
DeepSeekScript generation via LLMHong Kong / SingapourTexte source de l'article, contexte de générationContract performance
Lovable AI GatewayAI request routing for support assistant and internal tasksUS (DPF)Texte du message, métadonnées de sessionContract performance
Fournisseur de synthèse vocale studio (ElevenLabs)Voice synthesis and voice cloning (biometric data — separate explicit consent required)US (DPF)Texte du script, échantillon vocal (uniquement si clonage), identifiant de voixContract performance + explicit consent under GDPR art. 9 for cloning
fal.aiImage and video clip generationUSPrompts texte dérivés du scriptContract performance
CreatomateFinal video rendering (text + voice + visuals assembly)Pays-Bas (UE)Assets vidéo, audio, sous-titresContract performance
FirecrawlDiscovery and extraction of article content from public URLs provided by the userUSURLs soumises par l'utilisateur, contenu public récupéréContract performance
TikTok (ByteDance)Publishing videos to the user-connected accountIrlande / Singapour / USJeton OAuth, vidéo publiée, métadonnées de publicationContract performance (explicit user action)
Meta (Instagram)Publishing Reels to the user-connected accountIrlande / US (DPF)Jeton OAuth, vidéo publiée, métadonnées de publicationContract performance (explicit user action)
TelegramInternal admin notifications (operational alerts, monitoring)Émirats Arabes UnisEmail utilisateur tronqué, nature de l'événement (aucun contenu personnel détaillé)Legitimate interest (service monitoring)
PostHog (PostHog EU)Product analytics (pageviews, funnels) — only if you enable 'Analytics' in the cookie bannerUE (Francfort)Identifiant utilisateur, événements d'usage anonymisés, pages visitées. Aucun enregistrement vidéo de session, aucune saisie sensible.Consent (GDPR art. 6.1.a)
Sentry (Functional Software, EU region)Browser JavaScript error capture to improve reliability — only if you enable 'Diagnostics'UE (Francfort)Trace d'erreur, URL, navigateur. Emails, tokens et mots de passe automatiquement masqués avant envoi.Consent (GDPR art. 6.1.a)

5. Transfers outside Switzerland / EU

Some sub-processors are established in the United States or Asia. Transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU-US / Swiss-US Data Privacy Framework. A copy of the safeguards is available on request.

6. Retention periods

CategoryDuration
Account data (email, settings)Account lifetime + 30 days after deletion request
Generated content (articles, scripts, videos)Account lifetime, deleted on closure
Cloned voices (biometric data)Until manual deletion or consent withdrawal (immediate effect)
Social OAuth tokensUntil disconnection by the user
Technical logs (IP, requests)90 days
Support conversations12 months
Invoices and accounting data10 years (art. 958f Swiss CO)
Consent registry (voice)Account lifetime + 3 years (proof)

7. Your rights

Under nFADP and GDPR you have the rights of access, rectification, deletion, objection, restriction, portability, and the right to withdraw consent at any time.

  • Export: Settings → Account → Privacy → "Download my data" (JSON).
  • Deletion: Settings → Account → Privacy → "Delete my account" (effective after a 30-day grace period, cancellable).
  • Withdraw voice consent: Settings → Account → Privacy → "Withdraw consent" (cloned voices are deleted).
  • Contact: legal@feedreels.ai.

You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your national data protection authority.

8. Cookies and local storage

By default we only use strictly necessary cookies / local storage: authentication session, theme and language preferences, support assistant state, cookie-consent preference. Two optional categories, off by default, can be enabled in the banner: Analytics(PostHog, EU-hosted — pageviews and funnels, session replay disabled) and Diagnostics(Sentry, EU-hosted — JavaScript error capture, PII scrubbed before send). No advertising, no third-party tracking for marketing purposes. See the cookie policy for the full breakdown.

9. Security

Data encrypted in transit (TLS 1.2+) and at rest. Per-user isolation via Row Level Security in the database. Encrypted OAuth tokens. Secrets stored in a dedicated secrets manager. Access review and key rotation policies.

10. Biometric data (voice cloning)

Voice cloning relies on biometric data within the meaning of GDPR art. 9 and nFADP art. 5 § 1 (c). No processing occurs without your explicit consent, collected via a dedicated dialog explaining the purpose, sub-processor, country, retention period and your rights. Withdrawing your consent immediately deletes your cloned voices from our systems and from the partner sub-processor.

11. Platform integrations (TikTok & Meta/Instagram)

When you connect your TikTok or Instagram account via OAuth, FeedReels receives and stores only the information strictly necessary to publish videos on your account:

  • TikTok (Login Kit + Content Posting API): TikTok identifier (open_id,union_id), display name, avatar, and encrypted OAuth tokens (access_token and refresh_token). Requested scopes:user.info.basic, video.upload, video.publish. This data is used only to publish videos you generate on FeedReels to your own TikTok account, at your explicit request. We do not read, analyse or share any audience data, follower lists, direct messages or pre-existing content on your account. No TikTok data is sold, used for advertising, or transferred to any third party (beyond the strictly necessary Lovable Cloud / Supabase hosting layer). TikTok user data is never used to train AI models. Data is retained while the connection is active and deleted immediately when you disconnect from Settings → Connections, or when you delete your FeedReels account. You can also revoke access at any time from the TikTok app (Settings → Security & permissions → Manage apps).
  • Meta / Instagram (Graph API): Instagram Business identifier, username, encrypted access tokens. Used only to publish Reels to your connected account at your explicit request. Same guarantees: no reading of messages, audience or existing content, no resale, no advertising, no AI model training, immediate deletion on disconnection.

In accordance with the TikTok Developer Terms of Service and the Meta Platform Policy, FeedReels never uses this data to train AI models, does not aggregate it for public statistics, and does not allow any human access except on your explicit support request.

11 bis. Data deletion (TikTok / Meta)

To request deletion of data associated with your TikTok or Instagram connection, three options:

  1. Disconnect the account in Settings → Connections (immediate deletion of tokens and associated metadata).
  2. Delete your FeedReels account in Settings → Account → Privacy (full deletion within 30 days).
  3. Email legal@feedreels.ai with your TikTok / Instagram identifier: handled within 7 days, confirmation by email.

12. Minors

The service is restricted to users aged 18 and over. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us for immediate deletion.

13. Marketing attribution (first-party)

On your first visit, we capture locally (in your localStorage) any utm_*parameters present in the URL and the referrer hostname. This is used solely to measure our own marketing. It is kept for 30 days and sent to our server only if you create an account(then attached to your user id in a dedicated signup_attributions table). No data is transferred to any third party (no Google, no Meta, no TikTok). Legal basis: legitimate interest; you can request deletion at any time via legal@feedreels.ai.

14. Changes

We may amend this policy. Material changes (new sub-processor, new purpose) are notified by email at least 30 days before they take effect.

Other legal documents