Privacy Policy
This policy explains how Bhaasa collects, uses, shares, retains, and protects personal data across our newsroom production, subtitle, media, organization, developer, and hosted-video services (the "Service").
Table of Contents
| # | Section | Description |
|---|---|---|
| 1 | Scope and who we are | Who this policy covers, our role, and how to contact us. |
| 2 | Information we collect | Account, newsroom, media, organization, billing, developer, and usage data. |
| 3 | How we collect information | Information you provide, content you import, and information created through use of Bhaasa. |
| 4 | How we use information | Why we process data to provide, secure, support, and improve the Service. |
| 5 | AI and media processing | How content is processed when you request transcription, translation, narration, or video generation. |
| 6 | Legal bases | The legal grounds on which we process personal data. |
| 7 | How information is shared | Service providers, workspace members, integrations, public publishing, and legal disclosures. |
| 8 | Organizations and workspaces | How organization administrators, workspace roles, invitations, and audit records affect privacy. |
| 9 | Hosted players, APIs, and integrations | What happens when you publish, embed, connect, or automate content. |
| 10 | Cookies and local storage | Essential sessions and preferences used across Bhaasa domains. |
| 11 | Retention and deletion | How long account, project, export, organization, and operational records may be kept. |
| 12 | International processing | How data may be processed across borders with appropriate safeguards. |
| 13 | Security | Measures used to protect accounts, workspaces, media, and developer access. |
| 14 | Your privacy rights | Access, correction, deletion, portability, restriction, objection, and complaint rights. |
| 15 | Children’s privacy | Our minimum age requirement. |
| 16 | Changes and contact | How we update this policy and how to reach us. |
1. Scope and who we are
This policy applies to Bhaasa websites and subdomains, personal and organization accounts, dashboards, News Studio, subtitle tools, media and player features, developer services, support, and related communications.
Bhaasa is responsible for personal data processed through the Service unless another party, such as your employer or organization, determines why and how that data is used. In those cases, that organization may be the controller and Bhaasa may process data on its instructions.
This policy covers visitors, account holders, organization administrators and staff, invited members, API users, people who contact us, and viewers who access a Bhaasa-hosted or embedded video. It does not replace the privacy notices of customers who use Bhaasa to publish their own content.
Bhaasa is offered to users and organizations internationally. Contact us at hello@bhaasa.io, through our support channel, or through www.bhaasa.io.
2. Information we collect
Account and profile information
We may collect your name, verified email address, profile image, account type, language and onboarding choices, authentication events, plan, usage allowance, and account status. We do not receive payment-card credentials entered directly with a payment provider.
Newsroom, subtitle, and media content
We process information you submit or create, including article text, public article links, headlines, scripts, uploaded video, audio, images, logos, fonts, thumbnails, transcripts, subtitles, translations, speaker information, voice and presenter selections, visual presets, overlays, timing and editing data, generated footage choices, and rendered outputs. Project history and editor state may be stored so work can be reviewed, continued, or exported.
Security and device information
To protect confidential newsroom work and maintain accountable audit records, Bhaasa may record sign-in and destructive-action timestamps, the server-observed IP address, browser and device information, a pseudonymous device identifier, and coarse city, region, or country information supplied by our network edge. We do not collect precise GPS location for this purpose.
Organizations and workspaces
For organization accounts, we may collect organization name and domain, workspace names, member and invitation details, roles, permissions, access requests, administrative decisions, plan or sales-request information, and audit events such as membership, workspace, publishing, and security changes.
Publishing and developer information
If you use hosted delivery, embeds, APIs, webhooks, or connectors, we may process player titles, branding, allowed domains, publication status, API-key identifiers and permissions, request and response metadata, usage, timestamps, status codes, latency, errors, webhook destinations and delivery results, integration settings, and scheduled publishing information. Secret values are handled as credentials and should not be included in support messages or public content.
Billing, sales, and support
We may collect plan and transaction records, amount, currency, payment status and reference, invoice details, organization size, role, phone number, requirements, support messages, and correspondence. Payment providers process the financial credentials needed to complete payment.
Device, service, and viewer information
We may collect IP address, approximate location derived from IP, browser and device information, timestamps, pages or features used, referring address, security events, error reports, and operational logs. When someone views hosted content, we may receive delivery requests and basic playback or security information needed to operate, protect, and troubleshoot the player.
3. How we collect information
- Directly from you when you register, upload, edit, publish, purchase, invite staff, configure an integration, or contact us.
- From your organization or workspace administrator when they create an account, invite you, assign permissions, or manage your access.
- From content sources you direct us to import, such as a publicly available article page or a connected publishing service.
- Automatically when the Service creates transcripts, translations, generated media, thumbnails, exports, usage records, logs, and audit events.
- From payment, authentication, publishing, and other service providers when needed to confirm an event or provide a requested feature.
4. How we use information
- Authenticate accounts and provide personal, organization, and workspace access.
- Create, transcribe, translate, narrate, edit, render, store, export, host, embed, and deliver requested content.
- Maintain project history, media libraries, templates, player settings, publishing destinations, and live export updates.
- Operate developer features, verify API access, deliver webhooks, enforce quotas, and provide request logs and analytics.
- Manage roles, invitations, permissions, organization onboarding, audit trails, and administrative controls.
- Process purchases, manage plans, issue receipts, respond to sales requests, and provide customer support.
- Protect the Service, investigate misuse, prevent fraud, troubleshoot errors, maintain reliability, and comply with law.
- Develop and improve features using feedback, aggregated measurements, and content only where permitted by this policy or separately agreed.
We do not sell personal data. We do not use customer video, audio, articles, or private newsroom content to train general-purpose AI models unless we first obtain explicit permission or enter into a separate written agreement that clearly allows it.
5. AI and media processing
Bhaasa uses automated systems to perform tasks you request, which may include speech recognition, translation, language processing, narration, voice generation, presenter composition, visual selection, caption timing, and video rendering. We send only the information reasonably needed to perform the selected task to service providers acting on our behalf.
Automated output may be incomplete or inaccurate. Bhaasa provides review and editing controls, and users remain responsible for verifying facts, rights, pronunciation, translations, captions, synthetic presenters, and the suitability of any output before publication.
6. Legal bases
Depending on the context and applicable law, we rely on one or more of the following:
- Contract: processing needed to provide the Service you or your organization requested.
- Legitimate interests: securing, operating, supporting, and improving the Service, preventing abuse, and understanding performance.
- Consent: where you make an optional choice or applicable law requires consent.
- Legal obligation: retaining or disclosing information where law, regulation, court order, or a lawful request requires it.
8. Organizations and workspaces
If you join an organization, its authorized administrators control membership and may create or remove workspaces, assign roles and feature permissions, review organization or workspace audit records, manage shared projects, and remove access. Workspace administrators may have visibility into activity within the workspaces they manage.
Your organization may retain content and records under its own policies even after your individual access ends. Privacy requests concerning organization-controlled data may need to be directed to that organization; we will assist it as required by law and contract.
9. Hosted players, APIs, and integrations
Hosted and embedded players are designed for public or audience-facing delivery. Anyone with an active public link, or anyone visiting a site where it is embedded, may be able to view the published video and its configured title, poster, or branding. Domain restrictions can limit where an embed is used but should not be treated as a substitute for access control.
Updating a published export may change the media delivered through the same player URL. Disabling a player or deleting a project can stop future delivery, but copies already downloaded, cached, recorded, indexed, or shared by others may remain outside our control.
API keys and webhook secrets must be protected by the customer. Requests made with valid credentials are treated as authorized. Webhook payloads and content sent to an integration are subject to the recipient’s privacy practices after delivery.
11. Retention and deletion
We retain information only for as long as reasonably needed to provide the Service, meet the storage terms of your plan or organization agreement, preserve security and audit records, resolve disputes, enforce agreements, and comply with legal, tax, and accounting obligations.
- Free-plan projects are generally retained for 7 days after processing; Creator-plan projects for 90 days; Studio-plan projects while the subscription remains active; and Enterprise projects according to the applicable agreement or organization policy.
- Temporary processing files and superseded exports may be removed sooner when they are no longer needed to complete or deliver a project.
- Organization membership, permission, invitation, and audit records may be retained after a member leaves where needed for accountability and security.
- Developer request and webhook-delivery logs are retained for operational, billing, troubleshooting, and abuse-prevention purposes.
- Billing records may be retained for the period required by tax, accounting, and legal obligations.
- Backups and cached copies may take a limited period to expire after deletion and are isolated from ordinary use.
Deleting a project or disabling a player removes it from normal account access and future delivery as applicable. Deletion cannot recall content already exported, publicly shared, received by an integration, or copied by another party. Before deleting content, download anything you need to retain.
12. International processing
Bhaasa and the providers supporting the Service may process information in countries other than your own. Where required, we use contractual, organizational, and other lawful safeguards for international transfers. Data-protection laws may differ between countries.
13. Security
We use reasonable administrative, organizational, and technical safeguards designed to protect information, including encrypted transport, access controls, tenant and workspace authorization, credential protection, activity records, and restricted internal access. Payment credentials are handled by payment providers rather than stored by Bhaasa.
No service is completely secure. Keep sign-in access, API keys, webhook secrets, invitation links, and publishing controls confidential. Contact hello@bhaasa.io immediately if you suspect unauthorized access or a security incident.
14. Your privacy rights
Subject to your location and applicable law, you may have rights to:
- access and receive a copy of personal data;
- correct inaccurate or incomplete information;
- delete personal data or request account deletion;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- receive portable data where required; and
- complain to an appropriate data-protection authority.
Send requests to hello@bhaasa.io. We may verify your identity and authority before acting. If your account is managed by an organization, we may refer the request to that organization or require its authorization where it controls the relevant data.
15. Children’s privacy
Bhaasa is a professional service and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.
16. Changes and contact
We may update this policy as the Service, legal requirements, or our practices change. We will revise the date above and provide additional notice where a change is material and notice is required. Your continued use after an effective update is subject to the revised policy.
Questions or privacy requests may be sent to hello@bhaasa.io. You can also review our Terms and Conditions and Cookie Preferences.