Privacy Policy
ReelNotes Ltd (“ReelNotes”, “we”, “us”) provides a service that turns short-form videos you save (such as Instagram reels) into structured notes. This policy explains what personal data we collect, why, how we look after it, and the rights you have. ReelNotes Ltd is the data controller for the personal data described here. If you have any questions, email us at [email protected].
1. The data we collect
- Account details: your email address and an encrypted (hashed) password, or, if you sign in with Google, your Google account email and basic profile identifier; plus your plan tier and account settings.
- Content you save: the links you submit and files you upload, and the data we derive from them: transcripts, on-screen text (OCR), captions, summaries, key points, categories and other generated notes.
- Your Instagram session: only if you choose to connect Instagram (see section 4). We store the session cookies that let us fetch the reels you save on your behalf. We never receive or store your Instagram password.
- Usage and plan data: counts of saves and channels, processing activity and similar information used to operate your plan and limits.
- Technical data: IP address, browser/device information and server logs generated when you use the service, used for security and reliability.
- Payment data: if you subscribe to a paid plan, payment is processed by Stripe. We do not receive or store your full card details; we receive limited billing information (such as subscription status) from Stripe.
2. How we use your data, and our lawful bases
Under UK GDPR we rely on the following lawful bases:
- To provide the service (performance of our contract with you): creating your account, processing your saves, generating notes, powering search, filtering and channels, and enforcing plan limits.
- Our legitimate interests: keeping the service secure, preventing abuse, fixing problems, and understanding aggregate usage to improve the product, balanced against your rights.
- Your consent: where we ask for it, such as connecting your Instagram session. You can withdraw consent at any time (for Instagram, by disconnecting).
- Legal obligation: keeping records we are required by law to keep (for example, tax records for payments).
We do not sell your personal data, and we do not use it to serve advertising.
3. AI processing and the content you save
To generate notes, the transcript and caption text of your saves is sent to our AI processing providers, Anthropic and OpenAI, via their APIs. They process this text to return the summary and structured output. Under their API terms, content sent through the API is not used to train their models. We use only the caption and transcript as the basis for the generated notes.
To make your saves searchable by the people featured in them, ReelNotes may also send a small number of still frames from a saved video to Amazon Web Services (AWS Rekognition) for celebrity face recognition. Only those frames are sent; the recognised names are stored as search keywords on your account and are used for search only; never to generate the note text.
4. Connecting Instagram
Saving reels that require a logged-in session works by you connecting your own Instagram account. When, and only when, you click “Connect Instagram” (in the browser extension or the app), we capture your existing instagram.com session cookies and store them, encrypted in transit, against your account. We then use that session to fetch the specific reels you choose to save, acting on your instruction.
- We never ask for, see, or store your Instagram password.
- Your session is used only to fetch content you ask us to save. It is not shared with any third party.
- You can disconnect at any time, which deletes the stored session immediately.
- You are responsible for ensuring you have the right to save and process the content, and for complying with Instagram’s own terms (see our Terms of Service).
Because a stored session is sensitive, we treat it as confidential, restrict access to it, and delete it as soon as you disconnect or close your account.
5. Who processes data on our behalf (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Fly.io | Application hosting, database and file storage | UK / EU (London) |
| Anthropic | AI text synthesis of your saves | United States |
| OpenAI | AI text synthesis of your saves (failover) | United States |
| Amazon Web Services (Rekognition) | Celebrity face recognition (people featured in saves) | United States |
| “Sign in with Google” authentication (optional) | United States | |
| Stripe | Payment processing for paid plans | United States / UK |
6. International transfers
Some providers (Anthropic, OpenAI, Google, Amazon Web Services, Stripe) process data in the United States. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the providers’ data-processing agreements and Standard Contractual Clauses.
7. Cookies and local storage
We use a small set of strictly-necessary cookies to keep you signed in and to remember interface preferences (such as theme and density). We do not use advertising or third-party tracking cookies. Your browser’s local storage may hold interface preferences on your device.
8. How long we keep your data
- While your account is active, we keep your account and saved content so the service works.
- When you delete your account, we permanently delete your account, personal data and saved content from our live systems immediately. Residual copies in encrypted backups are overwritten within 30 days on our normal backup rotation.
- Saved media (downloaded video, thumbnails) is deleted when you delete the save, and all of it on account deletion.
- Your Instagram session is deleted immediately when you disconnect, and on account deletion.
- Billing records are retained for up to 6 years where required by tax law.
- Server logs are retained for around 90 days.
9. Security
We apply reasonable technical and organisational measures: encryption of data in transit (HTTPS), access controls, and isolation of each user’s data. We treat connected Instagram sessions as sensitive and restrict access accordingly. No online service can be guaranteed perfectly secure; if a breach affecting your data occurs, we will act in line with our legal obligations.
10. Your rights
Under UK GDPR you have the right to access your data, have inaccurate data corrected, have your data erased, restrict or object to certain processing, receive your data in a portable format, and withdraw consent where processing is based on consent. To exercise any of these, email [email protected]. You also have the right to complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk.
11. Children
ReelNotes is not intended for anyone under 16. We do not knowingly collect data from children under 16; if you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the service evolves. We will change the “last updated” date above and, for material changes, take reasonable steps to let you know.
13. Contact
ReelNotes Ltd: [email protected].
ReelNotes Ltd is the data controller, a company registered in England & Wales (company no. 17304579). Registered office: 76 Gore Park Road, Eastbourne, East Sussex, BN21 1TQ, United Kingdom.