Legal

Privacy Policy

What Riwayatak collects, why it collects it, which providers see part of it when a video is generated, how long it is kept, and what you can tell us to do with it.

  • Last updated
  • 14 sections
The short version
  • No advertising, no analytics tag, no tracking pixel. Cookies are limited to keeping you signed in, protecting the forms from abuse, and remembering your cookie choice.
  • Generating a video sends parts of your material to processing providers — the script to a voice provider, scene keywords to a media provider. Section 05 lists exactly which parts.
  • We do not use your content to train models, and we do not sell personal data.
  • Tokens for your connected YouTube or TikTok account are encrypted, used only for what you authorised, and deleted when you disconnect.
  • You can download a complete copy of your data, or close your account and delete everything in it, from inside your account — no email, no waiting.

This summary is written to be read. The numbered sections below are the policy itself, and they are what governs — the summary leaves detail out by design.

Contents Jump to a section

01 What this policy covers

This policy covers the public Riwayatak site and the client portal — everything under one account. It explains what we hold, why we hold it, who else processes it, and what you can require of us.

02 What we collect

  • Account: your name, gender, date of birth, email address, password (stored hashed — it is never held in a readable form), preferred language, and which plan you are on.
  • Optional contact: a WhatsApp number, if you give one. It is used for notifications about your account and nothing else — never to sign you in, never to recover the account, and never passed to anyone for marketing.
  • Consent records: the moment you accepted the Terms and Privacy Policy, and whether you asked for the newsletter. We keep these because the alternative is being unable to show that you agreed.
  • What you create: topics, briefs, scripts, narration text, captions, scene choices, anything you upload, and the videos that come out.
  • Connected platforms: access and refresh tokens for the accounts you connect (encrypted at rest), the channel or account identifier, and the performance figures we read back for videos published through Riwayatak.
  • Billing: your plan, invoices and payment status. Card details go to our payment provider and never reach our servers.
  • Technical: IP address, browser and device type, and the pages, timestamps and errors recorded in server logs.
  • Support: whatever you write to us, and our reply.

03 Where it comes from

  • From you: registration, everything you type or upload, and support messages.
  • From the platforms you connect: your channel identity and the performance figures for videos we published for you.
  • Automatically: the technical details every web server records when your browser makes a request.

04 What we use it for

Every purpose below is tied to a legal basis, in the terms the GDPR uses, because that is the strictest standard we are likely to be measured against.

  • Running the service you signed up for — generating, rendering, scheduling and publishing on your instruction: performance of our contract with you.
  • Billing you and keeping the records that go with it: contract, and legal obligation.
  • Keeping the service secure, preventing abuse, and enforcing plan limits: our legitimate interests.
  • Answering support requests: contract and legitimate interests.
  • Improving Riwayatak using aggregate figures that do not identify you: legitimate interests.
  • Meeting tax, accounting and other legal duties: legal obligation.
  • Sending occasional product email, which every message lets you turn off: legitimate interests, or consent where the law requires it.

05 What leaves our servers when you generate a video

Generating a video means handing parts of your material to specialised providers. This is the part of a privacy policy that is usually vague, so here it is concretely:

  • Your topic and brief go to a text-generation provider, which returns the script.
  • The script text goes to a speech provider, which returns the narration audio.
  • Scene keywords go to a stock media provider to find footage. Where a scene uses generated imagery instead, the scene description goes to an image-generation provider.
  • Caption timing is produced by transcribing the narration on our own infrastructure. That audio is not sent to a third party.
  • Rendering happens on our servers. The finished video is not sent anywhere for processing — only to the platform you asked us to publish it to.

06 Connected accounts

  • We request the narrowest set of permissions that lets us upload a video and read back how it performed.
  • Tokens are encrypted at rest and used only for the actions you authorised. No human at Riwayatak browses your connected account.
  • We read back performance figures for videos published through Riwayatak, and, where a platform provides them, aggregate audience figures such as which countries and hours your viewers are active — those are what scheduling decisions are made from.
  • Disconnecting an account from the portal deletes the stored tokens. Videos already published stay on your platform, under your control.

07 Cookies

Riwayatak sets strictly necessary cookies and nothing else. There is no analytics tag, no advertising cookie and no behavioural tracking anywhere on this site.

  • A session cookie, which is what keeps you signed in.
  • A CSRF token cookie, which stops another site from submitting forms as you.
  • A cookie recording your answer to the cookie notice, so we do not ask again on every page. It holds one of two words and nothing about you.
  • On the sign-up page only, and only while bot protection is switched on, Google reCAPTCHA sets its own cookie. It exists to tell a person from a script, it is not used to profile you, and it appears nowhere else on the site.
  • Your language is carried in the URL (/ar, /en), not in a cookie.

08 Who else processes your data

We use providers to perform specific parts of the service. Each one receives only what that part needs, and none of them is allowed to use it for their own purposes.

  • Hosting and storage — where the application, your files and your rendered videos live.
  • Text generation — writing the script from your topic.
  • Speech synthesis — turning the script into narration.
  • Stock media and image generation — the visuals in each scene.
  • Publishing platforms — YouTube, TikTok and any other account you connect.
  • Payments — subscription billing and invoices.
  • Email delivery — account, billing and support email.
  • Bot protection — Google reCAPTCHA, on the sign-up form, to keep automated scripts from creating accounts.

09 International transfers

Riwayatak is operated from Palestine and its providers sit in several countries, so data about you crosses borders in the ordinary course of the service working.

Where data protected by the GDPR or UK GDPR leaves that area, we use providers that offer an approved transfer mechanism — standard contractual clauses or an adequacy decision — and that commitment is one of the criteria we select providers on.

10 How long we keep it

  • Account details: for as long as your account is open.
  • Content and rendered videos: until you delete them, or until your account is closed.
  • After an account is closed: a wind-down window of 30 days, so an account closed by mistake can be recovered, after which everything is deleted for good. Closing is self-service — the Privacy & data page in the portal.
  • Connected-platform tokens: deleted the moment you disconnect that account or request closure, not at the end of the window — which is also what the YouTube API Services Developer Policies require of us, allowing seven days from the request.
  • Billing records: for as long as tax and accounting law requires us to hold them, which is usually several years. After an account is deleted they are kept against an anonymous reference that carries no name and no email.
  • Server logs: a short period, for security investigation and debugging. Whatever linked them to your account is removed when the account is deleted.

11 How it is protected

  • Everything travels over an encrypted connection.
  • Passwords are hashed. Nobody at Riwayatak can read yours, including us.
  • Connected-platform tokens are encrypted at rest with application keys held outside the database.
  • Access to production data is limited to the people who need it to operate the service.

12 Your rights

Depending on where you live, some or all of these are legal rights; we apply them to everyone regardless.

  • Get a copy of the personal data we hold about you.
  • Have inaccurate details corrected.
  • Have your data deleted, subject to records we are legally required to keep.
  • Receive a portable copy, in a machine-readable format.
  • Object to, or ask us to restrict, processing based on legitimate interests.
  • Withdraw consent at any time, where consent is what we relied on.
  • Complain to your national data protection authority.

13 Children

Riwayatak is not for children. Accounts require you to be 18 or older, or the age of majority where you live. We do not knowingly collect data from children, and if we learn that we have, we delete it.

14 Changes to this policy

As the service grows this policy will change with it. The date at the top always shows the current version, and where a change materially affects you we will tell you by email or in the portal before it takes effect rather than quietly editing the page.

Back to top

Still have a question?

A real person reads this address. If something here is unclear, or you want to exercise a right described above, write to us — that is faster than guessing.

The other document Terms of Service

What we owe each other, and what you may publish.

EN AR
Start creating