Privacy Policy
Last updated 5 September 2026 · KeyVelo, a NYPTID Industries product
This explains what KeyVelo collects, why, and what we do with it. The section on machine learning is the one most people care about, so it is near the top rather than buried.
01Who we are
KeyVelo is a video editing marketplace operated by NYPTID Industries, based in Conyers, Georgia (Rockdale County). We are the controller of the data described here. Contact support@keyvelo.com.
02How your work trains the editor
What that means concretely:
- Briefs, style notes and NChat messages are used to improve how the editor interprets instructions.
- Footage you upload and the cuts we deliver may be used to improve editing quality — pacing, grading, caption timing.
- We do not sell your data, and we do not use your footage to train models operated by unrelated third parties.
- We do not publish your work in the public portfolio unless you have agreed to it for that specific project.
- You can opt out at any time by emailing us. Opting out applies to future work immediately, and we will remove past material from training sets on request. It never affects your price or your place in the queue.
03What we collect
- Account — name, email address, and a bcrypt hash of your password. We never store your password itself.
- Project data — briefs, references, style notes, uploaded files, deliverables, and NChat messages.
- Payment — handled entirely by Stripe. Card numbers never reach our servers. We store only Stripe's identifiers so we can match a payment to your order.
- YouTube channel data — only if you choose to connect a channel. See section 04.
- Operational logs — request logs and error traces, used to keep the service running and investigate faults.
We do not knowingly collect Social Security numbers, financial account numbers, or government ID numbers, and you should never send them to us.
04YouTube data, if you connect a channel
Connecting a channel is optional. KeyVelo uses YouTube API Services, and by connecting you also agree to the YouTube Terms of Service. Google's handling of your data is governed by the Google Privacy Policy.
- We request read-only access. We can see your channel details and video list. We cannot upload, edit or delete anything.
- We use it to understand your formats and pacing, and to set your pricing tier from real audience size.
- Access tokens are encrypted at rest with AES-256-GCM.
- Revoke at any time at Google security settings, or by removing the channel in your dashboard. We delete the stored tokens when you do.
05Who we share it with
Only the processors that make the service work:
- Stripe — payment processing.
- Resend — transactional email.
- Vercel and our own servers — hosting.
- Google — only if you connect a YouTube channel.
We do not sell personal data. We may disclose data if legally compelled, and will tell you unless prohibited from doing so.
06How long we keep it
- Account and order records are kept while your account is open.
- Source files are kept for 90 days after delivery unless you ask us to hold or remove them sooner.
- Deliverables stay available in your dashboard for 12 months.
- Records we must keep for tax and accounting are retained as long as Georgia and federal law require.
07Your rights
Georgia has no comprehensive consumer privacy statute of the kind California and the EU have. We are telling you that plainly rather than implying rights you do not have. We extend the same core rights to everyone anyway: you can ask us to access, correct, export or delete your data, and to stop using it for training.
If you are in the EEA or UK you have rights under GDPR; if you are in California you have rights under CCPA/CPRA, including the right not to be discriminated against for exercising them. Wherever you are, email support@keyvelo.com and we will respond within 30 days.
Georgia residents also have protections under the Georgia Fair Business Practices Act (O.C.G.A. § 10-1-390 et seq.), and may contact the Georgia Attorney General's Consumer Protection Division.
08Security and breach notification
- Passwords hashed with bcrypt; we cannot read them.
- Third-party OAuth tokens encrypted at rest.
- Emailed links stored only as SHA-256 hashes.
- All traffic served over TLS.
- Changing your password signs out every other session immediately.
No system is perfectly secure, and we will not pretend otherwise.
09Children
Accounts require you to be 18 or older, the age of majority in Georgia. We do not knowingly collect personal information from anyone under 13, consistent with COPPA. If you believe a child has given us data, email us and we will delete it.
10Governing law and changes
This policy is governed by the laws of the State of Georgia. Disputes are handled as set out in our Terms of Service.
If we change this policy materially — particularly anything in section 02 — we will email account holders before it takes effect.