Privacy Policy
1. Information We Collect
Plain English
We collect your account info (name, email), the files you upload, and basic usage data. We never sell your data.
We collect information you provide directly, including:
- Account information: name, email address, password (hashed)
- Workspace and team membership data
- Files you upload for watermarking and protection
- Distribution records and recipient information you provide
- API keys and webhook configurations
We also collect certain information automatically, including IP address, browser type, device information, and usage patterns through server logs.
2. How We Use Your Information
Plain English
We use your data to provide the service — watermarking, distribution tracking, leak detection — and to improve the platform.
- Provide, maintain, and improve our watermarking and content protection services
- Process and embed watermarks in your uploaded files
- Track distribution and detect potential content leaks
- Generate verification reports and evidence documentation
- Send service-related notifications and updates
- Monitor and analyze usage patterns to improve performance
- Prevent fraud, abuse, and security threats
3. Data Storage & Security
Plain English
Your files are encrypted at rest (AES-256) and in transit (TLS 1.3). We use isolated infrastructure per workspace.
We implement industry-standard security measures to protect your data:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Isolated compute and storage per workspace
- Regular security audits and penetration testing
- Access controls and audit logging for all operations
5. Your Rights
Plain English
You can access, export, correct, or delete your data at any time from your account settings or by contacting us.
- Access and download a copy of your personal data
- Correct inaccurate or incomplete personal data
- Delete your account and associated data
- Export your data in a portable, machine-readable format
- Opt out of non-essential communications
- Restrict or object to certain data processing activities
7. Data Retention
Plain English
We keep your data as long as your account is active. When you delete your account, we remove all your data within 30 days.
We retain your personal data for as long as your account is active or as needed to provide services. Upon account deletion, we will delete or anonymize your data within 30 days, except where we are required to retain it for legal, accounting, or compliance purposes.
8. International Data Transfers
Plain English
If your data crosses borders, we use standard contractual clauses and equivalent safeguards.
If we transfer your data outside your country of residence, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission and equivalent measures for other jurisdictions.
9. Children's Privacy
Venom is not directed to children under 16. We do not knowingly collect personal information from children. If we discover that a child has provided us with personal data, we will delete it promptly.
10. California Privacy Rights (CCPA)
Plain English
California residents have the right to know, delete, and opt out. We do not sell personal information.
If you are a California resident, you have the right to: (1) know what personal information we collect and how it is used; (2) request deletion of your personal information; (3) opt out of the sale of personal information (we do not sell personal information); and (4) not be discriminated against for exercising your rights.
11. European Privacy Rights (GDPR)
Plain English
EU residents have full GDPR rights — access, portability, erasure, rectification, and the right to lodge a complaint with your supervisory authority.
If you are in the European Economic Area, you have additional rights under GDPR, including the right to data portability, the right to restrict processing, the right to object to processing, and the right to lodge a complaint with your local data protection authority. Our legal basis for processing is contract performance (providing the service) and legitimate interest (improving and securing the platform).
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through an in-app notification at least 30 days before the changes take effect. Your continued use of the service after changes constitutes acceptance.
13. Contact Us
For privacy-related inquiries, data requests, or concerns, contact us at privacy@venom.dev. We will respond to all legitimate requests within 30 days.
Protect your content with confidence
Start Protecting Now