1. Who we are and scope
Vora is an AI-assisted video creation and distribution service and a product of Qadim Labs. In this policy, "Vora," "we," "us," and "our" refer to the operator identified above. This policy covers the Vora website, web application, browser recording studio, processing workers, APIs, support channels, billing features, product analytics, email communications, and connected publishing services.
This policy applies when you visit Vora, create or join a workspace, record or upload media, use AI-assisted tools, connect a third-party account, publish content, subscribe to a paid plan, contact support, or otherwise use the service. It does not govern a social network, identity provider, payment processor, AI provider, cloud host, or other third-party service after data is sent to that service under your instruction or the provider's own relationship with you.
If a separate written agreement, data processing agreement (DPA), order form, or workspace notice applies, that document may provide additional privacy terms. Where it expressly conflicts with this policy on a point the parties are free to agree, the signed document controls for that point. Nothing in a commercial agreement reduces rights that cannot lawfully be waived.
This policy is incorporated into the Terms of Service. Capitalised terms used but not defined here have the meaning given in the Terms of Service where the context permits.
2. Our privacy roles
Vora normally decides how account, billing, security, support, product-usage, and service-operation data is handled and acts as the controller (or "business" under certain US state laws) for that data.
For media, transcripts, prompts, publication copy, and other personal data placed in a workspace by or for an organisation (including footage of third parties), that organisation is typically the controller or business, and Vora processes the data as a processor or service provider only on documented instructions — including the instructions given through the product when an authorised user uploads, processes, edits, schedules, publishes, exports, or deletes content.
Workspace owners and administrators decide who can join, which integrations are connected, what is published, retention preferences, and when a workspace is deleted. If your account is managed by an organisation, direct content-related requests to that organisation first. We will assist it where applicable law or a written agreement requires.
Where roles are mixed for a single flow (for example, account login plus workspace media processing), each party remains responsible only for the processing it determines. Vora is not responsible for an organisation's failure to provide notices, obtain consents, or honour data-subject rights for content it controls.
3. Data we process
Account and workspace data
- Name, email address, authentication identifiers, password hashes or identity-provider references, profile settings, timezone, language or locale preferences, workspace name, membership, role, invites, and onboarding choices.
- Workspace preferences, brand settings, plan, feature entitlements, usage allowances, seat assignments, and administrative activity.
Content and AI workflow data
- Recordings, uploaded audio and video, thumbnails, keyframes, extracted audio, intermediate processing files, and other media you choose to submit.
- Transcripts, speaker labels, sampled visual context, topics, prompts, custom briefs, clip candidates, captions, edits, renders, titles, descriptions, hashtags, and publication copy.
- Inferences and generated results such as subject or topic labels, suggested highlights, quality or relevance scores, and processing status or error metadata.
Connections, publications, and billing
- Connected social account names, profile or channel identifiers, granted permissions/scopes, encrypted access and refresh credentials, publication settings, schedules, attempts, provider responses, and status.
- Subscription plan, Stripe customer and subscription identifiers, checkout or invoice status, billing country or address details supplied for tax, and limited payment metadata supplied by Stripe. Vora does not receive or store your complete card number or card security code.
Technical, security, support, and analytics data
- IP address, browser and device information, approximate location derived from IP where needed for security or localisation, request timestamps, session and authentication state, upload and job identifiers, diagnostic events, error details, rate-limit records, audit events, and security signals.
- Support messages, bug reports, screenshots or attachments you submit, and records of how the issue was resolved.
- For product statistics and privacy-masked session replay: coarse device and page information, explicit product events, and the masked replay associated with a temporary anonymous identifier on the public website or your stable internal Vora user identifier after sign-in. Vora does not send your email, name, or profile details to PostHog. Analytics is designed to exclude private media, transcript bodies, file names, email addresses, social handles, and signed media URLs.
Content may incidentally contain personal or sensitive information about you or others. Vora is not designed to identify people from biometric characteristics for recognition, authentication, or surveillance, and is not designed to infer sensitive traits for advertising or profiling. You should not submit sensitive data unless it is necessary, lawful, and appropriate for your use of the service, and you have every required notice and legal basis.
4. Where data comes from
- You and your workspace: when you register, change settings, upload, record, edit, connect, publish, pay, invite members, or contact us.
- Your browser and device: through necessary session technology, local recovery storage, technical logs, and permissions you actively grant (camera, microphone, screen, or system audio).
- Connected providers: when an identity provider, social platform, Stripe, email provider, or another integration returns account, authorization, billing, or publication information.
- Vora's processing: when the service derives transcripts, clips, usage totals, security signals, quality metrics, and other workflow results from the data above.
- Other people: when a workspace member uploads media that depicts or refers to you, or when someone provides your email to invite you.
5. How and why we use data
- Provide accounts, workspaces, recording, uploads, storage, transcription, analysis, editing, rendering, downloads, scheduling, publishing, billing, and support.
- Authenticate users, maintain workspace permissions, protect connected accounts, prevent fraud and abuse, enforce limits, detect malware or prohibited content where reasonably necessary, and investigate security incidents.
- Recover interrupted uploads or recordings, monitor job health, diagnose faults, measure reliability, and improve product usability and safety without training general-purpose public AI models on your media.
- Send essential account, security, billing, processing, and service messages. Optional product or marketing notifications are sent only where permitted and can be controlled in the product or by unsubscribing where that control is available.
- Comply with law, respond to valid legal process, resolve disputes, enforce agreements, keep accounting and tax records, and protect users, third parties, and Vora.
- Carry out a reorganisation, financing, sale, or transfer of the service or related assets, subject to confidentiality and notice where required.
We do not use personal data for cross-context behavioural advertising, do not sell personal data, and do not build advertising profiles from workspace media.
6. Lawful bases (where required)
Depending on the context and applicable law (including the UK GDPR / EU GDPR where they apply), we rely on one or more of the following:
- Contract: processing needed to provide the service you request, create and administer your account, process payments, and perform our agreement with you.
- Legitimate interests: operating, securing, troubleshooting, and improving Vora; preventing fraud and abuse; producing aggregate product statistics and diagnosing masked, anonymous product journeys where permitted; enforcing terms; and defending legal claims — balanced against your rights and expectations.
- Consent: browser media permissions, product analytics and privacy-masked session replay where consent is required, optional marketing where consent is required, and third-party account connections. You may withdraw consent without affecting earlier lawful processing; withdrawal may prevent the related feature from working.
- Legal obligation: tax, accounting, sanctions screening where applicable, responding to lawful requests, and retaining records required by law.
- Vital interests / public interest: only in rare cases where necessary to protect a person or comply with a narrow public-interest duty recognised by law.
Where an organisation is the controller of workspace content, that organisation is responsible for establishing its own lawful basis for instructing Vora to process the content.
7. Our data commitments
We design Vora around the following limits. These statements do not prevent a disclosure required by law, a narrowly necessary action to secure the service, or processing you expressly request through the product.
- We do not sell personal data or workspace media.
- We do not share personal data for cross-context behavioural advertising or give workspace media to advertisers, data brokers, or ad networks.
- We do not use recordings, transcripts, or clips to train Vora or third-party general-purpose public AI models.
- We do not publish to a social destination unless an authorised user selects and confirms that destination.
- We do not access a camera, microphone, or screen unless the user initiates capture and grants browser permission.
- We do not intentionally expose private workspace media through public links; media access uses private storage and time-limited authorization.
- We do not claim ownership of your source media or of outputs generated specifically for you from that media.
- We do not use sensitive personal data to infer characteristics for advertising.
Workspace content is used to provide, secure, troubleshoot, and support the workflow you request, subject to the limited exceptions explained in this policy and the Terms of Service.
8. AI and media processing
When you request AI-assisted processing, Vora may extract audio, transcribe speech, sample a limited set of video frames, combine that evidence with your instructions, and generate topics, suggested clips, captions, titles, descriptions, or other publication copy. Vora currently uses OpenAI for configured transcription and analysis tasks and uses media-processing infrastructure (including FFmpeg-based workers) to inspect, transform, and render files.
We send providers the task data reasonably needed for the selected operation. We use business or API services intended not to train general-purpose models on customer content under the provider's applicable business terms. Providers may retain limited data for abuse monitoring, safety, or legal compliance under those terms. Vora personnel do not routinely review workspace media; access is limited to authorised support, security, trust-and-safety, or operational purposes when necessary and permitted.
AI results can be inaccurate, incomplete, biased, or unsuitable, and may reproduce information contained in your source. You control whether to use, edit, download, or publish them. If visual-context processing is available, you can control it in workspace settings. Sending content to an AI provider is an instruction you give through the product when you start or continue the relevant job.
Vora does not guarantee that AI processing will detect every instance of prohibited, infringing, private, or sensitive content. You remain responsible for what you submit and publish.
9. Browser recording and device storage
Screen, camera, microphone, and system-audio access is requested only after you choose a source and respond to your browser's permission prompt. Your browser and operating system show what is being shared and let you stop access. Vora cannot bypass those controls and is not responsible for a device, browser, extension, or operating-system failure that continues sharing after you intended to stop.
To make recording and uploads resilient, Vora may store recording manifests, media chunks, and upload-resume information in IndexedDB or other browser storage on your device. This data can remain until the recording is uploaded, discarded, cleared in Vora, removed by the browser, or erased with site data. Anyone with access to an unlocked device or browser profile may be able to interact with locally stored recovery data, so use a private device profile where appropriate.
Local recovery storage is provided for convenience. It is not a backup service. Clear it when finished on a shared device.
10. Cookies and similar technology
Vora uses necessary cookies and browser storage to keep you signed in, refresh authentication, protect requests (including CSRF and similar controls), remember interface choices, preserve demo or onboarding settings, resume uploads, and recover recordings. A sidebar preference cookie may remain for up to seven days. Authentication cookies normally remain for the duration set by the authentication service or until you sign out or clear them.
Vora uses PostHog's EU service through a Vora endpoint to collect limited product statistics and privacy-masked session replay. On the public marketing website, both start automatically by default where permitted and can be changed through the Analytics choices control. Inside an authenticated workspace, capture begins only after the workspace settings load and can be changed in Privacy & data settings. Public visitors use a temporary memory-scoped identifier. After sign-in, Vora identifies allowed analytics with your stable internal Vora user ID so events and recordings can be investigated across sessions. Vora does not send your email, name, or profile details to PostHog. Event autocapture, surveys, advertising profiling, and automatic page-view collection are disabled. Your objection choices are retained so Vora can continue to respect them.
Session replay is anonymous and masked before data leaves the browser: inputs and page text are masked, identity areas are omitted, and sensitive URL information is stripped. Turning off product analytics stops both new events and replay. Turning off replay alone preserves anonymous statistical events while stopping future recordings.
Vora does not use third-party advertising cookies or sell or share data for targeted advertising. Because those activities do not occur, browser Global Privacy Control or "Do Not Track" signals do not change an advertising sale or sharing practice. You can still use Vora's analytics controls or contact us to object to product analytics.
You can also control cookies through your browser settings. Blocking necessary cookies may prevent sign-in, uploads, or other core features from working.
11. Connected platforms
Vora account authentication uses your email address and password and is separate from connecting a YouTube channel. If you connect YouTube, Vora uses the permissions you grant to work with the channel you select, publish only content you approve, and keep its publishing status up to date. Nothing is published without confirmation, and you can disconnect or revoke access at any time.
When you connect YouTube, TikTok, Instagram, Facebook, LinkedIn, X, or another supported destination, the provider tells Vora which account was authorised and which permissions were granted. Vora stores provider access credentials in encrypted form and uses them to perform actions you request, refresh authorization, and retrieve publication status.
What each platform grants Vora — and what it doesn't
Vora requests exactly the permissions below for each destination, never more, and cannot act outside them. If a platform's own permission dialog shows something different from what is listed here, that dialog controls — you always see and approve the exact grant before Vora receives it.
YouTube
See the connected channel's basic identity and upload videos with the title, description, and visibility you approve.
Read comments, manage other videos or playlists, or access anything else in your Google account.
TikTok
See the connected account's basic profile (name, username, avatar) and publish clips you approve.
Read your existing videos, comments, followers, or direct messages, or take any action you did not request.
Identify the linked Instagram professional account and publish content you approve to it.
Read direct messages, followers, or comments on posts, or manage ad accounts.
List the Pages you manage and publish approved posts or videos to a Page you select.
Change Page settings, access Groups, or read private messages.
Identify your LinkedIn profile and publish approved posts as you.
Read your connections, messages, or company Page data.
X
Read your basic profile and publish approved posts.
Read direct messages, manage lists, or access analytics beyond what publishing requires.
Content and publication metadata are sent only to destinations an authorised workspace user approves. Once sent, the destination's own terms, privacy policy, audience settings, retention, moderation, monetisation rules, and deletion controls apply. Disconnecting an account prevents new Vora actions but does not remove content already published or copies retained by the destination. Delete those copies through the destination as well.
Vora is not responsible for a destination's independent use, disclosure, ranking, demonetisation, suspension, or retention of content you instructed us to send.
13. Retention and deletion
We keep data only for as long as reasonably needed for the purposes above, subject to workspace choices, plan limits, technical recovery periods, and legal obligations. Current operational periods include:
- Source media:plan storage windows currently range from 7 days on Free to 30 days on Creator, 90 days on Pro, and 365 days on Studio. The applicable plan window is a maximum even if "keep original" is enabled.
- Keep-original setting: if disabled, original source media is normally scheduled for removal 30 days after processing, or earlier if the plan limit is shorter. Derived clips, transcripts, and project records may remain until separately deleted.
- Trashed sources: a source is normally recoverable for 30 days before permanent purge.
- Workspace deletion:an owner's request has a 7-day cancellation period, after which private objects and workspace records are purged. Account identity may remain if the person belongs to another workspace.
- Temporary records: OAuth state and upload or request-deduplication records are generally short lived; provider webhook events are normally retained for around 30 days for security and reliability.
- Local recovery: browser recording data remains until uploaded, discarded, cleared, or removed with browser site data.
- Billing, security, and legal: invoices, tax records, abuse investigations, and dispute files may be retained for longer periods required by law or needed to establish, exercise, or defend legal claims.
Some data may remain longer in restricted backups, security logs, audit records, billing records, or legal holds where necessary for fraud prevention, dispute resolution, tax, accounting, security, or law. When deletion from active systems is complete, residual copies age out under backup cycles. Data sent to a connected destination is governed by that destination and must be deleted there separately.
Vora is not an archival or disaster-recovery service. Download or separately back up anything you need to keep before retention windows expire.
14. Security
Vora uses safeguards appropriate to the nature of the service, including workspace-scoped database authorization, private object storage, short-lived signed media links, encrypted social-provider credentials, transport encryption (TLS), rate limits, request-origin checks, webhook verification, audit events, least-privilege service access, and isolated processing jobs.
No online service can guarantee absolute security. You are responsible for using a strong unique password or secure identity provider, protecting your device, reviewing workspace membership and connected accounts, enabling available security features, and promptly reporting suspected compromise to the contact below. If a personal-data breach requires notice, we will notify affected people and authorities as required by applicable law.
Suspected security issues should be reported promptly to the contact below. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and remediate.
15. Your controls and privacy rights
Product controls
- Correct profile and workspace information and manage membership and permissions.
- Opt out of product analytics or privacy-masked session replay, and control visual-context processing, notifications, and original-media retention where those settings are available.
- Disconnect social accounts, delete or trash sources, download available media, and export workspace metadata, transcripts, clips, publication history, and audit events. The structured workspace export does not include encrypted credentials, temporary security records, or every binary media object.
- Request workspace deletion. Only an authorised owner can delete a shared workspace because deletion affects every member.
Legal rights
Depending on where you live and whether an exemption applies, you may have rights to know or access personal data, obtain a portable copy, correct inaccurate data, delete data, restrict or object to processing, withdraw consent, and appeal a refused request. You may also complain to your local privacy or data-protection authority (for example, the UK Information Commissioner's Office).
Send a request to the contact below and describe the account, workspace, data, and right involved. We may verify identity and authority, ask an authorised agent for proof, retain a limited record of the request, and deny or limit a request where law permits—for example, to protect another person, preserve security, comply with a legal obligation, or because the organisation that controls the workspace must handle the request. We will respond within the period required by applicable law and explain any available appeal.
We will not discriminate against you for exercising a privacy right that the law protects. Some features may unavoidably require certain data to function; if you ask us to delete that data, those features may stop working.
16. US state privacy notices
Residents of California and certain other US states may have rights to confirm processing, know categories of personal information collected, access a copy, correct inaccurate information, delete personal information, obtain a portable copy, opt out of sale, targeted advertising, or qualifying profiling, limit use of sensitive personal information in certain cases, and not receive discriminatory treatment for exercising a right.
Vora does not sell personal information and does not share it for cross-context behavioural advertising as those terms are commonly defined under US state privacy laws. We do not use sensitive personal information to infer characteristics for advertising. Product analytics and privacy-masked replay are used for product improvement and security, not advertising sale or sharing.
Categories of personal information we may collect are described in section 3. Sources, purposes, and disclosures are described in sections 4–5 and 11–12. Retention practices are described in section 13. To exercise a right, contact us as described in section 22. If we deny a request, you may appeal by replying to our response and stating that you are appealing.
17. International data transfers
Vora and its providers may process data in the United Kingdom, European Economic Area, United States, and other countries. Those countries may have different privacy laws. Where applicable law restricts a transfer, we use a recognised legal mechanism and supplementary safeguards as appropriate, which may include adequacy decisions, contractual protections, or standard contractual clauses. You may contact us for more information about safeguards relevant to your data.
By using Vora, you understand that your data may be transferred to and processed in countries other than your own as needed to operate the service you request.
18. Children
Vora is not directed to children under 16, and we do not knowingly collect their personal data. A user who is 16 or 17, or otherwise below the age of legal majority where they live, must have a parent or legal guardian review these terms and consent where local law requires. Workspace owners must not invite an ineligible child or upload a child's data without every consent and legal basis required for that recording and use.
If you believe a child under 16 has provided personal data, contact us so we can investigate and delete it where appropriate. We may suspend accounts used to submit child sexual abuse material or other unlawful content involving minors and report to authorities as required.
19. Sensitive and prohibited data
Unless a written agreement expressly permits it and you have every required legal basis, do not upload or instruct Vora to process:
- Special-category or sensitive personal data (such as health, biometrics used for unique identification, precise geolocation tracking payloads, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, or sex-life data) except where incidental and unavoidable in ordinary content you are lawfully entitled to process.
- Government-issued identity numbers, payment-card full PAN/CVC data, passwords, or authentication secrets belonging to others.
- Content you are not legally entitled to record, store, or publish — including confidential employer or client material without authorisation, and recordings made without required notices or consents.
If you submit such data anyway, you do so at your own risk and remain solely responsible. Vora may delete or restrict processing of data that creates legal or security risk.
20. Your responsibilities
You are responsible for the lawfulness of content you (or people using your workspace) submit. That includes providing required notices to people appearing in recordings, obtaining required consents, honouring workplace and venue policies, respecting data-protection and publicity rights, and not instructing Vora to process data for an unlawful purpose.
If you use Vora for an organisation, you must ensure that only authorised people have access, that roles are assigned correctly, and that your organisation's privacy notices cover Vora as a processor or service provider where required.
Browser permission prompts are not another person's consent. Publishing to a social network does not transfer responsibility for the content to Vora.
21. Automated processing
Vora uses automated systems to transcribe, score, suggest clips, generate captions or titles, detect abuse signals, enforce rate limits, and route jobs. These systems help deliver the product you request. They do not, on their own, make legal or similarly significant decisions about you without human involvement of a kind that would typically trigger additional automated-decision rights — except for ordinary access-control, fraud, billing, and security decisions needed to operate the service.
You should review AI suggestions before relying on or publishing them. If applicable law gives you a right to contest a solely automated decision with legal or similarly significant effects, contact us.
22. Changes and contact
We may update this policy when the service, providers, or law changes. The date above shows when the current version takes effect. If a change materially affects how we use existing personal data, we will provide additional notice or request consent where law requires. Continued use after the effective date constitutes acceptance of the updated policy to the extent permitted by law.
Questions, complaints, privacy requests, and security reports can be sent to the contact shown below. Please do not email passwords, payment-card details, social access tokens, or private media unless an authorised support process specifically asks for it.
This policy is intended to be clear and protective for both users and Vora. It is not legal advice to you. If your use involves regulated data or high legal risk, obtain your own professional advice before uploading or publishing.