Back

Privacy Policy for Summd

Effective Date: March 26, 2026

Welcome to Summd! Your privacy is important to us. This Privacy Policy outlines how we collect, use, store, handle, and protect your information when you use our website (summd.io) and Chrome extension.

1. Information We Collect

Personal Data:
  • Name and email address (collected during account registration)
  • Payment information (collected during subscription checkout, processed by Stripe)

Usage Data:
  • YouTube video URLs and transcript data for videos you choose to summarize
  • Chat messages you send when interacting with video summaries
  • Product usage analytics (pages visited, features used)

Automatically Collected Data:
  • The Chrome extension transmits the URL of the YouTube video you are watching to our servers in order to fetch the video transcript
  • Web cookies to maintain your session and enhance your experience
  • Browser type and version
  • Server logs (IP address, request timestamps, request URLs)

2. How We Use Your Data

We use your data for the following purposes:
  • To provide our core service: summarizing YouTube videos and enabling chat-based interaction with video content
  • To process payments and manage your subscription
  • To authenticate your account and maintain your session
  • To improve our product through anonymous usage analytics

3. How We Handle Your Data

When you use Summd to summarize or chat with a YouTube video:
  • The video transcript is fetched and sent to Google Gemini to generate summaries and respond to your chat messages
  • Your chat messages are sent to Google Gemini along with the video transcript as context
  • Google Gemini processes this data according to its own privacy policy

4. Data Storage and Retention

  • Account data (name, email) is stored in our authentication database
  • Chat history and video summaries are stored in our PostgreSQL database hosted on Railway.com
  • Temporary session data may be cached in Redis
  • Chat history is automatically deleted after 1 month
  • We retain your account data (name, email) for as long as your account is active
  • Upon account deactivation (available upon request), all your data — including account information, chat history, and video summaries — is permanently deleted from our systems

5. Data Sharing and Third-Party Services

We use the following third-party services to operate Summd:
  • Stripe — payment processing (handles your payment information directly; we do not store card details)
  • Google Gemini — AI provider that processes video transcripts and chat messages to generate summaries and responses
  • PostHog — anonymous product usage analytics
  • PocketBase — user authentication and account management

We do not sell your personal data to any third parties. Data is shared with the above services only as necessary to provide our product. We may also disclose your data if required by law, to comply with legal process, or to protect the rights, safety, or property of our users or the public. In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, and we will notify you via email if your data becomes subject to a different privacy policy.

Your authentication credentials, payment information, and financial data are never publicly disclosed or made accessible to other users.

6. Data Security

We implement appropriate technical measures to protect your data, including:
  • Encryption at rest for all data stored in our database
  • Encrypted connections (HTTPS/TLS) for all data in transit
  • Secure authentication tokens for session management
  • Access controls to limit data access to authorized services only

No Summd employees or contractors access your personal data unless required for: providing customer support you have requested, investigating a security incident, or complying with legal obligations. Any such access is logged and limited to the minimum data necessary.

7. Your Rights

You have the right to:
  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your data

To exercise any of these rights, please contact us at the email below.

8. Children’s Privacy

Our services are not intended for children under the age of 13, and we do not knowingly collect any data from children. If we become aware that we have collected data from a child, we will delete it promptly.

9. Updates to This Privacy Policy

We may update this Privacy Policy from time to time. If material changes are made, we will notify you via email. The "Effective Date" at the top of this page indicates when the policy was last updated.

10. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:
Email: corp.tiny@gmail.com

Thank you for trusting Summd!