Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains how splento.ai collects, uses, and protects information about you when you use our service. It covers the UK GDPR and the EU GDPR, and it describes what we actually do — every processor and every retention period below is one the service really uses.
Who is responsible for your data
The data controller is the company operating splento.ai. For any question about this policy, or to exercise any of the rights described below, write to [email protected]. We answer within one month, as the GDPR requires.
Information we collect
When you create an account, we collect your email address, display name, and any profile information you choose to provide. If you sign in with Google, we receive your name, email, profile picture, and Google account identifier through the OAuth consent you grant.
We also collect usage information such as activity logs, device and browser metadata, and content you create on the platform, in order to operate and improve the service.
How we use information
We use this information to provide and improve splento.ai, authenticate you, communicate service updates, and comply with our legal obligations. We do not sell your personal data.
Cookies, analytics and advertising
We store a small amount of data in your browser to run the service: your sign-in session, your language and playback preferences, and your choice about analytics. These are necessary for the site to work and are not used for advertising.
With your consent we also use Google Analytics 4 to understand which videos and pages are useful, and Google Ads to measure whether an advertisement led to a sign-up or a subscription. Where consent is required, these are switched off until you accept, using Google Consent Mode: before you choose, Google receives no analytics or advertising identifiers from us. You can change your choice at any time — signed-in users in Account → Privacy, everyone else by clearing this site's data in the browser.
With your consent we use Microsoft Clarity to record how pages are used — pointer movement, scrolling, clicks and the resulting page views — so that we can find navigation that does not work. Recording is limited to public pages of the library and is switched off entirely for signed-in areas, and Microsoft acts as a processor on our behalf. Text you type is masked before it leaves your browser; we do not use these recordings for advertising.
When you give us your email address — in the form that unlocks a free download, or by creating an account — we also send it to Google in hashed form so that a subscription can be matched to the advertisement you clicked. Hashing happens in your browser and Google receives no readable address. We send the address you entered yourself and nothing else: no name, no postal address, no phone number. This applies only where you have accepted advertising cookies, and you can change that choice at any time.
With your consent we also use the Meta pixel and Meta's conversions interface to measure whether an advertisement on Instagram or Facebook led to a sign-up or a subscription. Until you accept, no pixel is loaded and Meta receives nothing from us.
If you arrive from an advertisement, the click identifier that the advertising platform appends to the link (gclid, gbraid or wbraid from Google, fbclid from Meta, ttclid from TikTok, msclkid from Microsoft) is stored for up to 90 days so that a later subscription can be attributed to that advertisement. It is a campaign identifier, not a profile of you, and it is deleted when you delete your account.
We also run our own first-party analytics on infrastructure we operate, and we do not sell your personal data or share it with data brokers.
Why we are allowed to do this
Under the UK/EU GDPR every use of your data needs a legal basis. Ours are:
- Performance of a contract — creating and running your account, delivering the videos you download, taking payment, and providing support. Without this data we cannot supply the service you asked for.
- Legal obligation — keeping invoices and payment records for tax and accounting.
- Consent — analytics, advertising measurement and session recording. Consent is asked for where it is required, it is never bundled with anything else, and you can withdraw it at any time without affecting the service.
- Legitimate interests — keeping the platform secure (rate limiting, abuse and fraud prevention), moderating the library, and understanding which content is useful so we can improve it. We only rely on this where our interest does not override your rights, and you can object at any time.
How long we keep it
- Account and profile — until you delete your account. Deletion starts a 30-day window: your profile and works are hidden immediately, and you can restore everything by signing in during that time. After 30 days your personal data is anonymised in active systems and cannot be recovered.
- A keyed hash of your email after deletion — six years. It is not your address and cannot be turned back into one; it only lets us match a later claim or dispute to the deleted account it concerns. The legal basis is the establishment and defence of legal claims (Article 17(3)(e) UK GDPR), and six years is the limitation period for contract claims. It is deleted automatically after that.
- Usage and analytics events — 90 days, after which they are deleted automatically. Aggregated counts that identify no one may be kept longer.
- Search terms — 30 days in raw form.
- Advertising click identifiers — up to 90 days, so a later subscription can be attributed to the advertisement you clicked.
- Support conversations and administrative logs — 12 months.
- Invoices and payment records — at least six years, as UK tax and accounting rules require. We keep the record of the purchase, not your card details.
- Backups — encrypted copies roll off on their own schedule; data deleted from live systems disappears from backups as they expire.
Who else processes your data
These companies process data on our instructions, under contract, and for no purpose of their own beyond what is stated here:
- Stripe — payments and subscriptions. Card details go to Stripe directly; we never see or store them.
- Hetzner — the servers this service runs on, located in Germany.
- Cloudflare — content delivery and protection against attacks; it sees requests to the site.
- Google — Google Analytics 4 and Google Ads measurement (with your consent), and the Gemini API, which helps describe and quality-check the video library.
- Meta — the Meta pixel and conversions interface, with your consent, to measure whether an advertisement led to a sign-up or a subscription.
- Microsoft — Clarity session recording on public pages, with your consent.
- Resend — the emails we send you (sign-in links, service notices).
Our database, file storage, analytics store and sign-in service run on our own infrastructure, so no additional company is involved in them.
Sending data outside the UK and EEA
Our servers are in Germany. Some of the providers above are based in the United States, so using them means your data can be transferred there. Those transfers rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and — where the provider is certified — the EU-US and UK-US Data Privacy Framework.
Your choices
You can update or delete your account at any time from the profile settings. Deleting it hides your profile and works at once and gives you 30 days to change your mind — sign in during that period and you can restore everything as it was. After that your personal data is anonymised in active systems, subject to retention required by law.
Your Splento account is separate: deleting your splento.ai profile does not remove it, and removing it is a step on your Splento account page.
Your rights
Under the UK/EU GDPR you have the right to:
- ask what personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- ask us to restrict how we use it, or object to uses based on legitimate interests;
- receive your data in a portable, machine-readable form;
- withdraw consent for analytics, advertising or session recording at any time — this does not affect anything done before you withdrew it;
- not be subject to a decision made solely by automated means with a legal effect. We make no such decisions.
Export and deletion are available in your profile settings; for anything else, write to [email protected]. Exercising these rights is free, and we will not treat you differently for it.
If you think we have handled your data badly, you can complain to a supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EEA it is the authority in the country where you live. We would rather you told us first, so we can put it right.
Security and children
Access to personal data is restricted to those who need it, traffic is encrypted in transit, and payment details never reach our systems. No service can promise perfect security, and we will tell you and the regulator about a breach when the law requires it.
splento.ai is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 18; if you believe we have, tell us and we will delete it.
Changes to this policy
We update this policy when what we do changes. The date at the top of the page is the version in force, and material changes are announced in the product before they take effect.
Contact us
Questions about this policy? Email [email protected].