Be-Roll: Privacy Policy

Last updated: August 16, 2026

This Privacy Notice for Be-Roll describes how and why we might access, collect, store, use, and/or share your personal information when you use our services, including when you visit our website at https://www.be-roll.io, use Be-Roll, or engage with us in other related ways.

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies, please do not use our Services. Contact us at isaac@be-roll.io.

1. What information do we collect?

We collect personal information that you voluntarily provide to us, including:

  • Email addresses
  • Usernames
  • Creator metrics data (sensitive, processed with consent)

Payment Data

All payment data is handled and stored by Stripe. Stripe Privacy Policy.

Google API

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2. How do we process your information?

We process your information to provide, improve, and administer our Services, communicate with you, ensure security and fraud prevention, and comply with law.

3. When and with whom do we share your information?

  • Business Transfers: mergers, acquisitions, asset sales.
  • AI Service Providers: Anthropic, Google Gemini, OpenAI.
  • Service Providers: Stripe, Vercel, Supabase.

4. Do we offer AI-based products?

Yes. Our AI Products use Anthropic, Google Gemini, and OpenAI for:

  • Video analysis
  • AI document generation
  • Content recommendations

5. Connected social accounts (TikTok, YouTube, Instagram)

Be-Roll lets you connect your social accounts (TikTok, YouTube, Instagram) through their official OAuth flows so we can analyse the performance of your own content. When you connect an account, we access, strictly with your consent and only for the scopes you approve, the following data:

  • Public profile: display name, avatar and account identifier (e.g. TikTok open_id).
  • Aggregate account stats: follower count and other public profile metrics.
  • Your videos' metrics and metadata: title, description, cover image, publication date, views, likes, comments and shares for the videos on your own connected account.

Why we collect it. This data is used solely to measure your content's performance and to generate AI-powered insights, recommendations and scripts for you. It is shown back to you inside Be-Roll.

We never post on your behalf. We do not publish, edit, delete or otherwise act on your social accounts, and we never share this data with other users.

5 bis. Google user data: YouTube API Services

This section applies specifically to data obtained through the YouTube API Services when you connect your YouTube account. Be-Roll uses the YouTube API Services; by connecting your account you also agree to the YouTube Terms of Service and to the Google Privacy Policy.

(a) What Google user data we access

We request the following OAuth scopes, and only these. Each one is requested because a specific feature needs it:

  • youtube.readonly, to list your channel and your videos, with their titles, descriptions, thumbnails and publication dates.
  • yt-analytics.readonly, to read the analytics of your own videos: views, watch time, average view duration and percentage, likes, comments, shares, impressions and click-through rate, the audience-retention curve, viewer demographics and traffic sources.

Both scopes are read-only. We request no write-capable scope at all: we never upload, modify or delete videos, and we never post, reply to, moderate or delete comments. We also do not request access to your revenue or monetisation data.

Public comments on your videos are read separately, through YouTube's public Data API using our own API key, not through your account and not with your credentials.

(b) How we use Google user data

Google user data is used for one purpose only: to show you the performance of your own content inside Be-Roll and to produce AI-generated analyses, recommendations, scripts and shooting plans for you, the account owner. For example, your view counts are used to identify which of your videos performed best so that a generated plan can build on it.

We do not use Google user data for advertising, we do not sell or rent it, we do not use it for credit or lending purposes, and we do not build profiles for any purpose other than serving you inside the product.

Google user data is used only to provide or improve user-facing features that are prominent in the Be-Roll user interface and visible to you, the owner of the connected account. It is never used for any purpose you cannot see in the product.

Be-Roll uses third-party AI providers (Anthropic, Google Gemini, OpenAI) to generate analyses, scripts and shooting plans. When you trigger one of these features, metrics from your own videos may be sent to the provider as part of the prompt, so that the result is grounded in your real performance. These providers act as our subprocessors: they process the data on our instructions, for that single request, and they do not retain it for their own purposes. Google user data is never used to train, retrain, fine-tune or otherwise develop any AI or machine-learning model, whether ours or a third party's, and it is never used for advertising or ad targeting.

(c) How we share or transfer Google user data

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We never sell Google user data, never share it with other Be-Roll users, and never use it for advertising or ad targeting. Google user data is disclosed only to the infrastructure and AI subprocessors strictly required to operate the features you use:

  • Supabase (hosting and database) and Vercel (application hosting), storage and serving.
  • Anthropic, Google (Gemini) and OpenAI, when a feature you trigger generates an analysis, a script or a shooting plan, the relevant metrics of your own videos (for example view counts and performance figures) may be included in the prompt so that the output is grounded in your real results. This processing happens on your request and for your account only.

Google user data is never used to train, retrain or fine-tune any AI model, ours or a third party's. Our AI providers process it as subprocessors under contract and do not retain it for their own purposes.

(d) How we protect Google user data

  • All traffic is encrypted in transit (HTTPS/TLS), and data at rest is encrypted by our hosting providers.
  • OAuth access and refresh tokens are stored server-side only. They are never exposed to the browser, never included in analytics or logs, and never shared with third parties.
  • Access is scoped per user: our database enforces row-level security so that one account cannot read another account's connected-platform data.

Human access to Google user data is restricted. No member of the Be-Roll team reads your Google user data, except in the limited cases allowed by the Google API Services User Data Policy:

  • when we have first obtained your affirmative agreement to view specific data, for example when you ask us for support on a specific problem;
  • when it is necessary for security purposes, for example investigating a bug or abuse;
  • when it is necessary to comply with applicable law; or
  • when the data, including any derivation of it, is aggregated and used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements.

Outside these cases, Google user data is processed only by automated systems.

(e) How long we keep Google user data, and how to delete it

  • While your account is connected: we keep the imported metrics so that you can see the evolution of your performance over time. Metrics are refreshed by re-syncing your account; each re-sync replaces the previous snapshot rather than adding to an unbounded history.
  • When you disconnect your YouTube account: open Analytics, select your connected YouTube account, then click « Déconnecter » (Disconnect) and confirm: the stored OAuth tokens and the imported YouTube data associated with that connection are deleted immediately from our database, and we also ask Google to revoke the token on their side. You can revoke Be-Roll's access yourself at any time from your Google account permissions page.
  • When you delete your Be-Roll account: your personal data, including all Google user data, is deleted from our production database. Encrypted backups may retain it for up to 30 days before rotating out.
  • On request: email isaac@be-roll.io and we will delete your Google user data within 30 days.

Disconnect and delete. You can disconnect any account at any time from the Analytics section of the app. When you disconnect, the associated tokens and imported metrics are deleted. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. How long do we keep your information?

We keep personal information only as long as necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required by law.

7. How do we keep your information safe?

We have implemented appropriate technical and organizational security measures. However, no electronic transmission is 100% secure.

8. Do we collect information from minors?

We do not knowingly collect data from children under 18. Contact us at isaac@be-roll.io if you become aware of any such data.

9. What are your privacy rights?

You may have rights regarding your personal information, including access, correction, deletion, and consent withdrawal. Email us at isaac@be-roll.io.

10. Updates to this notice

We will update this notice as necessary. Changes are indicated by an updated "Last updated" date.

11. Contact us

Be-Roll
60 Rue François 1er
Paris, Île-de-France 75008
France
Email: isaac@be-roll.io