Privacy Policy

Last updated: 25 July 2026

This Privacy Policy describes how Deepsoch AI (“we”, “us”, or “our”), the operator of transcode (the “Service”), handles personal data. We are based in Bengaluru, Karnataka, India. This Policy applies to the website, dashboard, support channels, payments, and API. It does not govern third-party services that process data under their own privacy notices.

1. Data we collect

  • Account and identity data: name, email address, email-verification state, role, profile information supplied by an identity provider, and a password hash when credentials sign-in is used. We do not store your plaintext password.
  • Authentication and security data: session identifiers, API-key identifiers and hashes, login and verification events, IP address, browser and device information, security events, and fraud or abuse signals. API-key secrets are shown once and are not stored in plaintext.
  • Usage and job data: selected tools or presets, options, job status, timestamps, progress, file names, file type, file size, media metadata, credits charged, storage usage, and error information.
  • Customer Content: uploaded media, saved outputs, generated frames, and technical derivatives required to perform processing. We do not use Customer Content to train machine-learning models.
  • Billing data: plan, credit balance, orders, payment status, amount, currency, payment identifiers, invoices, and related records. Razorpay handles payment credentials such as card or bank details; we do not receive or store complete payment-card details.
  • Communications: support requests, emails, feedback, complaint details, and information you choose to provide when contacting us.
  • Local preferences: essential cookie and browser-storage values used for sessions, security, theme, and acknowledgement of the cookie notice.

2. Sources of data

We receive data directly from you, automatically from your device and use of the Service, from Google when you choose Google sign-in, from Razorpay in connection with a payment, from our infrastructure and media-processing providers, and from security or support investigations. If you submit another person's data or media, you are responsible for having authority and providing any required notice.

3. How and why we use data

We process data as reasonably necessary and permitted by applicable law to:

  • create, authenticate, secure, administer, and support accounts and API keys;
  • upload files, plan and execute jobs, generate outputs, and provide saved storage;
  • measure usage, enforce plan and technical limits, calculate credits, and maintain job history;
  • process and reconcile payments, prevent duplicate allocation, record reversals and service-credit corrections, and keep financial records;
  • detect, investigate, prevent, and respond to fraud, abuse, unlawful content, attacks, and policy violations;
  • debug, maintain, analyse, and improve the reliability, safety, and usability of the Service using operational data;
  • communicate transactional, security, support, legal, and material service notices;
  • establish, exercise, or defend legal claims and comply with valid legal obligations.

We do not sell personal data and do not use Customer Content for advertising or model training. We may create aggregated or de-identified statistics that do not reasonably identify a person and use them for operations, capacity planning, reporting, and service improvement.

4. When we disclose data

We may disclose the minimum data reasonably necessary to:

  • Service providers: payment, authentication, hosting, object storage, database, email, network, monitoring, support, and media-processing providers acting for or with us;
  • Professional advisers: lawyers, accountants, auditors, insurers, and consultants subject to appropriate duties;
  • Legal and safety recipients: courts, regulators, law enforcement, rights holders, or affected parties where we reasonably believe disclosure is required or appropriate to comply with law, enforce terms, investigate abuse, or protect rights, safety, property, users, or systems;
  • Corporate transactions: actual or prospective investors, lenders, acquirers, successors, or counterparties in a financing, reorganisation, merger, acquisition, asset sale, insolvency, or transfer of the Service, subject to appropriate confidentiality where practicable;
  • Your direction: recipients you authorise, including when you share an output URL or use an integration.

Key providers currently include Razorpay for payments and Google for optional sign-in, together with our cloud, storage, database, email, and processing infrastructure. Providers may maintain independent obligations and privacy notices for services they control.

5. Media handling and retention

Inputs are uploaded to protected storage so the processing service can retrieve them. We intend to remove temporary input objects after a job reaches a terminal state, although retries, failures, backups, security preservation, or provider behaviour may extend deletion. Unsaved outputs are made available through temporary provider URLs and may expire. Outputs you explicitly save, or that eligible accounts configure for automatic saving, remain in platform storage until deleted, the applicable retention period ends, the account closes, or storage is otherwise cleared under our Terms.

We retain account, security, job, credit, and support records while reasonably needed to operate the Service, resolve disputes, prevent abuse, and comply with law. Payment, tax, audit, and legal records may be retained for statutory periods. Deletion from active systems may not immediately remove encrypted backups, logs, or records we must retain; those are isolated and removed or overwritten according to normal cycles.

6. International and cross-border processing

The Service and its providers may process or store data in India and other countries where infrastructure is operated. Those countries may have different data-protection laws. Where required, we use contractual, technical, or organisational measures and comply with applicable restrictions on cross-border transfers.

7. Security

We use reasonable technical and organisational safeguards designed for the nature of the Service, including encrypted transport, hashed credentials and API keys, access controls, scoped URLs, rate limits, and operational logging. No service can guarantee absolute security, availability, or deletion. You are responsible for secure devices, strong credentials, key rotation, access control, and independent copies of important files. If we identify a personal-data breach, we will take responsive steps and provide notices where and when applicable law requires.

8. Your choices, rights, and duties

Subject to applicable law and verification, you may request access to a summary of personal data, correction or completion of inaccurate data, erasure, withdrawal of consent where processing depends on consent, and grievance redressal. Withdrawing consent does not affect prior lawful processing and may prevent us from continuing the related Service. We may retain or decline to erase information where needed for legal obligations, security, fraud prevention, dispute resolution, establishment of claims, or another lawful purpose.

You must provide authentic information, must not impersonate another person, and must not submit a false or frivolous grievance or rights request. We may request information reasonably necessary to verify identity, authority, account ownership, and request scope before acting.

9. Children

The Service is not directed to anyone under 18 and accounts may be created only by adults. We do not knowingly seek personal data from children. If you believe a child has provided personal data, contact us with sufficient information to investigate. Users must not upload children's personal data or media unless they possess every legally required authority and consent.

10. Cookies and external links

We use essential cookies and browser storage as described in our Cookie Policy. Third-party sign-in, payment, and linked websites may set their own technologies and are governed by their own notices. We are not responsible for third-party privacy practices.

11. Policy changes

We may update this Policy to reflect operational, legal, security, or product changes. The updated version will show a revised date. For material changes, we may provide an additional notice through the Service or account email where appropriate or required. Unless otherwise stated, changes apply when posted.

12. Privacy and grievance contact

To submit a privacy request, report a concern, or seek grievance redressal, email contact@deepsoch.aiwith the subject “Privacy Request”. Include the account email and details needed to understand the request. We may verify your identity before responding. You may also pursue remedies available from the competent authority under applicable law.