Privacy Policy for Thumbflow
Last updated: June 6, 2025
1. Introduction
Thumbflow (“we,” “our,” or “the Company”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data when accessing or using Thumbflow’s services (the “Service”). By using Thumbflow, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Personal Information You Provide
- Account Registration: Name, email address, and any other details you submit when signing up.
- Uploaded Assets: Logos, images, design files, or video clips you upload for thumbnail generation.
- API Credentials: OAuth tokens or other authentication data needed to integrate your YouTube Creator Studio (we never store raw passwords).
2.2 Usage Data (Automatically Collected)
- Service Interactions: Which thumbnail variations you view, select, or A/B test.
- Trend & Competitor Analysis Queries: Data on your chosen video categories for trend reporting.
- Device and Log Information: Browser type, IP address, pages visited, timestamps, and error logs. We use this strictly for service monitoring and debugging (we do not use third-party tracking for advertising).
3. How We Use Your Information
- Thumbnail Generation: To generate, render, and deliver AI-powered thumbnail variations based on your prompts, assets, and video data.
- Trend & Competitor Analysis: To scrape and analyze trending thumbnails in your chosen niche and present insights.
- Service Improvement: To monitor system performance, fix bugs, and improve features, including refining our emotion-scoring algorithms and Trend Alerts.
- A/B Testing & Reporting: To deploy thumbnail variants to YouTube via your authenticated credentials, track CTR and watch-time metrics, and provide performance reports.
- Customer Support: To respond to inquiries, resolve issues, and keep you informed of service updates.
- Legal Compliance: To comply with applicable laws, regulations, or lawful requests from authorities.
4. Cookies and Tracking Technologies
- Essential Cookies: We use session cookies strictly to maintain your logged-in status, remember your asset library selections, and manage A/B testing sessions.
- No Third-Party Advertising Cookies: We do not employ third-party cookies for ad retargeting or user profiling.
- Analytics: We collect anonymized usage statistics (e.g., number of A/B tests run, popular emotion scores) to help us improve Service performance. Any analytics data is aggregated and does not identify individual users.
5. Data Sharing and Third-Party Services
- Service Providers: We may share your data with trusted vendors (e.g., cloud hosting, analytics, email delivery) solely to support Service operations. All such providers are bound by contractual obligations to keep your data secure and use it only for the tasks we authorize.
- YouTube API Integration: We transmit your OAuth token to YouTube’s API for A/B test deployment; we do not store your password.
- Legal Requests: We may disclose or preserve personal information if required to do so by law or in good faith belief that such action is necessary to comply with legal processes.
- Business Transfers: If Thumbflow is acquired, merges, or undergoes a reorganization, user data may be transferred as part of that transaction. We will notify you via email or prominent notice on our website before data is transferred.
6. Security Measures
- Encryption at Rest & In Transit: All user data, including uploaded assets and generated thumbnails, is encrypted at rest using AES-256. Data in transit is protected via TLS 1.2+.
- Credentials Storage: OAuth tokens and API credentials are stored in secure vaults; we never store unencrypted passwords.
- Access Controls: Access to production databases and servers is restricted to authorized personnel only, using multi-factor authentication and the principle of least privilege.
- Ongoing Audits: We perform regular security assessments and vulnerability scans to identify and remediate potential risks.
7. Your Data Rights
7.1 GDPR (for European Users)
- Access & Portability: You may request a copy of all personal data we hold about you, including your asset library, emotion-scoring logs, and trend-analysis reports, in a machine-readable format.
- Rectification: If any personal information is inaccurate or incomplete, you may request corrections.
- Erasure (“Right to be Forgotten”): You can request deletion of all assets, generated thumbnails, usage logs, and account information. We will process such requests within 30 days, unless otherwise restricted by law.
- Restriction & Objection: You have the right to restrict processing of your personal data or object to our processing in certain circumstances.
7.2 CCPA (for California Users)
- Right to Know: You may request disclosure of the categories of personal information collected, sources, purposes, and third parties with whom we share your data in the past 12 months.
- Right to Delete: You can request deletion of any personal data we have collected from you, subject to limited exceptions.
- Right to Opt-Out of Sale: We do not sell any personal information.
- Non-Discrimination: Exercising any of these rights will not result in discriminatory treatment by Thumbflow.
8. Children’s Privacy
Thumbflow is not directed to children under 16. We do not knowingly collect personal data from individuals under 16. If you believe we have inadvertently collected information from a child under 16, please contact us immediately so we can delete it.
9. International Users
If you are accessing Thumbflow from outside the Singapore, please note that your data will be transferred to and processed in servers located in the Singapore (UTC+08:00). By using the Service, you consent to this transfer and processing.
10. Data Retention
We retain personal information and usage logs for as long as your account is active or as needed to provide the Service. If you request account deletion, we will remove all personal information and generated thumbnails (and related logs) within 30 days, except as required to maintain transactional records for legitimate business or legal purposes.
11. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time. When significant changes occur, we will update the “Last updated” date and notify you via email or a prominent notice on Thumbflow’s website. Continued use of the Service after changes are posted constitutes acceptance of those changes.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:
Your privacy matters. Thumbflow pledges to keep your data secure, transparent, and fully within your control at all times.