Last updated · 3rd of August, 2026

Privacy Policy

This policy explains how Bhaasa collects, uses, shares, retains, and protects personal data across our newsroom production, subtitle, media, organization, developer, and hosted-video services (the "Service").

Table of Contents

#SectionDescription
1Scope and who we areWho this policy covers, our role, and how to contact us.
2Information we collectAccount, newsroom, media, organization, billing, developer, and usage data.
3How we collect informationInformation you provide, content you import, and information created through use of Bhaasa.
4How we use informationWhy we process data to provide, secure, support, and improve the Service.
5AI and media processingHow content is processed when you request transcription, translation, narration, or video generation.
6Legal basesThe legal grounds on which we process personal data.
7How information is sharedService providers, workspace members, integrations, public publishing, and legal disclosures.
8Organizations and workspacesHow organization administrators, workspace roles, invitations, and audit records affect privacy.
9Hosted players, APIs, and integrationsWhat happens when you publish, embed, connect, or automate content.
10Cookies and local storageEssential sessions and preferences used across Bhaasa domains.
11Retention and deletionHow long account, project, export, organization, and operational records may be kept.
12International processingHow data may be processed across borders with appropriate safeguards.
13SecurityMeasures used to protect accounts, workspaces, media, and developer access.
14Your privacy rightsAccess, correction, deletion, portability, restriction, objection, and complaint rights.
15Children’s privacyOur minimum age requirement.
16Changes and contactHow we update this policy and how to reach us.

1. Scope and who we are

This policy applies to Bhaasa websites and subdomains, personal and organization accounts, dashboards, News Studio, subtitle tools, media and player features, developer services, support, and related communications.

Bhaasa is responsible for personal data processed through the Service unless another party, such as your employer or organization, determines why and how that data is used. In those cases, that organization may be the controller and Bhaasa may process data on its instructions.

This policy covers visitors, account holders, organization administrators and staff, invited members, API users, people who contact us, and viewers who access a Bhaasa-hosted or embedded video. It does not replace the privacy notices of customers who use Bhaasa to publish their own content.

Bhaasa is offered to users and organizations internationally. Contact us at hello@bhaasa.io, through our support channel, or through www.bhaasa.io.

2. Information we collect

Account and profile information

We may collect your name, verified email address, profile image, account type, language and onboarding choices, authentication events, plan, usage allowance, and account status. We do not receive payment-card credentials entered directly with a payment provider.

Newsroom, subtitle, and media content

We process information you submit or create, including article text, public article links, headlines, scripts, uploaded video, audio, images, logos, fonts, thumbnails, transcripts, subtitles, translations, speaker information, voice and presenter selections, visual presets, overlays, timing and editing data, generated footage choices, and rendered outputs. Project history and editor state may be stored so work can be reviewed, continued, or exported.

Security and device information

To protect confidential newsroom work and maintain accountable audit records, Bhaasa may record sign-in and destructive-action timestamps, the server-observed IP address, browser and device information, a pseudonymous device identifier, and coarse city, region, or country information supplied by our network edge. We do not collect precise GPS location for this purpose.

Organizations and workspaces

For organization accounts, we may collect organization name and domain, workspace names, member and invitation details, roles, permissions, access requests, administrative decisions, plan or sales-request information, and audit events such as membership, workspace, publishing, and security changes.

Publishing and developer information

If you use hosted delivery, embeds, APIs, webhooks, or connectors, we may process player titles, branding, allowed domains, publication status, API-key identifiers and permissions, request and response metadata, usage, timestamps, status codes, latency, errors, webhook destinations and delivery results, integration settings, and scheduled publishing information. Secret values are handled as credentials and should not be included in support messages or public content.

Billing, sales, and support

We may collect plan and transaction records, amount, currency, payment status and reference, invoice details, organization size, role, phone number, requirements, support messages, and correspondence. Payment providers process the financial credentials needed to complete payment.

Device, service, and viewer information

We may collect IP address, approximate location derived from IP, browser and device information, timestamps, pages or features used, referring address, security events, error reports, and operational logs. When someone views hosted content, we may receive delivery requests and basic playback or security information needed to operate, protect, and troubleshoot the player.

3. How we collect information

  • Directly from you when you register, upload, edit, publish, purchase, invite staff, configure an integration, or contact us.
  • From your organization or workspace administrator when they create an account, invite you, assign permissions, or manage your access.
  • From content sources you direct us to import, such as a publicly available article page or a connected publishing service.
  • Automatically when the Service creates transcripts, translations, generated media, thumbnails, exports, usage records, logs, and audit events.
  • From payment, authentication, publishing, and other service providers when needed to confirm an event or provide a requested feature.

4. How we use information

  • Authenticate accounts and provide personal, organization, and workspace access.
  • Create, transcribe, translate, narrate, edit, render, store, export, host, embed, and deliver requested content.
  • Maintain project history, media libraries, templates, player settings, publishing destinations, and live export updates.
  • Operate developer features, verify API access, deliver webhooks, enforce quotas, and provide request logs and analytics.
  • Manage roles, invitations, permissions, organization onboarding, audit trails, and administrative controls.
  • Process purchases, manage plans, issue receipts, respond to sales requests, and provide customer support.
  • Protect the Service, investigate misuse, prevent fraud, troubleshoot errors, maintain reliability, and comply with law.
  • Develop and improve features using feedback, aggregated measurements, and content only where permitted by this policy or separately agreed.

We do not sell personal data. We do not use customer video, audio, articles, or private newsroom content to train general-purpose AI models unless we first obtain explicit permission or enter into a separate written agreement that clearly allows it.

5. AI and media processing

Bhaasa uses automated systems to perform tasks you request, which may include speech recognition, translation, language processing, narration, voice generation, presenter composition, visual selection, caption timing, and video rendering. We send only the information reasonably needed to perform the selected task to service providers acting on our behalf.

Automated output may be incomplete or inaccurate. Bhaasa provides review and editing controls, and users remain responsible for verifying facts, rights, pronunciation, translations, captions, synthetic presenters, and the suitability of any output before publication.

7. How information is shared

We disclose information only where reasonably necessary for the following purposes:

  • Service providers: companies that support authentication, media processing, AI functions, hosting, storage, delivery, payments, email, support, security, and operations under contractual restrictions.
  • Your organization: administrators and authorized workspace members may access content, membership details, usage, settings, publishing information, and audit events according to their role.
  • Your requested integrations: connected services, webhook destinations, publishing channels, or other recipients you instruct us to use.
  • The public: content and related player information you intentionally publish through a public link, hosted player, or embed.
  • Business and legal events: professional advisers, authorities, or a successor in a merger, financing, acquisition, reorganization, or sale, subject to appropriate safeguards.

We may also preserve or disclose information when we reasonably believe it is necessary to comply with law, protect rights or safety, investigate fraud or abuse, or enforce our Terms and Conditions.

8. Organizations and workspaces

If you join an organization, its authorized administrators control membership and may create or remove workspaces, assign roles and feature permissions, review organization or workspace audit records, manage shared projects, and remove access. Workspace administrators may have visibility into activity within the workspaces they manage.

Your organization may retain content and records under its own policies even after your individual access ends. Privacy requests concerning organization-controlled data may need to be directed to that organization; we will assist it as required by law and contract.

9. Hosted players, APIs, and integrations

Hosted and embedded players are designed for public or audience-facing delivery. Anyone with an active public link, or anyone visiting a site where it is embedded, may be able to view the published video and its configured title, poster, or branding. Domain restrictions can limit where an embed is used but should not be treated as a substitute for access control.

Updating a published export may change the media delivered through the same player URL. Disabling a player or deleting a project can stop future delivery, but copies already downloaded, cached, recorded, indexed, or shared by others may remain outside our control.

API keys and webhook secrets must be protected by the customer. Requests made with valid credentials are treated as authorized. Webhook payloads and content sent to an integration are subject to the recipient’s privacy practices after delivery.

10. Cookies and local storage

Bhaasa uses cookies and similar browser storage to maintain secure sessions across relevant subdomains, complete sign-in redirects, remember theme and workspace preferences, preserve selected dashboard or connector state, retain a pseudonymous device identifier for security attribution, and improve media loading. Signed-in browser sessions are configured for up to 24 hours. Essential storage may be required for the Service to function.

We do not use this storage to sell personal data or serve third-party behavioral advertising. Read our Cookie Preferences page for more detail and browser controls.

11. Retention and deletion

We retain information only for as long as reasonably needed to provide the Service, meet the storage terms of your plan or organization agreement, preserve security and audit records, resolve disputes, enforce agreements, and comply with legal, tax, and accounting obligations.

  • Free-plan projects are generally retained for 7 days after processing; Creator-plan projects for 90 days; Studio-plan projects while the subscription remains active; and Enterprise projects according to the applicable agreement or organization policy.
  • Temporary processing files and superseded exports may be removed sooner when they are no longer needed to complete or deliver a project.
  • Organization membership, permission, invitation, and audit records may be retained after a member leaves where needed for accountability and security.
  • Developer request and webhook-delivery logs are retained for operational, billing, troubleshooting, and abuse-prevention purposes.
  • Billing records may be retained for the period required by tax, accounting, and legal obligations.
  • Backups and cached copies may take a limited period to expire after deletion and are isolated from ordinary use.

Deleting a project or disabling a player removes it from normal account access and future delivery as applicable. Deletion cannot recall content already exported, publicly shared, received by an integration, or copied by another party. Before deleting content, download anything you need to retain.

12. International processing

Bhaasa and the providers supporting the Service may process information in countries other than your own. Where required, we use contractual, organizational, and other lawful safeguards for international transfers. Data-protection laws may differ between countries.

13. Security

We use reasonable administrative, organizational, and technical safeguards designed to protect information, including encrypted transport, access controls, tenant and workspace authorization, credential protection, activity records, and restricted internal access. Payment credentials are handled by payment providers rather than stored by Bhaasa.

No service is completely secure. Keep sign-in access, API keys, webhook secrets, invitation links, and publishing controls confidential. Contact hello@bhaasa.io immediately if you suspect unauthorized access or a security incident.

14. Your privacy rights

Subject to your location and applicable law, you may have rights to:

  • access and receive a copy of personal data;
  • correct inaccurate or incomplete information;
  • delete personal data or request account deletion;
  • restrict or object to certain processing;
  • withdraw consent where processing is based on consent;
  • receive portable data where required; and
  • complain to an appropriate data-protection authority.

Send requests to hello@bhaasa.io. We may verify your identity and authority before acting. If your account is managed by an organization, we may refer the request to that organization or require its authorization where it controls the relevant data.

15. Children’s privacy

Bhaasa is a professional service and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.

16. Changes and contact

We may update this policy as the Service, legal requirements, or our practices change. We will revise the date above and provide additional notice where a change is material and notice is required. Your continued use after an effective update is subject to the revised policy.

Questions or privacy requests may be sent to hello@bhaasa.io. You can also review our Terms and Conditions and Cookie Preferences.