Your work stays yours.
How ReelLab handles your data.
Your projects, timeline, media, microphone and camera content, and private conversations are not collected into a ReelLab content library or used by ReelLab to train models.
Most editing happens in your browser
Core audio and video editing, playback, composition, effects, face landmark detection, and face swapping run locally after the required app assets or models are available. Local face analysis does not send your camera frames or face images to ReelLab servers.
Limited usage telemetry
To understand whether ReelLab is being used and which tools are useful, telemetry records a random visitor and session ID, page path and referrer, language, screen and viewport size, session timing, signed-in state, and the name of buttons or features used.
Telemetry is for service and feature decisions. It is not intended to contain your media, messages, prompts, recovery phrase, payment credentials, or the contents of text fields.
Accounts and payments
If you sign in, ReelLab stores an account key, display name, avatar URL, sign-in provider, hashed email/provider identifiers, plan and entitlements, AI-credit balance, purchase history, and payment or blockchain transaction references needed to fulfil purchases and refunds.
Raw card details, Apple Pay or Google Pay credentials, PayPal passwords, OAuth access tokens, browser-wallet private keys, and mnemonic recovery phrases are not stored by ReelLab. Sessions use HttpOnly cookies; sensitive data files are blocked from public static access and administrative views require access control.
Relays, uploads, and AI tools
Room, podcast, camera, livestream, and project relays route data between participants and do not create a permanent ReelLab content archive. Data can exist briefly in server memory or temporary files while it is delivered, converted, or processed, then is discarded.
Cloud AI, speech, or voice tools send the content you deliberately submit and relevant project context to the configured VPS or selected provider. Autonomous agent tasks retain conversation and progress records on the VPS so tasks can resume; provider API keys are excluded from those records. Other generation and speech requests are processed transiently by the relay. The external provider processes submitted content under that provider's own privacy and retention terms.
Personal AI keys and saved projects
When you choose personal API keys, the ReelLab relay receives the selected OpenAI or xAI/Grok key over HTTPS with your AI request and uses it to authenticate to that provider. Personal keys are held temporarily in relay memory, including up to two hours per agent session. They are not intentionally saved in account records, agent task records or telemetry. Video job records retain the owner, provider job reference, billing state and a key fingerprint, not the key or prompt, so you can retrieve results later.
API keys entered in AI settings remain inside saved and transferred project files and are restored on opening. Sharing a project also shares any keys it contains. You are responsible for guarding the project and backups, removing keys before sharing, and revoking exposed keys. Use strong external encryption for sensitive projects; the editor's legacy ZIP password protection is not a secure secret vault. Removing a key does not erase previous project copies.
Prompts, media and results sent to OpenAI or xAI are subject to the selected provider's privacy and retention terms. Personal-key usage is charged to your provider account. Do not put API keys in prompts or support messages.
In plain language
- ReelLab does not sell your data or use your private creative work for advertising or model training.
- Private chat and relay content is forwarded for delivery, not saved as conversation history by ReelLab.
- Using ordinary local editing tools does not upload your project or face to a ReelLab server.
- Any cloud or payment action is user-initiated and may also be governed by the selected provider's policy.
No online service can promise absolute security. ReelLab minimizes the sensitive information it receives and avoids permanent storage of creative content wherever the feature does not require it.