← Back to Bandi
Privacy Policy
Last updated: 26 September 2026
1. Data Controller
The data controller for your personal data is Miguel Melgarejo Sánchez (Spain), owner of Bandi (getbandi.io). For any privacy-related enquiry you may write to soporte.bandi@gmail.com.
2. Data We Collect
- Account data: email address and name (when you register by email or with Google).
- Payment data: managed entirely by Stripe. Bandi does not store card numbers; we only store subscription/customer identifiers and your plan status.
- Content you create: topics, scripts, settings, and the resulting videos.
- Technical usage data: logs necessary to operate the service (errors, quotas, session identifiers).
- Free-trial abuse prevention: we store a device identifier and technical signals from your browser (as a hash) linked to your account. They are not used for advertising purposes.
3. Purposes and Legal Basis
- Providing the service (creating your account, generating and delivering videos) — performance of a contract.
- Managing payments and billing — performance of a contract and legal obligations.
- Support and communications regarding your account — legitimate interest / performance of a contract.
- Service improvement and security — legitimate interest.
4. Processors Acting on Our Behalf
To operate Bandi we use service providers (data processors), some located outside the EEA, in which case appropriate safeguards apply (standard contractual clauses):
- Supabase — authentication and database.
- Stripe — payment processing.
- Cloudflare R2 — video storage and delivery.
- Vercel — web hosting.
- AI providers (image, voice, and text generation) — receive only the content required to generate your video.
- Google — only if you sign in with Google (name, email address, and profile picture).
5. Retention
We retain your data for as long as your account is active and, after closure, for the periods required by law (e.g. tax obligations). Data are then deleted or anonymised.
6. Your Rights
You may exercise your rights of access, rectification, erasure, objection, restriction, and portability by writing to soporte.bandi@gmail.com. If you consider that your rights have not been adequately addressed, you may lodge a complaint with the Spanish Data Protection Authority (AEPD) (www.aepd.es).
8. Minors
The service is not directed at persons under 14 years of age. If you are a minor, you require the consent of your parent or guardian in accordance with applicable law.
9. Changes to This Policy
We may update this policy. If the changes are material, we will notify you by a reasonable means. The version currently published on this page is the version in force.
10. Connected Social Accounts (TikTok and YouTube)
You may choose to connect your TikTok accounts and YouTube channels to Bandi in order to publish the videos you generate and to view their statistics. This connection is optional and is authorised by you on each platform's official screen (OAuth). Bandi never sees your password.
- Data we access: the account or channel identifier, name and picture; the list of published videos and their public metrics (views, likes, comments); and permission to upload videos on your behalf.
- How we use it: solely to show you your connected accounts and their statistics inside Bandi, and to publish the videos you choose to publish, with the title, description, privacy setting and audience declaration you select for each post. We do not use this data for advertising and we do not sell it.
- How we store it: access tokens are stored encrypted (AES-256-GCM) and are used only by our servers for the actions above. Statistics are fetched from the platform when you open the screen and are not shared with third parties.
- How we protect this data: all communication with Google, TikTok and our servers is encrypted in transit (TLS 1.2 or higher). Tokens are encrypted at rest with AES-256-GCM using a key that lives only in the server environment, never in the browser or in the code; the database enforces row-level access policies so no user can read another user's connected accounts, and administrative access is restricted to the Bandi team under individual credentials. We do not keep copies of your YouTube videos or comments; statistics are read on demand and are not stored permanently. Tokens are deleted when you disconnect the account or delete your Bandi account, and Google user data is never transferred, sold or used for advertising, profiling or training models. If we detected a security breach affecting this data, we would notify you and the competent authority within the legally required timeframes.
- How to revoke access: from your Bandi profile (Disconnect), and also from your Google security settings (https://myaccount.google.com/permissions) or TikTok settings. When you disconnect we delete the tokens; when you delete your Bandi account all associated data is erased.
Bandi uses YouTube API Services. By connecting a channel you agree to the YouTube Terms of Service and the Google Privacy Policy. Bandi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.