sum.video

Privacy Policy

Last updated: 10/24/2025

1. Data Controller

Company Name: Questly Kft.

Country: Hungary

Tax Number: 32757402-1-42

Registered Office: 1065 Budapest, Révay utca 6. Fsz. 7. ajtó

Email: privacy@questly.com

Questly Kft. is the data controller responsible for processing your personal data in accordance with the General Data Protection Regulation (GDPR) and Hungarian data protection laws.

2. Types of Personal Data We Collect

Account Information

  • Email address (for authentication and communication)
  • Password (encrypted and stored securely)
  • Account creation date and last login information

Service Usage Data

  • YouTube video URLs submitted for processing
  • Video metadata (title, duration, channel information)
  • Generated summaries and transcripts
  • Usage patterns and frequency
  • Subscription status and payment information

Technical Data

  • IP address and location data
  • Browser type and version
  • Device information and operating system
  • Cookies and similar tracking technologies

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: To provide the summarization service you have subscribed to
  • Legitimate Interest: To improve our service, prevent fraud, and ensure security
  • Consent: For marketing communications and optional data processing
  • Legal Obligation: To comply with applicable laws and regulations

4. How We Use Your Data

Service Provision

  • Process YouTube videos and generate summaries
  • Maintain your account and subscription
  • Provide customer support
  • Process payments through Stripe

Service Improvement

  • Analyze usage patterns to improve AI accuracy
  • Optimize service performance and reliability
  • Develop new features and capabilities
  • Conduct research and analytics (anonymized)

Communication

  • Send service-related notifications
  • Provide updates about your subscription
  • Respond to your inquiries and support requests
  • Send marketing communications (with consent)

5. Data Sharing and Third Parties

We may share your data with the following third parties:

Supabase (Database & Authentication)

We use Supabase for user authentication and data storage. Your account information and usage data are stored securely on Supabase's infrastructure.

Stripe (Payment Processing)

Payment information is processed by Stripe. We do not store credit card details on our servers.

OpenAI (AI Processing)

Video transcripts are sent to OpenAI for AI-powered summarization. We do not share personal information with OpenAI beyond the content you submit.

YouTube API

We access YouTube's API to retrieve video metadata. We only process publicly available video information.

PostHog (Analytics)

We use PostHog for user behavior analytics and event tracking to improve our service. PostHog may set cookies for analytics purposes.

Sentry (Error Tracking)

We use Sentry for error monitoring and performance tracking. Sentry may set cookies to track application performance and errors.

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

6. Data Retention

Account Data

Retained for the duration of your account plus 3 years after account closure for legal and business purposes.

Usage Data

Video URLs and summaries are retained for 2 years to improve service quality and provide account history.

Payment Data

Retained for 7 years as required by Hungarian accounting and tax regulations.

Technical Data

Logs and technical data are retained for 1 year for security and performance monitoring.

7. Your Rights Under GDPR

As a data subject, you have the following rights:

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data in certain circumstances.

Right to Restriction

Limit how we process your personal data.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests.

To exercise these rights, contact us at privacy@questly.com. We will respond within 30 days.

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication
  • Secure data centers and infrastructure
  • Employee training on data protection
  • Incident response procedures

9. Cookies and Tracking

We use cookies and similar technologies for:

  • Authentication and session management (Supabase)
  • Remembering your preferences (theme, sidebar state)
  • Analytics and user behavior tracking (PostHog)
  • Error monitoring and performance tracking (Sentry)
  • Security and fraud prevention

We also use browser localStorage for certain preferences like theme selection and video URL storage. Unlike cookies, localStorage data is not sent to our servers automatically.

You can control cookie settings through your browser preferences. Some features may not work properly if cookies are disabled. For detailed information about our cookie usage, please see our Cookie Policy.

10. International Data Transfers

Some of our service providers may be located outside the European Economic Area (EEA). We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Certification schemes and codes of conduct
  • Binding corporate rules

11. Children's Privacy

Our service is not intended for children under 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete such information.

12. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email or service notification. We encourage you to review this policy periodically.

13. Supervisory Authority

You have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

NAIH

Address: 1055 Budapest, Falk Miksa utca 9-11.

Website: https://naih.hu

14. Contact Information

For questions about this privacy policy or to exercise your rights, please contact us:

Data Protection Officer: Questly Kft.

Address: 1065 Budapest, Révay utca 6. Fsz. 7. ajtó

Email: privacy@questly.com

Response Time: Within 30 days

This privacy policy is compliant with the General Data Protection Regulation (GDPR) and Hungarian data protection laws.