Data Controller
Under the General Data Protection Regulation (GDPR), the controller of your personal data is:
- Legal name: Codelabs Studio S.L.
- Tax ID (CIF): B88708797
- Registered address: Pasaje Federico García Lorca 6, 3º E, 29130 Alhaurín de la Torre, Málaga
- Contact e-mail: Loading...
Introduction
At TubExperto, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
1. Information We Collect
1.1 Personal Information
- Full name and email address when you register
- Optional profile information (photo, bio)
- Billing information if you purchase a paid plan
1.2 Usage Information
- URLs of YouTube channels you analyze
- Conversations with the AI experts you create
- Language and visual theme preferences
- Service usage history and query statistics
1.3 Technical Information
- IP address and approximate location
- Browser and device type
- Pages visited and time spent
- Cookies and similar technologies
2. How We Use Your Information
We use your information to:
- Provide the service: Process and store your AI experts, manage your account
- Improve the platform: Analyze usage to optimize functionality and performance
- Communicate with you: Send updates, important notifications, and technical support
- Personalize your experience: Remember your preferences and settings
- Security: Prevent fraud, detect technical issues, and protect the platform
- Legal compliance: Respond to legal requirements and protect our rights
3. Sharing Information
We do not sell your personal information. We only share data in these cases:
- AI model providers: Google, Cerebras, Alibaba Cloud, Mistral AI and OpenAI, each with the role and country detailed in section 3.1
- Other service providers: YouTube Data API, Stripe (payment processing), Resend (email), Cloudflare R2 (file storage)
- Legal requirements: When required by law or to protect legal rights
- Business transfers: In case of merger, acquisition, or asset sale
- With your consent: When you explicitly authorize us
3.1 AI Processing (model providers)
TubExperto does not train models of its own on your data. We send text to artificial intelligence model providers for these kinds of task. Each task has a primary provider and a fallback that only comes into play if the primary fails or runs out of quota:
- Catalogue indexing: transcripts, titles and descriptions of public YouTube videos, together with the chapters, summaries, analyses, infographics and audio we generate from them. This task involves no personal data of yours.
- Chat with your experts and research: your question or research topic, together with the fragments of indexed content retrieved to answer it.
- Voice: if you record a voice note, in voice interaction or in audio feedback, the recording is sent to a transcription provider to turn it into text.
- Semantic search: to locate the fragments that answer your question we compute vectors (embeddings) of the content and of the question itself. This task runs on an open model hosted on our own infrastructure, in the European Union, and never leaves it.
These are the providers involved today:
| Provider | Processing country | What it is used for and what data it receives | Transfer basis | Retention and training |
|---|---|---|---|---|
| Codelabs Studio S.L. (infraestructura propia) | European Union | Computation of the search vectors (embeddings) for transcripts and for your questions, with an open BGE-M3 model hosted on our own server. | No transfer: the computation happens on our own infrastructure, inside the European Union. | The vectors are stored in our database alongside the content they belong to. Neither the text nor the vectors are sent to a third party for this task, and they are not used to train any model. |
| Google (Gemini API) | United States and other Google data centres | Primary provider for catalogue indexing (chapters, summaries, analyses, infographics and audio), for research and for chat. It receives public video content and, in chat and research, your question. | Transfer outside the EEA covered by the standard contractual clauses incorporated into the API terms. | Under the API terms for paid services, Google does not use inputs or outputs to train its models. |
| Google Cloud (Vertex AI, vía nuestra pasarela) | European Union for the Flash models; global region for the Pro model | Fallback for the same tasks when the direct route is unavailable or out of quota. Calls leave through a Codelabs-operated gateway. The Flash models are served from a European region; the Pro model, used for research curation, is served from Google’s global region, which may process data outside the European Union. | Processing in the European Union for the Flash models. For the Pro model in the global region, the transfer outside the EEA relies on the Google Cloud data processing addendum, which incorporates the standard contractual clauses. | Vertex AI does not use customer content to train its foundation models, per its data governance documentation.Data processing addendum |
| Cerebras Systems, Inc. | United States | Primary provider for synthesising the answers of the chat with your experts. It receives your question and the transcript fragments retrieved to answer it. | Transfer to the United States covered by standard contractual clauses; data processing agreement in progress. | It does not retain the inputs or outputs of its inference services and does not use them to train or fine-tune models, per its privacy policy and terms of service. It publishes a SOC 2 Type 2 report in its trust centre.Terms of serviceTrust centre |
| Alibaba Cloud (Model Studio, modelos Qwen) | Singapore | Fallback for catalogue indexing, which is public YouTube content, and, only if the primary provider fails, for research curation and advanced reasoning tasks, where it may receive the topic or question you typed. | Transfer to Singapore; transfer paperwork (standard contractual clauses and data processing agreement) in progress. | We have not verified a published no-retention or no-training commitment equivalent to the other providers in this table. That is why its ordinary use is limited to public catalogue content. |
| Mistral AI | Paris, France (European Union) | European fallback for interactive chat. It receives your question and the context fragments when the primary provider is unavailable. | Processing within the European Union: no international transfer. | Its data processing addendum lets Mistral train on the data unless the customer turns that off: on our account it is turned off, so it does not train on your inputs or on its answers. That addendum sets no short default retention period: data is kept for the duration of the agreement and stops being accessible within thirty days of the end of access, and calls undergo automated abuse monitoring unless zero data retention is enabled. |
| OpenAI | United States | Speech-to-text for the voice notes you record, in voice interaction and audio feedback. It plays no part in chat or indexing. | Transfer to the United States under its API terms. | It does not use data sent through the API to train its models and, per its documentation, may retain it for up to 30 days for abuse monitoring. |
Speech synthesis. If you use voice interaction or audio summaries, the text of the answer (not your recording) is sent to the Google Cloud text-to-speech service to be turned into audio.
Anthropic. Earlier versions of this policy mentioned Anthropic Claude. No task is routed to that provider today: it is kept only as a contingency option, and this table will be updated before it is activated.
Important: we do not train models on your conversations and we do not sell them. Google, Cerebras and OpenAI state in their terms that they do not use the data they receive through their API for training, and on Mistral AI we keep the setting that would allow training on our API calls turned off for our account. For Alibaba Cloud we have not been able to verify an equivalent commitment, which is why its ordinary use is limited to public catalogue content. Except for the retention periods listed in the table, providers process the text to generate the answer at that moment and do not store it permanently.
3.2 Cloud Storage (Cloudflare R2)
TubExperto uses Cloudflare R2 to store the content generated from your activity on the platform: podcasts, infographics, and dubbing audio.
- Data stored: Podcasts, infographics, and dubbing audio generated from your AI experts
- Purpose: Securely host the media files you generate and make them available when you access them
- Retention: Files are kept while your account is active, per section 6 (Data Retention)
- Location: Cloudflare operates a global network of data centers; transfers outside the European Economic Area are covered by Cloudflare's contractual safeguards (Standard Contractual Clauses)
More information: Cloudflare Privacy Policy
3.3 Connecting your memory (MemoryFirst)
You can connect your MemoryFirst account from Connections. It is optional and starts only with your explicit consent on MemoryFirst's own screen. Once connected, TubExperto holds a read-onlypermission over your memory and reads it only when you turn on "Use my memory" in a research, and only from the project you pick.
The memory fragments retrieved are sent to TubExperto's AI provider to produce the answer, the same way as the rest of the content we process (section 3.1). They are stored inside that research so you can see exactly what was taken into account, they are used for no other purpose, and they are deleted when you delete the research.
You can disconnect your memory at any time from Connections, or revoke the permission from your MemoryFirst account. On disconnection we stop reading it immediately and delete the access credentials we held.
4. Data Protection
We implement robust security measures:
- SSL/TLS encryption for all communications
- Secure storage on encrypted servers
- Restricted access only to authorized personnel
- Regular security audits
- Automatic backups and data loss protection
5. Your Rights (GDPR)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion of your data (“right to be forgotten”)
- Portability: Receive your data in a structured, transferable format
- Object: Object to the processing of your data in certain cases
- Restriction: Request restriction of processing of your data
- Withdraw consent: At any time, for consent-based processing
To exercise these rights, contact us at Loading...
6. Data Retention
We retain your personal information while your account is active and for a reasonable additional period to comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account and associated data at any time.
7. Cookies and Similar Technologies
We use cookies and similar technologies to improve your experience. See our Cookies Policy for more information.
8. International Transfers
Your data may be transferred and processed on servers located outside the European Economic Area. In such cases, we ensure appropriate safeguards are implemented to protect your information, in accordance with GDPR and other applicable regulations. The table in section 3.1 shows, provider by provider, the processing country and the basis each transfer relies on.
9. Children's Privacy
TubExperto is intended for persons 18 years of age and older. We do not knowingly collect personal information from persons under 18. If we discover we have collected data from a minor, we will delete it immediately. If you believe a minor has provided information, please contact us.
10. Changes to this Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by email or through a prominent notice on our website. We recommend reviewing this policy regularly.
Contact
If you have questions about this Privacy Policy or how we handle your data:
- Email: Loading...
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe the processing of your data does not comply with regulations.