Back to the main page
Legal

Privacy Policy

Everything PraiseReel stores about you, and about the people who wrote the reviews you use. Written from the code, so it says what actually happens rather than what would sound good.

Last updated Eleven sectionsTerms of Service

Who is responsible

The people who run PraiseReel are the data controller for everything described on this page — the ones answerable for it. You reach them at support@praisereel.com.

Write to support@praisereel.com about anything here, or use the contact form. If your review has appeared in someone's post, the fastest route is the takedown page.

There is no data protection officer: the operation is too small to need one. The address above reaches the person who actually runs it.

What we store

All of it, concretely. There is no other list.

From signing in

  • Your Whop user id, name and username, the link to your Whop avatar, and your e-mail address if Whop gives us one. Whop hands these over when you sign in; we never see a password.
  • Whether the account currently has Pro. We ask Whop this and hold the answer for a minute at a time. We do not receive, and cannot see, your card.
  • A sign-in record on our server holding the Whop tokens for your session. The browser only ever holds a meaningless id that points at it.

From using the app

  • Each business you set up: its name, Instagram handle, logo image, brand colour, business type, language, and — if you used "Find your business" — its address, rating, review count and Google review link.
  • The reviews you put in: the review text as you enter or edit it, the reviewer's name (the tool keeps only its first word), and the star rating. If you drop in a screenshot, the reading is done on our own server and the image is not kept.
  • The posts that come out: the video and image files, a poster frame, and a small meta.json holding the review, the text on the post and the settings that made it.
  • A count of how many free posts the account has used, stored against a one-way hash of your Whop id rather than the id itself.

From the site running

  • A security log: one line per interesting event — a sign-in, a refused request, a delete — with the time, the account id and the IP address it came from. It is written so that review text, names, message bodies, passwords and tokens are dropped before anything is saved.
  • Messages you send us through the contact or takedown form: your name, e-mail, what you wrote, and the IP it came from.
  • The usual short-lived web-server records while a request is being answered.

There is no analytics, no tracking pixel, no advertising network and no third-party script on the app pages. We do not build a profile of you and we do not sell anything to anybody.

Why we may

  • To run the service you asked for — sign you in, store your businesses, render and keep your posts, and know which plan you are on. (Performing our contract with you.)
  • To keep the service safe and working — the security log, the rate limits, the backups. (Our legitimate interest in a site that is not abused and does not lose your work.)
  • To answer you when you write to us, and to deal with a takedown request. (Our legitimate interest, and our legal obligations.)
  • The reviews themselves are personal data about the reviewer, and you are the one who decides to use them. We process them for you, on your instructions, so that you can publish them. You are responsible for having the right to use them; see section VI of the terms.

Cookies

Three, all strictly necessary, none of them for advertising or analytics. That is why there is no cookie banner: there is nothing to consent to.

  • rr_session — a signed, meaningless id that tells our server which sign-in you are. It is set once you sign in, cannot be read by page scripts, is not sent when another site links to us, and lasts 30 days or until you sign out.
  • rr_csrf — a random token the pages read and send back with every change they make, so that another site cannot make your browser act as you. It holds nothing about you and lasts 30 days.
  • rr_oauth — a ten-minute cookie that exists only while the sign-in round trip with Whop is happening, so that we can check the answer that comes back is the one we asked for. It is deleted the moment sign-in finishes.

The Whop checkout on the upgrade page is Whop's own page inside a frame and sets its own cookies under Whop's policy; it cannot read ours.

How long we keep it

  • Businesses and posts: until you delete them. We do not expire them and we do not clear them out.
  • A deleted business is moved out of sight at once and permanently removed once its ten-second undo window has passed. If the site restarts before that, the sweep on start-up removes it.
  • Deleting your whole account removes every business and post immediately, with no undo window.
  • Backups are taken nightly and kept for 30 days, then deleted. So something you delete today is fully gone within 30 days.
  • Sign-in records end when you sign out and in any case 30 days after they were last used.
  • The security log rotates: the current file is kept until it reaches about 5 MB, then five older files are kept behind it and the oldest falls off. How long that is in days depends on how busy the site is.
  • The free-post count is kept for as long as the Whop account exists, including after you delete your account here — as a number against a hash, with your id removed. Without it, deleting and signing up again would hand out a fresh set of free posts.
  • Contact and takedown messages are kept as long as we may need them to show what was asked and what we did about it, and then deleted.

Who else touches it

Four companies, at most, and each one only gets the part it needs. Nobody is paid for your data and nobody is given it to use for their own purposes.

  • Whop — sign-in and payments. They hold your account and your card; we hold neither. They tell us your id, name, username, avatar and e-mail, and whether you have paid.
  • The AI text provider — none at the moment: AI text is switched off today, and this page will name the provider before it is ever switched on. Only when AI text is switched on: When it is, the review text and your business name and type are sent so it can pick which sentence to feature and write the eyebrow, closing line, caption and suggested reply. When it is off, the app uses a simple local rule instead and nothing leaves the server. Reviewer names are not needed for that and are not part of what makes the caption.
  • The hosting provider[HOSTING PROVIDER — to be confirmed]. The machine the files and the site run on.
  • The e-mail provider[EMAIL PROVIDER — to be confirmed], and only if one is configured. Until then, a message from the contact or takedown form is written to a folder on the same server and read there.

One more, and only when you ask for it: using "Find your business" sends what you typed to Google Places, or to OpenStreetMap when no Google key is set, so it can suggest matching businesses. Nothing about your account goes with it.

Reading a review out of a screenshot happens on our own server — the image is not sent to anyone, and it is not kept afterwards.

We will also hand something over if the law makes us. If that ever happens and we are allowed to tell you, we will.

Where it is

Your files sit on the hosting provider named in section VI. Whop and the AI provider are American companies, so signing in, paying, and generating AI text involve your data being handled in the United States — which, for people in the EU/EEA, means a transfer outside it. We rely on those providers' own standard contractual clauses for that, and we have not yet reviewed each one; that is being worked through as part of getting ready to launch. If this matters to you, the AI text can be switched off, and everything except sign-in and payment then stays where the site is hosted.

Your rights

If you are in the EU/EEA — and in practice we treat everyone the same way — you have these, and two of them are buttons rather than requests:

  • See it and take a copy. Your account pageDownload my data. One zip with every business, logo, post, file and a small account file. No waiting, no e-mail.
  • Delete it. Same page → Delete my account. Everything goes at once, with no undo window. A single business can be deleted from the businesses page instead.
  • Correct it. Business details, review text and the text on a post are all editable in the app. If something we hold elsewhere is wrong, write to us and we will fix it.
  • Object, or ask us to restrict what we do. Write to us and tell us what you object to.
  • Take it elsewhere. The export is machine-readable — JSON and ordinary media files.
  • Complain. To us first, if you would: it is usually quicker. You can also complain to a supervisory authority — in Denmark that is Datatilsynet, in the Faroe Islands Dátueftirlitið, and elsewhere in the EU/EEA it is the data protection authority of the country you live in.

We answer requests within a month. We may ask you to sign in, or to prove who you are, before acting on one — otherwise the "delete my data" button would be a way to delete someone else's.

If you are in a review

You did not sign up here, and you may never have heard of us. A business you wrote a review about has used PraiseReel to turn it into a post. This section is for you.

  • What is held: the review text, the name and the star rating as the business entered them. The business can edit all three, so they may differ from what you wrote; the tool keeps only the first word of a name and has no place for a photograph, an address or anything else about you.
  • Where it came from: the business, who pasted it in or dropped in a screenshot of it. We do not collect reviews ourselves and we have no connection to Google, Instagram or any review site.
  • What you can do: use the takedown page, or write to support@praisereel.com. Tell us where you saw it. If we can find the post, we may remove the copy kept on our own service and pass your request on to the business; for anything we hold ourselves we handle your request as data-protection law requires. We do not publish posts and cannot remove or change anything on Instagram or any other platform, and we cannot make a business do so — only whoever posted it, or that platform, can. We cannot promise a result.
  • You have the same rights as anyone else here: to see what we hold about you, to have it corrected, to have it deleted, to object, and to complain to your data protection authority.

Children

PraiseReel is a tool for businesses. It is not meant for, aimed at or advertised to anyone under 16, and we do not knowingly hold an account for one. If you believe a child's information has ended up here — in a review, for instance — tell us and we will remove it.

Looking after it

In plain words, what actually protects this:

  • No passwords to lose. Sign-in is Whop's; we never hold one.
  • Your browser holds nothing worth stealing. The session cookie is a meaningless id that page scripts cannot read; the real tokens stay on the server, outside anything the web server can serve as a file.
  • Every request is checked against the account that owns the thing. Another customer asking for your business, your file or your render job gets "not found", not a copy.
  • The pages are locked down. A strict content policy means only our own scripts run, and every change your browser makes has to carry a token another site cannot read.
  • The logs are written to be dull. Review text, names, message bodies and anything that looks like a secret are dropped before a line is saved.
  • Backups, nightly, kept 30 days, so a broken disk does not cost you your work.
  • Connections are encrypted in the normal way once the site is live on its own domain.

None of this is a guarantee. No site can promise it will never be broken into. If something does happen that puts your data at risk, we will tell you, and the supervisory authority, as the law requires.

Changes to this policy

We will update this page when what we do changes — a new provider, a new feature, a retention period that turns out to be wrong. The date at the top always says when it last changed. If a change is significant we will tell you in the app or by e-mail rather than quietly editing the page.

Anything on this page you would like explained, or think is wrong? support@praisereel.com, or the contact form. The agreement itself is in the terms of service.