ReelVaultPrivacy Policy

Legal

Privacy Policy

Last updated: June 17, 2026

ReelVault ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights — both for the ReelVault web application and the ReelVault Chrome Extension.

By using ReelVault, you agree to the practices described in this policy.


01

What Data We Collect

We collect only the minimum data necessary to provide the ReelVault service:

  • Account Information: Your email address and name, provided when you sign up via Google OAuth or email/password through Supabase Auth.
  • Instagram Reel Metadata: Public reel shortcodes (URLs), captions, thumbnail images, and video links extracted from your Instagram Saved Reels page or DM threads. We do not access your Instagram login credentials or private account data.
  • AI-Generated Content: Categories and action plans generated by Google Gemini based on reel captions you import.
  • Usage Data: Basic anonymous usage analytics (e.g. feature usage frequency) to improve the product. No personally identifiable information is attached to these events.
02

How the Chrome Extension Works

The ReelVault Chrome Extension operates locally in your browser. Here is exactly what it does and does not do:

  • Reads only Instagram pages you explicitly trigger it on — it only activates when you click "Import" in the extension popup.
  • Extracts reel metadata (URLs, captions, thumbnails) from the Instagram page currently open in your browser tab.
  • Stores a local deduplication cache in chrome.storage.local — a list of reel shortcodes already imported — so we never send duplicates to the server. This data stays on your device and is never transmitted separately.
  • Sends reel metadata to the ReelVault backend over HTTPS once you confirm the import.
  • Does not track your Instagram browsing outside of an active import session.
  • Does not read, store, or transmit your Instagram password or session cookies.

The extension requests the following Chrome permissions:

  • activeTab — to read the currently open Instagram tab during an import.
  • scripting — to inject the content script that scrolls and extracts reel data.
  • storage — to save your auth token and deduplication cache locally.
  • Host permission (instagram.com) — required to run the content script on Instagram pages.
  • Host permission (reelvault.app) — required to sync your auth token between the web app and extension.
03

How We Use Your Data

  • To provide the core service: importing, categorizing, and displaying your reels.
  • To generate personalized AI action plans based on your reel content using Google Gemini.
  • To authenticate you securely across sessions.
  • To deduplicate imports so you are never charged twice for the same content.
  • To improve ReelVault features based on aggregated, anonymized usage patterns.

We do not sell your data. We do not use your data to train AI models. We do not share your data with third parties except as described in Section 4.

04

Third-Party Services

ReelVault uses the following third-party services to operate:

  • Supabase — database and authentication. Your account data and imported reels are stored in Supabase. See Supabase Privacy Policy.
  • Google Gemini API — AI categorization and action plan generation. Reel captions are sent to Gemini for processing. See Google Privacy Policy.
  • Vercel — web application hosting. See Vercel Privacy Policy.
05

Data Retention

Your account data and imported reels are retained as long as your account is active. You may request deletion of your data at any time by contacting us (see Section 8). Upon account deletion, all your reels, categories, and action plans are permanently removed from our systems within 30 days.

The local deduplication cache stored by the Chrome Extension in chrome.storage.local is deleted when you uninstall the extension or sign out.

06

Data Security

All data is transmitted over HTTPS. Auth tokens are stored in chrome.storage.local (not accessible to web pages) and in Supabase with row-level security policies. We do not store Instagram session tokens or cookies.

07

Your Rights

You have the right to:

  • Access the data we hold about you.
  • Delete your account and all associated data.
  • Export your reel data at any time from the dashboard.
  • Opt out of any non-essential data collection.

To exercise any of these rights, contact us at the email below.

08

Contact Us

If you have any questions about this Privacy Policy or want to exercise your data rights, please contact us at:

Email: privacy@reelvault.app

09

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of ReelVault after any changes constitutes acceptance of the updated policy.