Privacy Policy
Last updated: 2 August 2026
This policy explains what personal data Aposs Archive ("we", "us") collects when your organisation uses the archive, why we collect it, and how it's handled. It applies to the staff of client organisations (councils, agencies and other organisations we hold an archive for) who hold a login, and to anyone whose likeness appears in footage stored in the archive.
Who this covers
Aposs Archive is provided to organisations, not to the general public. If you're a member of an organisation's team with a login (admin, client or freelancer access), this policy covers your account data. If you appear in footage held in an archive, this policy covers how that footage and any description of it is handled — but the organisation that uploaded the footage is responsible for having the right to film and use it in the first place; see "Footage of identifiable people" below.
What we collect
Depending on how you use the archive, we hold:
- Account details: name, email address, role (admin, client or freelancer), and the organisation and projects you have access to. Passwords are stored as salted hashes, never in plain text.
- Uploaded footage and metadata: the video files themselves, plus title, description, tags, location, date filmed, mood, shot type, camera movement, and flags for whether people or vehicles are visible and the associated consent risk.
- AI-drafted metadata: when Creative Recall™ is enabled, still frames from uploaded footage are sent to our AI provider to draft the fields above automatically. These drafts can be edited or overridden by your organisation's admin at any time.
- Usage and security logs: sign-in attempts (including IP address, to prevent brute-force login attempts), and a record of who downloaded which piece of footage and when.
- Email delivery records: a log of automated emails sent to you (account creation, password resets), including delivery status, so we can diagnose delivery problems.
How we use it
- To provide and secure the archive: authenticating you, enforcing which projects and organisations you can see, and rate-limiting suspicious login activity.
- To make footage findable: Creative Recall™ uses the metadata above to power natural-language search across your archive.
- To keep the service running: sending account and password-reset emails, and diagnosing faults if an email fails to arrive.
- We do not use your data for advertising, and we do not build cross-organisation profiles for marketing purposes.
Footage of identifiable people
Some footage held in an archive may show identifiable individuals. The organisation that commissioned or filmed that footage is responsible for having a lawful basis to film and to keep it (for example, appropriate notices at an event, or consent where required). The "people visible" and "consent risk" fields in the archive are a tool to help your organisation flag and manage this — they are not a substitute for your organisation's own consent process, and Creative Recall™'s assessment of these fields is a starting draft, not a legal determination.
If you believe footage of you is held in an archive and you have a concern about it, contact the organisation that filmed it directly, or reach us at the address below and we'll help route your request to the right organisation.
Who we share data with
We use a small number of specialist providers to run the service. Each only receives the data it needs to do its job:
- Cloud storage (an S3-compatible object storage provider) stores the video files and thumbnails themselves, in a private bucket that isn't publicly browsable.
- OpenAI receives still frames extracted from uploaded footage, when Creative Recall™ is enabled, in order to draft searchable metadata.
- Resend sends transactional emails (account creation, password resets) on our behalf, and receives the recipient's email address and message content to do so.
We do not sell personal data, and we do not share footage or account data between client organisations — each organisation's archive is kept separate.
How long we keep data
We keep account data and footage for as long as your organisation's archive remains active. Security logs such as login attempts are kept only as long as needed to detect abuse, and are periodically cleared. If your organisation ends its use of the archive, contact us to discuss deletion of the underlying data.
Cookies
We use a single essential session cookie to keep you signed in, plus a short-lived token to protect forms against cross-site request forgery. We don't use advertising or third-party analytics cookies.
Your rights
Depending on where you're based, you may have rights to access, correct, or ask us to delete the personal data we hold about you, and to object to or restrict certain processing. For account data, the quickest route is usually your organisation's admin, since they manage who has access. You can also contact us directly using the details below.
Changes to this policy
We may update this policy as the service changes. We'll update the date at the top of this page when we do.
Contact
Questions about this policy, or about data held in an archive, can be sent to matty@aposs.tv.