Topee

Privacy Policy

Last updated: September 3, 2026 · Questions: mloza@placehub.mx

1. Overview

Topee AI. (“Topee,” “we,” “us,” or “our”) turns a real product flow — a staging or preview URL you give us — into an editable, narrated demo or launch video. This policy explains what information we collect across topee.io and the Topee application (together, the “Service”), why we collect it, who we share it with, and the choices you have.

This policy is written for people who use Topee directly (account holders, workspace members) and, in the sections that apply to them, for people who only view a video someone shared with them.

2. Information We Collect

We collect the following categories of information.

a. Account and workspace information

Name, email address, and password (stored as a salted hash, never in plain text) when you create an account. If you sign in with Google, we receive the name, email address, and profile photo that Google shares with us under the permissions you grant. We also store your workspace and organization memberships and your role within them (owner, admin, editor, viewer).

b. Billing information

Subscription plan, billing address, and transaction history. Payment card details are collected and processed directly by our payment processor, Stripe — we never receive or store full card numbers.

c. Content you provide

  • The staging or preview URL of the product you want turned into a video.
  • Brand assets you upload — logo, colors, fonts, and, where you choose to use a photo or catalog avatar, a reference image for the avatar.
  • Your own video, image, and audio files uploaded to the Asset Library, and any rights declaration you make about them.
  • Scripts, prompts, briefs, and edits you write or approve inside the editor.

d. Product capture data

To build a video, Topee opens the URL you provide in a controlled, isolated browser session and records what happens there — screen recordings, screenshots, accessibility-tree snapshots of the page, and the sequence of actions taken. This data is scoped to the URL and session you authorized; the browser session does not carry credentials for our own internal systems.

e. Optional GitHub Reader access

If you connect a GitHub repository, access is read-only and repository-selected. We read the context needed to describe your product accurately — routes, UI copy, test identifiers, and API contracts — not your full source tree, and we never request write access.

f. Generated content and viewer analytics

The videos, project documents, and exports Topee generates for you. If your plan includes viewer analytics and you share a video through a share link, we collect engagement data about people who view it — approximate location, device and browser type, referrer, and watch time — so you can see how the video performs. We do not require viewers to create an account to watch a shared video.

g. Waitlist and marketing sign-ups

If you join our waitlist or request demo access, we collect the email address you provide and use it to notify you and to follow up about early access.

h. Usage and device data

IP address, browser and device type, pages visited, and timestamps, collected automatically through server logs and cookies as described in Section 6.

3. How We Use Information

  • To operate the Service: authenticate you, run browser sessions against the URL you provide, plan and render videos, and store your projects.
  • To generate narration and avatar video, where you request it, using the providers listed in Section 4.
  • To process payments and manage subscriptions.
  • To provide viewer analytics on shared videos, for plans that include that feature.
  • To respond to support requests and send service notices.
  • To send product updates or marketing email, which you can opt out of at any time.
  • To monitor, secure, and improve the Service, including diagnosing errors and preventing abuse.
  • To comply with legal obligations and enforce our Terms of Service.

4. AI Processing and Automated Video Generation

Building a video involves several automated steps: a language model plans which parts of your product to capture and drafts narration, our system operates a real browser against the URL you provided, and a rendering pipeline assembles the final video. A few things we want to be explicit about:

  • We do not fabricate functionality. Any product behavior shown in a video comes from an action actually performed and recorded in your session. Motion graphics, titles, and captions may frame or explain that behavior, but they do not imply a feature that was not really captured.
  • Automation is non-destructive by design. The browser session is instructed not to take destructive actions (such as deleting data or sending payments) while exploring your product.
  • Your content is not used to train third-party foundation models. We send the minimum content necessary — page structure, your brief, and similar inputs — to our AI subprocessors to generate your video. We do not authorize those providers to use your submissions to train models for other customers.
  • Every generated video remains editable and reviewable by you before you share or publish it — nothing is published automatically on your behalf.

5. How We Share Information

We do not sell your personal information. We share it only as follows.

Service providers (subprocessors)

We use vetted third parties to run the Service, each processing only what their function requires:

  • Cloud hosting, database, and authentication infrastructure (Supabase; application hosting on Fly.io and Vercel).
  • Private media storage for uploads and rendered video (Cloudflare R2).
  • Video rendering (AWS Lambda, via Remotion).
  • AI planning and content generation (Anthropic’s Claude models).
  • Text-to-speech narration (ElevenLabs).
  • Avatar video generation, where you opt into an avatar (HeyGen).
  • Payment processing (Stripe).
  • Product analytics (PostHog) and site analytics (Vercel Analytics).
  • Error monitoring (Sentry).
  • Waitlist management (Clerk) and, for outreach, our CRM (Attio) and internal team notifications (Slack).
  • Optional, read-only source of product context (GitHub), only if you connect it.

Within your organization

Content inside a workspace is visible to members of that workspace according to their role. A video you generate is not visible to other workspaces or organizations unless you explicitly share it.

Legal and safety

We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Topee, our users, or the public.

Business transfers

If Topee is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to this policy or a successor policy of which you will be notified.

6. Cookies and Similar Technologies

We use two categories of cookies and similar technologies:

  • Essential: required for the site and application to function — keeping you signed in, remembering your cookie preference, and basic security protections. These cannot be turned off.
  • Analytics: help us understand how the Service is used, so we can improve it. You can decline these from the cookie banner shown on your first visit, or by clearing your cookie preference in your browser to see the banner again.

7. Data Retention

We keep account and project data for as long as your account is active, plus a limited period afterward to allow recovery and to meet legal, accounting, or dispute-resolution requirements. Uploaded media you delete from the Asset Library is marked for deletion and removed from active storage; deleted media that is still referenced by a video you have already generated is retained only as long as needed to keep that video working, or until you remove the reference. Waitlist entries are kept until you ask us to delete them or until we complete the outreach they were collected for.

8. Security

We apply the following practices, consistent with what we describe publicly on our Security page:

  • Data encrypted in transit and, where supported by the underlying provider, at rest.
  • Uploaded and generated media is stored privately; it is never publicly listable, and access requires a short-lived, scoped link.
  • Workspace-level access control — a member only sees the workspaces they belong to, and their role determines what they can change.
  • GitHub connections are read-only and scoped to the repositories you select.
  • Each internal service (the app, the render pipeline, the browser-automation worker) uses its own least-privilege credentials rather than one shared key.

No method of transmission or storage is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.

9. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to or restrict certain processing. To exercise any of these rights, contact us at mloza@placehub.mx. We will respond within the time required by applicable law.

If you are in the EEA, UK, or Switzerland

You have the rights described above under the GDPR / UK GDPR, and the right to lodge a complaint with your local data protection authority.

If you are a California resident

You have the right to know what personal information we collect, to request deletion, and to opt out of the “sale” or “sharing” of personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

You can also unsubscribe from marketing email at any time using the link in that email.

10. International Data Transfers

We and our service providers may process information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to protect information transferred internationally.

11. Children's Privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

13. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify active account holders by email or through the Service before the changes take effect. The “Last updated” date at the top of this page always reflects the current version.

14. Contact Us

Questions about this policy or requests regarding your personal information can be sent to mloza@placehub.mx.