Privacy Policy
This policy describes how Grabbing The Vid is designed to handle information when you use the service. It is written for India-facing operations with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 in view.
1. Who we are
“Grabbing The Vid”, “we”, “us”, and “our” refer to the operator of grabbingthevid.com. The operator’s legal name, registered address, and monitored privacy contact point must be published here before production launch.
2. Information we process
- The video URL you submit for analysis or downloading.
- Job identifiers, selected quality, job state, timestamps, and limited operational metadata needed to run the queue.
- Technical and security information needed to rate-limit requests, prevent abuse, diagnose failures, and protect the service.
- Information contained in a submitted public URL may itself contain personal data. Do not submit data you are not authorised to process.
3. What we do not intentionally collect
The service does not require a user account, profile, password, contact list, social-media login, or advertising identifier to perform a download. We do not intentionally ask for sensitive personal data to use the downloader.
4. Purposes of processing
- Validate whether a URL belongs to a supported service and is safe to process.
- Analyze source metadata and create a download job.
- Process the requested media and deliver the resulting file.
- Operate, secure, rate-limit, monitor, troubleshoot, and improve the service.
- Meet applicable legal, security, and fraud-prevention requirements.
5. Lawful processing and notice
We intend to process digital personal data only for a permitted purpose and with the notices, consent, or other lawful ground required by applicable law. Where consent is required, it should be requested in a clear and specific manner and withdrawal should be reasonably easy. The service will not condition unrelated processing on consent that is not necessary for that purpose.
6. Data minimisation
We aim to collect and retain only information needed for the stated purposes. URLs and job metadata are operational inputs rather than a permanent content library.
7. Retention and deletion
The job queue is configured around temporary processing. The current application configuration uses a 1,800-second job TTL. Completed media is kept on temporary Render server storage and is deleted after download or stale-job cleanup.
8. Security safeguards
- Strict allowlisting of supported hosts.
- HTTPS-only input and rejection of credentials and unsafe destination addresses.
- Rate limiting at the API layer.
- Isolated background media processing with FFmpeg and yt-dlp.
- Temporary server storage with automatic cleanup after download or job expiry.
- Security headers and secret values kept outside source control.
9. Your rights
Subject to the DPDP Act, applicable commencement dates, verification requirements, and lawful exceptions, a Data Principal may have rights relating to access to information about personal data and processing, correction and erasure, grievance redressal, withdrawal of consent where consent is the applicable basis, and nomination. Requests should be submitted through the monitored privacy contact point published before launch.
10. Children
The service is not designed to collect children’s personal data. The operator must apply the child-data requirements and verifiable parental-consent safeguards that are applicable to the service when the relevant legal provisions take effect. Do not knowingly submit a child’s personal data for purposes unrelated to a lawful request.
11. Security incidents
The operator will maintain an incident-response process for personal-data breaches and will provide notices to the Data Protection Board and affected Data Principals when and to the extent required by the applicable law and Rules.
12. Service providers
The service architecture uses infrastructure providers for cloud hosting, queueing, and media processing. Providers may process data on the operator’s instructions or as independent controllers where their own terms and law require. Vendor access will be limited to what is necessary for the service and security controls.
13. Changes
This policy may be updated when the service, law, vendors, retention periods, or security controls change. Material changes should be reflected through a new effective date and any notices required by law.