Privacy Policy
Last updated: February 2026
1. Introduction
Waddle ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered video generation service at waddle.run ("Service").
2. Information We Collect
2.1 Information You Provide
- Account Information: When you sign in via Google or Apple, we receive your name, email address, and profile picture from your authentication provider.
- Content: Images you upload and text descriptions you provide for video generation.
- Payment Information: When you subscribe to a paid plan, payment details are processed securely by Stripe. We do not store your full credit card numbers.
- Communications: Any messages you send to our support team.
2.2 Information Collected Automatically
- Usage Data: Information about how you interact with the Service, including pages visited, buttons clicked, features used, videos created, and time spent. Collected via PostHog analytics (see Section 7).
- Device Information: Browser type, operating system, device type, and screen resolution.
- Log Data: IP address, access times, pages viewed, and referring URLs.
- Error Data: Frontend errors and diagnostic information to help us identify and fix bugs.
- Session Replays: With your consent, we may record anonymised replays of your browsing session (mouse movements, clicks, page content with sensitive fields masked) for troubleshooting purposes. See Section 7.4 for details.
- Cookies: We use essential cookies for authentication and session management. PostHog analytics does not use cookies. Google advertising cookies and session replay are only enabled with your consent. See Section 7 for details.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process your video generation requests
- Manage your account and subscriptions
- Process payments and prevent fraud
- Send you service-related communications
- Respond to your inquiries and support requests
- Analyze usage patterns to improve user experience
- Ensure security and prevent abuse
- Comply with legal obligations
4. How We Share Your Information
We do not sell your personal information. We may share your information with:
- Service Providers: Third-party companies that help us operate the
Service, including:
- Supabase (authentication and database)
- Stripe (payment processing)
- Cloudflare (content delivery and security)
- PostHog (product analytics and error tracking, EU-hosted)
- Google (advertising measurement via Google Tag Manager)
- GPU infrastructure providers (video processing)
- Legal Requirements: When required by law, court order, or governmental authority.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred.
- With Your Consent: For any other purpose with your explicit consent.
5. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this policy:
- Account Data: Retained while your account is active and for a reasonable period after deletion.
- Uploaded Images: Temporarily stored during processing and deleted after video generation is complete.
- Generated Videos: Stored for 30 days, after which they may be automatically deleted unless saved to your account.
- Payment Records: Retained as required for tax and legal compliance.
6. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your personal data.
- Portability: Request your data in a portable format.
- Opt-out: Unsubscribe from marketing communications.
- Withdraw consent: Where we process data based on your consent (e.g., analytics cookies and session replay), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Object to legitimate interest: Where we process data based on legitimate interest (e.g., cookieless analytics), you have the right to object. Contact us and we will assess whether our interest overrides your rights.
To exercise these rights, contact us at support@waddle.run. You can also delete your account through your account settings. To withdraw cookie consent, clear your browser's cookies and localStorage for waddle.run — the consent banner will reappear on your next visit.
7. Cookies, Analytics, and Tracking
7.1 Essential Cookies
Required for authentication and basic site functionality (e.g., session tokens, login state). These cannot be disabled and do not require consent under the ePrivacy Directive as they are strictly necessary to provide the Service you requested.
7.2 Analytics (PostHog)
We use PostHog, a product analytics platform hosted in the EU (eu.i.posthog.com), to understand how our Service works and to identify errors and usability issues. We use PostHog for the following purposes:
- Funnel and click tracking: understanding whether buttons, forms, and user flows work correctly
- Error tracking: detecting and diagnosing frontend errors so we can fix problems quickly
- Session replay: recording anonymised replays of user sessions to troubleshoot issues (only with your consent — see below)
7.3 How Analytics Works — No Cookies From PostHog
PostHog is configured with persistence disabled — it does not set any cookies or store any data on your device. No PostHog cookies, localStorage entries, or other client-side storage are ever created, regardless of your consent choice.
User identification: If you are signed in, we associate your analytics events with your account using a pseudonymous identifier (your internal account ID). This allows us to understand user journeys across pages, such as tracking whether the upload-to-video flow works correctly. If you are not signed in (e.g., browsing the landing page), events are fully anonymous and not linked across page views.
Because PostHog does not store anything on your device, this processing does not require consent under the ePrivacy Directive. The legal basis for this processing is our legitimate interest (GDPR Article 6(1)(f)) in maintaining, monitoring, and improving the reliability of our Service. We have assessed that this interest does not override your rights given that: no data is stored on your device, no cross-site tracking occurs, data is processed on EU servers, and you can object at any time (see Section 7.6).
7.4 Session Replay (Consent Required)
If you accept cookies via our consent banner, PostHog may record a replay of your session — including mouse movements, clicks, scrolls, and page content. We use session replays solely to troubleshoot bugs and improve the user experience. Sensitive form fields (e.g., password inputs) are automatically masked. Session replays are stored on PostHog's EU servers and are retained according to PostHog's data retention policies. The legal basis for session replay is your consent (GDPR Article 6(1)(a)). Session replay is never active unless you have accepted cookies via our consent banner.
7.5 Google Ads and Google Tag Manager
We use Google Tag Manager and Google Consent Mode v2 for advertising measurement. All Google advertising and analytics cookies (ad_storage, ad_user_data, ad_personalization, analytics_storage) are denied by default and are only enabled if you accept cookies via our consent banner. If you decline or do not interact with the banner, no Google advertising cookies are set on your device.
7.6 Your Choices
When you first visit the Service, a cookie consent banner gives you the option to accept or decline non-essential cookies. Accepting enables session replay and Google advertising cookies. Declining keeps these disabled. You can change your preference at any time by clearing your browser's cookies and localStorage for waddle.run, which will cause the consent banner to reappear on your next visit.
PostHog event tracking (page views, clicks, errors) operates without any cookies and cannot be disabled via the cookie banner. If you wish to object to this processing under your right to object to legitimate interest, please contact us at support@waddle.run and we will cease processing your data.
Most browsers also allow you to control cookies through their settings. Note that disabling essential cookies may prevent you from using the Service.
PostHog does not track you across other websites. We do not sell analytics data to third parties.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (HTTPS) and at rest, secure authentication, and regular security assessments. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable laws.
10. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
11. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these websites. We encourage you to read the privacy policies of any third-party sites you visit.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes indicates acceptance of the updated policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at: