PRIVACY POLICY
This policy explains what personal data BUBLEDUB collects, why, on what legal basis, who it is shared with, how long it is kept, and what rights you have.
1. Controller
The data controller is SIA RODLEN, a company registered in the Republic of Latvia.
- Registration number: 42103078116
- Registered address: Ģenerāļa Baloža iela 13–21, Liepāja, LV-3414, Latvia
- Correspondence address: Gubu iela 6, Medemciems, Olaines pagasts, Latvia
- Privacy contact: info@rodlen.com
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy requests are handled at the address above.
2. What we collect
2.1 Account data
- Email address and the identifier supplied by your sign-in provider (Google).
- If you link Telegram: your Telegram user ID and chat ID. We do not need or store your phone number.
- Your settings: target languages, voice preset, caption mode.
2.2 Media and derived content
- The video or audio you upload or send to the bot.
- Content derived from it during processing: the extracted audio track, the transcript of the speech, the translation, the synthesised voice-over, subtitle files, a thumbnail frame, and the finished output file.
About voices. We process recorded speech in order to transcribe and re-voice it. We do not analyse voices to identify or authenticate anyone, and we do not create voice clones or voiceprints. We therefore do not process biometric data for the purpose of uniquely identifying a person within the meaning of Article 9 GDPR.
Your source material may nevertheless contain personal data of other people. You are responsible for having a lawful basis and any necessary consent before submitting it (see our Terms).
2.3 Transaction data
- Credit balance, ledger entries, job history and cost accounting.
- Purchase records: pack purchased, amount, currency, Stripe identifiers, payment status. We never receive or store your card number — card data goes directly to Stripe.
2.4 Technical data
- Server logs with request metadata, timestamps, error codes and job identifiers, used to operate, debug and secure the Service. We deliberately keep transcripts, file URLs and tokens out of logs.
- Analytics events (only if you consent — see section 7): sign-in, upload completed, checkout started, and similar product events, collected via Google Analytics for Firebase.
3. Why we process it, and on what legal basis
- To provide the Service — hosting your upload, transcribing, translating, synthesising speech, rendering and delivering the output, maintaining your credit balance. Legal basis: performance of a contract (Art. 6(1)(b)).
- To take payment — creating checkout sessions, recording purchases, handling refunds and chargebacks. Legal basis: performance of a contract (Art. 6(1)(b)) and legal obligation for accounting records (Art. 6(1)(c)).
- To keep the Service secure and prevent abuse — rate limiting, fraud and abuse detection, enforcing our Terms. Legal basis: legitimate interests (Art. 6(1)(f)) in protecting our service and our users.
- To improve the product — aggregated performance, reliability and cost metrics. Legal basis: legitimate interests (Art. 6(1)(f)).
- Analytics cookies and similar technologies — Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time.
We do not sell personal data, and we do not use your media or transcripts to train machine-learning models.
4. Who processes data on our behalf
- Google Cloud / Firebase (Google Ireland Limited) — hosting, authentication, database, file storage, and the AI models used for speech recognition, translation and speech synthesis. Our infrastructure and stored files are located in the EU (europe-west4, Netherlands).
- Stripe (Stripe Payments Europe, Ltd.) — payment processing and payment records.
- Telegram (Telegram FZ-LLC) — only if you use the bot: message delivery and temporary storage of the files exchanged with the bot, under Telegram’s own privacy policy.
5. International transfers
Our storage, database and compute run in the European Union. However, one component — the speech-synthesis model used for the highest-quality voice — is currently offered by Google only through a global endpoint, which means the text sent for synthesis may be processed outside the European Economic Area.
Such transfers are covered by the European Commission’s Standard Contractual Clauses within our data processing agreement with Google, together with Google’s supplementary technical measures. Only the text to be spoken and technical parameters are sent for synthesis; your account identifiers are not.
6. How long we keep it
- Uploaded sources, rendered outputs, subtitles and thumbnails — deleted automatically 30 days after creation by a storage lifecycle rule. Scratch files used during processing are deleted within days.
- Job records (status, timings, transcript and translation text, usage) — kept while your account exists, so you can see your history; deleted when the account is deleted.
- Credit ledger and payment records — retained for up to 5 years after the transaction to meet Latvian accounting and tax obligations, even after account deletion.
- Server logs — retained for up to 30 days.
- Account data — kept until you ask us to delete the account.
7. Cookies and local storage
We keep this minimal.
- Strictly necessary — your sign-in session is stored in your browser (local/session storage) by Firebase Authentication so you stay logged in. Without it the studio cannot work, so it needs no consent.
- Analytics (optional) — Google Analytics for Firebase, loaded only after you accept in the consent banner. If you decline, no analytics identifier is created. Your choice is remembered in your browser and can be changed by clearing site data.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (“right to be forgotten”);
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out.
To exercise any of these, write to info@rodlen.com from the email address on your account. We respond within one month. Note that we may keep records we are legally required to retain (section 6).
If you believe we handle your data unlawfully, you may complain to the Latvian supervisory authority — Datu valsts inspekcija (dvi.gov.lv) — or to the authority in your country of residence.
9. Security
Access to production data is restricted to the operators of the Service. Traffic is encrypted in transit and files are encrypted at rest by our cloud provider. Client applications can read only their own records; all writes go through our backend. Internal processing endpoints are not publicly reachable. No system is perfectly secure, and we cannot guarantee absolute security.
10. Children
The Service is not directed at children. You must be at least 18 years old to use it. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes
We may update this policy. The current version and its effective date are always published here. Material changes will be announced by email or in the Service before they take effect.
Privacy questions and requests: info@rodlen.com