Updated October 10, 2026
Your work.
Your information.
Here is what DVIDIA stores as you explore, sign in and record.
Optional landing-page measurement
We compare a few landing-page designs. Before you agree to measurement, the design choice stays in page memory and no experiment events are sent. If you allow it, we save a random experiment identifier, your assigned design and phone-or-desktop category in this browser for up to 30 days. The same design is reused on later visits. Refusing saves only your privacy preference. Do Not Track and Global Privacy Control disable measurement.
With your permission, our own Cloudflare service counts exposure, main-button use, successful handle claims reported by the browser, recording starts and loading time. We store a hash of the random identifier, not an account ID, handle, email, video, full browsing history or advertising identifier. Normal network information is processed to deliver requests and prevent abuse; temporary hashed rate-limit records are separate. No third-party analytics script is used. Experiment rows expire after 30 days and are removed by scheduled cleanup. Counts represent consenting browsers, not all visitors or verified unique people.
You can change your choice at /privacy-settings. Turning measurement off removes the experiment identifier from browser storage and stops new events. Existing pseudonymous results expire normally; they are not linked to your account. This choice does not affect signup, recording, public activity or any paid service.
Invitations
Your claimed handle forms a public invitation link. Opening the link does not create a referral or add a tracking cookie. If a new member explicitly accepts, we store the inviter and accepting account IDs and acceptance time in Cloudflare D1. The inviter sees only their accepted-invite count, not a list of invited accounts or their email addresses. Each account can accept one inviter within its first seven days. Invitation records do not create cash rewards or a payment entitlement. Contact hello@dvidia.org to request removal.
Accounts and handles
When email signup is enabled, we store your verified email address, account ID, unique handle and account timestamps in Cloudflare D1. Your email is private; your handle identifies your contributions. Claiming a handle does not subscribe you to marketing.
Sign in with Apple
When Apple sign-in is available and you choose it, Apple verifies your account. DVIDIA stores Apple's account identifier and verified email address, including a private relay address if you choose Hide My Email. Your Apple password is never shared with DVIDIA. We do not request your name or store Apple's authorization codes or access tokens.
A short-lived, secure cookie and a one-time sign-in record protect the return from Apple. An existing DVIDIA account is connected only after you sign in to that account and explicitly choose to connect Apple. Signing in does not subscribe you to email campaigns or upload your recordings.
Sign in with X
When you choose X sign-in, X verifies your account. DVIDIA stores your stable X account ID and, for a new account, the confirmed email X shares with your permission. If X does not share a confirmed email, sign in with an email code first and explicitly connect X to that account. We do not store your X password, posts, authorization codes or access tokens.
A secure temporary cookie and a one-time sign-in record protect the return from X. We request profile and email access for sign-in, not posting, messaging or ongoing background access. An email match alone never links an existing DVIDIA account. Signing in does not upload recordings or subscribe you to marketing.
Sign-in emails and sessions
SendGrid processes your email address to deliver a requested verification code. Codes expire after ten minutes. We store a keyed hash of the code, never the code itself. Sign-in uses a secure, HTTP-only cookie valid for up to 30 days; signing out revokes that session.
We keep hashed rate-limit identifiers to limit abuse. Scheduled cleanup removes expired challenge, session and rate-limit records in bounded batches. Account details remain until removal is arranged; automated account deletion is not yet available.
Recordings and skillspace plans
Current browser recordings, plans and review drafts are saved on your device. Signing in does not upload or back them up. Download originals you want to keep. Choosing a local video for review does not send its contents to DVIDIA or an AI provider.
Signing in, exploring a public starter or making a local brief does not submit a video. A shared contribution requires a separate confirmation of permission.
Optional video descriptions and tags are saved separately on this device, linked to the original file fingerprint. They stay local unless you explicitly confirm them and choose Save to my account. That separate action sends the confirmed description and tags with your video; it does not send them for AI analysis. Edit them or remove their text and tags to clear them. Clearing this site's browser data also removes local details and recordings.
Saved recording context
When signed in, choosing Save context stores your observation, optional task description and video timestamp with your account ID and the source recording revision in Cloudflare D1. These notes are private to your account in the current product. They do not change publisher labels, publish an annotation, or send a video to an AI provider. Contact hello@dvidia.org to request removal.
Temporary video analysis
When analysis is available, choosing a file first previews it on your device. Sending it for analysis is a separate action. The analysis service keeps a temporary private copy with an expiry shown in its receipt, normally up to 24 hours; you can request earlier removal. This does not publish the video or add it to a shared skillspace.
When you choose Analyze & suggest tags, the server first analyzes sampled video frames. TypeSafe's JEV receives only the resulting coarse activity category and model revision to suggest tags; it does not receive the video, filename, your description, account identity or file fingerprint. Cached suggestions become unavailable when analysis expires, within 24 hours, and are cleared by hourly cleanup. Removing the server copy also clears its cached suggestions. Aggregate request counts cap cost. Save details keeps your chosen tags on this device; it does not approve a dataset label or authorize publication.
Private skillspace contributions
When shared contributions are enabled, your verified account and handle connect an explicitly submitted video to a specific, versioned task brief. We store the original bytes, filename, file digest and size, your confirmed description and tags when supplied, consent version and timestamp, and submission and review history on our separate contribution server. Authorized operators can view the original for intake review. Upload progress is saved so you can resume with the same file.
Contribution originals remain private unless you separately choose to publish an open release. Withdrawal removes their media from the active contribution store and ends review; a minimal receipt and event history remain to record the withdrawal. Contact hello@dvidia.org about removal of retained account or audit information. The current intake service does not create a backup or promise recovery after disk failure.
Private intake permission does not transfer ownership or authorize public dataset publication, model training or a payout. Intake approval does not grant those rights either. Any broader use needs a separate permission and release process. Existing local recordings and earlier analysis permissions are not upgraded automatically.
Public profiles and conversations
Your claimed handle starts with a public creator page. A display name, bio and source links appear there when you save them. Public pages may appear in search results and have a readable Markdown mirror. The activity calendar counts days on which currently public videos were originally shared, using UTC dates. Video, Like and Helpful totals use currently public contributions; they do not track logins, private recordings or browsing activity. Public profile activity may also appear beside your invitation link.
You can set Profile privacy to Private on your own profile. Only your signed-in account can then view that profile, calendar and totals. We exclude the private page from our profile sitemap and search indexing; previously indexed search results may take time to disappear. Already-public videos, creator credits, comments and your claimed-handle invitation link remain public under their separate sharing settings. Profile privacy does not revoke a video license or publish private videos or personal Skillspaces. The privacy setting is stored with your account in Cloudflare D1.
Comments and their attached source links are public on an openly shared video. We store them with your account ID, public handle and timestamp in Cloudflare D1. You can remove your own comment; the video creator can also remove comments on their video. Removal clears the comment text and links, while a minimal identifier is retained to prevent a delayed retry from restoring deleted content. Like and Helpful counts are public; individual reaction choices are associated with your account and can be undone.
X post chips are links, not embedded posts. We do not fetch or copy post text or load X tracking scripts for these references. Opening a chip takes you to X. Hiding a video also hides its discussion from public access; its stored discussion returns if the same release is made public again.
Waitlist and service providers
The separate waitlist stores the email and optional details you submit in Cloudflare KV. Existing waitlist entries are not converted into verified accounts. Cloudflare serves the website and processes normal request information. Verification emails have open and click tracking disabled in the application.
Questions or removal requests
Email hello@dvidia.org for privacy questions, removal requests, or questions about terms and service agreements. Never post sign-in codes or private account details publicly. Available sign-in methods are shown on the login page. Google sign-in is not enabled.