Biometric Data
Notice
Contents
2. Where This Applies in VLStudio
3. The Structural Gap: Consent for People Who Are Not the Uploader
This notice explains how VLStudio's features can process biometric identifiers, facial geometry from video frames and voiceprints from audio, and what US state biometric privacy laws require around that processing. Read this alongside our AI Features Terms and Privacy Policy.
1. Why This Notice Exists
Several US states regulate biometric identifiers separately from general privacy law, with sharper consent and retention requirements than GDPR's Article 9 special-category framework.
Illinois Biometric Information Privacy Act (BIPA) requires written consent before a private entity collects or captures a person's biometric identifier or biometric information, and requires the entity to publish a retention schedule and a destruction guideline for that data. Consent has to happen before collection, not after.
Texas Capture or Use of Biometric Identifier Act (CUBI) and Washington State's biometric privacy law impose parallel, though not identical, consent and handling obligations.
2. Where This Applies in VLStudio
Three surfaces in VLStudio Desktop can process data that falls within these biometric statutes' scope:
- AI Visuals frame upload: when you use AI Visuals, raw JPEG frames extracted from your footage, up to six per turn, are sent to Google Gemini. If a frame contains a person's face, that face is included in the uploaded image. This can constitute the collection of a biometric identifier (facial geometry) depending on how the receiving system processes the image.
- Caption paths, including Groq Whisper: two of VLStudio's three caption paths send audio off-device for transcription, including the path that uses Groq's Whisper implementation. Audio containing a person's speech can carry voiceprint characteristics, which is biometric information under these statutes.
- Review uploads: the Review and collaboration feature uploads the actual project video to cloud storage so a reviewer or project owner can view it. If that footage contains third parties' faces or voices, faces and voices belonging to people who are not the uploader and who have not interacted with VLStudio directly are uploaded as part of this feature.
3. The Structural Gap: Consent for People Who Are Not the Uploader
This is the core unresolved problem and it is stated here plainly rather than described as solved.
BIPA-style statutes require consent from the specific person whose biometric identifier is being collected. When a VLStudio user uploads footage, that user can consent on their own behalf. That user cannot give legally effective, statute-compliant consent on behalf of any other person who happens to appear in that footage. A person filmed in someone else's project has not agreed to anything, has typically never used VLStudio, and has no relationship with us at all.
We are stating this as an open risk, not a resolved one. If your footage contains identifiable third parties, you are relying entirely on your own diligence in having obtained their consent before you upload; VLStudio's systems do not check for this.
4. Retention and Destruction
VLStudio does not currently maintain a biometric-specific retention and destruction schedule separate from its general data retention practice. Frames sent for AI Visuals and audio sent for cloud captioning are processed by Google Gemini or Groq under those providers' own terms (see our AI Features Terms, Section 5, on provider retention status: [[AI_PROVIDER_RETENTION]]). Video uploaded for Review is retained per the signed-URL and storage retention described in our Privacy Policy.
A dedicated biometric retention and destruction schedule, stating a fixed period after which facial geometry and voiceprint data derived through these features is destroyed, is not yet published. This is a gap we are working to close.
5. What This Means for You
If you are uploading your own footage of yourself, you are consenting on your own behalf by using the feature.
If your footage contains other identifiable people, whether that is an interview subject, a bystander, a colleague, or anyone else, you are responsible for having obtained their consent before you upload that footage into any AI Visuals, cloud caption, or Review workflow. VLStudio does not verify this and cannot verify this today.
6. Related Documents
- AI Features Terms: the full data-flow disclosure for AI Visuals and the caption paths, and the output-ownership and rights-warranty clauses.
- Privacy Policy: general personal-data processing, retention, and your rights.
- Terms of Service: the user-content rights warranty.
7. Contact
Questions about this notice: [[CONTACT_EMAIL_LEGAL]] (interim: vlstudiopartners@hotmail.com).
VLSTUDIO
← Back to site