1. Introduction
Welcome to Superdegree ("we", "our", or "us"). We are committed to protecting your privacy and personal information.
This Privacy Policy explains how SUPER DEGREE (ABN 95 926 075 671) (“Superdegree”) collects, uses, discloses, and safeguards information when you use our AI-powered video and documentation platform at super.degree (the "Service").
Superdegree turns screen recordings and web applications into edited product videos and written guides. Because of what the product does, two categories of data deserve particular attention, and each has its own section below: the contents of the recordings you give us (section 2.2) and what our Ask agent sees while it operates a browser inside an application you nominate (section 2.3).
By using our Service, you acknowledge the collection and use of information as described in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
We may collect:
- Account Information: Email address and password for authentication. When you sign in with Google, we collect your name, email address, and profile picture URL as provided by your Google account settings.
- Organisation Information: Organisation name, member list, roles, invitations, and access requests.
- Payment Information: Payment and subscription information processed securely through Stripe. We do not store full payment-card details.
- User Content: Screen recordings and uploaded video, audio files, images, documents, task instructions and prompts you write, and URLs of applications you ask the agent to work in.
- Voice Samples: Audio you record or upload to create a custom or cloned voice.
- Generated Content: Transcripts, narration scripts, synthesised audio, edited videos, captions, avatar segments, images, and written guides produced from your inputs.
- Customization Data: Logo uploads, brand colours, background images, formatting preferences, saved templates, and project organisation.
- Communications: Messages sent to us, including support requests, emails, waitlist and feature-access requests, feedback, meeting communications, and other business correspondence.
2.2 Recordings, Transcripts, and What They Contain
When you upload or record video, we process the entire file. This means:
- Everything visible on screen is captured, including application data, customer names, email addresses, documents, or other personal information displayed during the recording.
- Speech in the recording may be transcribed to text, and that transcript may be used to generate narration scripts, captions, and written guides.
- Video frames, audio, transcripts, and related content may be sent to our AI service providers for processing as described in section 4.
We do not screen recordings for sensitive content before processing them. Processing is generally automated and may begin as soon as you submit content.
You decide what appears in a recording and, under our Terms of Service, are responsible for having the rights, permissions, notices, consents, or other lawful authority required to record and submit it. We recommend using test or demonstration data rather than real customer records where practicable.
Where a recording contains other people's personal information and you determine why and how that information is processed, you act as the controller of that information and we process it on your behalf and on your instructions.
2.3 Ask Agent Session Data
When you run the Ask agent, it operates a browser hosted by our cloud-browser provider against the application you nominate.
During a run we may collect and process:
- Page Content: Screenshots, page text, and structural information from screens the agent visits. This may include real data belonging to you, your organisation, or your customers as displayed in the application.
- Navigation and Action Data: URLs and hostnames visited, elements clicked, text entered by the agent, approved execution plans, and traces of actions performed.
- Session Recordings: Recordings of browser sessions where applicable to the functionality used.
- Learned Application Knowledge: Notes, rules, and navigation information the agent builds about an application to help later runs work more reliably. This may be stored per organisation and hostname.
- Saved Applications: Application hostnames your organisation has added.
- Diagnostic Information: Execution traces, screenshots, errors, technical metadata, and other information used to investigate failed or unusual executions, troubleshoot problems, and improve reliability.
Sign-in and credentials. You sign in to the target application yourself through a live view of the browser session. We do not ask for or intentionally store your passwords for third-party applications in our own database.
The resulting authentication state, including session cookies, may be held in a persistent browser context by our cloud-browser provider so that you do not need to sign in again for every run. Browser contexts are isolated according to the Service's access-control mechanisms.
Anything you enter during sign-in necessarily passes through the cloud-browser provider's infrastructure. You can ask us to delete a stored browser context by contacting support.
Page content captured during a run may be transmitted to AI providers so that the model can interpret the page and determine or perform the requested actions. You should assume that information visible on a screen reached by the agent may be transmitted to those providers.
2.4 Voice and Likeness Data
If you use custom or cloned voices, we collect the voice sample you provide and send it to our speech provider to create the requested voice. We may store the source sample and an identifier associated with the generated voice against your organisation.
If you use avatar or other likeness-generation functionality, we may process the source image, audio, or video of the relevant person.
Depending on the jurisdiction and processing performed, voice recordings, voice information, facial information, or information derived from them may constitute biometric, special-category, or other sensitive personal information.
Under our Terms of Service, you must be the person represented by the applicable sample or hold the necessary rights, permissions, notices, consents, or other lawful authority before using these features.
We use voice samples to provide and support the custom or cloned voice functionality requested through the Service.
2.5 Automatically Collected Information
We may automatically collect:
- Device Information: Browser type, operating system, and device information.
- Usage Data: Features used, videos and guides generated, minutes of video processed, agent runs started, credits consumed, session duration, and interactions with the platform.
- Log Data: IP address, access times, pages viewed, API requests, application logs, errors, and exceptions.
- Analytics and Session Replay Data: Page views, custom events, feature usage, user behaviour patterns, and session interaction or replay information.
- Cookies and Tracking: Session cookies, authentication tokens, and similar technologies.
- Transaction Data: Credit purchases and grants, usage history, per-member spend, transaction timestamps, subscription information, and payment status.
Analytics and session replay information may be associated with account or user identifiers, including names and email addresses, where reasonably necessary for product analytics, support, troubleshooting, security, and service improvement.
2.6 Content Processing Data
We may process:
- Task Metadata: Job status, progress indicators, durations, workflow state, and processing parameters.
- Media Files: Source recordings, intermediate frames, rendered videos, generated audio, images, and exported files.
- Timing Information: Word-level audio timestamps, video durations, and animation parameters.
2.7 Google Sign-In Data
When you sign in with Google OAuth, we access and store only the information required for authentication and account management, such as:
- Email address;
- Profile name; and
- Profile picture.
Superdegree's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google Sign-In information for authentication and account-management purposes and do not use Google Sign-In to access unrelated Google account content.
3. How We Use Your Information
We use information to:
- Deliver the Service: Provide video editing and rendering, transcription, narration, captioning, avatar generation, documentation creation, media hosting, and related functionality.
- Provide AI Functionality: Process content through AI services to generate or transform transcripts, scripts, speech, voices, images, video, documentation, and other outputs.
- Operate Agent Runs: Operate cloud browsers at your instruction, interpret content displayed on screen, execute requested workflows, and produce outputs.
- Manage Accounts and Organisations: Create accounts and organisations, authenticate users, handle invitations and access requests, and maintain session security.
- Process Billing: Process subscriptions and credit purchases, meter usage, grant or deduct credits, and manage payment-related activities.
- Store Content: Store recordings, projects, generated media, documentation, and customization preferences.
- Perform Background Processing: Queue and execute asynchronous jobs for ingest, media processing, audio synthesis, rendering, and agent runs.
- Communicate With You: Send service notifications, processing updates, access decisions, support responses, implementation communications, and other business communications.
- Analyse and Improve the Service: Evaluate usage, generated outputs, prompts, workflows, failures, reliability, safety, and performance; troubleshoot problems; conduct quality assurance; and improve features and user experience.
- Enable Sharing and Integrations: Enable share links, exports, publishing, and Customer-selected integrations.
- Maintain Security: Detect, prevent, investigate, and address technical problems, security incidents, fraud, abuse, or unauthorised activity.
- Comply With Legal Obligations: Comply with applicable law and enforce our agreements.
- Perform Administrative Functions: Maintain operational and security records, perform administrative actions, and maintain platform integrity.
We do not use your Customer Content to train or fine-tune our own general-purpose artificial intelligence or machine-learning models unless you expressly authorise us to do so.
We do not sell your personal information.
4. AI Processing and Third-Party Services
Our platform relies on third-party providers to deliver and support the Service.
Not every provider processes information for every user. Processing depends on the features you use, your configuration, and operational requirements.
4.1 AI and Content Generation
We may use:
- Google AI services: AI and machine-learning processing for applicable AI-assisted functionality.
- OpenAI: AI and machine-learning processing for applicable AI-assisted functionality.
- Inworld: Speech-to-text transcription, speech generation, and custom or cloned voice functionality.
- fal.ai: AI-assisted image, video, audio, avatar, and other media generation or processing.
Depending on the functionality used, these providers may receive Customer Content, prompts, instructions, screenshots, images, audio, video, generated outputs, or related information necessary to perform the requested processing.
We use AI providers under applicable business, API, or other service terms and, where available for the relevant service, use terms or configurations that restrict Customer Personal Data from being used to train general-purpose models without authorisation.
4.2 Cloud Browser Infrastructure
Ask agent runs use cloud-browser infrastructure provided by Browserbase.
Pages visited during a run, information displayed on those pages, information you enter into the live browser, Customer instructions, execution information, and persistent authentication state may be processed through Browserbase infrastructure.
Browserbase may retain browser-session recordings for up to 30 days as part of its observability infrastructure.
Authentication state used to keep you signed in between runs may be stored separately in a persistent browser context. We do not intentionally store passwords you enter into third-party applications in our own database.
Persistent browser contexts can be deleted when they are no longer required.
4.3 Infrastructure and Business Services
We may use:
- Supabase: Managed database, authentication, database backups, and supporting application infrastructure.
- Vercel: Application hosting, delivery, and supporting infrastructure.
- Cloudflare: Private object storage, media delivery, and network infrastructure, including Cloudflare R2.
- Amazon Web Services (AWS): Cloud infrastructure used for video rendering and temporary media processing.
- Inngest: Workflow orchestration and background-job processing.
- Resend: Transactional and notification email delivery.
- Google Workspace: Business productivity, communication, video conferencing, documentation, file storage, and collaboration.
- SpaceMail: Business email hosting and communications.
Customer Personal Data may therefore be included in emails, support communications, documents, files, meeting recordings or transcripts, implementation records, and other business records created or received in connection with providing and supporting the Service.
4.4 Payments and Analytics
We may use:
- Stripe: Subscription management, billing, payment processing, and related payment infrastructure.
- PostHog: Product analytics, usage analysis, session replay, error and exception monitoring, troubleshooting, and service-improvement analytics.
- Microsoft Clarity: Session analytics on our public marketing website.
Stripe may collect payment-card and certain billing information directly from you. We do not intentionally receive or store full payment-card details collected directly by Stripe.
4.5 Customer-Selected Integrations and External Services
You may choose to connect Superdegree to third-party services, publishing destinations, or integrations.
For example, where you elect to publish content to YouTube, information necessary to perform that publishing operation — such as OAuth information, channel information, selected video content, and video metadata — may be transmitted to Google or YouTube.
Where a third party processes information independently under its own terms or directly at your instruction, that third party may act independently of Superdegree for that processing.
4.6 Data Handling by Third Parties
We select service providers appropriate to the functions they perform and use contractual and other safeguards where appropriate.
Third-party providers may have their own retention periods, security measures, processing locations, and legal obligations.
Where we use a third party as a processor or sub-processor of Customer Personal Data, we use appropriate contractual arrangements as required by applicable data protection law.
4.7 Google API Services
Superdegree's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Data Sharing and Disclosure
We may share information in the following circumstances:
- Service Providers: With providers that process information as necessary to operate, support, secure, and improve the Service.
- Within Your Organisation: Content created within an organisation workspace may be accessible to other members according to their role. Administrators may be able to manage content, membership, and organisation usage.
- Shared or Published Content: When you intentionally create a share link, publish content, or use an external integration, the applicable content may be accessible to recipients or third parties you select.
- Legal Requirements: Where required by applicable law, regulation, legal process, or governmental request, or where reasonably necessary to protect rights, security, or safety.
- Business Transfers: In connection with a merger, acquisition, financing, reorganisation, sale of assets, or similar transaction.
- With Your Consent or Instruction: Where you authorise or instruct us to share information for a particular purpose.
- Aggregated or De-identified Information: We may use or share information that has been aggregated or de-identified so that it no longer constitutes personal information under applicable law.
We do not sell personal information or share it for cross-context behavioural advertising as defined by the California Consumer Privacy Act.
6. Data Security
We implement technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures include, as appropriate:
- Encryption: Encrypted transport for data in transit and encryption at rest provided by applicable managed database and storage infrastructure.
- Authentication: Secure authentication and session-management mechanisms.
- Access Controls: Database and server-side controls designed to restrict access according to authenticated user and organisation context.
- Tenant Isolation: Logical controls designed to segregate Customer organisations and prevent cross-tenant access.
- Private Media: Customer media is stored in private object storage and accessed through authenticated or time-limited mechanisms except where you intentionally publish or share particular content.
- Administrative Security: Multi-factor authentication on administrative infrastructure, source-control, and service-provider accounts where supported.
- Secrets Management: Administrative credentials, API credentials, and other secrets are maintained using access-controlled environment or secrets-management mechanisms.
- Security Testing: Testing designed to verify Customer and tenant isolation across relevant database, application, privilege, and media-access paths.
- Logging and Monitoring: Operational and security logging used for troubleshooting, reliability, security, and incident investigation.
- Payment Security: Payment-card processing is handled by our payment provider and we do not intentionally store full payment-card details.
No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
You are responsible for maintaining the confidentiality and security of your account credentials.
Additional information about our security practices is available on our Security page.
7. Data Retention
We retain personal information only for as long as reasonably necessary to provide and support the Service, comply with your instructions, fulfil the purposes described in this Privacy Policy, or meet applicable legal obligations.
Our principal retention practices include:
- Active Account Data: Retained while your account is active and as reasonably necessary to provide and support the Service.
- Source Recordings and Generated Content: Recordings, projects, videos, guides, images, audio, prompts, and other Customer Content are generally retained until you delete them or close your account.
- Deleted Content: Deleted projects and associated content may remain recoverable for up to 30 days. Following that period, we permanently delete the content from active systems, subject to legal obligations, technical processes, and applicable backup retention.
- Temporary Media Processing: Intermediate media files created during rendering, compression, and other processing workflows are stored temporarily and automatically deleted through lifecycle controls. Depending on the processing workflow, temporary artifacts may remain for up to 7 days.
- Agent Project Data: Agent session information associated with a project, including relevant screenshots, action information, and outputs, may be retained with that project.
- Agent Diagnostic Data: Diagnostic evidence, execution traces, and related technical information separately retained from failed or investigated Agent executions are ordinarily retained for no more than 90 days. They may be retained longer where reasonably necessary to investigate a security incident, respond to a support request, establish or defend legal claims, or comply with applicable law.
- Browserbase Session Recordings: Browserbase may retain browser-session recordings for up to 30 days as part of its observability infrastructure.
- Learned Application Knowledge: Information learned about an application may be retained until the saved application or applicable organisation information is deleted or is otherwise no longer required.
- Persistent Browser Contexts: Authentication state used to maintain sign-in to a third-party application may be retained until you or we delete the applicable browser context or it is otherwise no longer required.
- Voice Samples and Clones: Voice information may be retained while necessary to provide the applicable custom or cloned voice functionality, subject to applicable provider retention processes.
- Analytics and Session Replay: Identifiable analytics and session replay information may be retained for as long as reasonably necessary for analytics, service improvement, Customer support, troubleshooting, security, and related operational purposes. We periodically assess whether identifiable information remains necessary and may delete, anonymise, or aggregate it when it is no longer reasonably required.
- Aggregated or De-identified Data: Information that has been aggregated or de-identified so that it no longer constitutes Personal Data may be retained for longer periods.
- Security and Administrative Records: Security logs, administrative actions, and related records may be retained for as long as reasonably necessary for security, incident investigation, fraud prevention, dispute resolution, and legal or compliance purposes.
- Transaction and Business Records: Billing, accounting, transaction, contractual, and administrative records may be retained where reasonably necessary for tax, accounting, fraud-prevention, contractual, dispute-resolution, or other legal purposes.
Account Deletion
When you request deletion of your account or workspace, Customer Personal Data may remain recoverable for up to 30 days.
Following that period, we delete personal information from active systems without undue delay, subject to applicable legal obligations and backup-retention processes.
We may perform earlier permanent deletion where requested and technically and legally practicable.
Backups
We maintain automated database backups for disaster-recovery and business-continuity purposes.
Our database backups are currently retained on a rolling basis for up to 7 days. Information deleted from active databases may therefore remain in backups until the applicable backup expires through the ordinary backup lifecycle.
Backups are not used for ordinary production processing.
If a backup is restored, we take reasonable steps to reapply relevant deletion actions where appropriate.
Object-based Customer media is not included in these database backups and is subject to its applicable media-storage and deletion processes.
Other service providers may maintain limited backup or disaster-recovery copies according to their applicable infrastructure and retention practices.
8. Your Rights and Choices
Depending on your location and applicable law, you may have rights including:
- Access: Request access to personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of personal information, subject to applicable exceptions.
- Portability: Request a copy of certain information in a structured format where applicable.
- Restriction: Request restriction of processing in circumstances provided by applicable law.
- Objection: Object to certain processing where applicable.
- Marketing Opt-out: Unsubscribe from marketing communications. Certain operational or service-related communications may still be necessary.
- Withdraw Consent: Withdraw consent where processing relies on consent, without affecting processing that occurred before withdrawal.
- Delete a Browser Context: Ask us to delete a stored browser context used by the Ask agent.
- Delete a Custom Voice: Remove a custom or cloned voice and associated information through available Service functionality or by contacting us.
To exercise applicable rights, contact us at [email protected].
We may need to verify your identity before fulfilling a request. Where you use the Service through an organisation, certain requests concerning Customer Personal Data may need to be directed to that organisation because it controls the relevant workspace and content.
EEA and UK
Where the GDPR or UK GDPR applies, our legal bases may include:
- performance of a contract;
- our legitimate interests, including operating, securing, troubleshooting, and improving the Service;
- compliance with legal obligations; and
- consent where required for particular processing.
Where Superdegree processes Customer Personal Data on behalf of a business Customer, the Customer generally determines the applicable legal basis for that processing.
Australia
Where the Australian Privacy Act 1988 (Cth) applies, you may have rights to access and correct personal information and to make a complaint concerning our handling of personal information.
9. Personal Data in Customer Content
Where recordings, documents, prompts, Agent sessions, browser pages, or other Customer Content contain personal information relating to other people — such as colleagues, customers, prospects, or end users — the Customer generally determines the purposes and means of processing that information and Superdegree processes it on the Customer's behalf.
Customers are responsible for having the rights, permissions, notices, consents, lawful bases, or other authority necessary to provide that information to Superdegree and instruct us to process it.
If an individual contacts us directly regarding personal information contained in a Customer's content, we may refer the individual to the relevant Customer where appropriate.
Business Customers requiring a Data Processing Addendum may request one at [email protected].
10. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service and understand its use.
These may include:
- Essential Cookies: Required for authentication, security, session management, and core functionality.
- Analytics Technologies: Used to understand product usage, user flows, interactions, and performance.
- Preference Technologies: Used to maintain settings and preferences.
You can configure your browser to restrict cookies, although disabling essential cookies may prevent parts of the Service from functioning correctly.
Product Analytics and Session Replay
We use PostHog, hosted in the United States, for product analytics, usage analysis, error and exception monitoring, and session replay within the Service.
Information collected may include page views, feature usage, user flows, interactions, browser or device information, diagnostic information, and account or user identifiers where reasonably necessary.
We use this information to understand how the Service is used, troubleshoot problems, provide support, evaluate reliability and performance, and improve the product.
Marketing Website Session Analytics
Our public marketing website uses Microsoft Clarity, which may record interactions such as clicks, scrolling, and mouse movement to produce heatmaps and session replays.
This applies to our public marketing pages rather than the signed-in Superdegree product and is subject to Microsoft's applicable privacy practices.
11. Children's Privacy
The Service is not intended for children under 16 years of age, consistent with the eligibility requirements in our Terms of Service.
We do not knowingly collect personal information from children under 16. If you become aware that a child has provided personal information to us, please contact us.
12. International Data Transfers
Your information may be processed in Australia, the United States, and other countries in which Superdegree or our service providers operate.
This may include:
- United States: AI services, analytics, cloud-browser infrastructure, rendering, storage, payment processing, and other supporting services.
- Australia and Global Cloud Infrastructure: Business operations, database, storage, delivery, and supporting infrastructure depending on the service used.
- Other Provider Locations: Third-party providers may process information in jurisdictions in which they or their infrastructure operate.
These countries may have privacy and data-protection laws different from those in your jurisdiction.
Where applicable law requires a particular mechanism for an international transfer, we use appropriate mechanisms and safeguards, which may include contractual protections such as the European Commission's Standard Contractual Clauses and applicable UK transfer mechanisms.
We also use technical and organisational measures appropriate to the nature and risks of the processing.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our processing practices, service providers, or applicable legal requirements.
When we make changes, we will update the "Last updated" date at the top of this policy.
Where appropriate or required by law, we may provide additional notice of material changes.
14. California Privacy Rights
If the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), applies to you, you may have rights including:
- the right to know or access certain personal information;
- the right to request deletion, subject to applicable exceptions;
- the right to request correction of inaccurate personal information;
- the right to receive information concerning categories of personal information collected, used, or disclosed;
- the right to opt out of the sale or sharing of personal information where applicable; and
- the right not to receive discriminatory treatment for exercising applicable privacy rights.
Superdegree does not sell personal information or share personal information for cross-context behavioural advertising as those terms are defined by the CCPA.
To submit an applicable California privacy request, contact [email protected] and identify the request as a California privacy request.
Where Superdegree processes personal information on behalf of a Customer as a service provider or contractor, requests concerning that information should generally be directed to the relevant Customer.
15. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or your privacy rights, contact:
Superdegree
ABN 95 926 075 671
Email: [email protected]
Website: super.degree
For Australian users, if you have a complaint about how we handle your personal information, please contact us first so that we can investigate and respond.
If you are not satisfied with our response, you may have the right to contact the Office of the Australian Information Commissioner (OAIC).