AI processing
What leaves your workspace when Vidext generates something, who processes it, how long it is kept, and what Vidext will not do with it.
Vidext generates learning with AI, so producing a module means sending your material to model providers. This page explains what that involves: what leaves your workspace on a request, who processes it, what Vidext stores afterwards, and where the limits are today.
The live catalog is in the product
Admins and members can open Settings → Data & AI for the current inventory: exact model IDs, each provider's published handling of request data, and the date the catalog was last reviewed. This page explains how processing works; that page lists what is in use right now.
What Vidext commits to
- Your content is not used to train models. Vidext does not train AI models on Customer Content, and contractually prohibits its AI sub-processors from doing so.
- Your content stays yours. You keep your rights to the material you provide and to the content generated for your organization, subject to applicable law.
- Processing is purpose-limited. Customer Content is processed to perform the feature you asked for, provide support, maintain security, and meet legal obligations — not for other purposes.
- Nothing is sold or rented. Vidext does not sell or rent Customer Content or personal information to third parties.
The first commitment is contractual, not just a product behavior: it is written into the Data Processing Agreement in the Terms and Conditions, which binds every AI sub-processor Vidext uses.
What leaves your workspace on a request
A request carries your instruction plus the context that specific feature needs. Vidext does not send your whole organization or knowledge base to a model on every call.
- You provide content — messages, documents, images, audio, video, voice samples, or content from a source you authorized.
- Vidext selects context — the feature combines your instruction with the relevant source material, conversation history, and system instructions.
- A provider processes it — the request is routed to the model or media service suited to the task, including configured fallbacks when a provider is unavailable.
- Vidext stores the result — outputs, plus the operational records needed for history, editing, delivery, billing, reliability, and security.
What is processed and stored
The exact data depends on the feature you use.
| Category | What it covers |
|---|---|
| AI conversations | User messages, model responses, tool calls and results, reasoning parts, and attachments — stored to provide conversation history and an audit trail. |
| Documents and source material | Uploaded originals, extracted text, tables, page images, OCR results, and authorized connector content, used as generation context. |
| Images, voices, audio, and video | Reference images, narration text, voice samples, generated media, alignment data, and provider identifiers. |
| Operational metadata | Provider and model, token or character usage, cost, duration, status, cache state, and trace identifiers. |
What Vidext deliberately does not record — learner free text from quizzes, personal data in activity metadata — is covered in Data handling.
Who processes it
Different parts of a module are produced by different specialist providers: text generation and conversation, document OCR, audio transcription, text-to-speech narration, image generation, and avatar video rendering. Requests to language models are routed through a gateway that Vidext configures, rather than called directly.
Today those providers are Google, OpenAI, Anthropic, xAI, Mistral AI, Cloudflare, ElevenLabs, Inworld AI, and RunPod. Two lists are authoritative and kept current, and this page is neither:
- Settings → Data & AI — the live model catalog, what each provider receives, and each provider's published retention behavior, with a last-reviewed date.
- The DPA in the Terms and Conditions — Appendix A lists every sub-processor with the service it provides, its location, and the transfer safeguard that applies (adequacy decision, EU–US Data Privacy Framework, or Standard Contractual Clauses).
The model catalog changes as quality, availability, safety, and cost change. Sub-processor changes follow the DPA's notification and objection process.
Retention and deletion
Vidext's own storage and a provider's temporary processing are separate things.
- Content in Vidext is retained while the account and organization are active, or until it is deleted or a deletion request is completed, subject to contractual and legal obligations.
- Backups may keep account data for up to one year after account deactivation, or longer where law requires it — see the Privacy Policy.
- Provider-side processing may involve temporary retention for delivery, safety, abuse prevention, or legal compliance. Each provider's published standard handling is listed in Settings → Data & AI.
Current limits
There is no setting for a custom retention period, and Vidext does not claim end-to-end Zero Data Retention across the full processing chain. If your organization needs a specific retention commitment, raise it with the Vidext team — it is a contractual conversation, not a toggle.
Who can see your content
- Your organization. Content is scoped to the authenticated organization and its role-based permissions. See Access control.
- Vidext personnel and processors — only those authorized and only where access is needed to provide support, investigate security or abuse, operate the service, or meet legal obligations.
- Gateway logs. Vidext configures Cloudflare AI Gateway not to persist raw request and response bodies. Metadata such as provider, model, tokens, cost, status, and duration remains available for usage accounting, reliability, and incident investigation.
- AI observability. Production traces use compact mode: model and provider metadata, usage, timing, errors, prompt hashes, and content lengths may be recorded, but raw model inputs and outputs are excluded. Full payload tracing is restricted to preview environments.
Access, export, and deletion requests
To request access, correction, export, or deletion of personal data, write to datos@vidext.io. What happens to workspace records when a person or an organization is deleted is described in Data handling.
Where the formal commitments live
Security and Trust
ISO/IEC 27001 certification, access safeguards, transfers, and incident response.
Privacy Policy
Data categories, purposes, rights, transfers, and account-level retention.
DPA and sub-processors
Processor obligations, the training restriction, international safeguards, and the current provider list.
Data handling
What Vidext stores first-party, what it strips, and what deletion removes.
Last updated on