Privacy policy

What we collect, why, who processes it for us, how long we keep it, and what you can ask of us. The affiliate terms and the copyright notice page cover their own subjects.

Last updated 7 October 2026.

1. Who we are

  • Pellio is run by ScaleMath Ltd, 128 City Road, London EC1V 2NX, United Kingdom (company registered in England and Wales; VAT number GB417393977). Write to support@pellio.io about anything in this policy.
  • This policy covers pellio.io, the Pellio app (pellio.io/app), the API (api.pellio.io), the player (play.pellio.io and the embed script customers put on their sites), the WordPress plugin, and our emails.

2. Two roles

  • For visitors to pellio.io, people with a Pellio account, people who write to us and affiliates, we are the controller: we decide what we collect and why, and this policy applies in full.
  • For people who watch videos our customers host with Pellio ("viewers"), the customer is the controller and we are their processor. What a customer collects about you through their videos (whether you are identified by name or email, whether a lead form is shown) is their decision, under their own privacy policy. We process viewer data only on their instructions and as described in section 5.

3. What we collect from visitors and customers

  • Account: your name, email address, password (stored as a hash) or Google sign-in, two-factor settings, profile picture, and the workspaces you belong to.
  • Content: the videos, captions, transcripts, thumbnails, titles, descriptions and settings you upload or create, and the share links, embeds and playlists you make. Videos are stored on our hosting provider and a copy of each original on a second provider (section 7).
  • Billing: the name, billing address and VAT number you give us, the plan you choose, invoices and receipts. Card details go to Stripe and never reach our servers; we keep the card brand, the last four digits and the expiry date to show you which card is on file.
  • Usage and security: sign-ins (time, address, browser), API keys and their use, connected apps, the audit log of changes in your workspace, storage and bandwidth use, and server logs kept for security and troubleshooting.
  • Support and forms: what you send through "Help & support" in the app, the contact form, the beta access request, the report-a-video form, DMCA notices and counter-notices, and our replies. Support requests are handled in Missive (section 7).
  • Affiliates: your application, your affiliate code, clicks on your link (as counts per day; a visitor’s address is kept only as a hash, for that day), the workspaces linked to you, commissions, and the bank details, address and VAT number you give us to be paid.
  • Emails: whether an email we sent bounced or was marked as spam, so we stop sending to addresses that can’t receive mail.

4. Why, and on what basis

  • To provide the service you signed up for: hosting, playing and protecting your videos, analytics, billing, support (performance of a contract).
  • To keep Pellio safe and running: sign-in security, fraud prevention, abuse and copyright handling, backups, monitoring (our legitimate interests, and legal obligations such as copyright law).
  • To run the affiliate program and pay affiliates, and to keep the financial records the law requires (contract and legal obligation).
  • To send you emails about your account, your videos, your billing and your requests. Reports and marketing emails are opt-in and every one has a way to stop them. We don’t sell personal data and we don’t show advertising.

5. Viewers: what the player records

  • When a video plays, the player sends us: which video, how much of it was watched and when, playback quality (start time, stalls, errors, resolution), the browser and device type, the page the video is on, and the viewer’s IP address, from which we derive an approximate country and then discard the address from analytics. This lets customers see how their videos perform.
  • If the customer’s site or learning platform identifies you to the player (a name, an email, a learner ID), or you fill in a form in the video, the customer sees who watched. Pellio shows that only to the customer’s workspace and to integrations the customer connects (their CRM, their LMS, Zapier).
  • For compliance features (watch-to-complete lessons, attestations, learner logs, SCORM and cmi5 packages), the player records the seconds actually watched so the customer can prove completion.
  • A viewer can report a video from the player ("Report this video"); the report goes to our trust and safety team.
  • To exercise your rights over viewer data, contact the customer whose video you watched; we help them answer. Write to us if you can’t reach them.

6. Cookies and local storage

  • Signing in sets a session cookie on pellio.io so you stay signed in; a second cookie protects against cross-site request forgery. They are first-party and deleted when you sign out or the session expires.
  • Preferences such as your theme, the workspace you were last in, and unsent drafts are kept in your browser’s local storage, never sent anywhere.
  • If you arrive through an affiliate’s link (a pellio.io address with ?ref=), we set a first-party cookie named pellio_ref holding the affiliate’s code for 60 days, so they are credited if you create a workspace. It contains nothing about you and is not used for anything else. Delete it in your browser settings if you’d rather we didn’t keep it.
  • The player sets no cookies to track you across sites. When a customer runs an A/B test on a video, a small partitioned cookie on play.pellio.io remembers which version you saw so it doesn’t change between visits; it cannot be read by other sites.
  • We use no advertising cookies, no third-party analytics scripts and no social media pixels on pellio.io.

7. Who else processes data for us

  • Railway (hosting of our servers, database and video storage), Backblaze (a copy of every original video, for safety), Cloudflare (network security and delivery for pellio.io, api.pellio.io and play.pellio.io), Stripe (payments and invoices), Postmark (sending our emails), Missive (our support inbox), Google (sign-in with Google, if you use it), ElevenLabs (AI dubbing, only for a video whose owner orders a dub), Revolut (paying affiliates), and MaxMind’s GeoIP database (run on our own servers to turn an IP address into a country; nothing is sent to MaxMind).
  • Our help center, blog and changelog are published from a WordPress site we run; reading them involves no account.
  • Integrations you connect yourself (HubSpot, Mailchimp, Customer.io, ActiveCampaign, Klaviyo, Zapier, an LMS, an AI assistant through MCP) receive the data you choose to send them, under their own terms.
  • Some of these providers are in the United States. Transfers from the UK rely on the UK-US data bridge where the provider is certified, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.

8. How long we keep things

  • Your account and content: while your account exists. A video you delete stays in the Trash for 30 days, restorable, then it and its files are removed; the safety copy of the original is removed within a further 30 days. When you delete your account, the same applies to everything in it.
  • Viewer analytics: as long as the customer’s workspace exists, so their statistics stay complete.
  • Invoices, receipts, affiliate payouts and other financial records: six years after the year they relate to, as UK tax law requires.
  • Support conversations, reports and copyright notices: kept after the account is closed, so we can show what was said if a dispute arises. Evidence kept for a trust and safety decision is retained for one year.
  • Server and security logs: a short period, measured in weeks.

9. Your rights

  • You can see, correct, download or delete the personal data we hold about you, object to or restrict some processing, and withdraw consent where we rely on it. Most of this you can do yourself in Settings; for the rest, write to support@pellio.io and we answer within a month.
  • You can complain to the Information Commissioner’s Office (ico.org.uk) or, if you are in the EU, to your national data protection authority. We would rather hear from you first.
  • Pellio is for businesses and adults; we don’t knowingly collect data from children under 16, and we delete it if we learn we have.

10. Changes

  • We update this policy when the service changes. The date below says when; a material change is announced by email to account holders before it takes effect.