Sevev← Back to sign in

Privacy Policy

Last updated: September 6, 2026

Who we are

Sevev (“Sevev”, “we”, “us”) is a video-review workspace for creative teams, operated by Or Shimonov, Authorized Dealer (עוסק מורשה) no. 321693681, registered in Israel under the business name MUVEWEAR, and available at sevev.io. This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to everyone who uses Sevev: workspace owners, the team members they invite, and clients who review a video through a shared link.

Information we collect

  • Account information: When you sign in with Google or with an email and password, we receive your name, email address, and profile picture. Passwords are handled by our authentication provider and are never stored by us in readable form.
  • Google Drive connection (optional, workspace owner only): A workspace owner may connect their Google Drive so the team can upload footage and cuts straight into it. New connections ask for full Google Drive access so active workspace admins and editors can browse, download, create folders, and choose upload destinations through Sevev, including personal folders in the connected account. Older per-file connections remain limited until the owner reconnects. To keep the connection alive we store a Google refresh token, encrypted at rest (AES-256-GCM) on our server. See “Google user data” below for exactly what we do with it.
  • Videos: Videos reach Sevev three ways: you paste a Google Drive link you have shared as “Anyone with the link”; you upload a file through Sevev into the connected Drive; or you upload a file directly to our video provider. In every case the video is encoded and streamed by our video provider so it can be reviewed. For Drive-backed videos we also keep a copy of the original file in our private storage (the “master archive”), so review and downloads keep working even if the Drive copy is moved or removed.
  • Content you create: Projects, videos and their versions, timestamped comments, drawings, voice notes, file attachments, raw-footage links, deadlines, and project/deal details you enter.
  • Reviewer information: When someone opens a share link and signs in to comment, we record the name, email, and picture from their sign-in so their feedback is attributed. If they comment without signing in, we store the name they type. A reviewer’s name and picture are kept in their browser for 30 days so they stay recognized on that link.
  • Your clients’ contact details: If you add a client’s email address or phone number to a project, we store it and use it to send them review links and notifications about their project. A phone number is sent to our messaging provider to deliver a WhatsApp or SMS message.
  • Voice recordings: A comment can be a recorded voice note. That is an audio recording of your voice, stored privately and played back only to people who can already see that video.
  • Financial records: If you use the money features, we store deal totals, payments, editor rates, VAT settings, and any notes you add to them. These are visible to the workspace owner only.
  • Viewing activity: When a shared video is opened we record who opened it and when, so the studio knows their client has seen the cut.
  • Technical data: Basic request information such as IP address and browser type. IP addresses are used only in memory to rate-limit abuse — we do not store them in our database or write them to logs.
  • Diagnostics: If the app crashes in your browser, we email ourselves the error, the page address you were on, and your browser version so we can fix it.

Cookies and local storage

Sevev uses only strictly necessarycookies: the session cookie that keeps you signed in, and an interface-language preference cookie so pages open in your chosen language. We set no analytics, advertising, or tracking cookies, and we do not use third-party trackers, which is why you will not see a cookie banner. Preferences such as your theme, list layout, and a reviewer’s remembered name are kept in your browser’s local storage and never leave your device.

When a workspace owner opens Google’s file window from inside Sevev, that window is a Google page and is governed by Google’s own cookies and privacy policy.

How we use your information

  • To provide the service: Host and play your videos, capture and display review comments, place uploads in your Drive where you tell us to, notify collaborators and clients, and keep projects organized.
  • To secure the service: Authenticate you, enforce who may access which workspace, prevent abuse, and diagnose problems.
  • To communicate: Send transactional messages you ask for — invitations, review notifications, and account or security notices. We do not send marketing messages.

We do not sell your personal information, and we do not use it to serve advertising.

Google user data

Sign-in. If you sign in with Google, Sevevrequests only your basic profile — name, email address, and profile picture — to identify your account.

Google Drive (optional). If a workspace owner connects Google Drive, Sevevrequests the drive scope for full Drive access. Active workspace admins and editors can browse and download files across the connected account, including personal folders, and upload to folders the account can write to. Existingdrive.fileconnections remain limited until reconnected. With the owner’s permission we:

  • create project folders and upload the files your team sends through Sevev into the folder you choose;
  • list the folders and files Sevev can see, so team members can choose a destination in Sevev’s own folder browser;
  • copy a video’s original file into our private master archive so review keeps working;
  • keep Drive sharing unchanged on full-access connections. Authorized team members download through Sevev; videos selected for review are sent to Cloudflare through temporary, single-video links. Legacy per-file connections may still set “Anyone with the link” on uploaded folders or review imports; sharing already set in Google Drive is unchanged by an upgrade.

The refresh token that keeps the connection alive is stored encrypted at rest and used only on our servers. Full-access Google tokens stay on the server. Folder listings and downloads are authorized through Sevev; upload bytes go directly from the browser to Google through a file-specific upload session. Legacy per-file connections can send a short-lived, narrowly scoped access token to authorized members for Google’s picker.

Sevev’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not:

  • use Google user data for advertising;
  • sell Google user data;
  • use Google user data to train generalized or non-personalized AI/ML models;
  • transfer Google user data to anyone except as needed to provide the service, comply with the law, or as part of a merger or acquisition with prior notice to you;
  • allow humans to read your Google data, except with your explicit consent, where required for security or to comply with the law, or on de-identified/aggregated data for internal operations.

You can disconnect Google Drive at any time from Settings — we delete the stored token and revoke it at Google — and you can revoke Sevev’s access to your Google account at myaccount.google.com/permissions.

How we share information

We share data with service providers who process it on our behalf to run Sevev. We do not share your personal information with anyone else except as described here or at your direction (for example, when you invite a reviewer to a project).

  • Supabase: Database, authentication, and private file storage (voice notes, attachments, backups, the master archive).
  • Vercel: Application hosting and delivery.
  • Cloudflare Stream: Video encoding, storage, and streaming.
  • Google: Sign-in (basic profile). When Google Drive is connected: folder creation, uploads, sharing settings, and file listings as described above. When you import a video by public link, the file is fetched from Google’s public download endpoint.
  • Resend: Transactional email delivery — receives recipient addresses and the contents of the notification or diagnostic message.
  • Twilio: WhatsApp / SMS delivery, where enabled — receives your client’s phone number and the message text.

We may also disclose information if required by law, or to protect the rights, safety, and security of Sevev, our users, or the public.

Who can see your content

Each workspace is isolated. Your projects, videos, comments, deadlines, and deal details are visible only to members you invite to your workspace and are never visible to other Sevev customers.

  • Workspace members: People you invite (admins, editors, reviewers) see the projects and videos in your workspace, at the level their role allows. With a full Drive connection, active admins and editors can browse and download files across the owner’s connected Drive, including personal folders, and choose writable upload destinations. Reviewers and viewers do not receive this Drive browsing access. Financial figures are visible to the workspace owner only.
  • Clients with a review link: Someone opening a share link sees the shared video and its versions, its comments, and the name and picture of the studio that sent it — so they know who they are reviewing for. They do not see your other projects, your team, your email, or any workspace data beyond that shared video.
  • Commenters: When a reviewer comments, their name and picture are shown next to their feedback to everyone who can see that video. Their email is not shown to reviewers.
  • Anyone holding a Drive link: Folders and files Sevev shares as “Anyone with the link” in your Drive can be opened by anyone who has that link. Treat those links as you would the files themselves.

Data retention

We keep your information for as long as your account is active or as needed to provide the service. When you delete a comment, video, or project, we delete both the record and the files that belong to it — voice notes, images, attachments, the streaming copy, and the master-archive copy. Files that live in your own Google Drive stay there, under your control. To delete your whole account, email us and we will remove your workspace and its files.

We take an encrypted nightly backup, kept for 14 days and then destroyed, so deleted data can persist there for up to that long. We may also keep records we are required to keep by law.

Your choices and rights

Under Israel’s Privacy Protection Law — and, where it applies, the EU/UK GDPR — you have rights over your personal data:

  • Access and correction: You can view and edit your account information and content in the app, or ask us for a copy of the personal data we hold about you.
  • Deletion: Delete any comment, video, or project in the app and its files go with it. To close your account entirely, email ohr13shimonov@gmail.com and we will delete your workspace, its files, and your sign-in.
  • Export: Ask us for an export of your workspace content and we will provide it in a common format.
  • Objection and restriction: Ask us to stop or limit a particular use of your data; we will comply unless the law requires otherwise.
  • Disconnect Google: Revoke Sevev’s Drive connection in Settings, or its sign-in access from your Google account permissions page, at any time.
  • Messages: If you receive a notification from us on behalf of a studio and no longer wish to, reply to the message or contact us and we will stop.

To exercise any of these, email ohr13shimonov@gmail.com. We respond within 30 days. You may also complain to the Israel Privacy Protection Authority or, where the GDPR applies, to your local supervisory authority.

Security

We protect your data with encryption in transit, encryption at rest for stored Google tokens, access controls that keep each workspace’s data separate, and server-side checks on every request. Every video stream and thumbnail is served through short-lived signed addresses (about 48 hours), so when a share link expires or is revoked the video genuinely stops playing. Voice notes, note attachments, the master archive, and backups are held in private storage that can only be read through an access-checked link. Sign-up refuses passwords that have appeared in known data breaches. No system is perfectly secure, but we work to protect your information and to address issues promptly.

If something goes wrong

If we learn of a security incident that affects your personal data or your content, we will tell you without undue delay, explain what happened and what we did about it, and notify the Israel Privacy Protection Authority and any other regulator where the law requires.

Children

Sevev is not directed to children under 16, and we do not knowingly collect their personal information.

International users

Sevev is operated from Israel, and your information may be processed in Israeland in the countries where our service providers operate. This policy is governed by the laws of Israel.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above, and significant changes will be communicated through the app.

Contact us

Questions about this policy or your data? Email us at ohr13shimonov@gmail.com.

See also our Terms of Service and Accessibility Statement.