Privacy Policy
Last updated April 29, 2026
1. The short version
We collect the minimum we need to run SoCaptions: your Google account info, your videos and captions, and basic billing data when you subscribe. We don’t sell your data. We don’t train AI models on your videos. You can delete everything by emailing us.
2. Who is responsible
SoCaptions is the data controller for the personal data described in this policy. You can reach us at daveedsgn@gmail.com.
3. What we collect
Account information — when you sign in with Google, we receive your name, email address, and Google profile picture.
Subscription information — when you subscribe to Pro, our payment processor (Polar) handles your card details and shares limited billing metadata back to us (subscription status, plan, renewal date). We never see or store your card number.
Uploaded videos — the videos you upload to be captioned, plus any captions, edits, and exported MP4s you generate. Stored in Vercel Blob and processed via AWS S3 / MediaConvert during export.
Transcripts — the text our AI produces from your audio. Stored against your account so you can keep editing.
Usage data — basic logs about your account activity (sign-in time, minutes transcribed, exports requested) for billing, security, and debugging.
Cookies — a session cookie set by our authentication system to keep you signed in. We do not use third-party advertising or tracking cookies.
4. Why we collect it
We use the data above to:
- Provide the service — transcribe your videos, render captioned MP4s, and let you sign back in.
- Bill you correctly — track minutes used and process your subscription via Polar.
- Enforce limits and prevent abuse — keep free-tier users under 5 minutes, Pro users under 100 minutes per month, and stop spam or misuse.
- Improve the service — we look at aggregate patterns (e.g. how many minutes are processed per day) but never train AI models on your videos or transcripts.
- Communicate with you — service emails, billing receipts, and important changes.
5. Legal bases (GDPR)
If you’re in the EU/EEA or UK, the lawful bases we rely on are: contract (running the service you signed up for), legitimate interests (security, abuse prevention, basic analytics), and consent (where required, and easy to withdraw).
6. Who we share it with
We share data with the third-party processors needed to run SoCaptions, and only what they need:
- Google — sign-in (OAuth). Receives the fact that you authenticated; does not see your videos.
- Vercel — hosting, edge network, and Vercel Blob storage for uploaded video.
- AWS (Amazon Web Services) — temporary video processing for MP4 export via S3 and MediaConvert.
- OpenAI — transcription via the Whisper API. Audio is sent for transcription. OpenAI’s API does not retain or train on data submitted via paid API requests by default.
- Polar — billing and merchant of record for Pro subscriptions.
We do not sell personal data and we do not share it with advertising networks.
7. How long we keep it
Account info — until you delete your account.
Uploaded videos — kept while you have access to the project and for a short retention buffer afterwards (up to 30 days) so you can recover deleted work, then permanently deleted.
Transcripts and edits — kept while your account exists, deleted when you delete the account.
Billing records — retained for as long as required by tax law (typically 5–7 years), even after account deletion.
Logs — typically kept for 30–90 days for security and debugging.
8. Your rights
Depending on where you live, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correct — fix anything that’s wrong.
- Delete — ask us to delete your account and associated data.
- Port — receive your data in a portable format.
- Object or restrict — limit how we process your data in some cases.
- Withdraw consent — where consent is the legal basis.
Email daveedsgn@gmail.com to exercise any of these. We respond within 30 days.
If you’re in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority.
9. International transfers
Some of our processors (notably AWS, Vercel, and OpenAI) are based in the United States. When data is transferred outside the EU/EEA, we rely on standard contractual clauses or equivalent legal mechanisms approved by the European Commission.
10. Security
We use HTTPS for everything, encrypt uploads at rest, and require authentication on every API. No system is ever 100% secure, but we do our part. If you suspect a breach, email daveedsgn@gmail.com.
11. Children
SoCaptions is not intended for children under 13. We don’t knowingly collect personal data from children. If you think a child has signed up, email us and we’ll delete the account.
12. Changes to this policy
We’ll update this page when we change how we handle data. Material changes will be marked with a new “Last updated” date and, where appropriate, notified by email.
13. Contact
Questions about this policy or your data? Email daveedsgn@gmail.com.