tscaps

Privacy Policy

Last updated: 2026-07-23

tscaps is a client-side video editor that adds burned captions to your videos. This policy explains what data we collect, why, and how you can exercise your rights over it. We aim for the shortest list of data that lets the product work and we avoid storing anything we don't need.

Data we collect

  • Account. When you sign up we store your email address and, if you sign in with Google, the name and profile image Google sends us. We do not store your Google password.
  • Project metadata. When you save a project we store its title, your caption styling choices, and the transcript text on our servers so you can resume later. Your video file never leaves your browser — all editing and export happen locally on your device.
  • Transcription audio. When you use cloud transcription, the audio extracted from your video is sent to a third-party transcription provider (Deepgram or ElevenLabs, depending on current configuration) to produce a transcript. The audio is not retained by us. The provider's retention policy applies to its own copy and is documented in their privacy terms.
  • Transcript text for smart caption breaks. On the cloud version, after transcription we send the transcribed words to a scoring model that estimates good places to break captions, so line breaks feel natural instead of landing mid-thought. Only the text of the words is sent. No audio, no video, no account information. The words are processed for the duration of the request and are not retained.
  • Billing. Payment details (card number, billing address) are handled by Polar, our billing provider. We never see or store them. We do store your subscription status and the email used for billing receipts.
  • Session cookies. A session cookie keeps you signed in. It is strictly necessary for the product to function. We do not use third-party tracking cookies for advertising.
  • Anonymous product analytics. We record a small set of named events with non-identifying context (device type, browser, viewport size, release version). We use this to understand which parts of the product are useful and where users get stuck. The events are sent to PostHog (described below), and they do not include your video, your transcript text, or any account information. The analytics adapter runs entirely in memory — no cookies, no localStorageentries, no cross-session identifier. The local version (/local) sends the same anonymous events: technical facts about the flow (video duration, file size, format and codec, export settings, timings) and technical error details when something fails. Never your video, your audio, your transcript text, or any account information. If you want a build with no telemetry at all, the open-source self-hosted version ships with analytics disabled.
  • Anonymous page views on the marketing site. Every marketing page — including the local landing — captures a single page_viewed event with the visited path and the referring URL. Nothing else. The events use the same PostHog adapter described above (cookieless, in-memory, IP-discarded, DNT-respecting).
  • Error reports. On the cloud version, when the app or our server hits an unexpected error, we send a report with the error message, a stack trace, and the technical context of the failure (route, device type, release version) to Sentry. These reports help us notice and fix bugs without waiting for you to tell us. They do not include your video, your transcript text, or your password. The local version does not send error reports.

Anonymous cloud trial signals

When you use the cloud version of tscaps without an account, we briefly store two technical signals so we can offer a free trial without burning our budget on automated abuse: your IP address (which may be stored in a partial or hashed form) and a non-personally-identifying signature of your browser computed locally on your device. They are used only to count your free trial and to throttle attempts that look automated, never shared with third parties, never used for advertising, and never linked to a marketing profile.

These signals are deleted within 30 days. If you create an account, your account replaces this anonymous tracking.

Where your data is processed

We use the following subprocessors to operate tscaps. Each one only receives the slice of data needed for its role:

  • Hetzner (Germany) — application hosting.
  • Neon (EU) — database (accounts, project metadata, subscription status).
  • Cloudflare (global) — DNS, CDN, and TLS termination for our domain.
  • Cloudflare R2 — object storage for cloud project videos (only when you save or transcribe a project in the cloud version).
  • Cloudflare Turnstile — bot and abuse prevention on sign-up, sign-in, and password-reset pages.
  • Polar — billing and payment processing (acts as Merchant of Record).
  • Resend — transactional email (verification, billing receipts).
  • Deepgram and ElevenLabs — speech-to-text for cloud transcription (only if you opt into the cloud path).
  • Modal (United States) — hosts the model that scores where cloud captions should break. Receives only the transcribed words for the duration of the request; no audio, no video, no account information.
  • Google — OAuth sign-in (only if you choose Google as your sign-in method).
  • PostHog (EU region, Frankfurt) — anonymous product analytics for the web app (cloud and local versions) and page-view analytics on the marketing site (except the local landing), configured to discard client IP data. Only the named events described above reach this provider.
  • Sentry — error tracking for the cloud version. Receives stack traces and the technical context attached to the error. Configured with personally-identifying defaults turned off, no session replay, no tracing.

How long we keep your data

We keep your account data for as long as the account is active. When you delete your account, we delete your projects and personal data within 30 days. Billing records may be retained longer to comply with accounting and tax obligations. Anonymous cloud trial signals (IP and fingerprint, described above) are kept for at most 30 days. Backups are rotated within 30 days.

Your rights

You can request access to the data we hold about you, correction of inaccuracies, deletion (the "right to be forgotten"), and a portable copy in a machine-readable format. Email us at the address below and we will respond within 30 days.

Contact

Questions or requests: hello@tscaps.io.

Changes

We may update this policy as the product evolves. We will update the "Last updated" date above and, for material changes, notify you by email or in the app before the changes take effect.

This document is a plain-language summary of how we handle your data. It is reviewed periodically and refined as the product changes.