LEGAL

Privacy Policy

We make one thing: a captions tool. Your videos are yours, we keep the data we need to run the product and nothing else.

Last updated 2 September 2026 · Effective 2 September 2026

01

The short version

This summary is here so you don't have to read the rest. It isn't a substitute for the full policy below, but nothing below contradicts it.

  • Your videos stay until you delete them. Finished exports are deleted automatically after 24 hours.
  • We never use your videos, audio, or transcripts to train models.
  • We don't sell your data and we run no ad trackers. We do count page views and a few product events, through one analytics provider, to see which parts of the product work.
  • You can delete your account and everything in it at any time, from Settings — that removes your files as well as your rows.
02

What we collect

We collect the smallest set of information that lets the product work and lets us bill you correctly.

Account information

Your email address, your password (stored as a salted hash — we never see it), your display name if you set one, and your preferred interface language.

Billing information

Your subscription status, plan, renewal date, and country for tax purposes. Card numbers are handled entirely by Stripe and never reach our servers.

Your projects

For each video: the name you gave it, its size, length and format, the transcript, and the caption style applied to it. That is what the product is made of — without it there is nothing to open when you come back.

Technical information

Server logs record the IP address and browser making each request.

We also run analytics, through a provider called DataFast, served from a subdomain of this site. It records which pages you open, your approximate location derived from your IP address, your browser and device, and a short list of product events: signing up, uploading a video, reaching the paywall, starting a checkout, and finishing an export.

While you are signed in it also receives your account id — the same opaque identifier our own database uses — so that a run of visits reads as one person rather than a crowd of strangers. Not your name, not your email address, and nothing from your videos.

It is there so we can tell which parts of the product work and where people get stuck, and it is deliberately the smallest set that answers that. It does not read your videos, your audio or your transcripts. We do not sell or share any of it, there is no advertising network involved, and nothing here follows you to other sites.

03

Your videos and audio

This is the part most people care about, so we'll be specific.

When you upload a video, it goes to encrypted storage. We extract the audio track and send it to our transcription provider to produce a transcript with word-level timings. The transcript is stored alongside your project so you can edit it and re-export.

  • Source videos stay until you delete the project or your account. We don't expire them behind your back — they're the thing you came here with.
  • Rendered exports are deleted automatically 24 hours after they finish. You can always re-export from the source.
  • Transcripts and caption styles stay until you delete the project or your account.
  • No human at Add Captions watches your videos.

We do not use your content to train, fine-tune, or evaluate any machine learning model, ours or anyone else's. Our transcription provider's own policy on not training from customer audio was part of why we chose them; their terms, not ours, govern what they do, and we link them here rather than paraphrasing.

04

How we use your data

We use what we collect to run the service, to charge you, to answer your support emails, to keep accounts from being abused, and to understand which features are worth keeping.

We will email you about your account — receipts, renewal reminders, failed payments, security notices. Product announcements are opt-in and every one of them has a working unsubscribe link.

We do not build advertising profiles, and we do not run behavioural ad trackers on our site.

05

Who we share it with

We share data only with the providers we need to run the product. Each is bound by a data processing agreement.

PROVIDERWHAT THEY DOLOCATION
StripePayments and subscriptionsUnited States
SupabaseDatabase and authenticationGermany
Cloudflare R2Video and export storageEuropean Union
Amazon Web ServicesVideo renderingGermany (eu-central-1)
AssemblyAISpeech-to-text transcriptionUnited States
SequenzyTransactional email
DataFastWebsite and product analytics

We will also disclose information if we are legally required to, and we'll tell you when we're allowed to. If the company is ever acquired, your data moves with the service and you'll get notice before anything changes.

06

Cookies

We use three. One is a session cookie that keeps you logged in, and the product does not work without it. The other two belong to our analytics and mark your visit, so that coming back tomorrow is not counted as a stranger.

All three are first-party: set on this domain, sent only to us, and useless to anyone else. There is no advertising cookie, no cross-site identifier, no fingerprinting and no third-party pixel on any page.

07

How long we keep things

  • Source video: until you delete the project or your account.
  • Exported files: 24 hours after the render finishes.
  • Transcripts, caption styles and projects: until you delete them.
  • Account record: until you delete your account.
  • Invoices: 7 years, because tax law requires it.
  • Server logs: 30 days.

Deleting your account removes the files as well as the database rows — the videos, the thumbnails and any exports still in flight are all cleared from storage at the same time.

08

Your rights

Wherever you live, you can ask us to show you the data we hold about you, correct it, export it in a machine-readable format, or erase it. Most of this you can do yourself from Settings → Account without asking anyone.

If you're in the EEA or UK, your legal bases are contract (running the service you paid for), legitimate interest (security and product analytics), and consent (marketing email). You can object or withdraw consent at any time, and you can complain to your local data protection authority.

If you're in California, you have the right to know, delete, correct, and opt out of sale or sharing. We don't sell or share personal information, so there's nothing to opt out of, but the request form works anyway.

We answer rights requests within 30 days and we don't charge for them.

09

Security

Traffic is encrypted in transit, and stored files are encrypted at rest by our storage provider. Your password is hashed by our authentication provider with a standard slow hashing function before it reaches any database — it is never stored in a form we or they can reverse, and nobody here can read it.

Add Captions is built and run by its two founders. Production access is theirs, there are no shared credentials, and there is no wider team whose laptop could be the way in. That is a smaller attack surface than most companies have and also, honestly, a smaller team than most companies have — we would rather you knew which.

If we ever have a breach that affects you, we'll notify you and the relevant regulator within 72 hours of finding out.

10

Children

Add Captions isn't for people under 13, and we don't knowingly collect anything from them. If you believe a child has created an account, email us and we'll remove it.

11

Changes to this policy

When we change something material, we'll email every account holder at least 30 days before it takes effect and note the change at the top of this page. Older versions stay available in our public changelog.

12

Contact us

Questions, requests, or complaints go to [email protected] and reach a person, not a queue. We usually answer within two business days.

Want your data, or want it gone?

Export or delete everything yourself in Settings → Account.

Email [email protected]