Projects are kept primarily in your browser. When a requested feature needs server processing, raw uploads and processing artifacts are automatically deleted within 24 hours after the job succeeds or fails. We do not sell personal data or use your content to train general-purpose AI models.
1. Who is responsible for your data
Captionate is operated by CHANHUI HAN. For applicable privacy law, the operator is the controller or business responsible for personal data described in this Policy.
Privacy contact and responsible department: Captionate Privacy, support@captionate.app.
This Policy applies to Captionate’s website, account system, editor, processing features, support, and paid subscription services. Third-party websites and services have their own policies.
2. Data we collect
| Category | Examples | How collected |
|---|---|---|
| Account and authentication | Email address, account identifier, authentication status, confirmation and password-recovery events. Password credentials are handled by our authentication provider; we do not receive your plain-text password. | From you and our authentication provider when you register, sign in, or manage your account. |
| User Content | Video, audio, subtitle files, captions, transcripts, text, prompts, instructions, translations, styles, and generated exports. | From you when you create a project or request a processing feature. |
| Project and usage data | Project and track names, media duration, selected ranges, processing status, feature used, language, credit usage, timestamps, and error information. | Generated as you use the service. |
| Technical data | IP address, browser and device type, operating system, referring page, requested URL, timestamps, cookie or similar identifiers, and server access/security logs. | Collected automatically when your device connects to the service. |
| Billing and subscription data | Plan, billing status, subscription and transaction identifiers, purchase amount, currency, tax country, renewal and cancellation status. Payment-card details are collected directly by Paddle and are not stored by Captionate. | From Paddle when you open checkout, purchase, renew, cancel, or request billing support. |
| Support communications | Your email, message, attachments you choose to send, and our response history. | From you when you contact us. |
Please avoid including sensitive personal data in prompts, captions, or support messages unless it is necessary for your intended use and you have a lawful basis to process it.
3. Why and on what basis we process data
| Purpose | Data involved | Basis where applicable |
|---|---|---|
| Create and secure your account | Account, authentication, and technical data | Performing our contract; security and fraud-prevention interests; legal obligations |
| Provide caption, translation, editing, export, and AI features you request | User Content, project, usage, and technical data | Performing our contract and your requested action |
| Measure credits and operate subscriptions | Account, usage, billing, and transaction data | Performing our contract; accounting, tax, and consumer-law obligations |
| Maintain, troubleshoot, and protect Captionate | Technical logs, diagnostic data, account and limited job metadata | Our legitimate interests in a reliable and secure service; legal obligations |
| Answer support and rights requests | Account and support communications | Performing our contract; consent where relevant; legal obligations |
| Understand website usage and improve the product | Analytics and technical data | Consent where required; otherwise our legitimate interest in understanding and improving the service |
If we rely on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal. If we need information to provide a contracted feature and you do not provide it, that feature may not work.
4. Projects stored in your browser
Captionate uses browser storage, including IndexedDB and local storage, to keep project data, imported captions, attached media references or files, editor preferences, and session state on your device. This allows much of the editing workflow to remain local to your browser.
Browser-stored projects remain until you delete them in Captionate, clear the site’s browser data, use a private session that ends, or your browser or device removes the data. They are not automatically synchronized across devices. Clearing browser data can permanently remove projects that you have not exported or backed up.
When you request a server-based feature—such as caption generation, translation, AI assistance, or MP4 rendering—the content needed for that request is sent to Captionate’s server and relevant service providers as described below.
5. Service providers and disclosures
We disclose only the data reasonably needed for the following providers to perform services for Captionate. They may not use it for their own unrelated purposes. Provider names and roles may change as we improve the service; material changes will be reflected here.
| Provider | General purpose | Data involved |
|---|---|---|
| Google LLC | Processing audio and text to provide AI features requested by the user; website usage analytics | Requested User Content and job settings; for analytics, website usage and device data |
| Soniox Inc. | Processing audio and text to provide AI features requested by the user | Requested audio, related text or settings, and technical request data |
| Supabase, Inc. | Authentication, account and credit records, database infrastructure, and temporary object storage | Account, authentication, usage, credit, and temporary processing data |
| Paddle entities | Checkout, payment, subscriptions, invoices, tax, fraud prevention, and billing support as merchant of record | Contact, billing, transaction, subscription, device, and tax-location data |
| Plus Five Five, Inc. (Resend) | Sending account confirmation, password recovery, security, and service emails | Email address, message content, delivery and technical data |
We may also disclose data when required by law, to protect rights and safety, to investigate abuse or fraud, or as part of a business reorganization. If control of Captionate changes, we will require the recipient to honor this Policy or provide notice of material changes.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising, and we do not use User Content to train general-purpose AI models.
6. International processing and transfers
Captionate serves users globally. Because our providers operate internationally, data may be processed in countries outside your residence, including the United States and other provider or subprocessor locations. Those countries may have different privacy laws.
| Recipient and location | Data and purpose | Timing, method, and retention |
|---|---|---|
| Google LLC — United States, selected cloud processing regions, and approved subprocessor locations | Requested audio/text processing and website analytics | Transferred electronically when you request the feature or visit the site; retained only as needed for the service and under provider contract and policy |
| Soniox Inc. — United States or an available regional endpoint | Requested audio/text processing | Transferred electronically when the relevant feature is requested; Captionate requests deletion of remote job files after processing, while limited provider operational records may follow provider policy |
| Supabase, Inc. — selected project region and approved subprocessor locations | Authentication, database, credit, and temporary storage operations | Transferred electronically during account and service use; retained according to the account, content, and legal periods below |
| Paddle entities — United States, United Kingdom, Canada, and approved subprocessor locations | Payments, subscriptions, tax, fraud prevention, and buyer support | Transferred electronically when checkout or billing is used; retained by Paddle for transaction, fraud, tax, and legal requirements |
| Plus Five Five, Inc. — United States and approved subprocessor locations | Account and service email delivery | Transferred electronically when an email is requested or required; retained under the provider’s delivery, security, and legal schedule |
Where required, we rely on your requested performance of the service, consent, contractual safeguards, adequacy decisions, or another lawful transfer mechanism. You may contact us for more information about safeguards relevant to your location.
7. Retention and deletion
We keep personal data only for the period needed for its stated purpose, a legal obligation, security, or the resolution of a dispute. Our current schedule is:
| Data | Retention period |
|---|---|
| Raw media, audio, subtitle uploads, temporary processing copies, prompt/output artifacts, and generated server files | Automatically deleted within 24 hours after the requested job succeeds or fails. |
| Projects and media stored only in your browser | Until you delete the project, clear Captionate site data, or the browser/device removes it |
| Account profile, authentication link, credit balance, and subscription linkage | For the life of the account, then deleted without undue delay after a verified deletion request unless a legal exception applies |
| Server access, error, security, and short-term diagnostic logs | Normally 30 days, longer only when needed to investigate a specific security incident, abuse, or legal claim |
| Pseudonymous product-usage events retained for analysis | Up to 12 months; these records exclude raw User Content |
| Truly anonymized aggregate statistics that can no longer identify a person | May be retained indefinitely |
| Contract, cancellation, payment, and supply records retained to meet applicable transaction and consumer-protection requirements | 5 years |
| Consumer complaint and dispute-resolution records retained to meet applicable consumer-protection requirements | 3 years |
| Support communications not subject to a longer legal period | Up to 3 years from resolution |
| Residual copies in routine backups, if present | Isolated from ordinary use and overwritten or deleted on the normal backup cycle, ordinarily within 30 days |
When data reaches the end of its period, we delete it or irreversibly anonymize it. Electronic files are deleted using methods intended to prevent ordinary recovery. Records retained solely because of law are separated or access-restricted and are not used for other purposes.
8. Your privacy rights
Depending on where you live, you may have the right to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about disclosures and international transfers. You may also have the right to complain to a privacy regulator.
To exercise a right or request account deletion, email support@captionate.app from the address associated with your account. Describe the request and the account involved. We may need to verify your identity before acting. We will respond within the period required by applicable law and will explain if an exception applies.
You can remove browser-stored projects yourself from the Projects page or by clearing Captionate site data in your browser. Deleting browser data is separate from deleting your Captionate account.
We will not discriminate against you for exercising a privacy right.
9. Cookies, local storage, and analytics
Captionate uses browser storage and similar technologies for authentication, security, project storage, preferences, responsive interface state, and service operation. These technologies may be essential for features you request.
We also use Google Analytics to understand visits and interactions such as pages viewed, general device information, referrals, and approximate geography. Google Analytics may set or read identifiers and cookies. Where local law requires consent for non-essential analytics, we will request it before enabling those technologies.
You can limit cookies through your browser and may use browser privacy controls or extensions. Blocking essential storage can prevent sign-in, project persistence, or other features from working.
10. Security
We use reasonable technical and organizational safeguards designed to protect data, including encrypted network transport, access controls, managed authentication, limited retention, provider access restrictions, and separation of operational roles. No internet service can guarantee absolute security.
If we identify a personal-data breach that requires notice, we will notify affected users and authorities as required by applicable law.
11. Children
Captionate is not directed to children under 14, and we do not knowingly collect personal data from them. If you believe a child under 14 has provided data, contact us so we can investigate and delete it. Users below the age of legal majority must have permission from a parent or legal guardian, and paid subscriptions may be purchased only by a person with legal capacity to contract.
12. Changes to this Policy
We may update this Policy when our service, providers, or legal obligations change. We will post the new version and update the date above. If a change materially affects how we use personal data, we will provide additional notice or obtain consent where required.
13. Contact and complaints
Privacy contact: support@captionate.app
If we cannot resolve your concern, you may contact the privacy or consumer-protection authority in your country or region.