Draft for legal review
This Privacy Policy is a draft for legal review and does not constitute final legal advice. The content is based on a code audit and may change after legal review and before launch.
Overview
AutoStitch is a creator-focused video processing tool that allows you to upload or link videos, apply AI-powered clipping, and export merged videos. This policy describes how we collect, use, and protect your information when you use our service.
You are responsible for the content you upload or link to our service. By using AutoStitch, you agree to the data practices described in this policy. Your use of the service is also governed by our Terms of Service.
Information we collect
Account and authentication information
When you create an account, we collect your email address and password (hashed by our authentication provider). We use Supabase for authentication, which handles user accounts and session management. If you sign up via Google OAuth, we receive your basic profile information from Google.
Uploaded videos and files
When you upload videos, we process them temporarily for clipping and export workflows. Uploaded files are stored temporarily during processing and are deleted after processing completes. We collect file metadata such as file size, type, and name.
Video links and source URLs
When you provide a video link (e.g., from YouTube or another platform), we store the URL and download the full source video from that link so we can process it — probing, downloading, normalizing, and rendering clips from it. The downloaded source video is held temporarily on our processing infrastructure for the duration of processing; the clips and other outputs you generate from it are stored as described below.
Generated clips, thumbnails, captions, transcripts, and processing outputs
Our service generates video clips, thumbnail images, transcript text, caption text with timestamps, and other processing outputs. These are created as part of the clipping workflow and may be stored temporarily or persistently depending on your use of the feature. Persisted video artifacts (such as your generated clips and thumbnails) are stored as private objects in Cloudflare R2 object storage and are served only through our authenticated API — never from a public bucket URL.
Job, project, and processing metadata
We store job metadata and history to track processing jobs and results. This includes job IDs, status, processing parameters, and timestamps. This information is held in our Supabase (Postgres) database and in our job queue/store (Upstash Redis), which also holds the source URLs you submit and other job metadata while a job is queued, processed, and served from your library. (Supabase provides authentication and our database; the video files themselves are stored in Cloudflare R2, not Supabase.)
Credits, billing, subscriptions, and payment information
We use Stripe for payment processing. When you purchase credits or subscriptions, Stripe collects your payment information. We store your credit balance, billing ledger entries, payment records, subscription status, and Stripe customer ID in our database. We do not handle or store your full payment card details directly—Stripe handles all payment processing.
YouTube / Google OAuth integrations
If you connect your YouTube account for upload integration, we store OAuth access tokens, refresh tokens, token expiry, and connection status. This allows us to upload processed videos to your YouTube channel on your behalf. This integration is optional and only applies when you explicitly connect your account.
Cookies, local storage, and similar technologies
Supabase sets authentication cookies to keep you signed in. Stripe sets cookies for secure payment processing. We use browser localStorage to save your UI preferences, such as processing mode, transition duration preset, caption size, and default zoom percentage, and browser sessionStorage to briefly hold in-progress navigation state (such as a link you started from the landing page and your recent project history). We do not set marketing or analytics cookies directly. For a full description of the cookies and browser storage we use, see our Cookie Policy.
Logs, errors, and diagnostics
We collect logs, error messages, and diagnostic information to debug issues and maintain service reliability. This information may include error messages, warnings, and technical details about service operation.
Analytics and tracking
No analytics or marketing tracking tools were detected in the current code audit. If we add analytics tools in the future, we will update this policy to describe what we collect and how we use it.
How we use information
We use the information we collect to:
- Provide, operate, and improve our video processing service
- Process your uploaded videos and generate clips, captions, and transcripts
- Authenticate you and maintain your account
- Process payments and manage credits and subscriptions
- Enable YouTube upload integration when you connect your account
- Save your UI preferences for a better user experience
- Debug technical issues and maintain service reliability
- Communicate with you about your account and service updates
How we share information
We share information with the following third parties to provide our service:
- Supabase: Authentication and our Postgres database — user accounts and sessions, credit/billing ledger entries, job metadata, and (if you connect YouTube) your OAuth tokens.
- Stripe: Payment processing, checkout sessions, customer portal, and subscription management. Full card details are handled by Stripe; we store only your Stripe customer ID and subscription status.
- Google / YouTube: OAuth authentication and, when you connect your account, uploading your finished videos to your YouTube channel.
- Cloudflare R2: Private object storage for your generated video artifacts — clips, thumbnails, and other output files.
- Upstash (Redis): Our job queue and job store, which holds the source URLs you submit and job metadata while jobs are queued, processed, and served from your library.
- RunPod: GPU compute for the worker that downloads, decodes, and renders your video during processing.
- Render: Hosting for our backend API.
- Vercel: Hosting for our web application.
We do not sell your personal information to third parties for marketing purposes.
Data retention
TODO: define retention periods after product/legal review.
Uploaded files are processed temporarily and deleted after processing completes. Job metadata and account data may be retained for as long as needed to provide the service.
Security
We implement reasonable security measures to protect your information, including encryption in transit and secure authentication practices. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
User choices and deletion requests
You can request deletion of your account and associated data by emailing us at kokojamgotchian007@gmail.com. We do not currently offer self-serve, in-app account deletion; we handle deletion requests manually. After we verify your request, we will remove your account, your generated clips and other artifacts (stored in Cloudflare R2), and your job records (in our database and job store) within 30 days, except where we are required to retain certain records to comply with law. Some copies may persist briefly in routine backups before they are overwritten.
You can clear your browser localStorage at any time through your browser settings, which will remove your UI preferences.
You can disconnect your YouTube account at any time through your account settings, which will revoke our access to your YouTube channel.
Children's privacy
TODO: define age/eligibility rule after legal review.
Our service is not intended for children under the applicable age. We do not knowingly collect personal information from children.
International users / data processing locations
TODO: define data processing locations and jurisdiction after legal review.
Your information may be processed and stored in the countries where our service providers (such as Supabase and Stripe) operate. By using our service, you consent to this international data transfer.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date.
Contact
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: kokojamgotchian007@gmail.com
TODO: legal company name placeholder
TODO: legal mailing address placeholder