Privacy policy

What is processed, why, on which legal basis, who else sees it, how long it lasts, and what you can ask us to do about it.

Last updated
29 August 2026
In force from
29 August 2026
Provided by
Simone Panini
Governed by
The law of Italy

1Who is responsible, and for what

Simone Panini (Software developer), established in Italy — VAT 04241900366 — is the data controller for the personal data described here. Write to intheclips.business@gmail.com about any of it.

This policy covers the website, the application and the processing pipeline behind it. It does not cover other people’s sites we link to.

Two roles, and the line between them. For your account we are the controller: we decide what is collected and why. For the footage you upload we are a processor acting on your instructions — you decide what goes in, and you are the controller of any personal data of other people that appears in it. If that matters for your compliance, a data processing agreement is available at intheclips.business@gmail.com.

2What we process

  • Account. Email address, display name, the user identifier issued by Firebase Authentication, sign-in and password-reset events, and the plan you are on. We never receive your password.
  • Workspace content. The sources you add (a link or an uploaded file), the transcript produced from them, the moment list and its scores, your keep and pass decisions, render presets, and the finished clips.
  • Whatever is inside the footage. A video contains voices, faces and names. That is personal data about the people in it, processed on your instruction — which is why you confirm you have the rights to it.
  • Jobs and usage. Analysis and render jobs, their state and duration, minutes of source used against your allowance, error records, and rate-limit counters.
  • The declaration you make when you import a link. Which basis you picked, the exact wording you were shown, the version of the terms it was shown under, the time, and the IP address it came from. We keep it because it is the reason the import was allowed, and it has to still be there if somebody later asks why.
  • Billing. The Stripe customer and subscription identifiers, plan, period dates, invoices and refunds, and the billing email. Card numbers go to Stripe and never reach our servers.
  • Technical. IP address, user agent and timestamps in server and edge logs, kept for security, abuse prevention and debugging.
  • What you send us. The contents of a message to one of our inboxes or the contact form, and anything you attach to it.

There is no advertising network, no cross-site tracking and no data broker in any of this. Nothing is sold or shared for anyone else’s marketing.

3Why, and on what legal basis

  • To provide the service — performance of a contract. Creating the account, transcribing, ranking, rendering, delivering files, keeping the library, and support.
  • To take payment — performance of a contract, and legal obligation. Subscriptions and invoices, plus the tax records the law of Italy requires us to keep.
  • To keep the platform up and safe — legitimate interests. Rate limiting, abuse detection, capacity planning, error monitoring, and defending legal claims. Our interest is running a service that stays available and is not used to harm anyone; it is balanced against your interests by keeping this data minimal and short-lived.
  • To answer you — legitimate interests. Replying to a message you sent us.
  • Product email — consent. If we ever send product news, it is because you opted in, and every one of those messages can be unsubscribed from in a click. Service emails about billing, security and outages are not marketing and are not optional while you have an account.

Where consent is the basis, you can withdraw it at any time; that does not affect what was done before you withdrew it.

4Who else sees it, and where

The pipeline is assembled from specialist providers, each of which sees only what its job needs. All of them are listed by name, purpose, data and region on the sub-processors page — including which are only called for optional features.

  • Each is bound by a written processing agreement and may act only on our instructions.
  • Several are in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the provider is certified under it.
  • We disclose data to authorities only where a valid legal order requires it, and we tell you unless we are forbidden from doing so.
  • If the business is sold or merged, data may transfer with it. You will be told before that happens, and this policy continues to apply until you are given a new one.

5How long it is kept

  • Account records — for as long as the account exists. Closing it deletes them in the same request, along with every file under it and the sign-in credential itself; nothing is left waiting for a scheduled sweep.
  • The link declaration — with the source it belongs to, and deleted with it.
  • Uploaded sources and rendered clips — for the window of the plan they were made under: seven days on the free trial, ninety on Starter, a year on Creator, no limit on Studio. The window is fixed when the file is made and is never shortened later. Deleting either yourself removes it from storage immediately.
  • Transcripts and moment lists — with the source they belong to, and deleted with it.
  • Server and edge logs — a short rolling window, measured in days, then discarded.
  • Invoices and tax records — for the period the law of Italy requires, regardless of account closure.
  • What a job cost us to run — kept indefinitely, because it is how we know whether a plan pays for itself. Closing an account detaches those lines from it: what remains is how many minutes a machine spent and what the provider charged, with nothing left in the row that points back at a person.

6How it is protected

  • Everything travels over TLS, and stored files sit in encrypted object storage.
  • Video bytes never pass through the API process: the browser talks to storage directly using short-lived signed URLs, which keeps both the attack surface and the copies small.
  • Access to production is limited to the people who need it, and secrets are held in the platform’s secret store rather than in the codebase.
  • Payment card data never reaches us. Passwords never reach us — authentication is delegated to Firebase.
  • If a breach is likely to put your rights at risk, we notify the supervisory authority within 72 hours and tell you without undue delay. Report anything you find to intheclips.business@gmail.com.

7Your rights

Under the GDPR you may ask for access to your data, correction of it, erasure of it, restriction of processing, a portable copy of it, and you may object to processing based on legitimate interests. There is no automated decision-making that produces legal or similarly significant effects on you: a score ranks a passage, it does not decide anything about a person.

Write to intheclips.business@gmail.com. We answer within one month, and tell you if a complex request needs longer. There is no charge unless a request is manifestly unfounded or repetitive.

You can also complain to a supervisory authority — for us that is the Garante per la Protezione dei Dati Personali — or to the authority where you live or work.

If you are in California or another US state with a privacy law. You may request the categories and specific pieces of personal information we hold, ask for deletion or correction, and you will not be treated differently for asking. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. Use the same address above.

8Children, cookies, and changes to this policy

  • Children. The service is not for people under 14, which is the digital-consent threshold in Italy. If we learn an account belongs to someone younger without a guardian, we close it and delete the data.
  • Cookies. What is needed to keep you signed in and to remember three interface preferences, plus your answer to the banner. Google Analytics loads on top of that, and only if that answer was yes. The detail is on the cookie policy.
  • Changes. The date at the top says when this last changed. Material changes are announced by email or in the app before they take effect.