Privacy Policy
Last updated: [DATE]
1. Controller
The controller of your personal data is [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. Contact: [PRIVACY CONTACT EMAIL]. [DPO / EU REPRESENTATIVE IF REQUIRED]
2. What we collect
- Account data: email address, password (stored hashed by our authentication provider), plan and role, and the date you accepted our Terms.
- Content: videos you upload or link to, transcripts and highlight scores generated from them, and clips and captions you create.
- YouTube data: if you connect a channel, OAuth tokens (stored encrypted), channel identifiers, and view counts of videos you publish through PeakCut.
- Billing data: handled by Stripe; we store customer and subscription identifiers, not card numbers.
- Technical data: IP address and request logs, used for security and rate limiting.
3. How and why we use it
To provide the service (contract), to secure it and prevent abuse (legitimate interest), to process payments and meet legal obligations. [LAWYER: confirm purposes and legal bases]
4. Who we share it with
We use these service providers (processors) to run PeakCut:
- Supabase: database, authentication and file storage
- Vercel: web hosting
- OpenAI: audio transcription for highlight detection
- Stripe: payments
- Google / YouTube: publishing and analytics, only if you connect a channel
- [WORKER HOSTING PROVIDER, EMAIL PROVIDER, OTHERS]
[INTERNATIONAL TRANSFERS AND SAFEGUARDS (e.g. SCCs)]
5. YouTube API Services
PeakCut uses YouTube API Services. Google's handling of data is described in the Google Privacy Policy. You can disconnect YouTube in Settings, or revoke PeakCut's access at any time via Google security settings. [LAWYER: confirm YouTube API Services disclosure requirements]
When you connect a YouTube channel, PeakCut asks Google for two permissions, and uses them only as follows:
- Manage your YouTube videos (youtube.upload): used only to upload the clips you choose to publish, when you choose to publish them. PeakCut does not edit or delete your existing videos.
- View your YouTube account (youtube.readonly): used only to show which channel is connected and the view counts of clips you published through PeakCut.
PeakCut's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, use it for advertising, or use it to train AI models, and we store your Google access tokens encrypted.
6. Retention
[RETENTION PERIODS for uploaded videos, clips, transcripts, logs and account data after deletion]
7. Cookies
We only use cookies that are strictly necessary to keep you signed in. We do not use advertising or analytics cookies. [UPDATE IF ANALYTICS ARE ADDED]
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to complain to a supervisory authority [e.g. the CNIL in France]. To exercise these rights, contact [PRIVACY CONTACT EMAIL].
9. Security
We use encryption in transit, encrypt stored YouTube tokens, and restrict access to personal data. [ADDITIONAL MEASURES]
10. Children
PeakCut is not directed at children under [AGE].
11. Changes
We will post updates here and notify you of material changes [HOW].