Legal
Privacy Policy
Last updated
What we collect, why we collect it, who processes it for us, and the choices you have. This policy covers this website and the AutoEditor web app.
1. Who we are
UGC AutoEditor (“we”, “us”, “our”) makes AutoEditor, a web app that takes a UGC creator from a brand brief to finished, edited ad variations, and runs this website. In this policy, “the service” means both.
AutoEditor is currently in a private beta. Access is by invitation, and the features, the providers we use and this policy may change as the beta develops. We’ll keep this page up to date when they do.
2. Information we collect
When you request early access
- Your email address.
- Your name, if you give it.
- Your creator type and the plan you’re interested in, if you choose them.
- Which page on our site you sent it from, when you sent it, and when you last updated it.
When you have an account
- Your email address and, if you give it, your name.
- Your password — but never as you typed it. We store only a salted scrypt hash, which lets us check a password you enter without being able to read the original.
- Session records that keep you signed in: a random identifier, your account and when the session expires.
- The plan or access level on your account, and any access we’ve granted you.
Content you upload or create
The service exists to work on your material, so we store and process:
- Video, audio and image files you upload, or film in Shoot Mode. Filming uses your camera and microphone only after you allow it in your browser, and a take you throw away with Retake is never uploaded.
- Project details, such as the project, brand, product and campaign names.
- Brand briefs you paste, the requirements AutoEditor finds in them, and any changes you make to those.
- Transcripts of your talking clips, including words you correct.
- Scripts, hooks, calls to action, shot lists and shoot plans.
- Edits, variations, caption styles, approvals and exports.
- Analysis derived from your material: story moments, audio quality labels, descriptions of what’s in your footage, take coaching and Brief Check results.
Usage and technical information
- Allowance and usage counters, such as how many projects, Auto Edit runs or exports your account has used.
- Job records for processing work — transcription, analysis, Auto Edit, rendering — and whether it succeeded.
- Records of AI processing: which feature ran, the model, token counts, timing and estimated cost. These hold no creator content.
- Records of what you did with a suggestion (for example, kept, replaced or removed it), stored as fixed categories rather than your content, so we can tell whether suggestions are helping.
- Standard server logs. Our hosting providers process request information such as your IP address, browser and device type, the address requested and the time. Our own logs record events and errors so we can keep the service running.
Cookies and browser storage
- When you sign in, we set one essential cookie,
ugc_session. It’s HttpOnly, so scripts on the page can’t read it, and it keeps you signed in until you sign out or the session expires. - We don’t use advertising cookies, and this marketing site sets no tracking cookies.
- Pages on this site may ask our own server whether you’re already signed in, so they can show “Open AutoEditor” instead of “Sign In”. That check uses your existing session cookie, if there is one, and sets nothing new.
- The app keeps a few small flags in your browser’s local storage, such as whether you’ve already dismissed a notice. They stay on your device.
3. How we use information
- To provide the service: store your files, transcribe talking clips, read briefs, analyse footage, plan shoots, build edits and render exports.
- To run the beta: review early-access requests, decide who to invite, and contact you about access. If you have an account, we may also tell you about important changes to the service.
- To keep the service secure and working: sign you in, apply your plan’s access and allowances, prevent abuse and investigate errors.
- To measure capacity and cost: understand how much processing the service uses and whether AutoEditor’s suggestions help, so we can set allowances and improve the product.
- To meet legal obligations and enforce our terms.
We don’t sell your personal information, and we don’t use your content for advertising. We also won’t use your footage or other content in our own marketing without your permission. Our Terms of Service say the same.
4. AI and processing providers
We use a small number of providers to run the service. They process information on our behalf, and each receives only what’s needed for the part of the service it runs.
- OpenAI
- When AI features are enabled, transcription and the analysis of your footage and briefs run through OpenAI’s API. Depending on the feature, we send the audio of a talking clip (to transcribe it), still frames sampled from a clip (to understand what’s in it), or text such as your brief, transcript excerpts, product details or the direction you type when you ask for a new version of an edit. We don’t include your email address, your password or links to your stored files.
- Vercel
- Hosts this website and the AutoEditor web app.
- Supabase
- Hosts our Postgres database: account, project and usage records, briefs, transcripts and edit data.
- Cloudflare R2
- Stores your uploaded files and exports in a private bucket. Your browser reaches them only through short-lived signed links.
- Railway
- Runs our background media processing: preparing uploads, extracting audio for transcription, and rendering previews and exports.
We may also disclose information when the law requires it; to protect the rights, safety or security of our users, the public or the service; or as part of a merger, acquisition or sale of the business, in which case this policy continues to apply to the information transferred.
5. Links to other sites
This site may link to services we don’t run — for example, a referral link to Trybe, a place to find UGC campaigns. When you follow one, you leave our site, and that service’s own terms and privacy policy apply to what happens there. Our Referral Disclosure explains how referral links work.
6. How long we keep information
- Early-access requests: until we close the early-access list. If you ask us to delete your request sooner, we delete it by hand.
- Your account and content: while your account is active, or until you delete them. You can delete a project or a clip in the app at any time, and deleting a project removes its stored files with it. To delete your whole account, contact us.
- Sessions: each one expires on its own, and signing out ends it.
- Job records: while the project they belong to exists. Deleting a project deletes them.
- Usage and activity records (usage counters, records of AI processing and of what you did with a suggestion): kept to operate, secure and debug the service. We don’t yet delete these on a fixed schedule.
- Server logs: kept by our hosting providers for their own limited retention periods.
Deleted information can remain for a limited time in backups or provider logs before it expires. We may keep information longer where the law requires it, or where we need it to resolve a dispute or enforce our terms.
7. Your choices and rights
You can:
- Ask for a copy of the personal information we hold about you.
- Ask us to correct information that’s wrong.
- Ask us to delete your early-access request, your account, or specific information.
- Delete your own projects and clips in the app — download any exports you want to keep first.
- Ask us to stop contacting you about early access.
To make a request, use the details under Contact. We may need to confirm the request comes from you, for example by asking you to write from the email address on your account or request. Depending on where you live, you may have further rights, such as objecting to or restricting certain processing, or complaining to a data protection authority. We won’t treat you differently for using them.
8. Children
The service isn’t directed to children. You must be at least 18 to request early access or create an account, and we don’t knowingly collect personal information from anyone under 18. If you believe someone under 18 has given us personal information, contact us and we’ll delete it.
9. Security
We use measures designed to protect your information, including:
- Encrypted connections between your browser and the service, and to our database.
- Passwords stored only as salted scrypt hashes.
- A private storage bucket, reachable only through short-lived signed links.
- Access checks so an account can reach only its own projects and files.
No method of sending or storing information is perfectly secure, so we can’t guarantee absolute security. Use a password you don’t use elsewhere, and sign out on shared devices.
10. International processing
We and our providers may process and store information in the United States and other countries, whose data protection laws may differ from those where you live. Wherever it’s processed, we handle your information as this policy describes.
11. Changes to this policy
We’ll update this policy as the service changes — for example, if a feature starts using a new provider. When we do, we’ll change the “Last updated” date at the top. If a change materially affects how we handle your information, we’ll take reasonable steps to let you know before it takes effect, such as a notice in the app or a message to the email address on your account or request.
12. Contact
For privacy requests, or questions about this policy:
A contact address for privacy and legal requests hasn't been configured for this deployment yet.