Legal
Privacy Policy
On this page
1. What we collect
Account details
Your email address, your display name, and a profile picture if you upload one or sign in with Google. If you set a password we store only a scrypt hash of it, never the password itself. If you register a passkey we store its public key and credential ID — the private key never leaves your device. If you sign in with Google we receive your email, name and Google profile picture from that sign-in.
What you tell us during onboarding
Whether you are a creator or a clipper, the kinds of content you make, your niche, which platforms you are on, the TikTok and Instagram handles and display names you give us, the clipping accounts you plan to post from, and your auto-clipping preferences. We look up the public profile picture behind a TikTok or Instagram handle you enter so the portal can show it back to you.
Billing
Your name, email, optional phone number, plan, subscription and invoice identifiers, the amount charged, and the referral code an order came through. We never see or store your card details. Card data goes directly from your browser to Stripe; we only ever hold Stripe's identifiers for you.
Usage inside the portal
Your plan, token balance and a ledger of every token charge and grant; your projects, their status and their names; the clips Cutline produced and what you did with them; the ratings and written feedback you leave on clips; your saved render styles and layouts; who is currently viewing a project (so a workspace can see each other's avatars); and any bug report you submit, including the page URL and a screenshot if you attach one.
Technical data
Your IP address, which we use for rate limiting and abuse prevention, and ordinary server logs kept by our hosting providers. We do not run analytics, advertising or third-party tracking scripts on any Cutline site.
2. Connected channels
When you connect a YouTube, Twitch or Kick channel we receive an OAuth access token and refresh token from that platform, plus your channel ID, channel name, handle and avatar. We store those tokens and use them only to do the things you asked for: read your streams and VODs, download the footage you select, fetch your analytics, and — where you have switched it on — upload finished clips back to your channel.
We never post anything without an instruction from you or a rule you turned on yourself, and we never use your tokens to read anything unrelated to the clipping work you asked for.
You can disconnect any channel at any time from the portal, which removes the stored tokens for it. You can also revoke Cutline's access from the platform's own side: Google at myaccount.google.com/permissions, and the equivalent connections page on Twitch or Kick.
Cutline's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Our use of the YouTube API Services is subject to the YouTube Terms of Service and the Google Privacy Policy.
3. Your footage and clips
To find clips, Cutline downloads the stream or video you point it at and works on it. That means we hold, for as long as the work needs it and afterwards unless you ask us to remove it:
- the source footage, split into chunks, and its audio;
- a full transcript of the audio, with timings and speakers;
- chat messages from the stream, where the platform exposes them;
- the moments, candidate clips and scores the pipeline generated;
- the finished clips, their captions and titles, and their render layouts.
Your footage is yours. We do not sell it, license it, publish it, or show it to anyone outside your own workspace. We process it to run the service you are paying for, and for nothing else.
4. AI and automated processing
Cutline is an automated clipping pipeline, so parts of your content are sent to AI services to be understood:
| Service | What we send | Why |
|---|---|---|
| Google Gemini | Video and audio segments, transcripts, chat excerpts, clip metadata | Finding moments, choosing cut points, scoring and verifying clips, writing captions and titles |
| Deepgram | Audio from your footage | Transcription and speaker separation |
We use the paid API tiers of both. Under Google's and Deepgram's current terms for those tiers, content submitted through the API is not used to train their models. Those terms are theirs, not ours — if that matters to you, read them at source before connecting a channel.
No clip is published anywhere by an automated decision alone unless you have explicitly enabled auto-posting for that destination. Where the pipeline cannot find a clip worth making, it returns nothing rather than inventing one.
5. How feedback trains Cutline
When you rate a clip or write a note about one, we run that feedback through an analysis step that turns it into short editorial lessons — things like “this creator dislikes clips that end before the payoff.” Those lessons are attached to your account and are used to steer future runs on your footage.
Some lessons become global. We may promote an individual lesson so that it applies to every customer's clipping, because a genuinely good editorial rule helps everyone. A promoted lesson is a short line of editorial guidance — it never contains your footage, your transcripts, your clips, your identity or your channel. If you would rather your feedback were never promoted this way, email us and we will exclude your account.
6. How we use your data
- To run the service — download footage, find and render clips, publish where you asked, and show you your projects.
- To bill you — take subscription payments, apply your monthly token allotment, and charge tokens for the actions you run.
- To keep your account secure — authenticate you, rate-limit sign-in attempts, and investigate abuse.
- To support you — answer emails, act on bug reports, and diagnose failures using our logs.
- To improve the product — understand which clips land, in the way described in section 5.
- To send you service email — account invitations, password resets, and notices about your subscription. We do not send marketing email without asking you first.
Our legal bases, where that framing applies to you: performing our contract with you (running the service and billing you), our legitimate interests (security, abuse prevention, product improvement), your consent (connecting a channel, enabling auto-posting), and legal obligation (keeping financial records).
7. Who we share it with
We do not sell your personal data and we do not share it for advertising. We use the following providers to run Cutline, and each one only receives what its job requires:
| Provider | What it does for us |
|---|---|
| Netlify | Hosts our sites and serverless functions; stores account credentials and sign-in tokens |
| Google Cloud | Runs the clipping pipeline; Google Sheets holds our client, project and billing records; Gemini does the analysis |
| Cloudflare | R2 stores footage, clips and uploaded images; Queues moves jobs; Stream serves video playback |
| Supabase | PostgreSQL database for transcripts, clip data, feedback and analytics snapshots |
| Deepgram | Transcribes your audio |
| Stripe | Takes payments and holds your card details — we never see them |
| Resend | Sends transactional email (invites, resets, receipts) |
| RapidAPI | Looks up the public TikTok or Instagram profile behind a handle you enter |
| YouTube, Twitch, Kick, TikTok, Instagram | The platforms you connect — we read from and post to them on your instruction |
We will also disclose data where the law requires it, and if Cutline is ever sold or merged your data would transfer with it — we would tell you before that happened.
8. Cookies and local storage
Cutline sets three cookies, all of them necessary to keep you signed in. There are no analytics, advertising or tracking cookies anywhere on our sites, so there is nothing here to opt out of.
| Cookie | Purpose | Lifetime |
|---|---|---|
| cl_session | Your signed-in session. Server-signed and not readable by page scripts. | 24 hours |
| cl_refresh | Renews your session so you are not signed out every day. Not readable by page scripts. | 30 days |
| cl_user | Your email and display name, so the portal can render your name and avatar without a round trip. Readable by the page. | 30 days |
During onboarding, your in-progress answers are held in your browser's local storage so a refresh does not lose them. Signing out clears your session cookies.
9. Where your data lives
Cutline runs in the United States. Our pipeline runs in Google Cloud's us-east1 region, our database is in us-east-2, and our hosting, storage and payment providers are US companies operating global infrastructure. If you are in the UK, the EEA or Switzerland, your data is transferred to the United States on the basis of the Standard Contractual Clauses or an equivalent transfer mechanism operated by each provider.
10. How long we keep it
Plainly: Cutline is early and we do not yet run an automated retention schedule. Today the position is:
- Raw footage chunks are deleted from storage when a clipping run's cleanup completes.
- Clips, transcripts, project records, feedback and account data are kept for as long as your account is open, and after that until you ask us to delete them.
- Billing records are kept for as long as tax and accounting law requires, which is typically seven years.
- Server logs are kept for as long as our hosting providers retain them, which is measured in weeks.
If you want your data gone sooner than that, ask us — section 11 says how, and we will do it.
11. Your rights and controls
You can, at any time:
- Disconnect a channel from the portal, which deletes its stored tokens. This one is self-serve.
- Ask for a copy of the personal data we hold about you.
- Ask us to correct anything that is wrong.
- Ask us to delete your account and everything attached to it.
- Object to or restrict how we process your data, and withdraw consent for anything you consented to.
- Ask us to exclude your feedback from the global lessons described in section 5.
How to exercise these. Email hello@cutline.co from the address on your account. There is no self-serve delete-my-account or export button in the portal yet; we handle these requests by hand and will complete them within 30 days. We will tell you when it is done.
Depending on where you live you may also have the right to complain to a data protection regulator — in the UK that is the Information Commissioner's Office. We would rather you came to us first.
12. Security
What we do:
- Every Cutline site is served over HTTPS only, with HSTS.
- Sessions are server-signed tokens in HttpOnly cookies. On the endpoints that read or change your account, projects, footage, clips and billing, your identity comes from that session and never from anything the browser claims.
- Passwords are hashed with scrypt and a per-user salt, and compared in constant time. Passkeys are supported and are stronger; we recommend them.
- Sign-in, password reset and lookup endpoints are rate limited.
- Access to the systems holding customer data is restricted to the people who operate Cutline.
And honestly: no system is perfectly secure, Cutline is a small operation, and we are still hardening it. If you find a security problem, email hello@cutline.co — we will read it the same day and we will not come after anyone who reports one in good faith. If a breach ever affects your data we will tell you and the relevant regulator without delay.
13. Age
Cutline is not for children. You must be at least 16 to use it, and at least 18 to buy a plan. We do not knowingly collect data from anyone younger; if we learn that we have, we delete it.
14. Changes to this policy
We will update this page when what we do changes, and the date at the top will move. If a change materially affects your rights we will email you before it takes effect rather than quietly editing the page.
15. Contact
Ask us anything about your data
Wilder Capital LLC, operating Cutline.
hello@cutline.co