Privacy policy

Last updated 9 September 2026

CaptionPipe takes a video, burns captions into it, and hands it back. This policy says what we hold while that happens, why, for how long, and how to have it removed.

Who runs CaptionPipe

The service is operated by Mobile Tech Media, LLC, a Wyoming, USA limited liability company, registered at 1309 Coffeen Avenue, STE 1200, Sheridan, WY 82801, USA. Anything in this policy reaches a person at [email protected]. CaptionPipe is sold to businesses and to the people who build automations for them. It is not intended for anyone under 18. Contact us if you believe a child has created an account.

Our role in what you send

For the video, audio and dictionary terms you submit, you decide what gets processed and why, and we process it on your instructions. For your account, your payments, our website and our own business records, the decisions are ours and this policy is our own commitment. If your organization needs a data processing agreement covering the first of those, write to us and we will work one out with you.

What we hold

Contact and account details: your email address, any name your sign-in provider passes on, and the state of your account. Account authorization information and protected API-key records. The media you submit and what we make from it: video, its audio, transcripts and word timings, caption files, and any dictionary of names sent with a job. Records of jobs and transactions: when a job ran, its status and duration, the seconds charged, and confirmation that a payment happened. Basic usage and device information of the kind every website receives, along with which pages were opened. And whatever you write to us for support, from the address you write from.

Why we hold it, and on what grounds

We use it to caption what you send, to run and protect your account, to take payment, to answer support, to keep the free trial to one per person, to understand in aggregate which parts of the product are used, and to meet legal obligations such as tax and accounting. Where a legal ground is required, we rely on performing our contract with you for the service and your account, on our legitimate interests in security and in preventing abuse of the trial, and on compliance with legal obligations for financial records. Where consent is required for analytics, we ask for it rather than assume it.

How long things stay

Your uploaded media, the captioned output and the caption files are deleted 24 hours after a job finishes, and dictionary terms are removed with them. An upload from a failed job goes on the same schedule or sooner. At our primary speech provider, uploaded audio is documented as deleted within 24 to 48 hours, and transcripts, stored references and related artifacts are held under a retention setting of 2 days; deletion begins when that period expires and can take additional days. A fallback speech provider, used only when the primary is unavailable, has a separate retention policy; we have not verified a deletion deadline for that service.

We retain account and job records while needed to provide the service. After closure, payment and related records may remain where required for tax and accounting. A keyed fingerprint of the email used for a free trial is kept so a second trial cannot be claimed; it cannot be read back as an address, but it is not anonymous and we treat it as personal data. Operational logs holding request metadata are kept for diagnosis and security, and no longer than we need them for that.

We do not use your media, transcripts or dictionaries to train our own models. We have opted out of our primary speech provider's model-improvement program. For our fallback provider we request the same, and our infrastructure provider's published policy states it does not use content run through its hosted models to train those models without our separate consent.

The companies that help us run this

These are the providers that handle personal data for us, and what each one gets.

Hetzner
Hosts our websites, on servers in Ashburn, Virginia, USA. Handles web requests and session information for the website and dashboard.
Cloudflare
Carries our traffic and runs the API, the video processing and the storage. Receives the media you submit, what we produce from it, and your account, job and payment records. When our primary speech provider is unavailable, Cloudflare also runs a fallback speech-to-text model (Deepgram Nova-3) on your video's audio, without a dictionary.
AssemblyAI
Transcribes speech as our primary provider. Receives the audio of your video and any dictionary terms sent with the job.
Clerk
Handles sign-in. Receives your email address, any name your sign-in provider supplies, and the method you signed in with.
Stripe
Takes payments and refunds. Receives your card and billing details on its own checkout page; we get confirmation, an identifier, the amount and the billing country.
PostHog
Product analytics hosted in the European Union. Receives nothing until you answer the analytics question. After that it receives usage events and browser information, and a signed-in account identifier only where you allowed analytics cookies.

Where processing happens

Our providers are not all in one country, and processing may happen outside the country you are in. Our websites are hosted in Ashburn, Virginia, USA. Storage location preferences do not guarantee where every processing operation or copy occurs. Where personal data moves between countries we rely on the contractual safeguards in our agreements with providers, where those apply to the transfer. Contact [email protected] for information about the safeguards that apply to your personal data, including how to obtain a copy.

Cookies and analytics

The dashboard sets the cookies needed to keep you signed in; without them it cannot work. A necessary cookie records your analytics choice. It is set across the website and the dashboard so a single answer covers both, it holds nothing but that choice, the version of the question it answers and the date it lapses, it carries no account identifier, and it is kept for 180 days so that we do not ask again and so a refusal survives your next visit. The analytics provider also stores a consent flag in browser storage after your answer; that flag is not an analytics identifier.

Analytics do not run until you answer. Before you choose, nothing is collected, nothing is held back to send later, and no analytics request is made at all. If you allow analytics cookies, analytics store an identifier in your browser, and in the dashboard events from a signed-in session are linked to your account identifier; we never send your name or your email address to the analytics provider, and the public website never links a visit to an account. If you reject analytics cookies, we still count usage in aggregate through the provider's server-side hashing, with no account identifier and no analytics identifier stored in your browser.

You can change your answer whenever you like, from Privacy choices in the website footer and at the foot of the dashboard. Stop all analytics there turns analytics off for that browser altogether and clears the analytics identifiers already stored, and afterwards no further event carries the identity from before. If your browser sends a Global Privacy Control signal, analytics are switched off whatever is saved, and we do not ask. There is no advertising, no sale of personal data, no session recording and no automatic click capture anywhere.

Your rights, and how to use them

You can ask for access to your personal data, for correction, for deletion, for a copy in a portable form, for restriction of or objection to processing, and you can withdraw consent where processing rests on it. You can complain to your data protection authority. Requests go to [email protected] and are handled by a person, so we verify them against the account's own address and answer within one month, or within 45 days for California residents.

Closing your account

Write to us from your account's address and we will close it. Deletion is handled by hand, so media from recent jobs expires on its ordinary 24 hour schedule while the request is worked through. If you have unused paid minutes, tell us and we will refund them under the terms. Analytics data linked to your account is covered by the same request; you do not have to ask twice. Visits that were never linked to an account cannot be found from your email address. Financial records and the trial fingerprint are kept, as described above.

How we protect it

Access to systems and data is limited to the people who run the service, everything in transit is encrypted, and your files sit in private storage reachable only through links that expire. No system is perfectly secure and we do not claim otherwise. Captioning is not end-to-end encrypted, because the media has to be readable to be captioned.

Agents and tools you connect

Most requests reach us from software acting for you. A request made with your credentials is treated as a request from you. The tool you chose runs under its own terms and its own privacy policy, and we do not list it as one of our providers.

Changes, and getting in touch

If a change materially affects how your data is handled, we will email the address on your account before the change takes effect. Questions, requests, or anything here that reads wrong to you: [email protected].