Privacy Policy
Last updated: 2 October 2026
This policy explains what information CutLuma (“we”, “us”) collects when you use our video editor, why we collect it, who helps us process it, and the choices you have. The short version: we collect what we need to run your account and store your videos, we don’t sell your data, and we don’t use advertising or tracking cookies.
1. Information we collect
- Account details — your name, email address and password. Passwords are stored only as a salted hash; we can’t read them.
- Your content — the videos, audio and images you upload or record, your projects, thumbnails, and exported videos you choose to save.
- Usage of your plan — your plan, storage used, number of projects, AI caption minutes used this month, and when you last signed in.
- Billing details — if you buy a plan, our payment provider Stripe collects your payment details. We receive a customer reference, your subscription status and a record of payments. We never see or store your full card number.
- Share pages — for videos you share by link we keep a view count, and the comments and reactions viewers leave (with the name they type). To prevent spam we store a one-way hash derived from the commenter’s IP address, not the address itself.
- Security records — to protect accounts we briefly record failed sign-in attempts and new sign-ups together with the IP address they came from. These records are deleted automatically after about 24 hours.
- Using the editor without an account — your project and files stay in your own browser and are not uploaded. If you use AI captions without an account, the audio is sent for transcription and we keep a one-way hash derived from your IP address for a few days to apply the daily free allowance.
- Videos sent through a collection link — when someone records or uploads a video through a testimonial link, the video, the name and the note they type are stored in the library of the account that created the link. To prevent abuse we briefly keep a one-way hash derived from the sender’s IP address.
- Invites — if you sign up through a friend’s invite link we record which account invited you, so both of you receive the reward.
- Anonymous counts — we count page views and how often features are used as daily totals. These totals contain no names, emails, IP addresses or other identifiers.
- Technical logs — like most websites, our hosting provider processes basic request data (such as IP address, browser type and pages requested) to deliver the Service and keep it secure.
2. How we use it
- to provide the Service: sign you in, save your projects, store and stream your media, export and share your videos;
- to apply your plan’s limits and process subscriptions;
- to generate captions when you ask for them;
- to keep the Service secure and prevent abuse, spam and fraud;
- to answer you when you contact us, and to tell you about important changes to the Service.
We don’t sell your personal information, and we don’t use your content to train AI models.
3. Cookies and browser storage
We use one essential cookie: a session cookie that keeps you signed in. It is HTTP-only, lasts up to 30 days and is removed when you log out. If you arrive through a friend’s invite link, a second cookie remembers the invite code for up to 30 days and is removed when you sign up. We don’t use advertising, analytics or cross-site tracking cookies.
The editor also saves a few preferences and temporary working data in your browser’s own storage on your device (for example, the name you last used on a comment, or your draft project and its files when you edit without an account). This stays in your browser and you can clear it at any time in your browser settings.
4. Who helps us process your data
We share information only with the service providers we need to run CutLuma:
- Cloudflare — hosts the website and application, our database, and stores your media files (Cloudflare R2). Cloudflare operates a global network, so data may be processed in countries other than your own.
- Cloudflare Workers AI — when you use AI captions, the audio of the clip you choose is sent to a speech-recognition model to produce the transcript. We don’t send audio for transcription unless you start it. When you use “Long video → shorts” the transcript is sent to a language model to pick highlights, and when you use “Product link → video ad” we fetch the page you paste and send its product text to a language model to draft the script.
- Resend — delivers the emails we send you (password resets, and notifications you can turn off in your account settings).
- Stripe — processes payments and manages subscriptions and invoices. Stripe handles your payment details under its own privacy policy.
- Google Fonts — our pages load fonts from Google, which means your browser requests them from Google’s servers.
We may also disclose information if the law requires it, or to protect the rights, safety and security of our users and the Service.
5. Sharing is your choice
Your media and projects are private to your account by default. A video becomes viewable by others only when you create a share link for it — then anyone who has the link can watch it and, unless you turn those options off, download it and comment. You can turn a link off at any time and it stops working immediately. Comments and names posted on a share page are visible to everyone who opens that link.
6. How long we keep things
- Your account, projects and media are kept until you delete them or ask us to delete your account.
- When you delete a media file it is removed from our storage, together with its share link, comments and reactions.
- Sign-in sessions expire after 30 days. Security records are deleted after about 24 hours, and the hashed records used for free AI allowances after a few days.
- Payment records may be kept for as long as tax and accounting laws require.
7. Deleting your account and your rights
You can update your name and password in your account settings and delete projects and media yourself at any time. To delete your account, contact us and we’ll remove it together with your projects, media files and share links.
Depending on where you live, you may also have the right to ask for a copy of your personal data, to have it corrected, to restrict or object to certain processing, and to complain to your local data-protection authority. Contact us and we’ll help.
8. Security
We protect your data with encrypted connections (HTTPS), hashed passwords, private-by-default file storage, and limits on repeated sign-in attempts. No online service can promise perfect security, so please use a strong, unique password and keep your own copies of important files.
9. Children
The Service is not directed at children under 13, and we don’t knowingly collect their personal information. If you believe a child has created an account, contact us and we’ll delete it.
10. Changes to this policy
If we change how we handle personal information we’ll update this page and the date at the top, and let you know in the app when the change is significant.
11. Contact
Questions or requests about your data? Please contact the site administrator.
See also our Terms of Service.