C
Captifor FCP

Data Processing & Providers

How Capti processes your data and which third-party providers we use

Capti uses several trusted third-party providers to deliver our service. This page explains what data we store, how we process it, and which providers have access to your data.

What We Store

Job Data

For each captioning job you create, we store:

Data TypeDescription
Job metadataJob name, status, settings, creation date
Audio fileThe audio extracted from your video
Transcription fileList of words with precise timestamps
Grouping fileOrganized words within caption groups
SRT filesStandard subtitle format exports
FCPXML filesFinal Cut Pro project files

User Data

For each user account, we store:

Data TypeDescription
PresetsYour saved caption styles and preferences
Subscription informationYour plan and payment status
Credit balanceAvailable credits for processing jobs

Storage Provider

All job files and user data are stored on Convex, our backend database and file storage provider.

Processing Providers

Audio Transcription — Deepgram

Deepgram is the default transcription provider. Your audio is sent to Deepgram for speech-to-text transcription.

What they receive:

  • Audio only (no video). We send Deepgram a Convex storage URL and Deepgram fetches the file from it
  • Your account identifier is not sent, and no job metadata is sent. The audio itself is personal data — it is a recording of someone's voice

What they provide:

  • Word-level transcription with timestamps and punctuation
  • Multilingual recognition via the nova-3 model

Privacy & retention:

Audio Transcription — AssemblyAI

You can pick AssemblyAI instead of Deepgram when creating a job. It is also used automatically for languages the Deepgram multilingual model does not cover.

What they receive:

  • Audio file only (no video), fetched from a Convex storage URL the same way as Deepgram
  • Your account identifier is not sent, and no job metadata is sent

What they provide:

  • Word-level transcription with timestamps
  • Support for 100+ languages
  • High-accuracy speech recognition

Privacy & retention:

  • AssemblyAI is processed in the United States. See International transfers below
  • AssemblyAI's published terms state that customer audio is not used to train their models; refer to their policy below for the authoritative wording
  • AssemblyAI keeps the finished transcript until it is explicitly deleted, so we delete it as soon as we have fetched the words. Nothing of yours is left on their servers after a job completes
  • AssemblyAI Privacy Policy
  • AssemblyAI Terms of Service

Caption Grouping — Google Gemini

Transcription data is sent to the Google Gemini API for AI-powered caption grouping, using the gemini-3.1-pro-preview model.

What they receive:

  • Transcription text and timestamps
  • No audio files
  • No user identification information

What they provide:

  • Optimized caption grouping
  • Natural language processing for readability

Privacy & retention:

  • Capti uses a paid tier of the Gemini API. Google does not use prompts or responses from paid services to improve or train its products
  • Google does log prompts and responses for a limited period, solely to detect and prevent violations of its Prohibited Use Policy
  • Gemini API Additional Terms of Service
  • Google Privacy Policy

Capti Studio Omni — Social platforms & storage

Omni (multi-platform video publishing) uses additional providers when you connect accounts or upload videos.

Cloudflare R2 (no longer used)

Omni video uploads used to be stored on Cloudflare R2. Omni is shelved and we no longer send anything to Cloudflare. If Omni returns, this page will be updated before any upload happens.

Social OAuth — X, TikTok, Instagram, Threads, Google (YouTube)

When you connect a platform in Settings → Omni → Platforms, Capti runs OAuth with that provider.

What they receive:

  • Standard OAuth authorization (scopes vary by platform)
  • Redirect back to Capti after you approve access

What we store after connection:

  • Access tokens (and refresh tokens where the provider supports them)
  • Platform account ID, username, and display name
  • Scopes granted for publishing

Instagram & Threads (Meta):

  • Instagram uses the Instagram Login API (instagram_business_basic, instagram_business_content_publish)
  • Threads uses the Threads API (threads_basic, threads_content_publish)
  • Meta may send deauthorize and data-deletion callbacks; Capti processes these to revoke stored tokens

Disconnecting:

  • Remove the connection in Omni settings, or revoke the app from the platform
  • Meta users can also trigger deletion via Meta's app removal flow

Provider policies:

User Management & Payments

Authentication - Clerk

User accounts and authentication are exclusively handled by Clerk.

What they manage:

  • User registration and login
  • Email verification
  • Account security
  • Email notifications for account and billing

Privacy & security:

Payments — Polar (Merchant of Record)

Billing is handled by Polar (Polar Software Inc.), acting as our Merchant of Record. Polar is the seller of record for your subscription: it accepts and processes payments on our behalf, and handles billing, invoicing, refunds and sales tax/VAT.

What they receive:

  • Your email address and account identifier, to link the subscription to your account
  • Subscription and payment status
  • Payment and billing details you enter during checkout

What Capti never sees:

  • Card numbers or other payment credentials — these go directly to Polar and its payment processor and are never stored by Capti

Downstream processing:

Security & compliance:

Marketing & Analytics

Web Analytics - Vercel & PostHog

We collect usage analytics through Vercel Analytics and PostHog, and ad conversion data through Google Ads.

Not all of this is anonymous, so it is worth being precise about which parts are:

ToolRuns whenTied to your account?
Vercel Speed InsightsAlways, no consent askedNo
Vercel AnalyticsOnly after you acceptNo
PostHog (browser)Only after you acceptYes — including your email address and name
PostHog session replayOnly after you acceptYes
Google AdsOnly after you acceptPseudonymous ad identifiers
PostHog (from our servers)Always, independent of the cookie bannerYes — account identifier only, no content

Vercel Analytics

What they collect:

  • Page views and navigation patterns
  • Performance metrics
  • Geographic location (country-level)
  • Device and browser type

Privacy:

PostHog

Our PostHog project runs on PostHog's EU cloud, and browser traffic is proxied through usecapti.com/ingest so it is not blocked by ad blockers.

What they collect in your browser (only if you accept cookies):

  • Product analytics: which features you use, uploads, exports, checkout steps
  • Your email address and name, attached to your PostHog profile so events can be tied to your account
  • Session replay: a recording of your screen inside the app, including the caption editor and therefore the text of your transcript. Retained for 30 days
  • Caught front-end exceptions

What they collect from our servers (regardless of the cookie banner):

  • Pipeline outcomes we cannot see from the browser: whether a transcription finished, how long it took, why it failed, model token counts
  • These carry your account identifier so they can be joined to your browser events. They carry no audio, no transcript text, no email and no name
  • We rely on legitimate interest for this. You can object at any time and we stop sending them — the switch is in Settings → Data & privacy

Privacy:

We run a Google Ads conversion tag (AW-18084619795) to measure which ads lead to signups.

  • It loads only after you accept cookies. Decline and no request is made to Google
  • Google receives pseudonymous ad identifiers and your IP address, in the United States
  • Google Privacy Policy

jsDelivr (removed)

No longer used. The FFmpeg WebAssembly build that extracts audio from your video in your own browser used to be fetched from the public jsDelivr CDN, which disclosed your IP address to that CDN as soon as you opened the upload screen. We now serve it ourselves, so no third party is involved.

Svix

Clerk delivers its account webhooks to us through Svix. Svix sees the webhook payload, which contains your account identifier, email address and name.

Data Retention & Deletion

Automatic Deletion

Your uploaded audio is deleted 30 days after you upload it. A daily job removes the recording. Everything else about the project stays — the transcript, the caption groups, the SRT and the FCPXML remain editable and downloadable, and the editor replaces the waveform with a note saying the audio expired. This applies whether or not the transcription succeeded: a failed job still holds a recording of someone's voice, so it is swept the same way.

Everything else is kept until you delete it. A two-year expiry for accounts that go completely unused is built but not switched on. We will update this page before it starts deleting anything.

Manual Deletion

You can delete your data at any time:

Delete a specific job:

  1. Open the job page
  2. Click the delete button
  3. Confirm deletion
  4. All associated files are immediately removed

Delete your account: go to Settings → Data & privacy → Delete account, then confirm under Security. (The same control lives in your avatar menu under Manage account.)

Deleting your account removes your jobs, all their files, your presets and your credit balance from Convex, and deletes your Polar customer record.

What happens after deletion:

  • Convex: jobs, presets, credits and all associated files removed immediately
  • Clerk: account and authentication data removed
  • Polar: invoices are kept for 10 years, because French accounting law requires it (Code de commerce, art. L123-22). We cannot delete these on request
  • Deepgram: refer to Deepgram's published retention policy, linked above
  • AssemblyAI: nothing to delete — we delete the transcript from AssemblyAI as soon as we have fetched it, long before you close your account
  • Google Gemini: Google retains prompts briefly for abuse prevention, on its own schedule
  • PostHog: your analytics profile, its events and any session recordings are deleted
  • Social accounts: stored tokens are revoked with the platform, then deleted
  • Cloudflare: no longer used, nothing of yours is held there

Security Measures

  • Encryption in transit: TLS

  • Encryption at rest: provided by Convex for the database and file storage

  • Authentication: session management handled by Clerk

  • Authorisation: every job, preset and file is checked against the account that owns it before it is returned

  • Transport: HSTS, and the app cannot be embedded in a frame by another site

Data Sovereignty

Capti is operated from France, and most of the services below process data in the United States:

ProviderWhereTransfer basis
ConvexUnited States (AWS)Convex's data processing agreement
DeepgramUnited StatesDeepgram's data processing agreement
AssemblyAIUnited StatesAssemblyAI's data processing agreement
Google GeminiGoogle Cloud regions, globalGoogle's data processing terms
ClerkUnited States, global CDNClerk's data processing agreement
Polar / StripeGlobalPolar's terms; Stripe's data processing agreement
PostHogEuropean UnionWithin the EU, no transfer
VercelGlobal edge networkVercel's data processing agreement

Each provider publishes the safeguards it relies on for transfers out of the EU — Standard Contractual Clauses and, where applicable, certification under the EU–US Data Privacy Framework. We are documenting the specific mechanism for each one; see Known gaps.

Your Rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify data that is wrong
  • Erase your data — the in-app deletion tools above, or ask us
  • Restrict or object to processing, including our server-side analytics
  • Portability — receive your data in a machine-readable format
  • Withdraw consent at any time, without affecting what was done beforehand
  • Give directives about what happens to your data after your death (art. 85, Loi Informatique et Libertés)
  • Lodge a complaint with the CNIL, the French supervisory authority — cnil.fr

To exercise any of these, email contact@usecapti.com, or use the in-app deletion tools.

We answer as quickly as we can and, as the GDPR requires, within one month of your request.

For access and portability you do not need to ask: Settings → Data & privacy → Download my data gives you a JSON file containing your account details, your caption presets and every job with its transcript and captions.

Known gaps

We would rather list what is not done than describe a product we have not built. Each of these is being worked on:

GapStatus
The audio URL we hand to transcription providers does not expireBeing fixed
Stored social-account tokens are not encrypted at restBeing fixed
Automatic deletion of long-inactive accounts is built but not switched onPending
No Content-Security-Policy on scripts yet, only on framingPending
The exact transfer mechanism for each US provider is not yet documented hereBeing documented

Closed recently: source audio now expires after 30 days; AssemblyAI transcripts are deleted as soon as we have fetched them; deleting your account now also deletes your social connections and their tokens, your Omni videos, and your PostHog profile and session recordings; the Google Ads tag no longer loads before you consent; session replay now masks your transcript; file downloads are authenticated and checked against the account that owns them; FFmpeg is served by us instead of a public CDN.

Last reviewed: 15 August 2026.

Questions?

If you have questions about data processing or privacy: