Data Processing & Providers
How Capti processes your data and which third-party providers we use
Capti uses several trusted third-party providers to deliver our service. This page explains what data we store, how we process it, and which providers have access to your data.
What We Store
Job Data
For each captioning job you create, we store:
| Data Type | Description |
|---|---|
| Job metadata | Job name, status, settings, creation date |
| Audio file | The audio extracted from your video |
| Transcription file | List of words with precise timestamps |
| Grouping file | Organized words within caption groups |
| SRT files | Standard subtitle format exports |
| FCPXML files | Final Cut Pro project files |
User Data
For each user account, we store:
| Data Type | Description |
|---|---|
| Presets | Your saved caption styles and preferences |
| Subscription information | Your plan and payment status |
| Credit balance | Available credits for processing jobs |
Storage Provider
All job files and user data are stored on Convex, our backend database and file storage provider.
- Data is encrypted in transit and at rest
- Convex publishes its own compliance certifications and its GDPR data processing agreement; we link them below rather than certify them ourselves
- Convex stores data in the United States (AWS). See International transfers below
- Convex Privacy Policy
- Convex Terms of Service
- Convex Data Processing Agreement
- Convex Subprocessors
Processing Providers
Audio Transcription — Deepgram
Deepgram is the default transcription provider. Your audio is sent to Deepgram for speech-to-text transcription.
What they receive:
- Audio only (no video). We send Deepgram a Convex storage URL and Deepgram fetches the file from it
- Your account identifier is not sent, and no job metadata is sent. The audio itself is personal data — it is a recording of someone's voice
What they provide:
- Word-level transcription with timestamps and punctuation
- Multilingual recognition via the
nova-3model
Privacy & retention:
- Deepgram is processed in the United States. See International transfers below
- The Convex storage URL we hand to Deepgram is not time-limited today. We are changing this — see Known gaps
- Deepgram Privacy Policy
- Deepgram Terms of Use
Audio Transcription — AssemblyAI
You can pick AssemblyAI instead of Deepgram when creating a job. It is also used automatically for languages the Deepgram multilingual model does not cover.
What they receive:
- Audio file only (no video), fetched from a Convex storage URL the same way as Deepgram
- Your account identifier is not sent, and no job metadata is sent
What they provide:
- Word-level transcription with timestamps
- Support for 100+ languages
- High-accuracy speech recognition
Privacy & retention:
- AssemblyAI is processed in the United States. See International transfers below
- AssemblyAI's published terms state that customer audio is not used to train their models; refer to their policy below for the authoritative wording
- AssemblyAI keeps the finished transcript until it is explicitly deleted, so we delete it as soon as we have fetched the words. Nothing of yours is left on their servers after a job completes
- AssemblyAI Privacy Policy
- AssemblyAI Terms of Service
Caption Grouping — Google Gemini
Transcription data is sent to the Google Gemini API for AI-powered caption grouping, using the gemini-3.1-pro-preview model.
What they receive:
- Transcription text and timestamps
- No audio files
- No user identification information
What they provide:
- Optimized caption grouping
- Natural language processing for readability
Privacy & retention:
- Capti uses a paid tier of the Gemini API. Google does not use prompts or responses from paid services to improve or train its products
- Google does log prompts and responses for a limited period, solely to detect and prevent violations of its Prohibited Use Policy
- Gemini API Additional Terms of Service
- Google Privacy Policy
Capti Studio Omni — Social platforms & storage
Omni (multi-platform video publishing) uses additional providers when you connect accounts or upload videos.
Cloudflare R2 (no longer used)
Omni video uploads used to be stored on Cloudflare R2. Omni is shelved and we no longer send anything to Cloudflare. If Omni returns, this page will be updated before any upload happens.
Social OAuth — X, TikTok, Instagram, Threads, Google (YouTube)
When you connect a platform in Settings → Omni → Platforms, Capti runs OAuth with that provider.
What they receive:
- Standard OAuth authorization (scopes vary by platform)
- Redirect back to Capti after you approve access
What we store after connection:
- Access tokens (and refresh tokens where the provider supports them)
- Platform account ID, username, and display name
- Scopes granted for publishing
Instagram & Threads (Meta):
- Instagram uses the Instagram Login API (
instagram_business_basic,instagram_business_content_publish) - Threads uses the Threads API (
threads_basic,threads_content_publish) - Meta may send deauthorize and data-deletion callbacks; Capti processes these to revoke stored tokens
Disconnecting:
- Remove the connection in Omni settings, or revoke the app from the platform
- Meta users can also trigger deletion via Meta's app removal flow
Provider policies:
- Meta Platform Terms
- Instagram Platform Policy
- Google API Services User Data Policy
- TikTok Developer Terms
- X Developer Agreement
User Management & Payments
Authentication - Clerk
User accounts and authentication are exclusively handled by Clerk.
What they manage:
- User registration and login
- Email verification
- Account security
- Email notifications for account and billing
Privacy & security:
- Clerk publishes its own SOC 2 Type II certification and GDPR commitments; we link them rather than certify them ourselves
- Clerk Privacy Policy
- Clerk Terms of Service
Payments — Polar (Merchant of Record)
Billing is handled by Polar (Polar Software Inc.), acting as our Merchant of Record. Polar is the seller of record for your subscription: it accepts and processes payments on our behalf, and handles billing, invoicing, refunds and sales tax/VAT.
What they receive:
- Your email address and account identifier, to link the subscription to your account
- Subscription and payment status
- Payment and billing details you enter during checkout
What Capti never sees:
- Card numbers or other payment credentials — these go directly to Polar and its payment processor and are never stored by Capti
Downstream processing:
- Polar uses Stripe as its underlying payment processor. Stripe publishes its own PCI-DSS Level 1 attestation
- Stripe Privacy Policy
Security & compliance:
Marketing & Analytics
Web Analytics - Vercel & PostHog
We collect usage analytics through Vercel Analytics and PostHog, and ad conversion data through Google Ads.
Not all of this is anonymous, so it is worth being precise about which parts are:
| Tool | Runs when | Tied to your account? |
|---|---|---|
| Vercel Speed Insights | Always, no consent asked | No |
| Vercel Analytics | Only after you accept | No |
| PostHog (browser) | Only after you accept | Yes — including your email address and name |
| PostHog session replay | Only after you accept | Yes |
| Google Ads | Only after you accept | Pseudonymous ad identifiers |
| PostHog (from our servers) | Always, independent of the cookie banner | Yes — account identifier only, no content |
Vercel Analytics
What they collect:
- Page views and navigation patterns
- Performance metrics
- Geographic location (country-level)
- Device and browser type
Privacy:
- No personal identification
- No cookies required
- Anonymized data only
- Vercel Privacy Policy
- Vercel Terms of Service
PostHog
Our PostHog project runs on PostHog's EU cloud, and browser traffic is proxied through
usecapti.com/ingest so it is not blocked by ad blockers.
What they collect in your browser (only if you accept cookies):
- Product analytics: which features you use, uploads, exports, checkout steps
- Your email address and name, attached to your PostHog profile so events can be tied to your account
- Session replay: a recording of your screen inside the app, including the caption editor and therefore the text of your transcript. Retained for 30 days
- Caught front-end exceptions
What they collect from our servers (regardless of the cookie banner):
- Pipeline outcomes we cannot see from the browser: whether a transcription finished, how long it took, why it failed, model token counts
- These carry your account identifier so they can be joined to your browser events. They carry no audio, no transcript text, no email and no name
- We rely on legitimate interest for this. You can object at any time and we stop sending them — the switch is in Settings → Data & privacy
Privacy:
- PostHog publishes its own GDPR and CCPA commitments and a data processing agreement
- PostHog Privacy Policy
- PostHog Terms of Service
Google Ads
We run a Google Ads conversion tag (AW-18084619795) to measure which ads lead to signups.
- It loads only after you accept cookies. Decline and no request is made to Google
- Google receives pseudonymous ad identifiers and your IP address, in the United States
- Google Privacy Policy
jsDelivr (removed)
No longer used. The FFmpeg WebAssembly build that extracts audio from your video in your own browser used to be fetched from the public jsDelivr CDN, which disclosed your IP address to that CDN as soon as you opened the upload screen. We now serve it ourselves, so no third party is involved.
Svix
Clerk delivers its account webhooks to us through Svix. Svix sees the webhook payload, which contains your account identifier, email address and name.
Data Retention & Deletion
Automatic Deletion
Your uploaded audio is deleted 30 days after you upload it. A daily job removes the recording. Everything else about the project stays — the transcript, the caption groups, the SRT and the FCPXML remain editable and downloadable, and the editor replaces the waveform with a note saying the audio expired. This applies whether or not the transcription succeeded: a failed job still holds a recording of someone's voice, so it is swept the same way.
Everything else is kept until you delete it. A two-year expiry for accounts that go completely unused is built but not switched on. We will update this page before it starts deleting anything.
Manual Deletion
You can delete your data at any time:
Delete a specific job:
- Open the job page
- Click the delete button
- Confirm deletion
- All associated files are immediately removed
Delete your account: go to Settings → Data & privacy → Delete account, then confirm under Security. (The same control lives in your avatar menu under Manage account.)
Deleting your account removes your jobs, all their files, your presets and your credit balance from Convex, and deletes your Polar customer record.
What happens after deletion:
- Convex: jobs, presets, credits and all associated files removed immediately
- Clerk: account and authentication data removed
- Polar: invoices are kept for 10 years, because French accounting law requires it (Code de commerce, art. L123-22). We cannot delete these on request
- Deepgram: refer to Deepgram's published retention policy, linked above
- AssemblyAI: nothing to delete — we delete the transcript from AssemblyAI as soon as we have fetched it, long before you close your account
- Google Gemini: Google retains prompts briefly for abuse prevention, on its own schedule
- PostHog: your analytics profile, its events and any session recordings are deleted
- Social accounts: stored tokens are revoked with the platform, then deleted
- Cloudflare: no longer used, nothing of yours is held there
Security Measures
-
Encryption in transit: TLS
-
Encryption at rest: provided by Convex for the database and file storage
-
Authentication: session management handled by Clerk
-
Authorisation: every job, preset and file is checked against the account that owns it before it is returned
-
Transport: HSTS, and the app cannot be embedded in a frame by another site
Data Sovereignty
Capti is operated from France, and most of the services below process data in the United States:
| Provider | Where | Transfer basis |
|---|---|---|
| Convex | United States (AWS) | Convex's data processing agreement |
| Deepgram | United States | Deepgram's data processing agreement |
| AssemblyAI | United States | AssemblyAI's data processing agreement |
| Google Gemini | Google Cloud regions, global | Google's data processing terms |
| Clerk | United States, global CDN | Clerk's data processing agreement |
| Polar / Stripe | Global | Polar's terms; Stripe's data processing agreement |
| PostHog | European Union | Within the EU, no transfer |
| Vercel | Global edge network | Vercel's data processing agreement |
Each provider publishes the safeguards it relies on for transfers out of the EU — Standard Contractual Clauses and, where applicable, certification under the EU–US Data Privacy Framework. We are documenting the specific mechanism for each one; see Known gaps.
Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectify data that is wrong
- Erase your data — the in-app deletion tools above, or ask us
- Restrict or object to processing, including our server-side analytics
- Portability — receive your data in a machine-readable format
- Withdraw consent at any time, without affecting what was done beforehand
- Give directives about what happens to your data after your death (art. 85, Loi Informatique et Libertés)
- Lodge a complaint with the CNIL, the French supervisory authority — cnil.fr
To exercise any of these, email contact@usecapti.com, or use the in-app deletion tools.
We answer as quickly as we can and, as the GDPR requires, within one month of your request.
For access and portability you do not need to ask: Settings → Data & privacy → Download my data gives you a JSON file containing your account details, your caption presets and every job with its transcript and captions.
Known gaps
We would rather list what is not done than describe a product we have not built. Each of these is being worked on:
| Gap | Status |
|---|---|
| The audio URL we hand to transcription providers does not expire | Being fixed |
| Stored social-account tokens are not encrypted at rest | Being fixed |
| Automatic deletion of long-inactive accounts is built but not switched on | Pending |
| No Content-Security-Policy on scripts yet, only on framing | Pending |
| The exact transfer mechanism for each US provider is not yet documented here | Being documented |
Closed recently: source audio now expires after 30 days; AssemblyAI transcripts are deleted as soon as we have fetched them; deleting your account now also deletes your social connections and their tokens, your Omni videos, and your PostHog profile and session recordings; the Google Ads tag no longer loads before you consent; session replay now masks your transcript; file downloads are authenticated and checked against the account that owns them; FFmpeg is served by us instead of a public CDN.
Last reviewed: 15 August 2026.
Questions?
If you have questions about data processing or privacy:
- Email: contact@usecapti.com
- See our Privacy Policy
- See our Terms of Service