Privacy policy

Last updated June 11, 2026

1. Overview

This policy explains what data EditorBuddy collects when you use our website, editing app, API and MCP server, why we collect it, and the choices you have. We've tried to write it in plain language — if anything is unclear, email support@editorbuddy.com.

2. Account data

We handle authentication ourselves. When you sign up with an email and password, we store your email address and a securely hashed password — we never store your raw password. You can also sign in with Google, in which case we receive your Google account's email and basic profile information (name and avatar).

3. Video, audio and project content

Files you upload are stored in Cloudflare R2, a private object store scoped to your account. Source files, intermediate renders and exports are accessible only to your account and the agents processing your jobs — they aren't used to train models for other users, and aren't shared with other accounts.

Deleted projects remove their files from R2 within 30 days, including intermediate render artifacts.

4. Transcripts and LLM processing

To plan and execute a job, our agents send relevant data — transcripts, scene descriptions, your prompt, and your stored style preferences — to large language models through our internal model router. User content is sanitized and clearly marked as untrusted input before it reaches a model; it is never placed in a system prompt.

We don't use your content to train foundation models. Some processing may use third-party model providers (selected per task for quality, speed or cost); they process your data under their own data-processing terms and don't retain it for training beyond what's contractually required for abuse prevention.

5. Memory

If you use EditorBuddy's memory feature, we store a model of your editing preferences — caption styles, pacing, banned words, and similar — as plain statements you can view, edit or delete from the memory panel at any time. Deleting a memory entry removes it from future jobs immediately.

6. Analytics

We use PostHog to understand how the product is used — which features get opened, where people get stuck, and aggregate performance metrics. PostHog collects device, browser and usage events; it doesn't have access to your video content or transcripts. You can opt out of analytics from /settings.

7. Cookies

We use essential, httpOnly cookies for authentication and session management (set by EditorBuddy), and analytics cookies (set by PostHog) if you haven't opted out. We don't use third-party advertising cookies.

8. Data sharing

We share data with the infrastructure providers required to run the service — Google (only when you choose Sign in with Google), Cloudflare (storage and edge compute), our LLM providers (via the model router), and PostHog (analytics) — each bound by their own data-processing agreements. We don't sell your data, and we don't share your video content or transcripts with advertisers.

9. Data retention and deletion

Project files and transcripts are retained while your account is active and for 30 days after a project is deleted, to allow recovery. Deleting your account removes your profile, projects, files and memory entries; this is irreversible after the 30-day grace period. Request deletion from /settings or by emailing support@editorbuddy.com.

10. Your rights

Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to certain processing. You can exercise most of these directly from /settings; for anything else, contact us and we'll respond within 30 days.

11. Children's privacy

EditorBuddy isn't directed at children under 13, and we don't knowingly collect data from them. If you believe a child has created an account, contact us and we'll remove it.

12. Changes to this policy

We'll update the date at the top of this page when this policy changes, and notify you of material changes by email or in-app notice.