Privacy Policy
We store your email, your billing reference and the videos you process — nothing beyond what the service needs.
No advertising trackers: audience measurement is first-party, served from our own domain, and stays off until you accept it in the banner. BYOK API keys are obfuscated in your own browser and never reach our servers.
Your content is never used to train AI models. Free-plan clips are deleted after 7 days.
1. Who is responsible
The data controller is TONVI TECH SL (CIF B-19780394), Calle Puerta del Mar 18, 5th floor, 29005 Málaga, Spain — the company behind OpenShorts (openshorts.app). For anything about your data, write to [email protected]. This policy is also available in Spanish; for residents of Spain, the Spanish version prevails in case of discrepancy.
2. What we process, why, and on what legal basis
Your account
Your email address (and, if you sign in with Google, your Google account identifier), sign-up and last-login dates. We use passwordless magic links, so we never store a password. Basis: performance of the contract (Art. 6.1.b GDPR).
Billing
Payments run entirely on Stripe: we store your Stripe customer reference, plan and subscription state, never your card number. Invoicing data is kept because tax law requires it. Basis: contract (Art. 6.1.b) and legal obligation (Art. 6.1.c).
The videos you process
The videos you upload or instruct us to fetch, their transcripts, and the clips generated from them are processed to deliver exactly the job you requested. Basis: contract (Art. 6.1.b). Where a video contains personal data of other people (their image, their voice), you are the controller of that data and we act as your processor on your instructions — see Section 6 of the Terms of Service.
Your rights declaration
Each time you submit a job you confirm you have the rights to the content. We keep that declaration with its date, your browser identifier and your IP address truncated to its network (the last part is discarded, so it identifies a network and not a device), as evidence of diligence in case of copyright or image-rights disputes. It is stored with the project it belongs to, and is deleted with your account. Basis: legitimate interest in establishing and defending legal claims (Art. 6.1.f).
Service emails, and the one that is not
We email you magic links, receipts, renewal reminders, clip-ready notices and warnings before clips are deleted. These are part of the service, not marketing. Basis: contract (Art. 6.1.b). One message is different: if you are on the free plan and run out of minutes, we send a single email suggesting an upgrade. That one is a commercial communication (Art. 21.2 of Spanish Law 34/2002, which permits it about our own similar products to our own customers), it carries an unsubscribe link and a one-click unsubscribe header in every send, and refusing it stops it permanently while leaving the service messages untouched. We do not run a newsletter and we never sell or rent your address.
Product analytics
We measure how the app is used with OpenPanel, running on an instance we operate ourselves; the measurement script is served from this domain, not from a third party. Nothing loads until you accept the "audience measurement" category in the cookie banner, and rejecting it is one click in the same banner — you can change your mind any time from the "cookies" link in the footer. We send the account's internal identifier (a random uuid) with these events so we can tell first-time from repeat use; we do not send your email address. No advertising pixels, no cross-site tracking, nothing shared with anyone. Basis: your consent (Art. 6.1.a GDPR and Art. 22.2 of Law 34/2002); withdraw it at any time in the banner or by emailing [email protected].
Security and anti-abuse
Server logs, IP-based rate limits and fraud signals, kept to protect the service and its users. Basis: legitimate interest (Art. 6.1.f). Application logs are kept in the container's rotating log for no more than 7 days and are not aggregated elsewhere; they do not contain your email address.
We do not process special categories of data (Art. 9 GDPR) as part of the service, we make no automated decisions with legal effects on you (Art. 22 GDPR), and we do not use your content or your data to train AI models — ours or anyone else's — nor sell it.
3. Cookies and local storage
We set no third-party cookies and load no third-party script on page load. What the site stores falls into two groups.
Strictly necessary — always on, no consent required. All of it is first-party and lives in your browser's local storage, not in a cookie: your session token (keeps you signed in), a short-lived media token (lets your browser fetch your own clips and thumbnails, which are not public), your interface preferences (last-used editor settings, tab, language), the first-visit referrer we record once at sign-up, and — if you use bring-your-own-key mode — your AI provider API keys. Those keys are obfuscated, not encrypted: the value is scrambled so it is not readable at a glance in developer tools, which is not the same as cryptographic protection, and anyone with access to your browser profile could recover them. They are sent only to perform your own jobs and are never stored on our servers. Your consent record itself is also stored here.
Audience measurement — always on, first-party only. OpenPanel (see section 2) writes an anonymous visitor identifier. The script is served from this domain; the instance is ours, the data is never shared and never used cross-site, which under the AEPD/CNIL criteria exempts it from prior consent. The consent banner is only shown to visitors in the EEA, the UK and Switzerland; identifiers live no longer than 13 months and raw data no longer than 25 months. "Reject all" and "Accept all" sit side by side in the banner, and the "cookies" link in the footer reopens it so you can withdraw consent as easily as you gave it.
Marketing. We use no advertising or remarketing trackers. The category exists in the banner so that if we ever add one it starts switched off.
4. Who receives data (processors) and where
Every provider we use, what each one receives, and where it is. The machine-readable version of this list, with the transfer safeguard for each, is kept in the public repository at docs/compliance/subprocessors.md and changes are recorded there.
- Google (Gemini API) — AI analysis to select moments, layouts, titles and thumbnails. It receives your video's transcript and sampled frames (which may show faces), the reference photo you pick for a thumbnail, and — only when the "screencast" layout check runs — the source video file itself, which we delete from Google's file store as soon as the answer comes back rather than letting it expire there. Google's paid API terms prohibit using customer data to train models. USA.
- ElevenLabs — AI dubbing and AI voices, only when you ask for it. Receives the clip's audio, which means the voice of whoever is speaking in it. USA.
- fal.ai — the image and video models behind AI Shorts (Flux for actor images, Kling and Hailuo for the talking avatar). Receives the actor photo you upload or generate — which may be a photograph of a real person — and the audio to lip-sync it to. USA.
- Stripe — payments and invoicing. USA/EU.
- Cloudflare R2 and Amazon Web Services S3 — storage of your clips and project files. EU/USA regions.
- Cloudflare — DNS and CDN in front of the website, so it sees the IP address and request metadata of every visitor. USA/global.
- Hetzner and Contabo — the servers the service runs on. Germany.
- Download proxies (DataImpulse and static ISP proxies) — when a video platform refuses our servers directly, the download is routed through a commercial proxy. It sees the URL of the video and carries its bytes; it receives no account data of yours.
- Upload-Post — publishing to social accounts you connect, only on your instruction, and the custodian of the platform tokens those connections produce. Operated by TONVI TECH SL under this same policy.
- Aikount — our own invoicing system, which issues the Spanish legal invoice for your payment and therefore receives your billing name, address and email from Stripe. Operated by TONVI TECH SL, servers in Germany.
- OpenPanel — first-party audience measurement, exempt from prior consent (section 3). The instance is ours and runs on our own servers in Germany; the script is served from this domain.
- Namecheap Private Email — delivery of service emails. USA.
- Google (sign in with Google) — only if you choose it, and only the "openid email profile" scope, so we learn your address and Google account id and nothing else. USA.
Two things we deliberately do not send anywhere: our internal operational alerts identify you by the first characters of your account identifier, never by your email address or the title of your video; and the face detection that decides where to crop runs on our own servers and produces no biometric template.
Where a provider processes data outside the European Economic Area, the transfer relies on the EU–US Data Privacy Framework where the provider is certified and, in any case, on the European Commission's Standard Contractual Clauses (Art. 46.2.c GDPR) as a fallback, together with the provider's technical safeguards. We prefer EU regions where the provider offers them.
5. How long we keep things
- Free-plan clips: 7 days, then permanently deleted (we warn you by email first).
- Paid-plan projects and clips: while your subscription is active, plus 7 days.
- Account data: while your account exists; after deletion, only what is needed to meet legal obligations or resolve disputes.
- Invoicing data: 6 years (Spanish commercial law).
- Rights declarations: up to 5 years with the project they belong to, matching the statute of limitations for civil claims, and deleted with your account if you delete it sooner.
- Working files on the processing server (the source download, the working copies): 1 hour after the job finishes. Uploads waiting for a job: 6 hours.
- Generated thumbnails and the video frames sampled to make them: 24 hours after you last downloaded one.
- Photos you upload to drive an AI actor: deleted with the job that used them, within the hour.
- Application logs: 7 days in the container's rotating log.
- Encrypted database backups: 30 days, after which a deletion you made is also gone from every copy.
- Analytics identifiers: 13 months; raw analytics data: 25 months.
The full, per-item version of this table, written against the actual code that enforces it, is in the public repository at docs/compliance/retencion.md.
6. Your rights
You can ask us for access, rectification, erasure, restriction, portability of your data, and object to processing based on legitimate interest — email [email protected] or [email protected] from your account address; we answer within one month. Two of these you can exercise yourself, right now, without asking anyone: Account → Download my data gives you a JSON file with everything our database holds about you plus a download link for every clip in your library (Art. 20), and Account → Delete account erases it (Art. 17). You do not need to ask us to erase your account: Account → Delete account in the dashboard does it yourself, immediately and permanently, taking your projects, clips, transcripts, API keys and social connections with it and cancelling any active subscription. Two things survive it, both listed in section 5: your invoices, which tax law requires us to keep, and a record that the deletion happened, which identifies you by a one-way hash of your email address rather than by the address itself. If you believe we are mishandling your data, you can complain to the Spanish supervisory authority (AEPD, aepd.es) or to the authority of your own EU country.
7. California residents (CCPA/CPRA)
If you live in California, this section is your notice at collection. In the last twelve months we have collected these categories of personal information: identifiers (the email address you sign in with); commercial information (your plan, your minute balance and the Stripe reference for your payments, never your card number); internet activity (first-party, self-hosted analytics about how the app is used); and audio and visual information (the videos you upload or link, their audio, the clips we produce and their transcripts). We collect them to run the service you asked for, to bill it, to keep it secure and to meet our legal obligations, as detailed in section 2. The sources are you and, where you paste a link, the platform you took the video from.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, and we do not do it with the data of anyone under 16. We disclose data to service providers only, for the purposes and to the recipients listed in section 4, under contracts that stop them using it for anything else.
Our reframing detects faces and subjects inside the picture so it knows where to crop. That happens on our own servers, is never used to recognise or identify anyone, and produces no faceprint or other identifier that could match a person across videos. We do not use sensitive personal information to infer characteristics about you, so the right to limit its use does not arise.
You have the right to know what we collect and to receive a copy of it, to have it corrected, to have it deleted, and not to be discriminated against for exercising any of these rights: we do not offer a worse service, a higher price or fewer features to anyone who does. Exercise them by emailing [email protected] from your account address, or delete everything yourself with Account → Delete account. We verify a request by the control you have over the account email, which is the same credential you sign in with, and we answer within 45 days. An authorised agent may act for you if they provide your written permission.
8. Age
The service is not directed at children. You must be at least 16, or the age of digital consent in your country if higher, to create an account, and you are asked to confirm that when you sign up. If you believe a minor has created an account, write to [email protected] and we will delete it.
8 bis. AI-generated content
Dubbing, AI Shorts and AI thumbnails produce synthetic content. We mark
what we generate in a machine-readable way — a metadata tag on video files and
an XMP DigitalSourceType: trainedAlgorithmicMedia marking on
generated images — as required by Art. 50(2) of Regulation (EU) 2024/1689 (the
AI Act). That marking does not always survive a platform re-encoding your
upload, so when you publish synthetic content you are the one who must turn on
the platform's own AI-content label (Art. 50(4)); the app reminds you at the
moment you post. Cloning a voice or animating a photograph of a real person
without their agreement is prohibited by the
Terms of Service, and both features ask you to confirm
you have that agreement before they run.
9. Changes
If we change this policy in any meaningful way we will tell you by email or in-app before the change takes effect, and the date on this page always reflects the current version.