OpenShorts logoOpenShorts Get free clips
Home Privacy Policy

Privacy Policy

TL;DR

We store your email, your billing reference and the videos you process — nothing beyond what the service needs.

No advertising trackers: audience measurement is first-party, served from our own domain, and stays off until you accept it in the banner. BYOK API keys are obfuscated in your own browser and never reach our servers.

Your content is never used to train AI models. Free-plan clips are deleted after 7 days.

1. Who is responsible

The data controller is TONVI TECH SL (CIF B-19780394), Calle Puerta del Mar 18, 5th floor, 29005 Málaga, Spain — the company behind OpenShorts (openshorts.app). For anything about your data, write to [email protected]. This policy is also available in Spanish; for residents of Spain, the Spanish version prevails in case of discrepancy.

2. What we process, why, and on what legal basis

Your account

Your email address (and, if you sign in with Google, your Google account identifier), sign-up and last-login dates. We use passwordless magic links, so we never store a password. Basis: performance of the contract (Art. 6.1.b GDPR).

Billing

Payments run entirely on Stripe: we store your Stripe customer reference, plan and subscription state, never your card number. Invoicing data is kept because tax law requires it. Basis: contract (Art. 6.1.b) and legal obligation (Art. 6.1.c).

The videos you process

The videos you upload or instruct us to fetch, their transcripts, and the clips generated from them are processed to deliver exactly the job you requested. Basis: contract (Art. 6.1.b). Where a video contains personal data of other people (their image, their voice), you are the controller of that data and we act as your processor on your instructions — see Section 6 of the Terms of Service.

Your rights declaration

Each time you submit a job you confirm you have the rights to the content. We keep that declaration with its date, your browser identifier and your IP address truncated to its network (the last part is discarded, so it identifies a network and not a device), as evidence of diligence in case of copyright or image-rights disputes. It is stored with the project it belongs to, and is deleted with your account. Basis: legitimate interest in establishing and defending legal claims (Art. 6.1.f).

Service emails, and the one that is not

We email you magic links, receipts, renewal reminders, clip-ready notices and warnings before clips are deleted. These are part of the service, not marketing. Basis: contract (Art. 6.1.b). One message is different: if you are on the free plan and run out of minutes, we send a single email suggesting an upgrade. That one is a commercial communication (Art. 21.2 of Spanish Law 34/2002, which permits it about our own similar products to our own customers), it carries an unsubscribe link and a one-click unsubscribe header in every send, and refusing it stops it permanently while leaving the service messages untouched. We do not run a newsletter and we never sell or rent your address.

Product analytics

We measure how the app is used with OpenPanel, running on an instance we operate ourselves; the measurement script is served from this domain, not from a third party. Nothing loads until you accept the "audience measurement" category in the cookie banner, and rejecting it is one click in the same banner — you can change your mind any time from the "cookies" link in the footer. We send the account's internal identifier (a random uuid) with these events so we can tell first-time from repeat use; we do not send your email address. No advertising pixels, no cross-site tracking, nothing shared with anyone. Basis: your consent (Art. 6.1.a GDPR and Art. 22.2 of Law 34/2002); withdraw it at any time in the banner or by emailing [email protected].

Security and anti-abuse

Server logs, IP-based rate limits and fraud signals, kept to protect the service and its users. Basis: legitimate interest (Art. 6.1.f). Application logs are kept in the container's rotating log for no more than 7 days and are not aggregated elsewhere; they do not contain your email address.

We do not process special categories of data (Art. 9 GDPR) as part of the service, we make no automated decisions with legal effects on you (Art. 22 GDPR), and we do not use your content or your data to train AI models — ours or anyone else's — nor sell it.

3. Cookies and local storage

We set no third-party cookies and load no third-party script on page load. What the site stores falls into two groups.

Strictly necessary — always on, no consent required. All of it is first-party and lives in your browser's local storage, not in a cookie: your session token (keeps you signed in), a short-lived media token (lets your browser fetch your own clips and thumbnails, which are not public), your interface preferences (last-used editor settings, tab, language), the first-visit referrer we record once at sign-up, and — if you use bring-your-own-key mode — your AI provider API keys. Those keys are obfuscated, not encrypted: the value is scrambled so it is not readable at a glance in developer tools, which is not the same as cryptographic protection, and anyone with access to your browser profile could recover them. They are sent only to perform your own jobs and are never stored on our servers. Your consent record itself is also stored here.

Audience measurement — always on, first-party only. OpenPanel (see section 2) writes an anonymous visitor identifier. The script is served from this domain; the instance is ours, the data is never shared and never used cross-site, which under the AEPD/CNIL criteria exempts it from prior consent. The consent banner is only shown to visitors in the EEA, the UK and Switzerland; identifiers live no longer than 13 months and raw data no longer than 25 months. "Reject all" and "Accept all" sit side by side in the banner, and the "cookies" link in the footer reopens it so you can withdraw consent as easily as you gave it.

Marketing. We use no advertising or remarketing trackers. The category exists in the banner so that if we ever add one it starts switched off.

4. Who receives data (processors) and where

Every provider we use, what each one receives, and where it is. The machine-readable version of this list, with the transfer safeguard for each, is kept in the public repository at docs/compliance/subprocessors.md and changes are recorded there.

Two things we deliberately do not send anywhere: our internal operational alerts identify you by the first characters of your account identifier, never by your email address or the title of your video; and the face detection that decides where to crop runs on our own servers and produces no biometric template.

Where a provider processes data outside the European Economic Area, the transfer relies on the EU–US Data Privacy Framework where the provider is certified and, in any case, on the European Commission's Standard Contractual Clauses (Art. 46.2.c GDPR) as a fallback, together with the provider's technical safeguards. We prefer EU regions where the provider offers them.

5. How long we keep things

The full, per-item version of this table, written against the actual code that enforces it, is in the public repository at docs/compliance/retencion.md.

6. Your rights

You can ask us for access, rectification, erasure, restriction, portability of your data, and object to processing based on legitimate interest — email [email protected] or [email protected] from your account address; we answer within one month. Two of these you can exercise yourself, right now, without asking anyone: Account → Download my data gives you a JSON file with everything our database holds about you plus a download link for every clip in your library (Art. 20), and Account → Delete account erases it (Art. 17). You do not need to ask us to erase your account: Account → Delete account in the dashboard does it yourself, immediately and permanently, taking your projects, clips, transcripts, API keys and social connections with it and cancelling any active subscription. Two things survive it, both listed in section 5: your invoices, which tax law requires us to keep, and a record that the deletion happened, which identifies you by a one-way hash of your email address rather than by the address itself. If you believe we are mishandling your data, you can complain to the Spanish supervisory authority (AEPD, aepd.es) or to the authority of your own EU country.

7. California residents (CCPA/CPRA)

If you live in California, this section is your notice at collection. In the last twelve months we have collected these categories of personal information: identifiers (the email address you sign in with); commercial information (your plan, your minute balance and the Stripe reference for your payments, never your card number); internet activity (first-party, self-hosted analytics about how the app is used); and audio and visual information (the videos you upload or link, their audio, the clips we produce and their transcripts). We collect them to run the service you asked for, to bill it, to keep it secure and to meet our legal obligations, as detailed in section 2. The sources are you and, where you paste a link, the platform you took the video from.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, and we do not do it with the data of anyone under 16. We disclose data to service providers only, for the purposes and to the recipients listed in section 4, under contracts that stop them using it for anything else.

Our reframing detects faces and subjects inside the picture so it knows where to crop. That happens on our own servers, is never used to recognise or identify anyone, and produces no faceprint or other identifier that could match a person across videos. We do not use sensitive personal information to infer characteristics about you, so the right to limit its use does not arise.

You have the right to know what we collect and to receive a copy of it, to have it corrected, to have it deleted, and not to be discriminated against for exercising any of these rights: we do not offer a worse service, a higher price or fewer features to anyone who does. Exercise them by emailing [email protected] from your account address, or delete everything yourself with Account → Delete account. We verify a request by the control you have over the account email, which is the same credential you sign in with, and we answer within 45 days. An authorised agent may act for you if they provide your written permission.

8. Age

The service is not directed at children. You must be at least 16, or the age of digital consent in your country if higher, to create an account, and you are asked to confirm that when you sign up. If you believe a minor has created an account, write to [email protected] and we will delete it.

8 bis. AI-generated content

Dubbing, AI Shorts and AI thumbnails produce synthetic content. We mark what we generate in a machine-readable way — a metadata tag on video files and an XMP DigitalSourceType: trainedAlgorithmicMedia marking on generated images — as required by Art. 50(2) of Regulation (EU) 2024/1689 (the AI Act). That marking does not always survive a platform re-encoding your upload, so when you publish synthetic content you are the one who must turn on the platform's own AI-content label (Art. 50(4)); the app reminds you at the moment you post. Cloning a voice or animating a photograph of a real person without their agreement is prohibited by the Terms of Service, and both features ask you to confirm you have that agreement before they run.

9. Changes

If we change this policy in any meaningful way we will tell you by email or in-app before the change takes effect, and the date on this page always reflects the current version.