Skip to content

legal

Privacy Policy

Last updated: September 4, 2026

Short version: we collect the minimum needed to provide the plugin and browser studio: account details, purchase and credit records, license activations, short-lived caption-job results, verified review submissions, affiliate application and commission records, messages you choose to send through the feedback page, pseudonymous first-party site-usage and performance measurements, your purchase-source answer, and your optional marketing preference. No advertising profiles and no selling data. Ever.

1. Who is responsible

Data controller: Sarbaz Jan, trading as Caption Plug, an independent software business based in the United Kingdom. Contact: support@captionplug.com (our postal address is available on request for legal correspondence).

2. What we collect and why

Cookieless page, event, and Web Vitals measurementsUnderstanding public-page use, failures, conversions, and performance without recording captions, file names, or video content (legitimate interest).
Verified review submissionPublishing your rating and review only with consent, and verifying product use against the same account (consent, legitimate interest).
DataWhy (legal basis)
Pseudonymous visitor, session, page, funnel, referrer-domain, and campaign recordsMeasuring first-party site use and purchase drop-off without storing raw IP addresses, ad IDs, caption content, file names, or video data (legitimate interest).
Optional “how did you find us?” answerUnderstanding which marketing channels help customers discover the product (legitimate interest).
Email + password (hashed)Your account: login, download access, password resets (contract).
Purchase recordsDelivering what you bought, refunds, tax/accounting obligations (contract, legal obligation).
Credit balance + immutable usage ledgerDelivering prepaid browser-studio credits and preventing double charging (contract).
Caption job timing + pseudonymous IP/audio hashesRetry recovery, one-credit idempotency, fraud prevention and rate limiting (contract, legitimate interest). Raw IPs and source videos are not stored in the studio database.
License + machine activation hashesEnforcing the 3-machine license and fighting piracy (legitimate interest). The hash is a fingerprint the plugin computes; we never see your files or hardware details.
Download log (IP, browser user-agent, time)Abuse and fraud tracing on signed download links (legitimate interest).
Support emails and product-feedback messagesAnswering you, fixing bugs, and improving the product (legitimate interest). Feedback message bodies are delivered to the developer inbox and are not stored in the website database.
Affiliate application, legal country, referral, commission, and payout recordsReviewing affiliate applications, opening the correct country-specific Stripe payout flow, calculating commission, preventing fraud, and paying affiliates (contract, legitimate interest, legal obligation).
Marketing-email preferenceRecording your signup choice (legitimate interest). Marketing is sent only where consent or the product-and-service soft opt-in applies. You can unsubscribe at any time.

Payment card, affiliate bank-account, identity-document, and verification data goes directly to Stripeand never touches our servers. Stripe acts as its own controller for payment and payout processing; see Stripe's privacy policy.

3. Plugin and browser-studio media

The Caption Plug plugin runs locally inside Premiere Pro. By default, the bundled Whisper model transcribes on your device, so your selected audio does not leave your machine. If you deliberately select an optional OpenAI or Groq integration, the audio goes directly from your machine to that provider using your own API key and still does not pass through our servers. The plugin contacts our servers only for license activation/validation (your account sign-in + machine hash) and to check for updates.

In the browser studio, your source video stays on your device. The browser extracts a mono audio track for a video of no more than 60 seconds and sends that audio through our authenticated server endpoint to Groq for transcription. We do not log or store the audio file. Groq returns transcript text and word timestamps; those results are available as a retry cache for 24 hours so a network retry cannot charge you twice. It is then made inaccessible and removed by the next daily cleanup (within 48 hours of creation). Caption rendering and final video export happen on your device.

4. Cookies

Supabase uses strictly-necessary authentication cookies to keep you logged in. Caption Plug sets pseudonymous first-party visitor and session cookies to connect page, checkout, and purchase steps. Vercel Web Analytics and Speed Insights use no advertising cookies. Analytics never contains transcript text, file names, caption text, private video data, or raw IP addresses. Blocking necessary cookies means login will not work; clearing site data resets the anonymous visitor and session identifiers.

5. Where data lives and who processes it

  • Supabase - database, authentication, file storage (processor).
  • Stripe - payments (independent controller for the transaction).
  • Vercel - website hosting and request logs (processor).
  • Groq - browser-studio audio transcription (processor).
  • Cloudflare Turnstile - account abuse prevention (processor).
  • YouTube - privacy-enhanced embedded product tutorials (independent controller).
  • Google Gmail - SMTP delivery and the developer support and feedback inbox (processor).

Transfers outside the EEA/UK rely on the processors' Standard Contractual Clauses / Data Privacy Framework participation.

6. Retention

  • Account data: until you delete your account.
  • Purchase records: as long as tax law requires (typically 6-10 years).
  • Download logs: 12 months.
  • Browser-studio transcript retry cache: accessible up to 24 hours, deleted within 48 hours.
  • Pseudonymous caption-job abuse records: up to 45 days.
  • Welcome-credit identity hash: retained to prevent repeatedly deleting and recreating an account for free credits. It cannot be reversed into your email without our separate secret.
  • Support emails and product-feedback messages: up to 24 months.
  • Pseudonymous product-feedback abuse events: 30 days. Message bodies are not stored with these events.
  • Pending or rejected review records: up to 24 months for moderation and abuse control; approved reviews remain until consent is withdrawn or the account is deleted, subject to legal retention needs.
  • First-party marketing analytics: up to 13 months, then deleted or aggregated. Vercel performance records follow the configured Vercel retention period.
  • Purchase-source answers: while the related purchase record is retained, or until you ask us to delete the answer.
  • Affiliate applications and financial ledgers: while the programme account is active and afterward for applicable tax, accounting, fraud-prevention, and legal retention periods.
  • Marketing preference: until you withdraw it or delete your account. A keyed, non-reversible suppression hash may remain afterward so a withdrawn address is not accidentally re-added.

7. Your rights (GDPR / UK GDPR / CCPA)

You can ask for access, a copy (portability), correction, deletion, restriction, or object to processing - email support@captionplug.comand we'll act within 30 days. You can complain to your local data-protection authority. We don't sell or "share" personal information as defined by the CCPA, and we don't use it for cross-context behavioral advertising. Deleting your account removes your personal data; purchase records we're legally required to keep are retained in minimized form.

8. Security

Row-level security on every table, transactional credit reservations, Stripe-signature and Price-ID validation, HMAC-pseudonymized abuse identifiers, signed 5-minute download URLs, layered rate limits, Turnstile, strict Content-Security-Policy and HSTS, and passwords hashed by Supabase Auth. No system is perfect; if we ever detect a breach affecting you, we'll notify you as required by law.

9. Changes

We'll update this page when anything changes and bump the date at the top. See also the Terms of Service.