Skip to content

Privacy Policy

Effective Date: October 5, 2026
Last updated: October 4, 2026

This Privacy Policy explains how Novaire Capital Corporation ("we", "us", "our") collects, uses, shares and protects personal information when you use ReCut - AI Video Editor ("ReCut"), our video editing app for iPhone. It also explains the choices you have and the rights the law gives you.

ReCut edits talking videos. You record or import clips, ReCut removes the dead air, filler words, retakes and tangents, and you finish the edit and export it to your Photos library. Almost all of that happens on your iPhone. The one step that needs our servers is the AI edit, and for that ReCut sends the audio track of your project, never the picture. This policy explains exactly what that means, who receives what, and for how long.

Please read it together with our Terms of Service and our Data Privacy Policy, which gives the full account of ReCut's AI processing, the in-app AI consent word for word, and every company that processes data for ReCut. All of them are listed in section 20.

1. Who we are

Novaire Capital Corporation, a corporation based in Ontario, Canada, makes ReCut and is responsible for the personal information described in this policy. Under the GDPR and the UK GDPR, it is the "controller" of that information.

Novaire Capital Corporation (Ontario, Canada)
Email: support@userecut.com (support, privacy requests and the Privacy Officer, copyright notices)

Privacy Officer. Under Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, the person in charge of the protection of personal information at Novaire Capital Corporation is our Privacy Officer. You can reach the Privacy Officer at support@userecut.com about anything in this policy, wherever you live.

EU and UK requests. We have not appointed a separate representative in the EU or the UK. Novaire Capital Corporation handles requests from the EEA, the UK and Switzerland directly: write to support@userecut.com about anything in this policy.

What this policy covers. It covers the ReCut app and the pages we publish about it. It doesn't cover what Apple, Google or the other companies named in section 7 do with information for their own purposes, such as running your Apple Account or your Google Account. Their own privacy policies apply to that.

2. Summary

  • Only the audio track of your video leaves your iPhone. Video frames, photos, thumbnails and your project library never do.
  • Projects live only on this iPhone. Deleting ReCut deletes them. ReCut keeps no copy of your projects or videos on its servers, so it can't restore them.
  • Nothing is sent to our AI providers until you agree to ReCut's AI consent, which you do by continuing on the sign-in screen, and you can turn AI processing off at any time.
  • ReCut does not train AI models on your videos, audio or transcripts.
  • We don't sell personal information. Advertising measurement is only for people who allow tracking in Apple's prompt. If you ask ReCut not to track, no advertising SDK starts.
  • ReCut is not directed to children under 13.

The rest of this policy gives the details.

3. Information we collect

We collect only what ReCut needs to work, to be paid for, to stay secure and to get better. This section lists all of it. Section 11 says how long each item is kept.

3a. Before you create an account

Before you sign in, ReCut can play a sample edit and ask you five questions: what kind of creator you are, the niches you make videos about, how often you post, how many videos you make a week and how long you spend editing. From your answers it estimates the editing time ReCut could save you. The answers are kept on your iPhone, and they are sent to PostHog as product analytics events (section 3l) under a random identifier. When you sign in, those events are joined to your account.

From the first launch, before you sign in, the subscription SDKs (RevenueCat and Superwall) and our crash reporting (Sentry) also start, each under a random identifier, and Superwall's SDK makes an install-attribution check (section 8e). Nothing you type during these steps is sent to our own servers, and ReCut can't be used beyond them without an account.

3b. Your account

You sign in with Apple or Google. ReCut has no passwords, and there is no way to use it without signing in.

When you sign in, we receive from Apple or Google:

  • your email address. If you use Apple's Hide My Email, we receive the relay address Apple creates, not your own address;
  • your sign-in identity: the identifier Apple or Google uses for you with ReCut, and which of the two you used;
  • with Google, your name and a link to your profile picture, which Google shares with every sign-in and our sign-in service stores with your account. ReCut doesn't use or show them. With Apple, ReCut doesn't ask for your name.

We create a random user ID for your account. It identifies your account inside ReCut and with our processors, and it contains nothing about you.

If you sign in with Apple, we also keep the authorization Apple gives ReCut, encrypted, so that we can revoke it with Apple when you delete your account (section 16).

3c. Your age

ReCut doesn't ask your age or your birthdate. If you gave an age range in an earlier version of the app, we keep it with your account until you delete the account, and we don't use it for anything.

Before ReCut sends any audio for an AI edit, you agree to its AI consent, which names our AI providers, by continuing on the sign-in screen (section 5a). We keep your answer, the version of the consent text you answered (currently ai-consent-v1), and when you answered. We keep this so that we can show you consented, and so that ReCut can ask you again if the text changes.

3e. The audio track of the projects you edit with AI

When you start an AI edit, ReCut makes a compressed, mono copy of the project's audio track on your iPhone, with no picture and no location data, and sends it to our servers for transcription (section 5). The audio contains whatever is said in your video, which may include other people's voices. It is deleted right after transcription (section 11). If other people speak in your videos, you are responsible for having the consent the law requires to record them and to edit their voices with AI (Terms of Service, section 11).

3f. Transcripts and cut plans

Our transcription provider turns the audio into a transcript: the words, when each one was said, and which ones were filler words. If retakes or tangents are switched on when you start the edit, our analysis provider reads the transcript and returns a cut plan: the parts it suggests removing, each with a reason. Both are sent to your iPhone, which builds the edit, and are then deleted from our servers (section 11).

Your iPhone keeps a copy of the transcript inside the project, because captions and the editor use it. It stays on your iPhone with the project.

3g. Usage and job records

For every AI edit we keep a record that holds no content: its status, when it started and finished, how long the audio was, how many clips it had, what it cost us to process, and any error code. We also keep a ledger of the edits and audio minutes you have used. These records enforce your plan's limits, help us prevent abuse, and let us control costs.

3h. Subscription and purchase information

Apple processes every payment. We never receive your card or other payment details. Through RevenueCat, we receive your subscription status from the App Store: your plan, whether you are in a trial, when your subscription renews or ends, and the purchase and renewal events of your subscription. If you enter a creator code, we record that you redeemed it and the access it gave you.

3i. Your push notification token

If you allow notifications, iOS gives ReCut a push token. We store it so that we can tell you when a cut is ready (section 10), together with your choice of which notifications you want.

3j. Feedback on cuts

In the editor you can rate a cut from one to five stars and tick reasons, for example that too much or too little was cut. We keep your rating and reasons. You can also choose to include the cut's transcript with your feedback, with the "Include the transcript" switch. It is off by default, and it applies only to the feedback you send with it. A transcript you include is kept for 30 days.

3k. Diagnostics

If ReCut crashes, freezes or hits an error, it sends a report to Sentry: the kind of error, your device model, your iOS and app versions, your user ID and an identifier Sentry creates for the installation. Section 9 explains what these reports never include.

3l. Product analytics

ReCut records in-app events and sends them to PostHog with your user ID, device model, app version, and your iPhone's language and time-zone settings. Examples are when the app is installed and opened, which onboarding steps you completed and what you chose there (if you answer them, the kind of creator you are, the niches you make videos about, how often you post, how many videos you make a week and how long you spend editing), when an edit starts and finishes, and which export settings you used. Events never contain your email, name, handle, transcripts, captions, on-screen text, project titles, file names or any code you enter. You can turn product analytics off (section 9).

3m. Device and advertising identifiers

  • Everyone. Superwall's SDK reads your iPhone's identifier for vendors (an identifier that is the same for every app from one developer on one iPhone), device model, locale, time zone and App Store country.
  • People who allow tracking, only. If you allow tracking in Apple's prompt, the advertising SDKs (Meta, TikTok and Appstack) can read your advertising identifier (the IDFA) and the identifier for vendors, and ReCut gives RevenueCat those identifiers, your IP address and device model, plus the ad-campaign details those SDKs report (such as the campaign, ad and click identifiers that brought you to ReCut). Section 8 explains how all of this is used. If you ask ReCut not to track, nothing in this second group is collected.

3n. IP addresses

ReCut's own servers never store your IP address. To limit abuse, they keep a salted, one-way hash of it for up to 48 hours, used only to count requests. Like any internet service, our processors see your IP address when the app connects to them, and RevenueCat records it for people who allow tracking (section 3m). PostHog is set to discard IP addresses, so ReCut doesn't work out where you are from them.

3o. Messages you send us

If you email us, including through Profile → Settings → Contact us, we receive your email address, your message and anything the email includes. The email ReCut drafts for you already holds your app version, iOS version, device model, plan and account ID, so we can help you faster; you can delete them before sending. We use what you send only to answer you and to keep a record of your request.

3p. What stays on your iPhone

Everything you make in ReCut is kept on your iPhone: the clips you record or import, camera drafts, edits, thumbnails and caches. Projects live only on this iPhone. Deleting ReCut deletes them. ReCut keeps no copy of your projects or videos on its servers, so it can't restore them.

ReCut uses your camera and microphone to record, and your Photos library to import the clips you pick and to save your exports. All of that happens on your iPhone. Exported videos go to your Photos library, where iOS and your own iCloud settings govern them.

If you give ReCut your first name or a handle during onboarding, they stay on your iPhone too. ReCut uses them only to greet you and never sends them anywhere; analytics records only whether you filled them in. Deleting your account removes them from the iPhone.

Your iPhone's own backups. If you back up your iPhone to iCloud or a computer, iOS includes ReCut's project files (such as each project's edits and transcript) and settings in that backup, but not your clips or videos. Apple and your own backup settings govern those backups; ReCut can't read them.

4. What we don't collect

  • Your video. Only the audio track of your video leaves your iPhone. Video frames, photos, thumbnails and your project library never do.
  • Your Photos library. ReCut reads only the clips you pick, through Apple's picker, and only on your iPhone. Its Photos permission lets it add your exports to the library, not read it.
  • Your location, precise or coarse. The audio file we receive carries no location data, and PostHog discards IP addresses.
  • Your age or birthdate. ReCut doesn't ask for either.
  • Your payment details. Apple handles payment.
  • Your contacts, browsing history, or health or financial information.
  • Biometric identifiers. ReCut does not create voiceprints or any other biometric identifier from your voice. We use the audio only to turn speech into text for your edit.

5. How ReCut's AI works

ReCut asks for your consent before any audio is sent, on its sign-in screen: the line under the sign-in buttons reads "By continuing you agree to the ReCut Agreement.", and continuing agrees to it. The ReCut Agreement, one tap away on that screen, shows the AI consent, which names Deepgram, OpenRouter and Anthropic, says what each one receives and says how long it is kept. It links to our Data Privacy Policy, which repeats the text word for word.

You can turn AI processing off at any time in Profile → Settings → AI processing. While it is off, nothing is sent: you can still edit by hand and use Quick cut, which removes silences on your iPhone without sending anything. If your agreement couldn't be recorded when you signed in, or the consent text changes, ReCut asks on a screen of its own, where you can choose "Not now". Our servers check your consent again before every AI edit, so no edit can start without it.

5b. What happens during an AI edit

  1. On your iPhone, ReCut finds the silences in your project and extracts its audio track.
  2. The audio track goes to temporary storage on our servers, hosted by Supabase in Canada.
  3. Deepgram turns the audio into a transcript with word timings and filler-word flags. Deepgram is told not to use your audio to improve its models. ReCut asks it to transcribe English, so ReCut works best with English speech.
  4. If retakes or tangents are switched on when you start the edit, Anthropic's AI models read the transcript text, not the audio, to find retakes, false starts, repeats and tangents. The transcript text reaches Anthropic's AI models through OpenRouter, a service that passes it to Anthropic and returns the answer. If both are off, neither OpenRouter nor Anthropic receives anything. Anthropic may keep the transcript text it receives for up to 30 days, and does not use it to train its models.
  5. Our servers check the suggestions and send the transcript and the cut plan to your iPhone, which builds the edit. Filler words come from the transcript and silences from your iPhone.

The audio is deleted right after transcription and is never kept longer than 48 hours. Transcripts and cut plans are deleted when your iPhone receives them, or within 7 days if it never does.

5c. Providers, not models

We name our AI providers, not the models they run. Which model we use is a setting on our servers. It can change without changing what is sent or who receives it. A change of provider, or of what is sent, changes this policy, the Data Privacy Policy and the in-app consent text together, and ReCut then asks for your consent again.

5d. No training

ReCut does not train AI models on your videos, audio or transcripts.

5e. No decisions about you

The AI suggests cuts to your video. It makes no decisions about you, and nothing it produces has legal or similarly significant effects on you. AI cuts can be wrong. Review your video before you share it; every AI cut can be restored.

We use personal information only for the purposes below. If we ever want to use it for a new purpose, we will tell you first and, where the law requires it, ask for your consent.

Purpose Information used Legal basis under the GDPR and UK GDPR
Create your account, sign you in and keep your account secure Account information, user ID Contract
Record your AI consent Consent answers and version Legal obligation (showing that consent was given)
Run AI edits and deliver the results to your iPhone Audio track, transcripts, cut plans, job records Consent (the AI consent you agree to at sign-in), and contract
Sell and manage subscriptions, apply plan limits and creator codes Subscription information, usage records Contract
Show the subscription screen and test versions of it User ID, plan attributes, paywall views and purchase outcomes Contract, and legitimate interests (improving our offers)
Tell you when a cut is ready Push token Consent (the iOS notification permission)
Understand how ReCut is used and improve it Analytics events, feedback Legitimate interests; consent for a transcript you include with feedback
Find and fix crashes and errors Diagnostics Legitimate interests
Measure our advertising (people who allow tracking only) Device identifiers, advertising identifier, registration and subscription events Consent through Apple's tracking prompt
Keep ReCut secure, prevent abuse and control costs Usage records, IP hash, account holds Legitimate interests
Answer your requests, prove deletions and comply with the law What the request or the law requires Legal obligation

Where we rely on legitimate interests, we have weighed them against your interests and rights, and you can object (section 14). Where we rely on consent, you can withdraw it at any time. Withdrawing doesn't affect processing that happened before.

In Canada, including Quebec, we rely on your consent. It is express for AI processing, tracking, notifications and any transcript you include with feedback. For what ReCut needs in order to work, to stay secure and to meet its legal duties, your consent is given when you create an account and use the app after reading this policy.

We never use your videos, audio or transcripts for advertising.

7. How we share personal information

7a. Our processors

We share personal information with the companies below, and give each one only what it needs for its purpose.

Processor What it does for ReCut Data it receives Where
Supabase Hosts ReCut's database, sign-in, file storage for the temporary audio upload, and server functions Account (email, sign-in provider identity; with Google, the name and profile picture link Google shares), profile (consent answers, notification choices; an age range only for accounts that gave one before October 2026), the audio track until it is transcribed, transcripts and cut plans until your iPhone receives them, usage and subscription records, push tokens, feedback Canada
Deepgram Turns the audio track into text with word timings and filler-word flags The audio track of the project being edited, fetched through a short-lived private link that contains your random user ID and the edit's ID United States
OpenRouter Passes the transcript text to Anthropic's AI models and returns their answer, only when retake or tangent cuts are on The transcript text of the project being edited United States
Anthropic Its AI models read the transcript, received through OpenRouter, to find retakes, false starts, repeats and tangents, only when those cuts are on The transcript text of the project being edited, through OpenRouter United States
RevenueCat Processes App Store subscriptions, restores purchases and reports subscription events User ID, purchase history; for people who allow tracking, device identifiers (the advertising identifier, the identifier for vendors, IP address and device model) and ad-campaign details (the Meta SDK's install identifier, Appstack's campaign, ad and click identifiers), so subscription events can be matched to the ads that led to them United States
Superwall Shows the subscription screen and runs paywall experiments User ID, plan attributes (plan, trial status, where the subscription screen was opened, app build), paywall views and purchase outcomes, and the device details its SDK reads (identifier for vendors, device model, locale, time zone, App Store country) United States
PostHog Product analytics, so we can see which features work User ID and in-app events without personal content (including your setup answers), device model, app version, language and time-zone settings; IP addresses are discarded United States
Sentry Crash and error reports, so we can fix problems User ID, device model, iOS and app version, error details with personal details removed; never screenshots or the screen's contents. Error reports from our servers carry no user ID United States
Meta Measures which Meta ads brought people to ReCut (people who allow tracking, only) Only for people who allow tracking: user ID, a registration event, device identifiers including the advertising identifier; subscription events arrive from RevenueCat Global (Meta's own infrastructure)
TikTok Measures which TikTok ads brought people to ReCut (people who allow tracking, only) Only for people who allow tracking: user ID, install and app-open events, registration, trial and subscription events, App Store purchase events, device identifiers including the advertising identifier Global (TikTok's own infrastructure)
Appstack Measures which ad campaigns brought people to ReCut (people who allow tracking, only) Only for people who allow tracking: user ID, install, first-open and sign-up events, device and install attribution data; subscription events arrive from RevenueCat. Apple's aggregate ad-attribution reports, which identify no one, reach it for every install United States (on Google Cloud)
Apple Sign in with Apple, App Store purchases, push notifications and ad-attribution postbacks Your Apple sign-in identity, purchases, a push token Global (Apple's own infrastructure)
Google Sign in with Google Your Google sign-in identity (email, name and profile picture link) Global (Google's own infrastructure)

Supabase, Deepgram, OpenRouter, Anthropic, RevenueCat, Superwall, PostHog and Sentry process information for us, under data processing terms that limit them to providing their service to ReCut. Meta, TikTok and Appstack receive information to measure our advertising, and may also use it under their own terms and privacy policies. Apple and Google provide sign-in, the App Store and push notifications, and handle your Apple Account and Google Account under their own privacy policies. The same list, with more detail, is in section 8 of our Data Privacy Policy (section 20).

7b. We don't sell personal information

We don't sell personal information, and we don't rent or trade it. Section 14e explains the one kind of disclosure that California law calls "sharing".

7c. Other disclosures

We may also disclose personal information:

  • when the law requires it, for example to answer a valid court order or an enforceable request from a public authority. We disclose only what is required and, where the law allows, we tell you;
  • to protect people and ReCut, when we believe in good faith that it is needed to protect the rights, property or safety of our users, the public or Novaire Capital Corporation, or to investigate fraud or abuse;
  • in a business transfer, such as a merger, acquisition, financing or sale of assets, to a recipient that must keep protecting it as this policy describes. We will tell you before your information becomes subject to a different privacy policy;
  • with your consent, for any other purpose you agree to.

8. Advertising and tracking

We advertise ReCut, and we measure which ads bring people to it. This section explains how, and the choices you have.

8a. Who can be tracked

Only people who allow tracking. The advertising SDKs in ReCut, from Meta, TikTok and Appstack, start only after you have allowed tracking in Apple's tracking prompt. ReCut doesn't ask your age, so Apple's prompt is the only thing that decides.

8b. Apple's tracking prompt

During onboarding, ReCut shows a short explanation and then Apple's own prompt, which says: "Allow tracking so we can see which ReCut ads brought you here. Your videos, voice and transcripts are never used for ads."

  • If you allow tracking, the SDKs may read your advertising identifier and use it, with the events below, to link ReCut installs and subscriptions to the ads that led to them.
  • If you ask ReCut not to track, no advertising SDK starts, they receive none of the events below, and ReCut gives RevenueCat no device identifiers. Apple's SKAdNetwork may still report ad results to the networks in aggregate, without identifying you.
  • You can change your choice at any time in iOS Settings → Privacy & Security → Tracking. The change applies from the next time ReCut opens.

8c. What the advertising networks receive

  • Meta receives a registration event when you create your account, your ReCut user ID and device identifiers. Your subscription events, such as a trial start or a purchase, reach Meta from RevenueCat.
  • TikTok receives install and app-open events, registration, trial-start and subscription-start events, your ReCut user ID, device identifiers, and the purchase events its SDK reads from the App Store on your iPhone.
  • Appstack receives a sign-up event, your ReCut user ID, and device and install attribution data. Your subscription events reach Appstack from RevenueCat.
  • Apple sends ad attribution reports through SKAdNetwork, and a copy of them goes to Appstack.

ReCut gives RevenueCat the identifiers these networks need (section 3m) only for people who allow tracking.

8d. What they never receive

The advertising networks never receive your videos, audio, transcripts, project titles, email or name. They don't receive your AI consent answers or any code you enter either, and ReCut doesn't send them hashed contact details for matching.

8e. Subscriptions are not advertising

RevenueCat and Superwall run your subscription and the subscription screen. They are not advertising networks. When ReCut first opens, for everyone, Superwall's SDK sends your identifier for vendors, device model, locale, time zone and screen size (and your advertising identifier only if you allow tracking) to Superwall's install-attribution service, which works out where an install came from. We don't turn on Superwall's integrations that forward data to advertising networks.

9. Product analytics, session replay and diagnostics

9a. Product analytics

PostHog receives the in-app events described in section 3l, linked to your user ID. We use them to see which features work and where people get stuck. PostHog is set to discard IP addresses.

9b. The Share analytics switch

You can turn product analytics off in Profile → Settings → Share analytics. Turning it off stops PostHog: ReCut sends no more analytics events, and PostHog remembers your choice on this iPhone. Share analytics is on until you turn it off. It doesn't stop RevenueCat and Superwall: they still receive the purchase and paywall data your subscription needs. It also doesn't change your answer to Apple's tracking prompt, which controls advertising tracking (section 8).

9c. Session replay

PostHog session replay is turned off in ReCut. If we ever turn it on, session replay will be masked, so the text you type and the images on screen are hidden. It never runs on the camera, import, editor, preview or export screens. Turning Share analytics off stops it too. We will update this policy before turning it on.

9d. Diagnostics

Sentry receives the crash and error reports described in section 3k. Sentry never attaches screenshots or the screen's contents. ReCut reduces each error to its type and code and removes personal details from the trail of events before a report is sent, and Sentry is set not to collect personal information by default.

10. Push notifications

Notifications say only that a cut is ready or couldn't be finished. They never contain your transcript or your video. The alerts read "Your cut is ready", "Your cuts are ready" or "We couldn't finish your cut".

We don't send marketing notifications unless you opt in to them separately. Apple delivers notifications through its push service, which receives your push token and the alert.

You can turn the "Cut ready" and "Cut failed" notifications off separately in Profile → Settings → Notifications, and our servers check that choice before sending one; iOS Settings → Notifications → ReCut turns all of them off. We delete a push token when Apple reports it is no longer valid, when it moves to another account on the same iPhone, after 180 days without being refreshed, or when you delete your account.

11. How long we keep information

What Where How long
The audio track ReCut's storage (Supabase, Canada), then Deepgram while it transcribes Deleted right after transcription; never kept longer than 48 hours
Transcript and cut plan ReCut's database Until your iPhone receives them; at most 7 days
Transcript text sent through OpenRouter to Anthropic Anthropic Up to 30 days
Transcript text passing through OpenRouter OpenRouter Under OpenRouter's own retention policy
Usage records (edits, durations, clip counts, costs; no content) ReCut's database 13 months
Subscription events ReCut's database 13 months
Cut feedback ReCut's database 12 months; a transcript you choose to include, 30 days
Push tokens ReCut's database Until they stop working, or 180 days without being refreshed
Rate-limit counters (your user ID, or a salted hash of your IP address, never the address itself) ReCut's database 48 hours
Account, profile, consent records, subscription status ReCut's database and sign-in service Until you delete your account
Deletion receipt (no personal data) ReCut's database 24 months
Operational alerts and webhook records ReCut's database 90 days
Database backups Supabase 7 days
Projects and videos Only your iPhone Until you delete them, your account (after you confirm) or the app
Copies held by PostHog, Superwall, Sentry, Meta, TikTok and Appstack The processor Under that processor's own retention policy

The AI data:

  • The audio is deleted right after transcription and is never kept longer than 48 hours.
  • Transcripts and cut plans are deleted when your iPhone receives them, or within 7 days if it never does.
  • Anthropic may keep the transcript text it receives for up to 30 days, and does not use it to train its models.
  • Deleted data can remain in database backups for up to 7 days before it is gone.

Details the table doesn't show:

  • Consent records are kept until you delete your account so that we can show you consented.
  • Push tokens are also deleted when Apple reports them invalid or they move to another account (section 10).
  • Operational records, such as records of processed subscription notifications and internal alerts that may name a user ID, lose that user ID when you delete your account.
  • The deletion receipt holds no email, name or content. We keep it so that we can show your account was deleted.

Our processors keep what they receive under their own retention periods. When you delete your account, we delete your customer record at RevenueCat. Events already held by PostHog, Superwall, Sentry and the advertising networks stay with them under their own policies, and Apple and Google keep what they hold under theirs.

12. How we protect information

  • Every connection between the app, our servers and our processors is encrypted in transit with TLS.
  • The app never reads our database directly. It goes through our server functions, which check who you are on every request and return only your own data. The database tables are closed to direct access from the app.
  • Sign-in sessions are stored in your iPhone's Keychain. The Sign in with Apple authorization we keep is encrypted on our servers.
  • The keys for our AI providers and for payments exist only on our servers, never in the app.
  • Our servers enforce plan limits and rate limits, and they can put an account on hold when they detect abuse.
  • Our logs exclude transcripts, email addresses, raw IP addresses and sign-in tokens.
  • We limit access to our systems to the people who need it to run ReCut.

No method of storing or sending information is perfectly secure, and we can't guarantee absolute security. If a security incident involving your personal information creates a real risk of significant harm to you, we will tell you and the regulators as the law requires.

13. Where information is processed

Supabase hosts ReCut's database, sign-in and temporary audio storage in Canada. Deepgram, OpenRouter, Anthropic, RevenueCat and Superwall process information in the United States. PostHog, Sentry and Appstack process it in the regions shown in the table in section 7a. Meta, TikTok, Apple and Google use their own infrastructure around the world.

This means your information may be processed outside your province or country, including in the United States. There it is subject to local laws, and courts, law enforcement and national security authorities may be able to access it.

  • Quebec. Before we communicate personal information outside Quebec, we assess whether it will be adequately protected, as Law 25 requires, and our agreements with the recipient reflect that assessment.
  • EEA, UK and Switzerland. Canada is recognized as providing adequate protection for commercial organizations subject to PIPEDA. For transfers to the United States and other countries, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or the UK's International Data Transfer Agreement where needed), or on the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where the recipient is certified. You can ask for a copy of the safeguards at support@userecut.com.

14. Your rights

14a. What you can do in the app

  • Delete your account: Profile → Settings → Delete account (section 16).
  • Turn AI processing off: Profile → Settings → AI processing (section 17).
  • Turn product analytics off: Profile → Settings → Share analytics (section 9).
  • Turn tracking or notifications off: tracking in iOS Settings (section 8); notifications in Profile → Settings → Notifications or in iOS Settings (section 10).

For anything else, such as a copy of your information or a correction to it, email support@userecut.com (section 14g).

14b. Canada

Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and similar provincial laws, you can:

  • ask for access to the personal information we hold about you, and how we have used and disclosed it;
  • ask us to correct information that is inaccurate or incomplete;
  • withdraw your consent, subject to legal or contractual restrictions and reasonable notice. We will tell you what withdrawing means for you; for example, without AI consent, ReCut can't make AI edits;
  • challenge our compliance with the law by writing to our Privacy Officer.

If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). In Alberta and British Columbia, you can also contact your provincial privacy commissioner.

14c. Quebec

Under Quebec's private-sector privacy law, as amended by Law 25, you can also:

  • reach our Privacy Officer at support@userecut.com;
  • access and correct your personal information;
  • receive the computerized personal information you gave us in a structured, commonly used technological format, or have it sent to a person or organization you choose;
  • withdraw your consent at any time;
  • be told about any decision made about you exclusively by automated processing, and about the information used to make it. ReCut makes no such decisions;
  • ask us to stop disseminating your information, or to de-index it, in the cases the law provides. ReCut doesn't publish information about you;
  • know which functions can be used to identify, locate or profile you, and how to turn them on. Advertising tracking is off unless you allow it in Apple's prompt (section 8).

We answer a written request within 30 days of receiving it. If you are not satisfied, you can complain to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).

French version. ReCut's legal documents are written in English, and the English version governs. We may publish French versions later; if we do, the English version still governs where they differ.

14d. EEA, UK and Switzerland

Under the GDPR, the UK GDPR and Swiss law, you have the right to:

  • access your personal information and receive a copy;
  • have inaccurate information corrected;
  • have your information erased;
  • restrict how we process it;
  • receive the information you gave us in a portable format, or have it sent to another company;
  • object to processing based on our legitimate interests;
  • withdraw your consent at any time, without affecting processing that happened before;
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you. ReCut makes no such decisions.

Our legal bases are listed in section 6, and how we handle EU and UK requests in section 1. We answer within one month, which the law lets us extend by two further months for complex requests; we will tell you if we need to. You can complain to the data protection authority where you live or work, or where you think the law was broken. In the UK, that is the Information Commissioner's Office.

14e. California

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives California residents the rights below. This section is also our notice at collection.

What we collect, and who receives it. In the last 12 months we collected these categories of personal information:

Category What ReCut collects Disclosed for a business purpose to
Identifiers Email address, user ID, sign-in identity, push token, device identifiers, IP address and, only with tracking allowed, the advertising identifier Supabase, RevenueCat, Superwall, PostHog, Sentry, Apple, Google; for people who allow tracking, Meta, TikTok and Appstack
Customer records Email address and, with Google sign-in, name Supabase, Apple, Google
Characteristics of protected classifications Age range, only from accounts that gave one in an earlier version of ReCut Supabase, PostHog
Commercial information Subscription status and purchase history Apple, RevenueCat, Superwall, Supabase; for people who allow tracking, Meta, TikTok and Appstack
Internet or other electronic network activity In-app events (including your onboarding answers), paywall views, diagnostics PostHog, Superwall, Sentry
Audio information The audio track of projects you edit with AI Supabase, Deepgram
Other content you provide Transcripts, cut plans, feedback Supabase, Deepgram, OpenRouter, Anthropic

We collect this information from you, from your iPhone, from Apple and Google when you sign in, and from the App Store through RevenueCat. We use it for the purposes in section 6 and keep it as section 11 describes. We collect no precise geolocation, and we don't use or disclose sensitive personal information for any purpose that would give you the right to limit it.

Sale and sharing. We don't sell personal information. ReCut "shares" personal information for cross-context behavioral advertising only when you allow tracking in Apple's prompt: then Meta, TikTok and Appstack receive identifiers, including your advertising identifier, and the events described in section 8c. If you ask ReCut not to track, they receive nothing from ReCut, and Apple's SKAdNetwork only reports ad results to them in aggregate. Sharing always starts with that opt-in, whatever your age.

How to opt out. Choose "Ask App Not to Track" in Apple's prompt, or turn tracking off for ReCut at any time in iOS Settings → Privacy & Security → Tracking. To stop product analytics as well, turn off Profile → Settings → Share analytics. ReCut is an iPhone app, so browser signals such as Global Privacy Control don't reach it; Apple's tracking setting is the way to opt out in the app.

Your rights. You can ask us:

  • to tell you what personal information we collected about you, where it came from, why we collected it and who received it, and to give you a copy of it;
  • to delete it;
  • to correct it;
  • not to share it, as described above.

We won't treat you differently for using these rights: no different price, service or quality. Some features need certain information, though; for example, AI edits need your AI consent.

Authorized agents. An authorized agent can make a request for you with your signed, written permission. We may ask you to confirm your identity with us directly.

Response times. We confirm a request within 10 business days and answer within 45 days. If we need up to 45 more days, we will tell you why.

We don't disclose personal information to third parties for their own direct marketing.

14f. Other US states

Residents of Colorado, Connecticut, Oregon, Texas, Virginia and other states with comprehensive privacy laws have similar rights: to confirm whether we process their personal information, and to access, correct, delete and receive a portable copy of it. They can also opt out of targeted advertising, of sales, and of profiling that leads to decisions with legal or similarly significant effects. We don't sell personal information and we don't profile anyone for such decisions. To opt out of targeted advertising, use Apple's tracking setting as section 14e describes.

If we decline your request, you can appeal by replying to our answer, or by emailing support@userecut.com with the subject "Privacy appeal". We answer appeals in writing within the time your state's law sets. If we deny the appeal, you can contact your state's Attorney General.

14g. How to make a request

Email support@userecut.com from the email address on your ReCut account. If you use Hide My Email, tell us the relay address, which your Apple Account settings show. Tell us whether you sign in with Apple or Google, and what you are asking for.

We verify each request by matching it to the account, and we may ask one follow-up question if that isn't enough. We never ask for payment details or sign-in codes. We answer within the time the law that applies to you sets, as the sections above describe, and we don't charge for a request unless the law allows it for requests that are clearly excessive. If we can't do all or part of what you ask, we tell you why and how you can complain or appeal.

15. Children

ReCut is not directed to children under 13. ReCut doesn't ask your age (section 3c).

  • If we learn that we hold personal information from a child under 13, we delete it.
  • Parents and guardians can write to support@userecut.com to tell us they believe a child under 13 has used ReCut, or to ask about, access or delete their child's information.

16. Deleting your account and data

In the app, go to Profile → Settings → Delete account (or the account menu on the subscription screen) and type DELETE to confirm. This deletes your account and all its data on our servers, revokes your Sign in with Apple authorization, deletes your customer record at RevenueCat, and then removes the projects on this iPhone once you confirm.

Deleting your account doesn't cancel your subscription. Cancel it in the App Store.

  • Deleting the app is not deleting your account. It removes your projects from the iPhone, but your account and your subscription stay in place.
  • Signing out is not deleting your account. It hides that account's projects on the iPhone until you sign in again.
  • If you can't use the app, email support@userecut.com and we will delete your account for you.

Our "Delete Your Data" page (section 20) describes every step, what is deleted, what may remain and the timelines.

To turn AI processing off, go to Profile → Settings → AI processing and choose Turn off. Turning AI processing off stops new AI edits and cancels AI edits that haven't finished; their audio and transcripts are then deleted. It doesn't recall data already processed, which is deleted on the schedule above. Manual editing keeps working. To use AI edits again, turn AI processing back on, or agree when ReCut asks.

Your other choices:

  • Tracking: iOS Settings → Privacy & Security → Tracking (section 8).
  • Notifications: Profile → Settings → Notifications, or iOS Settings → Notifications → ReCut (section 10).
  • Product analytics: Profile → Settings → Share analytics (section 9).
  • A transcript with your feedback: your choice each time you send feedback (section 3j).

18. Changes to this policy

We update this policy when ReCut or the law changes, and we change the "Last updated" date at the top each time. If a change materially affects how we handle your personal information, we tell you in the app or by email before it takes effect. If a change needs your consent, such as a new AI provider or a change in what is sent to one, ReCut asks for it before the change applies to you.

19. Contact us

We would like the chance to address a concern first, but you can contact a privacy regulator at any time (section 14).