Effective: September 6, 2026 · Version 2026-09-06
Saint Technology, Inc. ("Subtitles.app", "we", "us", or "our") operates subtitles.app. This policy describes the data used by the service, the providers that may process it, how deletion and retention work, and the choices available to you.
Saint Technology, Inc. is the controller for personal data processed through Subtitles.app.
Email: [email protected]
Address: 651 N Broad St, Suite 201, Middletown, DE 19709, United States
A job uses only the providers needed for its selected features and current service configuration. Provider terms and retention may change; the linked provider pages describe their controls. We do not sell customer content or share it for advertising.
| Provider | Purpose | Data sent | Provider information |
|---|---|---|---|
| OVHcloud | Canonical object storage for retained paid media and generated files | Uploaded media, transcripts, subtitles, and generated media selected for retention | Primary policy |
| Groq, Together AI, or DeepInfra | Cloud speech-to-text; the configured provider and model are recorded on each job | Prepared audio or video, language/model options, and request metadata | Primary policy Together AI DeepInfra |
| pyannoteAI | Optional speaker diarization | Prepared audio and job metadata when speaker identification is requested | Primary policy |
| Cloudflare Workers AI | Cloud machine translation | Transcript or subtitle text and source/target language | Primary policy |
| Google Cloud | Cloud media extraction, subtitle burning, and vocal separation; Google OAuth sign-in | Media required for the requested job; verified email/profile data for Google sign-in | Primary policy |
| Stripe | Checkout, payment processing, receipts, refunds, and disputes | Contact, billing, payment, and transaction data entered at Stripe | Primary policy |
| Mailgun (Sinch) | Magic-link and transactional email delivery | Email address, message content, and delivery metadata | Primary policy |
| Matomo | First-party-hosted product, audience, campaign, and conversion analytics | Page views, interaction events, first-party visitor/session identifiers, and checkout conversion attribution | Primary policy |
| Chatwoot | Support chat loaded after the visitor opens the widget or visits the dedicated Support page | Chat messages, contact details, IP address, browser/device data, and support metadata after support is opened | Primary policy |
| Sentry and Better Stack | Error reporting, redacted operational logs, support IDs, and alerting | Redacted error and request metadata; uploads, transcripts, credentials, cookies, and email fields are excluded by application filters | Primary policy Better Stack |
Subtitles.app uses cookies and browser storage to operate the site, remember your choices, keep the service secure, and measure site use.
You can turn analytics off or on for this browser here. Turning it off stops future analytics requests and removes analytics cookies from this browser.
You can clear cookies and browser storage with your browser controls.
| Category | Period or criterion | What happens |
|---|---|---|
| Free uploaded media | Customer access for about 30 minutes; server retention up to about 24 hours | The media becomes unavailable to the customer after the access window and is automatically deleted from active systems by the end of the retention window. Deleting the job removes it sooner. |
| Free transcript and subtitle files | Customer access for about 30 minutes; server retention up to about 24 hours | The files and public player become unavailable to the customer after the access window. The files are automatically deleted by the end of the retention window. The scheduled cleanup and your own delete action both leave the same minimized job record described under Deletion and backups. |
| Failed uploads | Up to 24 hours after the failure | We may keep a copy of the uploaded media briefly to investigate the failure, then it is automatically deleted. |
| Paid retained media | 30 days included | Heavy media is deleted after the included period unless a separately offered extension is active. Automatic monthly retained-media billing is not currently enabled. |
| Paid transcript and subtitle files | Until the customer deletes the job or the service no longer needs the record | Customer deletion permanently removes active artifact files; a job/billing record identifying the upload may remain. |
| Sessions and browser identifiers | Varies by purpose | They expire automatically or when you log out, rotate a key, or clear browser data. |
| Incomplete anonymous checkout bridge | Up to 24 hours | A one-way browser hash is temporarily associated locally with the Stripe Checkout session ID. The bridge expires automatically if checkout is not completed. |
| Incomplete checkout records | 90 days | Incomplete checkout records are automatically deleted. |
| Purchase, account, and transactional email records | For account service, accounting, fraud, disputes, and legal obligations | Stripe and Sinch also apply their own retention rules. We do not promise an unsupported fixed deletion date. |
| Local operational logs | 14 daily rotations in the documented deployment | Remote Sentry and Better Stack retention depends on the configured service plan. Sensitive fields are filtered before shipping. |
| Backups | According to the documented backup schedule and administrator retention | Backups may temporarily contain data deleted from active systems. Content-free deletion tombstones survive restore and prevent deleted media from being rehydrated. |
The owner of a completed job can use its delete action to remove active media, transcript, subtitle, translation, and generated artifact files immediately. For OVH object storage, deletion removes current objects, every historical version and delete marker, and incomplete multipart uploads. A content-free tombstone remains so a later database or filesystem restore cannot resurrect the deleted prefix.
A free job is also deleted automatically by the scheduled cleanup described under Retention, without you asking. That automatic deletion removes the same files and leaves the same minimized record as the delete action below.
An operational job record remains after job deletion, for free and paid jobs alike. It keeps the job identifier, the uploaded file name, the uploading IP address, any source link you supplied, deletion status/time, duration and credit accounting, provider/model and translation targets, support or fraud metadata, and the content-free tombstone. A source link is kept exactly as you entered it, so anything you embedded in that URL is retained with it.
Removed alongside the files are our access tokens and share links, the provider job handles, the speaker names and diarization evidence derived from your audio, the stored AI call logs for the job, and the recorded paths to the deleted artifacts. Backups may temporarily contain older copies until the applicable backup expires, but the restore process checks newer tombstones and refuses to restore deleted content into service.
You can delete your account yourself from your account page (Account → Delete account). The page lists what is removed and what must be retained before you confirm. To request account-level access, correction, or export, or deletion by another route, email [email protected] from the account email where possible and include the relevant job, purchase, or support identifiers. We verify the requester before disclosing or deleting account data. Purchase, fraud, dispute, security, and legal records may be retained when required even after account closure.
We use TLS in transit, restricted operator access, scoped storage credentials, signed media links, CSRF and session protections, redacted application logs, support IDs, and deletion tombstones. Storage and processor security controls depend on the configured provider and service; we do not make an unsupported blanket claim that every copy is encrypted at rest in every environment.
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a supervisory authority. Contact [email protected]. We respond after verifying identity and within the timeframe required by applicable law.
Providers may process data in other countries. Where required, we use the provider's contractual transfer safeguards. Provider locations and terms are available through the links in Section 4.
The service is not directed to children under 13, and we do not knowingly collect their personal data. Contact us if you believe a child submitted data.
We publish the effective date and version above. Material changes will be communicated where required, and prior versions are retained internally for the change record.