Last updated: 26 September 2026
VideoToShorts is operated by an individual based in Hong Kong SAR. This page says what we
store, who else touches it, and when it goes away. Questions or requests:
support@videotoshorts.app.
We do not sell your data, we do not run advertising, and we do not use your videos or
transcripts to train anything.
If you never sign in, we still need to count your free usage, so we store:
- A visitor id in a cookie (
vts_visitor, one year, not readable by scripts). This is
how "five transcripts a day, no sign-up" is possible at all.
- A hashed IP address. The address itself is not kept — only a hash. It is both the
backstop for a cleared cookie and a looser daily limit of its own, so that one address
cannot be farmed for free transcript reads.
- The job record: the link you pasted or the fact that you uploaded a file, the segment
you chose, the size of the bytes we moved, how long any audio we transcribed ran and which
speech-recognition service heard it, whether it succeeded, and the time.
If you create an account, additionally:
- Your email address and name. With Google sign-in, we also receive your Google profile
picture URL and Google account id. With email and password, we store a hash of the
password, never the password.
- The IP address you registered from, in the clear, along with your language and, if you
arrived through a tagged link, its
utm_source value.
- Your credit balance and transaction history, and the identifiers Stripe gives us for
your payments. We never see or store card numbers.
Your content, in both cases:
- The video you bring. A YouTube link is stored as a link. An uploaded file is stored as
a file.
- The transcript. For a link — YouTube, TikTok, Instagram or Facebook — the words are
keyed by the public post rather than by you, so the next person who pastes the same link
costs nothing and waits for nothing. An upload has no public post to key to, so its
transcript is stored against that one job.
- The clip we produce.
| Service | What it does | What it sees |
|---|
| Vercel | Hosts the site | Requests, including IP addresses, in ordinary server logs |
| Neon | Our database | Everything in the section above |
| Cloudflare R2 | Stores files (bucket region: Eastern North America) | Your uploads and clips |
| Modal | Runs the processing (fetching, transcribing, rendering) | Your video's bytes while a job runs |
| A residential proxy vendor | Carries the fetch on the occasions a platform refuses our own address | The request for the link you pasted, and the video's bytes in transit |
| Groq | Speech recognition | The audio of anything we transcribe by listening — uploads, TikTok, Instagram and Facebook links, and YouTube videos with no caption track |
| OpenAI | Backup speech recognition, when switched on — used only for a job Groq could not answer | The audio of that job |
| DeepSeek | Writes the AI summary or translation of a transcript when you ask for one, and the suggested moments on the clip page | The transcript's text — never the audio or the video |
| Cloudflare Turnstile | A browser check on transcript requests made without an account, when switched on | Your IP address and technical signals from your browser, used to tell a person from a script |
| Stripe / Link | Sells and takes payment as merchant of record | Your payment details, name and billing address, directly — not through us |
| Resend | Sends account emails | Your email address |
| Google | Sign-in, only if you choose it | That you signed in |
| Plausible | Website statistics | See below |
Three notes worth being plain about:
- Audio goes to Groq for speech recognition, under Groq's own terms — and not only for
uploads. A TikTok or Instagram link always sends audio, because neither platform
publishes a caption track anyone can read. A Facebook link sends audio only where the
uploader supplied no subtitles; where they did, we lift those and no audio leaves. A
YouTube link works the same way: a video with a caption track we can read is read from
that track and no audio leaves, and only a video without one is listened to. When Groq is rate
limited, down or does not answer in time, and we have the backup switched on, that same
audio goes to OpenAI instead, under OpenAI's own terms. If you would rather no third
party received the audio, a YouTube video that has captions is the path to use.
- Stripe is not merely our processor for payments — it is the seller. It decides what it
needs to collect for a sale, holds that data under its own privacy policy, and sends you
receipts from Link. You can ask Stripe directly to delete the data from your purchases;
if you do, Stripe cancels any subscription you bought and deletes the payment records on
both sides, including the copies in our Stripe account. See section 4 of the
Terms of Service for what that arrangement means for you.
- Plausible sets no cookies. Plausible states that it uses "no cookies or any other
persistent identifiers", collects no personal data, reports in aggregate only, and hosts
data in Germany. We chose it for that reason.
| Cookie | Why | How long |
|---|
vts_visitor | Counts your free daily usage without an account | 1 year |
| Session cookie | Keeps you signed in | Until you sign out |
NEXT_LOCALE | Remembers your language | 1 year |
utm_source | Records how you found us, once | Short-lived |
There are no advertising or tracking cookies, and no consent banner, because there is
nothing to consent to.
- Uploaded files: 72 hours without an account, 30 days with one. After that the link
stops working and a job that runs daily deletes the file from storage. Clips are cut
only with an account and are kept for 30 days from when they are made.
- An upload's transcript goes with the upload. A transcript read from a link stays
after your job is gone, because it is keyed by the public post and holds nothing that
points back to you.
- The job record — the row, not the file — is kept for accounting and to keep the free
tier from being farmed. Ask us and we will delete yours.
- Delete your account and we delete your files along with it.
Email support@videotoshorts.app to get a copy of what we hold about you, correct it, or
have it deleted. We will do it. If you are in the EU, the UK or another place with
data-protection law, you have those statutory rights regardless of what this page says, and
this section is how you exercise them here.
The service is not intended for anyone under 16, and we do not knowingly collect their data.
We are in Hong Kong, and the services above operate in the United States and the European
Union. Using the service means your data is processed in those places.
If this page changes materially we will update the date at the top and, where the change
affects you directly, say so in the product.