Privacy Policy
Your privacy is critically important to us. At Carmic Pro, we have a few fundamental principles:
- We don't ask you for personal information unless we truly need it.
- We don't share your personal information with anyone except to comply with the law, develop our products, or protect our rights.
- We don't store personal information on our servers unless required for the on-going operation of one of our services.
1. Information We Collect
We only collect information about you if we have a reason to do so — for example, to provide our Services, to communicate with you, or to make our Services better.
Information you provide directly:
- Account information: email address, name, and password when you create an account.
- Payment information: processed securely via Stripe. We never store full card numbers.
- Content: videos you upload and clips we generate. These are stored encrypted on Cloudflare R2.
- Usage data: features used, processing minutes consumed, and export formats selected.
Marketing Consent
By creating an account, you agree to receive marketing communications from us. You can opt-out at any time by clicking the "Unsubscribe" link in any email or updating your notification preferences in your dashboard.
2. AI Usage & Data Processing
Our platform utilizes Artificial Intelligence (AI) to optimize clip generation, analyze content for automated tagging, and generate smart highlights.
How we use your content:
- To provide automated captioning and translation.
- To detect content policy violations (safety).
- To improve our video compression algorithms (aggregated, anonymized data only).
- To generate clip scores and suggested titles.
We do not use your private video content to train generative models that would compete with your own IP.
3. Data Retention
Media storage retention depends on your plan tier:
- Free: Content expires after 3 days.
- Standard: Content retained for 29 days.
- Professional: 100GB fixed storage, no expiration.
- Business / Enterprise: 1TB+ fixed storage, no expiration.
You can delete any or all of your data at any time from your dashboard. Deletion is permanent and propagates across all CDN nodes within 24 hours.
4. Data Security
All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Our infrastructure runs on SOC 2 Type II compliant providers. Database access is restricted via PgBouncer with transaction-level pooling and IP whitelisting.
5. Third-Party Services
We use the following third-party services that may process your data:
- Stripe: Payment processing.
- Cloudflare R2: Media storage and CDN.
- Deepgram: Speech-to-text transcription (audio is processed and discarded).
- Sentry: Error tracking (no PII collected).
- Hetzner Cloud: GPU compute infrastructure (EU-based).
6. Your Rights (GDPR)
If you are a resident of the European Economic Area, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict processing.
- Data portability (receive your data in a structured format).
To exercise these rights, contact us at [email protected].
7. Contact
For privacy-related inquiries, reach us at [email protected].