Cuplikin Privacy Policy
1|# Cuplikin Privacy Policy 2| 3|Effective date: 28 August 2026 4|Last updated: 9 September 2026 5| 6|Cuplikin is a local-first macOS application operated by Ghozi Mahdi. This Privacy Policy explains which information stays on your device, which information is processed when you choose online features, why it is used, and the choices available to you. 7| 8|## 1. Local-first design 9| 10|Your local project catalog, source video files, locally generated audio and transcripts, editor state, captions, Final Clips, and exported files remain on your device by default. Cuplikin does not automatically synchronize those files to your account. 11| 12|Having a Cuplikin account does not mean that your entire workspace is uploaded. Information is sent only for the online features you choose and only with the context needed to provide those features. 13| 14|## 2. Information we process 15| 16|### Account and session information 17| 18|We process your email address, password hash, account status, legal-document acceptance, verification status, and session records to register and authenticate your account, verify your email, protect sessions, and recover access. Cuplikin does not store your plaintext password. 19| 20|### Device and network security information 21| 22|We process a pseudonymous installation identifier, platform type, minimized or hashed network-prefix information, request identifiers, rate-limit records, and security events to prevent abuse, protect free-credit eligibility, secure the service, and diagnose failures. Ordinary application logs are designed not to contain passwords, access tokens, provider secrets, raw transcripts, local file paths, or raw resolver URLs. 23| 24|### Credits, subscriptions, and purchases 25| 26|We process your account tier, credit balance and ledger, entitlements, provider product identifiers, and transaction, restore, refund, and reconciliation records. Apple processes payments. RevenueCat assists with subscription, entitlement, and purchase-state management. Cuplikin does not receive or store your full payment-card details. 27| 28|### Hosted AI information 29| 30|When you choose Cuplikin Cloud, we process the timestamped transcript, video title and duration metadata, language or locale, permitted instructions, AI output, hook candidates, scores, reasons, and operational provenance needed to run the analysis, return results, record credit use, and provide hosted history. 31| 32|The hosted hook-analysis path does not receive the local source-video binary, local file paths, Final Clips, exported files, or a custom-provider API key from the Cuplikin app. 33| 34|### URL resolver information 35| 36|When you ask Cuplikin to import from a supported URL, we process the submitted URL, resolver job status, technical metadata, and temporary resolver output needed to complete the request, enforce limits, prevent duplicate jobs, and support troubleshooting. Temporary resolver output is retained only for the operational period configured for the service and may expire automatically. 37| 38|### Support communications 39| 40|When you use Help & Support or send feedback, we store your user ID, account email, username, selected message type, and message. Account identity is obtained from your authenticated account, not from editable form fields. The username currently uses the part of your account email before @. We also retain a request reference and notification delivery status to process the message reliably. We store the message on Cuplikin's servers to handle and follow up on your request. An email notification containing these details is sent to the developer at ghozi.dev@gmail.com through Resend. The in-app form does not request a reply email or subject, and does not send an app version, platform, videos, or device logs. Information you voluntarily include in a direct email is also used to handle your request. 41| 42|## 3. How we use information 43| 44|We use information to: 45| 46|- provide authentication, email verification, credits, entitlements, hosted analysis, URL resolving, and support; 47|- operate, secure, maintain, and improve service reliability; 48|- prevent fraud, abuse, duplicated operations, and unauthorized access; 49|- process purchases, restores, refunds, and subscription status; 50|- comply with applicable transaction, audit, security, and legal obligations; and 51|- enforce our Terms of Use. 52| 53|Cuplikin does not create training datasets from your projects, transcripts, corrections, selections, history, or feedback. AI providers process requests according to their own service policies and account settings. Cuplikin does not claim zero retention by those providers. Choose local processing if you want your content to remain on your device. 54| 55|## 4. AI processing choices 56| 57|### Local or built-in mode 58| 59|When AI processing runs fully on your device, the content follows the local processing path and does not use Cuplikin Cloud credits. 60| 61|### Custom provider 62| 63|When you configure a custom AI provider, the information you submit is sent according to your configuration. The provider's privacy terms govern its processing. Cuplikin stores custom-provider credentials in secure on-device storage and does not send those credentials to the Cuplikin backend for hosted analysis. 64| 65|### Cuplikin Cloud 66| 67|When you explicitly choose Cuplikin Cloud, the minimum transcript and instruction context needed for analysis is sent to Cuplikin's hosted service and its AI processing provider or router. Cuplikin Cloud does not silently upload your entire local workspace. 68| 69|## 5. Service providers and disclosures 70| 71|Cuplikin may share the minimum necessary information with: 72| 73|- Apple, for App Store distribution, in-app purchases, and ratings or reviews you submit through Apple's interface; 74|- RevenueCat, for subscription, entitlement, purchase, restore, and refund state; 75|- Resend, for account verification and support or feedback email notifications; 76|- Anthropic (Claude), through a router operated by Cuplikin, for Cuplikin Cloud requests you initiate; 77|- Google Firebase, for remote application configuration, which uses a Firebase installation identifier; 78|- Contabo, for Cuplikin server infrastructure in Singapore; and 79|- authorities or professional advisers when disclosure is legally required or necessary to protect users, the service, or legal rights. 80| 81|We do not sell personal information and do not share personal information for cross-app advertising tracking. 82| 83|## 6. Retention 84| 85|Local media remains under your control on your device. Hosted information is retained only for as long as reasonably necessary to provide the relevant feature, maintain security and transaction records, resolve disputes, comply with law, and enforce agreements. 86| 87|URL-resolver output is temporary. Download links expire according to the service configuration; link expiry does not guarantee that the underlying file is physically deleted at the same time. Support and feedback messages are retained for handling and follow-up until no longer needed or deletion is requested. Account, billing, credit, security, and legal-acceptance records may be retained longer where needed for fraud prevention, accounting, audit, chargeback, or legal obligations. When deletion is requested, data not subject to a continuing legal or security requirement will be deleted or de-identified after the request and identity have been verified. 88| 89|## 7. Security 90| 91|Cuplikin uses access controls, owner scoping, authentication, rate limits, secure on-device credential storage, HTTPS in transit, and safeguards for hosted data. No system is completely risk-free. You should secure your device, use a strong password, and report suspicious activity promptly. 92| 93|## 8. Your choices and rights 94| 95|Depending on applicable law, you may request access to, correction of, export of, or deletion of personal information associated with your account. You may also: 96| 97|- choose local, custom-provider, or hosted processing before analysis; 98|- remove local projects and media from your device; 99|- revoke the current session by logging out; and 100|- manage or cancel subscriptions through Apple. 101| 102|To submit a privacy or account-deletion request, use Settings → Help & Support and select the relevant category, or email ghozi.dev@gmail.com from the address associated with your Cuplikin account. We verify your identity before completing deletion; submitting the form does not immediately delete your account. Deleting a Cuplikin account does not automatically cancel an Apple subscription; manage the subscription separately through Apple. 103| 104|## 9. Children 105| 106|Cuplikin is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and delete it where required. 107| 108|## 10. International processing 109| 110|Service providers may process information in countries other than your own. Where required, we use appropriate safeguards for international transfers and limit processing to the purposes described in this policy. 111| 112|## 11. Changes to this policy 113| 114|We may update this policy when features, providers, security practices, or legal requirements change. Material changes will be communicated in the app or through another appropriate channel before they take effect when required. 115| 116|## 12. Contact 117| 118|Data controller and developer: Ghozi Mahdi 119|Product: Cuplikin 120|Privacy, support, and deletion requests: ghozi.dev@gmail.com 121|Support page: https://api.cuplikin.com/support 122|