Privacy Policy
Last updated September 10, 2026
This privacy policy applies to the use of our website (in particular the domain slicecut.io) and to the use of our mobile application "slicecut" (the "App").
1. Privacy at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit our website or use our App. Personal data is any data by which you can be personally identified. For detailed information on the subject of data protection, please refer to the following sections of this privacy policy.
The short version for slicecut: your video never leaves your device. The App extracts the audio track of the footage you import and uploads only that, for transcription. Editing and rendering happen locally on your phone. This website counts its visitors with our own cookie-free Umami instance, which stores no personal data and needs no consent; there are no tracking pixels and no third-party analytics. In the App we measure which of our own advertisements brought you to slicecut, using the advertising identifier of your device through our measurement partner AppsFlyer — on iOS only if you allow tracking when the App asks. Nothing else is tracked, and no video, transcript or e-mail address is ever handed to an advertising network.
Who is responsible for data collection?
Data processing on this website and in the App is carried out by the operator. You can find the operator's contact details in the section "Note on the responsible party" in this privacy policy.
2. General information and mandatory disclosures
Data protection
The operator of this website and the App takes the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website or our App, various personal data is collected. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens.
We would like to point out that data transmission on the internet (e.g. when communicating by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.
Note on the responsible party
The responsible party (controller) for data processing on this website and in the App is:
Nicolas Goldstrass
Wackersbergerstr. 33
81371 München
Germany
E-mail: info@slicecut.io
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data remains with us until the purpose for the data processing no longer applies. If you assert a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion takes place once these reasons no longer apply.
General information on the legal bases of data processing
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. In the case of express consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to the access to information on your end device (e.g. via device fingerprinting), data processing is additionally carried out on the basis of § 25(1) TDDDG. Consent can be withdrawn at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data if this is necessary to fulfil a legal obligation on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. The legal bases applicable in each individual case are set out in the following sections of this privacy policy.
Your rights as a data subject
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out up to the point of withdrawal remains unaffected by the withdrawal.
Right to object to data collection in special cases and to direct advertising (Art. 21 GDPR)
IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS ASSOCIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT ADVERTISING (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged violation. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent that it is technically feasible.
Access, rectification and erasure
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to rectification or erasure of this data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. The right to restriction of processing exists in certain cases defined by law.
To exercise any of the rights described above, you can contact us at any time at the contact address given in the section "Note on the responsible party". Please note that you can also exercise some rights, such as the deletion of your videos and the data attached to them, directly and independently in the settings of our App.
Data security
For security reasons and to protect the transmission of confidential content, our website and our App use SSL or TLS encryption. This applies, for example, to requests you send to us or the synchronisation of your data between the App and our servers. You can recognise an encrypted connection on the website by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Data processing on our website
The following sections describe which data we collect and process when you use our website.
3. Hosting
Hetzner
We host the contents of our website on our own server operated at Hetzner. The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (hereinafter Hetzner). For details, please refer to Hetzner's privacy policy:https://www.hetzner.com/legal/privacy-policy/.
The use of Hetzner is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the most reliable presentation of our website possible.
Data processing agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
4. Data collection on our website
Cookies
Our website does not set any tracking cookies and does not use any cookies requiring consent. No consent banner is displayed because there is nothing to consent to: the site loads no third-party fonts, scripts or embeds, and the only statistics tool is our own cookie-free Umami instance (section 5). Should technically necessary cookies be used in the future (for example for security purposes), they would be stored on the basis of Art. 6(1)(f) GDPR — the website operator has a legitimate interest in the technically error-free and optimised provision of its services.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- time of the server request
- IP address
This data is not merged with other data sources. Server log files are deleted after seven days. The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website — for this purpose, the server log files must be collected.
Inquiries by e-mail
If you contact us by e-mail, your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of handling your request. The processing of this data is based on Art. 6(1)(b) GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested. The data you send to us via contact inquiries remains with us until the purpose for the data storage no longer applies.
5. Analytics, advertising and newsletter
On this website we count visits with the open-source software Umami, which we run ourselves on a server at Hetzner in Germany; no third party receives this data. Umami sets no cookies and stores no IP address: for each page view it records the page, the referrer, browser and operating system type, device type, screen size, language and the country derived from the IP address, plus which of the app store buttons was clicked. Visitors are told apart within one day by a salted hash that cannot be traced back to you and is discarded daily; no profile is built across days or across sites. Because no personal data is stored and no information is read from your device beyond what your browser sends with every request, no consent is required. Legal basis is our legitimate interest in understanding how the website is used (Art. 6(1)(f) GDPR); you can object at any time via the contact address above. Beyond that, this website uses no analytics tools (such as Google Analytics or PostHog), no advertising or remarketing services, no tracking pixels, no consent management platform and no newsletter.
In the App we measure the success of our own advertising. We advertise slicecut on Google (Google Ads), Meta (Facebook and Instagram), TikTok, OpenAI (ChatGPT) and Apple Search Ads. To learn which advertisement led to an installation and, later, to a subscription, we use the measurement partner AppsFlyer (see section 6 h). We do not show advertising inside the App, and we do not sell data. No analytics SDK other than the attribution described in section 6 h is included in the App.
Data processing in our mobile app "slicecut"
The following sections describe which data we collect and process when you install and use our mobile app "slicecut".
6. Data collection and processing in the App
a) Downloading the App
When you download the App, required information is transferred to the respective app store (Apple App Store or Google Play Store), in particular your account name, e-mail address, device identifiers and the time of download. We have no influence on this data collection; the respective store operator is responsible for it.
b) Creating a user account
To use the App, the creation of a user account is required. In doing so, we collect the following data:
- e-mail address
- password (stored only as a salted hash and not visible to us)
- a unique user ID (generated automatically)
This data is strictly necessary for providing your account, for authentication (login) and for synchronising your edit state with our servers.
Instead of an e-mail/password registration you can sign in withGoogle (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) or Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland). In that case we receive from the provider only the data needed to create and authenticate your account — in particular your e-mail address (with "Hide My Email", Apple's relay address) and a signed identity token. We receive no access to your Google or Apple account. The sign-in itself is subject to the privacy policy of the respective provider.
Legal basis: the processing of this data is carried out for the performance of our user contract with you pursuant to Art. 6(1)(b) GDPR.
b2) Transactional e-mail (Resend)
For account e-mails that the service requires — for example password reset codes or e-mail change confirmations — we use our own mail server and the delivery service Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as a processor. Resend receives the recipient address and the message content for the sole purpose of delivery. Insofar as data is transferred to the USA, the transfer is based on the standard contractual clauses of the EU Commission; we have concluded a data processing agreement (DPA) with Resend. We send no marketing e-mail. Further information:https://resend.com/legal/privacy-policy.
Legal basis: the processing is carried out for the performance of the contract pursuant to Art. 6(1)(b) GDPR.
c) Footage, audio and edit data
The core function of the App is editing video by removing words from a transcript. The video itself never leaves your device.The App extracts the audio track of the footage you import and uploads only that. Editing and rendering happen locally on your phone using its hardware codecs, so the footage is never sent to us or to anyone else. When you import footage, we receive:
- the extracted audio track, for transcription;
- your edit state — which words you removed, stored as timings;
- the duration and a fingerprint of each source file, so we can spot duplicates and bill imported minutes only once.
Legal basis: the processing is carried out for the performance of the contract pursuant to Art. 6(1)(b) GDPR. Please note that audio recordings may contain the voices of other people. Do not import recordings containing personal data of third parties unless you are permitted to process them.
d) AI-supported transcription (ElevenLabs)
To convert the audio track of your footage into a transcript, the audio is transmitted to the speech-to-text service of ElevenLabs Inc., 169 Madison Ave #2484, New York, NY 10016, USA ("ElevenLabs") and processed there. The result (the transcript with word timings) is returned to the App.
The transmission takes place exclusively when you import footage yourself. Only the audio data is processed, for the purpose of transcription. Within the scope of this processing, data may be transferred to third countries (in particular the USA). The transfer is based on the standard contractual clauses of the EU Commission; we have concluded a data processing agreement (DPA) with ElevenLabs. Further information can be found in ElevenLabs' privacy policy:https://elevenlabs.io/privacy.
Legal basis: the processing is carried out for the performance of the contract pursuant to Art. 6(1)(b) GDPR, since transcription is the core service of the App and is triggered by you actively importing footage.
d2) Retention of the audio track for error analysis
After transcription, the uploaded audio track remains in our EU object storage for 7 days and is then deleted automatically. This short retention exists for one purpose: when the automatic pause detection or transcription produces a wrong result and you report it, the audio is the only way to reproduce and fix the error — the stored waveform alone cannot show whether a sound was speech. The audio is deleted earlier the moment you delete the video it belongs to or your account.
Legal basis: our legitimate interest in diagnosing and fixing errors in the core function of the App pursuant to Art. 6(1)(f) GDPR. You can object to this retention at any time (see "Your rights as a data subject"); deleting the video removes the audio immediately.
e) Subscriptions and in-app purchases (Adapty)
To manage subscriptions, we use the service Adapty Tech Inc., USA ("Adapty"). When you take out a subscription, data such as your user ID, your e-mail address (so that we can find your purchase when you write to us), the subscription status and transaction receipts of the app stores are transmitted to Adapty for purchase verification. Adapty also receives the advertising identifier of your device and the AppsFlyer installation ID, so that a purchase can be matched to the advertisement that led to the installation (section 6 h). Adapty forwards purchase, renewal and refund events, including the amount, to AppsFlyer on our behalf.
We do not store or process any sensitive payment data such as credit card numbers ourselves. Payment is processed exclusively via your account with the respective app store (Apple or Google). Insofar as data is transferred to the USA, the transfer is based on the standard contractual clauses of the EU Commission; we have concluded a data processing agreement (DPA) with Adapty. Further information can be found in Adapty's privacy policy:https://adapty.io/privacy/.
Legal basis: the processing is carried out for the performance of the subscription contract pursuant to Art. 6(1)(b) GDPR.
f) Technical data and synchronisation
For the functionality of the App, technical data such as your IP address when communicating with our servers, timestamps of data entries and the device status (e.g. app version) are processed. This is necessary to provide the service, synchronise your edit state and resolve technical problems.
Legal basis: the processing is necessary for the performance of the contract (provision of the App) pursuant to Art. 6(1)(b) GDPR and to safeguard our legitimate interests (ensuring technical functionality) pursuant to Art. 6(1)(f) GDPR.
g) Server logs and error analysis
To ensure the technical stability of our service and to diagnose errors, our servers write log entries with a fixed allowlist of fields. The logs contain technical information only and none of your audio or transcript content. They are deleted after seven days.
Legal basis: the processing of this data is carried out to safeguard our legitimate interests in providing a technically error-free and stable service pursuant to Art. 6(1)(f) GDPR.
h) Advertising attribution (AppsFlyer)
To measure whether our own advertisements work, we use the mobile measurement partner AppsFlyer (AppsFlyer Ltd., 14 Maskit St., Herzliya 4673314, Israel; EU entity: AppsFlyer GmbH, Berlin, Germany) as a processor. When you install the App, the AppsFlyer software integrated in it transmits the following data to AppsFlyer:
- the advertising identifier of your device (Android: Google Advertising ID; iOS: IDFA, only after you have allowed tracking in the system prompt), the vendor identifier (IDFV) on iOS, IP address, device model, operating system version, language and time zone;
- the fact and time of installation and of app starts;
- if you reached the App through one of our advertisements: the advertising network, campaign, ad set and ad you clicked or saw.
When you take out or renew a subscription, or a purchase is refunded, Adapty (section 6 e) reports this event to AppsFlyer together with the amount, so that it can be attributed to the same advertisement.
Recipients of these events. AppsFlyer forwards the installation and purchase events — as a hashed advertising identifier together with the event and its amount — to the advertising network that showed you the advertisement, so that this network can measure and optimise its campaigns. Possible recipients are Google Ireland Ltd. (Google Ads), Meta Platforms Ireland Ltd. (Facebook, Instagram), TikTok Technology Ltd., OpenAI Ireland Ltd. (ChatGPT advertising) and Apple Distribution International Ltd. (Apple Search Ads). No video, audio, transcript or e-mail address in clear text is ever forwarded to an advertising network. On iOS, install attribution may additionally take place through Apple's SKAdNetwork framework, which reports to the network only aggregated, non-personal figures.
We ourselves store the attributed campaign together with the purchase event in our database (see section 6 e), so that we can evaluate which advertisements lead to subscriptions.
Legal basis. On iOS, the processing takes place only after your consent in the App Tracking Transparency prompt (Art. 6(1)(a) GDPR, § 25(1) TDDDG); you can withdraw it at any time under Settings → Privacy & Security → Tracking. On Android, the processing is based on our legitimate interest in measuring our own advertising (Art. 6(1)(f) GDPR); you can object at any time and reset or delete the advertising identifier under Settings → Google → Ads ("Delete advertising ID"), after which no further attribution takes place. When you sign up, the App points you to this measurement.
Third-country transfer. AppsFlyer processes data in the EU; insofar as data is transferred to Israel or the USA, this is based on the EU adequacy decision for Israel and the standard contractual clauses of the EU Commission respectively; we have concluded a data processing agreement (DPA) with AppsFlyer. Further information:https://www.appsflyer.com/legal/services-privacy-policy/. The advertising networks named above act as independent controllers for the data they receive; their privacy policies apply.
Storage. AppsFlyer retains device-level data for at most 24 months; the attributed campaign in our own database is deleted together with your account.
7. Storage locations, storage duration and data security in the App
a) Local storage on your device
Your footage and rendered exports are stored locally on your device and are never uploaded. Sensitive information such as authentication tokens is stored in the encrypted storage of your device.
b) Cloud storage (Hetzner and Supabase)
- Hetzner (Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany) — object storage in Nuremberg, Germany, holding the extracted audio track for at most 7 days after transcription (see section 6 d2), after which it is deleted automatically.
- Supabase — managed PostgreSQL database operated on servers in Frankfurt, Germany, holding your account data and edit state.
All our own infrastructure is located in the EU — Frankfurt and Nuremberg. There is one region and it serves everyone, wherever they are. We have concluded data processing agreements (DPA) pursuant to Art. 28 GDPR with both providers. Attribution data is processed by AppsFlyer and Adapty outside our own infrastructure, as described in sections 6 e and 6 h.
c) Security measures
We secure your data through modern technical and organisational measures. These include:
- Transport encryption: all communication between the App, this website and our servers is TLS-encrypted.
- Password security: passwords are stored using a strong hashing procedure and are not visible to us.
- Access controls: access to your data in our database is protected by strict per-account access restrictions.
d) Storage duration and deletion
We store your personal data only for as long as is necessary to achieve the respective purposes or as provided for by statutory retention periods.
- Account data: your account and edit state remain stored as long as your user account is active.
- Audio tracks: deleted from our storage automatically 7 days after transcription (section 6 d2), or immediately when you delete the video or your account.
- Deleting your videos: the App's settings include a "Delete all videos" action. It removes every video and everything attached to it — audio, transcript, edit state — on the device and on the server, and it cascades: nothing is kept behind as an orphan.
- Deleting your account: when you delete your account, your personal data is promptly removed from our active systems. You can also request deletion at any time via info@slicecut.io.
- Backups: for data security reasons, backups of our systems are created regularly. After deletion from the active systems, your data may remain in these encrypted, access-protected backups for a limited period (at most 14 days) before it is finally overwritten.
- Technical log data: server logs are deleted after seven days.
- Attribution data: the advertising identifier and campaign data held by AppsFlyer are deleted there after at most 24 months; the campaign stored with your purchase in our database is deleted with your account.
If we are legally obliged to retain data for longer (e.g. for tax or commercial law reasons), the data will be deleted after these periods have expired.
8. Children and minors
Our offer is generally directed at adults. Use of the App is not permitted for persons under the age of 16. We do not knowingly collect personal data from children and young people under the age of 16. Should we discover that such data has been transmitted to us without the consent of a legal guardian, we will delete it immediately.
9. Changes to this privacy policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy. In the event of material changes, we will inform you in the App or by e-mail. The new privacy policy then applies to your next visit. Earlier versions of this privacy policy remain available at /privacy/1/ (version 1, valid until September 10, 2026).