Privacy notice
Plain language, describing what the service actually does today — not aspirational boilerplate. Last updated 2026-09-19. Questions or requests: [email protected].
What we collect
- The video file(s) you upload, with their filenames and sizes.
- Technical metadata our analyzer extracts: container format, codec parameters, and the diagnosis result (e.g. "index missing").
- Your email address — only if you type it in. It is used to update you about your job, for the specific follow-up you asked for (for example, a note when support for your camera ships), and it appears in our internal operational alerts — never in any marketing list. It is removed from the job record automatically after a year at the latest, and immediately on request.
- Standard web-server logs: IP address, timestamps, browser type. The web proxy's logs are deleted within about 30 days; application logs are size-capped and rotate away on their own.
- Automated operational alerts about each job — file name, size, status, and the contact details you provided (for a failed upload, also the IP address it came from) — are emailed to the service operator, delivered via Google. They are how a one-person service notices problems quickly; they are operational only.
- A one-way fingerprint of the IP address that downloads or previews a recovered file — a keyed hash, computed per job, stored instead of the address itself. We keep no raw IP in the job database, and because the hash is salted with the job id the same visitor on two different jobs produces two unrelated values, so these records cannot be joined into a profile of a person.
- Anonymous usage statistics via Google Analytics (page views, upload-flow events — never file contents).
What we use it for
- Running the automated recovery and delivering your result.
- Counting how many different devices fetch one recovered file. Your download link is the only key to your file, so if it is forwarded, anyone holding it can fetch the footage. Counting distinct devices lets us notice that and switch that one link off — it is a safety limit on your own link, not analytics. Normal use (your phone, then your computer) is well inside it.
- Emailing you the outcome, if you asked for that.
- Improving the engine using job metadata and structural repair templates derived from files — container layout, codec parameters, index structure. These templates contain none of your picture or sound, and they are what lets a broken file from the same camera model repair automatically for the next person. Your actual picture and sound are never used for engine development, marketing, or AI training.
What we never do
- Watch your footage as a matter of routine. Processing is automated. A person may see a file only in these cases: during the beta, a team member may briefly check a recovered result for quality; an engineer examines a file if you ask us to investigate a failed recovery; and we may look at a file that is reported to us or appears to break our Acceptable Use rules. That is the complete list.
- Sell, share, or publish your files or your personal data.
- Run advertising, retargeting pixels, or social-media trackers. There are no customer accounts and no login cookies (one cookie exists solely for the operator's own maintenance links); Google Analytics, where active, sets its own. So that you can find a result again, your browser keeps a short list of your own recent recoveries (file name and status link) in its local storage, on your device only — it is never sent to us, and the home page forgets it in one click.
Retention
Uploaded files and recovered outputs are kept on our server while your job is processed and available for download, then deleted automatically by a daily cleanup: 7 days after a successful repair, 30 days after a failed one. Failed files are kept longer because they are what teaches the engine to recover new kinds of damage — and the files the engine could not recover may be kept beyond that window, in a research corpus, for as long as they still resist recovery (together with any healthy sample clip uploaded alongside them). Once such a file is finally recovered, it may stay in the corpus as an automated regression sample, so that a later change to the engine cannot silently break the fix that solved it. Corpus files are analyzed only by our automated pipeline, never shared, and deleted the moment you ask — a deletion request covers regression samples too. If you want your files deleted immediately, email [email protected] and we will do it right away and confirm. The hashed download fingerprints described above are deleted by the same daily cleanup, on the same schedule as the files they protect, and immediately if your job is deleted. The job record itself (file name, size, diagnosis, outcome) is retained so a re-upload of the same file is recognized and our statistics stay honest; the email address on it is removed automatically after a year at the latest. The job records and the research corpus also live in daily backups on a separate storage system at our hosting provider — a deletion here reaches those backup copies within about two weeks. Everything else exists only on our server, so deleting it is immediate and complete.
One exception overrides all of the above: where we are required by law, court order, or a lawful request from a public authority to preserve or disclose specific files or records — or where we reasonably believe specific files may be subject to such an obligation and preserve them while that question is resolved — the legal matter, not our normal schedule, determines how long the data is kept. This has applied to a very small number of jobs, and we never volunteer data beyond what the law compels.
Service providers
Infrastructure that necessarily touches your data: our hosting provider (Hetzner) stores files during processing and holds our daily backups; Cloudflare provides DNS, proxying and email routing; Google Analytics provides usage statistics; job and operational email is delivered via Google. Site pages also load fonts and an upload helper from public CDNs (Google Fonts, cdnjs), which see your IP address like any web request. If you press "Notify me" on a result page, your browser's own push service (run by your browser vendor) delivers that notification. None of these providers receive your footage for any purpose other than storage and transport on our behalf.
Your rights
You can ask what data we hold about you, ask us to correct it, or ask us to delete it — email [email protected] and we respond personally. EU/EEA residents also have the right to complain to their local data protection authority.