Privacy Policy for Captora
Captora (“the App”, “we”, “us”) is a video captioning app published by Xeobo Software d.o.o. Beograd, Šumadijske divizije 12, 11000 Beograd, Serbia (“the Provider”). This policy explains what data the App collects, why, who it is shared with, and what choices you have.
Contact for any privacy question or request: xeobo.doo@gmail.com.
1. Summary
- We do not require an account. There is no sign-up, no email, no password.
- Your video never leaves your device. Only the extracted audio is sent for transcription (OpenAI Whisper). After transcription, the recognised words are automatically proofread via AI (Google Gemini). Captioned videos are rendered entirely on your device.
- We collect anonymous usage analytics and subscription status, tied to a randomly generated identifier — not to your name, email, or Apple ID.
- We do not sell personal data, and we do not use your videos, audio, or transcripts to train AI models.
- We collect no face data and no biometric data of any kind (see 3.9).
2. Data stored on your device
The App stores the following locally, in its own app container:
- Imported videos (or references to them), generated thumbnails, and exported captioned videos.
- Transcripts and caption cues, including word-level text and timings.
- Project metadata: title, creation/update time, duration, chosen language, and caption styling.
- Your app settings.
This data is not accessible to us. It is removed when you delete a project or uninstall the App. iOS device backups may include it, governed by your iCloud settings and Apple’s privacy policy.
3. Data sent off your device
3.1 Audio for cloud transcription
When you generate captions, the App extracts the audio track only from your video, converts it to a 16 kHz mono WAV, splits it into chunks if it is long, and uploads each chunk over HTTPS to our captioning service. The video itself is never uploaded.
Along with the audio we send: the chunk duration, the spoken language you chose, and your subscription identifier (see 3.4).
Our service acts as a stateless proxy. It writes the audio chunk to a temporary file, forwards it to our speech-to-text provider, returns the recognised words to your device, and deletes the temporary file immediately after the request completes, including on failure. We do not store your audio and we do not keep transcripts on our servers.
Our speech-to-text provider’s transcription endpoint applies zero data retention: it retains no copy of the audio for abuse monitoring or otherwise, and does not use it to train or improve its models.
Sub-processor: OpenAI, L.L.C. (Whisper API).
3.2 Transcript text for AI proofreading
After transcription, the recognised words (text and timings — no audio, no video) are automatically sent to our service, which forwards them to a language model for proofreading and returns the corrected words. We do not store them.
The language-model provider logs the transcript text for a limited period — up to 30 days — solely to detect and prevent abuse, after which it is deleted. It is not used to train or improve their models.
Sub-processor: Google LLC (Gemini API).
3.3 Video rendering — always on your device
Captioned videos are rendered entirely on your device using iOS’s built-in video compositing. Your source video and the finished captioned video are never uploaded to our service. Your video never leaves your device.
3.4 Subscriptions and purchases
Subscriptions are handled by RevenueCat, Inc. on top of Apple’s In-App Purchase system. RevenueCat assigns your installation a random App User ID and records purchase and entitlement events (product purchased, renewal, expiry, country, device platform). We never see your payment details — those are handled entirely by Apple.
Your App User ID may be sent with requests to our captioning service so we can apply fair-use protections (rate limits and a global usage circuit breaker). Subscription is optional; Pro unlocks are handled via RevenueCat on device.
3.5 Usage limits
To prevent abuse and control costs, our service may count audio minutes processed across all users (a global circuit breaker) and rate-limit requests. Counters are stored in a Redis database keyed by your RevenueCat App User ID — or, if none is available, by your IP address — and expire automatically. No transcript or audio content is stored with these counters.
3.6 Analytics
We use PostHog to understand how the App is used. Screen-content autocapture is disabled. We record product events such as: onboarding progress, a video being picked, a project being created, opened or deleted, captioning started / completed / failed, export started / completed / cancelled / failed, settings being changed and their new value, paywall shown and its outcome, quota limits being hit, and review prompts.
Event properties include technical context (app version, OS version, device model, locale, and an IP-derived approximate location) and the anonymous identifier described in 3.4. We do not send your video, your audio, your transcript, or any caption text to analytics.
3.7 In-app feedback
If you open the “Before you go” feedback board and submit it, we receive the reason you selected and, if you typed one, your free-text note, delivered as a PostHog event. Please do not include personal or sensitive information in that note.
3.8 Server logs
Our captioning service produces standard operational logs (timestamp, request path, response status, errors, IP address). They are written to our hosting provider’s log stream, used for debugging and abuse prevention, retained for a short period (up to 7 days) and then automatically discarded. We keep no separate log archive.
3.9 No face data or biometric data
The App does not collect, process, store, share, or transmit face data, facial geometry, facial recognition or face-mapping data, faceprints, or any other biometric identifier. It contains no face detection, face tracking, or face recognition functionality, and it does not analyse the images or video frames of your video for any purpose.
The App does not request access to your camera and cannot capture your face. The only content it sends off your device is the extracted audio track (3.1) and the recognised transcript text (3.2). Your video and its frames never leave your device (3.3).
Because no face or biometric data is ever collected, none is retained, none is shared with any third party, and there is nothing of the kind to delete.
4. Permissions the App requests
| Permission | Why |
|---|---|
| Photo Library (read) | To let you pick the video you want to caption. |
| Photo Library (add) | To save the finished captioned video to your camera roll. |
The App does not use your microphone, camera, contacts, or location. It does not use the TrueDepth camera, Face ID, or any face-scanning hardware or API.
5. Legal bases (EEA/UK users)
- Performance of a contract — processing your audio to produce captions, and managing your subscription.
- Legitimate interests — analytics, abuse prevention, usage limits, and security logging, balanced against your rights and limited to non-content data.
- Consent — any feedback you choose to submit.
6. Data retention
| Data | Retention |
|---|---|
| Face data / biometric data | Never collected — nothing to retain (see 3.9) |
| Videos, transcripts, projects on your device | Until you delete them or uninstall |
| Audio uploaded for transcription | Deleted immediately after the request; zero retention at our provider |
| Transcript text sent for proofreading | Not stored by us; logged by the AI provider for up to 30 days for abuse detection |
| Usage-limit counters | Automatically expire (rate-limit and global breaker windows) |
| Analytics events | Up to 12 months |
| Subscription records | Per RevenueCat retention, for the life of the subscription |
| Server logs | Up to 7 days (see 3.8) |
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to processing based on legitimate interests. Because we hold no account, the practical route is:
- Delete on-device data: delete projects in the App, or uninstall it.
- Analytics and subscription data: email xeobo.doo@gmail.com and we will locate and delete the records associated with your installation. Because we hold no account, these records are tied only to a random identifier and not to your name, email, or Apple ID; in some cases this means we may be unable to link a request to specific records.
We respond to requests within 30 days. EEA users may also lodge a complaint with their local supervisory authority.
8. Children
Captora is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.
9. International transfers
Our service providers (OpenAI, Google, PostHog, RevenueCat) may process data in the United States and other countries. Transfers out of the EEA/UK rely on Standard Contractual Clauses or an equivalent safeguard offered by each provider.
10. Security
Traffic between the App and our service uses HTTPS. Uploaded content is limited in size, protected by rate limits and a global usage circuit breaker, and — for transcription — deleted as soon as the request completes. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. Changes to this policy
We will update this page and revise the “Last updated” date when this policy changes. Material changes will be announced in the App.
12. Contact
Xeobo Software d.o.o. BeogradŠumadijske divizije 12, 11000 Beograd, Serbia
xeobo.doo@gmail.com