Your information
Privacy Policy
Revised
Local captioning does not mean zero data collection. Here is what stays on your device, what goes to service providers, and what you can control.
1. Who we are and what this notice covers
Dynsell LLC, based in Bend, Oregon, United States, operates CaptionAddr and this website. We are responsible for the personal information we process to operate them. Contact CaptionAddr@gmail.com for privacy questions or requests.
This notice describes CaptionAddr’s app, website and support correspondence, including version 1.5 and the Mac version being prepared for release. The App Store listing determines which versions and platforms are available. Apple and other providers also process information under their own policies. Older releases may differ; tell us your app version if you have a question about an earlier release.
2. Your video, audio and captions
You select one video using Apple’s Photos picker on iPhone or iPad. On Mac, you can also select or drop a video file. CaptionAddr creates a local working copy, extracts audio locally, runs the bundled Whisper Small English model, and stores caption words, timing, edits and exports in app storage. These files are not sent to Dynsell or Firebase for transcription, model training or cloud media storage.
The picker limits access to the items you choose. Downloading an original from iCloud uses Apple’s services. When you save to Photos, the resulting copy can sync through iCloud Photos according to your settings. On Mac, saving through the file save panel creates a copy in your chosen location; a location such as iCloud Drive may sync according to its settings. Sharing sends a copy to the app, person or service you choose, under that service’s practices. Content you voluntarily email to support is handled as correspondence, not local transcription.
The current project is stored locally and recovery is best effort. CaptionAddr has no cloud project backup or project sync service. Project and diagnostic folders are marked to exclude them from ordinary device backup; do not rely on backup to preserve them. Original videos, saved Photos copies and files exported to other locations are managed separately by you and the services you choose.
3. Information used to operate the app and website
- Purchase and entitlement records
Information: Apple product and transaction identifiers, purchase and expiry dates, renewal, revocation or refund status, app account token, anonymous Firebase user ID and verification metadata. Received from the app and Apple.
Purpose: Verify paid access, restore purchases, reconcile subscription changes, handle disputes and prevent fraud.
Recipients: Apple and Google Firebase.
- Security and service metadata
Information: Firebase installation and App Check identifiers, Apple DeviceCheck signals, request timestamps, IP/network and technical request information processed by infrastructure providers.
Purpose: Authenticate requests, protect services, rate-limit abuse and deliver responses.
Recipients: Apple, Google Firebase and their infrastructure providers.
- Aggregate workflow counts
Information: Fixed milestones such as import succeeded, captions ready, export started, export saved, export failed and share opened, plus app version and build.
Purpose: Understand whether the workflow succeeds. The counter store keeps daily totals, not a raw event history or a per-user profile.
Recipients: Google Firebase.
- Diagnostics
Information: Crash reports, non-fatal errors, stack traces, Crashlytics installation identifiers, device and OS information, app version, operation names, duration, technical metadata and logs. Error reports can contain contextual information supplied by the operating system or an SDK, including file paths or filenames.
Purpose: Investigate crashes, failures, performance and compatibility. We do not intentionally attach media or transcripts to these reports.
Recipients: Google Firebase Crashlytics for automatic reports; local diagnostics remain on your device unless you share them.
- Website requests
Information: IP address, requested page, browser/request information and timestamps processed by Netlify and its hosting infrastructure.
Purpose: Deliver and secure the site and troubleshoot availability.
Recipients: Netlify and its hosting infrastructure providers.
- Support and privacy correspondence
Information: Your email address, message, attachments you choose to send, and information needed to verify or resolve your request.
Purpose: Respond to you, provide support, process rights requests and maintain necessary records.
Recipients: Our email providers and, when needed to resolve your request, the relevant service provider.
There is no named CaptionAddr account or automatic collection of your email address in the app. Anonymous identifiers can still be personal information; “anonymous authentication” does not mean every related record is unidentifiable. Apple processes your payment details. We do not receive your card number or Apple Account password.
Browsing this website does not require an account, a purchase or a message to us. Your browser still sends the request information needed to deliver the page. Contacting support is optional; without a reply address or enough information to identify an issue, we may be unable to respond or resolve it. Pro purchase and entitlement verification require the purchase and security information described above; without successful verification, we may be unable to provide or restore paid access.
4. Services and recipients
- Apple: App Store distribution and payments, StoreKit purchase verification and subscription notifications, Photos/iCloud services you use, DeviceCheck, and optional local export notifications. Apple privacy information.
- Google Firebase: anonymous authentication, App Check, Functions and Firestore for subscription/security infrastructure and aggregate counters; Crashlytics for crash and failure diagnostics. No Firebase Analytics product, ad display SDK or cross-app tracking flow is used by the current app. SDKs can nevertheless collect technical diagnostic identifiers and metadata. Firebase privacy and security information and Google Privacy Policy.
- Hugging Face: model delivery if bundled resources are unavailable and recovery downloads are needed. The provider receives ordinary download request information, not your media or transcript. Hugging Face privacy information.
- Netlify: website delivery and hosting/security request processing. Netlify Privacy Policy.
- Email providers: delivery and storage of support messages; our monitored address uses Gmail. Other recipients receive information only as needed to resolve your request, comply with law, protect rights or respond to a lawful authority.
We may disclose necessary information to professional advisers or in a lawful business transfer, subject to applicable safeguards and notice obligations. This does not authorize selling your information for advertising or changing existing privacy promises without a lawful basis.
5. Usage counts, diagnostics and local preferences
Workflow counts are sent automatically as best-effort requests. The counter payload contains a milestone name, schema version, app version and build, with no media, filenames, video duration, caption text, styling choices or user/installation identifier in that payload. The backend increments daily totals by version/build. Request handling and infrastructure logs can still process the security/network metadata described above. This is usage measurement, even though Firebase Analytics is not included.
Crashlytics is enabled in normal releases. Diagnostic services initialize when the app launches, before the welcome agreement screen; that screen is not a separate control for diagnostic collection. Failures may be reported automatically. The current app has no user-facing switch specifically for these diagnostic reports or aggregate workflow counts. Apple’s system analytics-sharing settings should not be treated as a CaptionAddr-specific opt-out. Contact us about applicable objection or deletion rights.
Operation timing and Apple MetricKit payloads are also kept locally, with bounded/rotated diagnostic files. Successful local performance reports are not automatically submitted to our performance telemetry endpoint in the normal app workflow. If you deliberately share a diagnostic export with support, it becomes support correspondence. A separate backend diagnostic endpoint supports controlled testing and can store an anonymous user ID, App Check ID, sanitized client/operation summaries and timestamps when invoked.
Local preferences include haptics on iPhone/iPad, watermark choice, accepted Terms version/date, progress calibration, and flags used to avoid repeating certain milestones. Version 1.5 uses a dark appearance and has no separate appearance setting; a saved preference from an older release may remain locally. A random purchase identity is stored in Keychain for subscription reconciliation and can survive reinstalling the app.
6. Website storage and links
This website serves static pages, styles and icons. Our site code does not set cookies, use browser local storage, load analytics or advertising scripts, or embed external videos, fonts or social widgets. There is no cookie-consent control on these pages because our site code does not use those storage or tracking features. Hosting/security providers can process request information as described above.
Following an App Store, subscription, provider-policy or email link takes you to that provider. Its own cookies, identifiers and privacy practices can then apply. Our site does not use personal data for targeted advertising or change that practice based on a browser’s Do Not Track or Global Privacy Control setting; there is no sale/sharing activity on this site to opt out of.
7. Purposes and legal bases
We use the information described here to provide the service and support, verify purchases, secure infrastructure, understand workflow reliability, investigate faults, and meet legal obligations.
Where GDPR or similar law applies, the relevant bases are performance of a contract for requested services and entitlements; legitimate interests in service security, fraud prevention, reliability and limited product improvement where those interests are not overridden by your rights; and legal obligations where retention or disclosure is required. Any processing based on consent is subject to your right to withdraw it without affecting earlier lawful processing. A device permission is specific to that permission, not blanket consent to all information use.
Purchase status determines access to Pro. We do not use the information described here for advertising profiles or decisions with legal or similarly significant effects beyond administering the requested service. Contact support if you believe an access decision is wrong.
8. Retention and deletion
Local project files remain until replaced, reset, removed by app cleanup or removed with the app. Reset clears the current project; recovery files, preferences or local diagnostics may remain. Keychain identifiers can persist after uninstall. Removing the Mac app may also leave its local app data. Photos copies, files saved outside the app, shared copies and provider backups are separate. See Privacy Choices before deleting anything important.
Subscription cleanup is designed to consider inactive, unpaid user mirror records after 30 days without updates; notification records after 90 days from processing; transaction records after 180 days without updates; and rate-limit records after 7 days without updates. These are cleanup thresholds, not guarantees that every copy is erased at that instant. Paid history and customer-token exceptions, job availability, processing limits, security investigations and legal obligations can affect retention. Deleting a user mirror is not deletion of the underlying Firebase Authentication account.
Customer/subscription summaries, authentication records, aggregate workflow totals and some diagnostic/support records have no fixed automatic deletion deadline in the current system. Entitlement records can be needed for renewal, restoration, disputes and fraud prevention. Support correspondence is retained while needed for the request and related business/legal records. Provider logs and backups follow provider settings and retention practices. Google’s published Crashlytics retention policy states that crash traces and associated installation identifiers are retained for 90 days before removal from live and backup systems begins; this is not a promise that every copy is erased on day 90. You may request access or deletion of identifiable information we control, subject to lawful exceptions. Non-identifying aggregate totals cannot ordinarily be separated into one person’s contribution.
9. Your rights and how to ask
Depending on your location and applicable law, you may request access, a copy/portability, correction, deletion, restriction, or objection to certain processing; withdraw consent where used; and opt out of sale, targeted advertising or qualifying profiling where applicable. We do not sell information or share it for cross-context behavioral advertising. We do not offer financial incentives for personal information.
Email CaptionAddr@gmail.com with “Privacy Request,” your location and what you want us to do. You do not need a named account. We may request the minimum reasonable verification or clarification needed to identify records and protect them. An authorized agent may contact us with evidence of authority where permitted. Do not send passwords, full payment details or private videos.
We will respond within the time required by applicable law, explain permitted extensions or exceptions, and will not discriminate against you for exercising protected rights. If we decline a request, you can reply with “Privacy Appeal” for a review where available. You can also contact your state attorney general or relevant privacy regulator; EEA residents may contact their national data protection authority; UK residents may complain to the Information Commissioner’s Office. These rights and protections apply as provided by the law that covers your situation.
The Privacy Choices page explains practical controls, what reset/uninstall do, and subscription cancellation.
10. International processing and security
Dynsell is based in the United States. Apple, Google, Netlify, Hugging Face and email providers may process service information in the United States and other countries where they operate. Protections and government-access rules can differ by country. Where international-transfer requirements apply, the relevant transfer must have a lawful basis and appropriate protections. Contact us for information about the providers and transfer arrangements applicable to your use.
Local processing, platform file protection, encrypted transport and backend access controls reduce risk. No storage or transmission system is guaranteed secure. Keep your device updated and secured, and review a provider’s privacy practices before sharing media with it.
11. Children
CaptionAddr is a general-purpose tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13. An App Store content age rating is not parental consent or confirmation of capacity to enter a contract. If you believe a child supplied personal information through our services or support, contact us so we can investigate and take appropriate action, including deletion where required.
12. Changes and contact
We will identify changes by updating this page’s revision date and provide additional notice or seek consent when required. A revised notice does not retroactively remove protections or authorize incompatible uses of information collected under earlier promises.
Dynsell LLCBend, Oregon, United States
CaptionAddr@gmail.com