1. Introduction
This Privacy Policy describes how Unfurl.video ("Unfurl," "we," "us"), operated by Mitchell Runyon, collects, uses, stores, and shares information when you use the Service.
2. Information We Collect
- Account information: your email address and a password, which is hashed with bcrypt before storage — Unfurl never stores or has access to your password in plain text.
- Uploaded content: the video and audio files you upload, and the transcripts, clips, captions, translations, voiceovers, and thumbnails generated from them.
- Usage data: how much video you've processed against your plan's limits, how many clips and uploads you've created, and basic account activity needed to operate the Service.
- Payment information: handled entirely by Stripe, our payment processor. Unfurl does not store your full card number or bank details.
- Security data: if you enable two-factor authentication, a TOTP secret and backup codes are stored to support account login.
3. How We Use Information
- To provide the core Service — transcribing your video, detecting and cutting clips, and generating the on-demand features you request (captions, voiceover, translation, thumbnails, SEO copy).
- To operate your account, enforce plan usage limits, and process billing.
- To monitor for and respond to technical problems — including automated alerting that notifies the founder when a real error affects a real user, so it can be diagnosed and fixed quickly.
- To communicate with you about your account, billing, or, if you're affected by a known issue, a direct outreach email (always reviewed by the founder before sending, never sent automatically).
4. How Your Content Is Processed — Third-Party Sub-Processors
Delivering Unfurl's features requires sending parts of your content to the following third-party services. Each is used only for the specific processing step described:
- Self-hosted transcription (faster-whisper) — video/audio is transcribed by a model Unfurl operates itself, not sent to a third-party transcription API.
- Anthropic (Claude) — receives your transcript text to detect clip-worthy moments, translate captions, and generate SEO titles/descriptions/hashtags.
- ElevenLabs — receives clip transcript text to generate AI voiceover audio, only when you request that feature.
- OpenAI — receives an extracted video frame image to enhance it for a thumbnail, only when you request that feature.
- Stripe — receives billing and payment information to process your subscription.
- Cloudflare (R2) — stores your uploaded video files and generated clip files.
- Supabase — hosts the database that stores your account information, usage records, and content metadata.
We do not sell your personal information or your video content to any third party, and we do not use your uploaded content to train our own or any third party's general-purpose AI models.
5. Data Retention and Deletion
Uploaded videos, transcripts, and generated clips are retained for as long as your account remains active, so that you can continue to access and download your content.
Self-service deletion: you can permanently delete your account at any time from
Profile & account → Danger zone inside the app. Doing so immediately cancels any active subscription, permanently deletes every uploaded video, generated clip, caption, voiceover, and thumbnail from storage, and deletes your account record — it is not a soft delete or a deactivation, and it cannot be undone. If you'd rather have it handled directly, you can still email
mitchellrunyon23@gmail.com and the founder will process the request manually instead.
6. Security
- Passwords are hashed with bcrypt and never stored in plain text.
- Authentication uses signed JWTs; optional two-factor authentication (TOTP plus backup codes) is available for account login.
- API endpoints are rate-limited to reduce abuse.
- Internal incident monitoring and real-time alerting help the founder detect and respond to security- or reliability-relevant bugs quickly.
No system is perfectly secure, and Unfurl cannot guarantee absolute security of information transmitted to or stored by the Service.
7. Children's Privacy
The Service is not directed to, and should not be used by, anyone under 18 years of age. Unfurl does not knowingly collect information from children.
8. International Users
Unfurl's infrastructure providers (including Supabase and Cloudflare) may process and store data in locations outside your country of residence. [Placeholder — specific data-transfer mechanisms and jurisdiction-specific rights (e.g., GDPR, CCPA) require legal review before this section is finalized.]
9. Your Choices
- You can update your account email and password from within the app.
- You can enable or disable two-factor authentication from your account settings.
- You can permanently delete your account and all of your content yourself, at any time, from Profile & account → Danger zone in the app (see Section 5) — or email mitchellrunyon23@gmail.com to have it done manually instead.
10. Changes to This Policy
Unfurl may update this Privacy Policy from time to time. Material changes will be communicated by email or an in-product notice before taking effect.
11. Contact
Questions about this Privacy Policy or your data can be sent to mitchellrunyon23@gmail.com.