CubCuts

Legal

Privacy

CubCuts turns a sentence about your business into a shot list. This page says what we store to do that, who else sees it, and how to make us stop.

Last updated 13 August 2026

Contents

What we hold

  • Your email address. It is how you sign in. There is no password.
  • What you type into the form — your video goal and any brand context — and the brief we generate from it.
  • How many briefs you have made in the current period, so the allowance works.
  • A billing reference if you subscribe: identifiers from Stripe that let us tell whether your subscription is active.

We never see or store your card details. Those go directly to Stripe and are never sent to us.

Who else it reaches

  • OpenAI — your goal and brand context are sent to generate the brief. There is no way to produce one without this.
  • Supabase — hosts the database and the sign-in system. Servers are in the United States.
  • Stripe — payments, if you subscribe.
  • Mixpanel — product analytics and session replay. See below. It records how you move through the pages; it does not receive what you write.
  • Vercel — runs the site itself, so every request you make passes through it on the way to us.

Analytics, specifically

We measure how the product is used, so we can see where it works and where people get stuck. Here is everything that does it:

  • Events recorded by your browser. Opening a page, reaching or starting the form, copying or downloading a brief, clicking through to pricing — things you do on the page. On top of the ones we name, Mixpanel’s script records ordinary page views, clicks and form submissions by itself. All of this needs your permission and stops the moment you take it away.
  • Events recorded by our own servers. Signing up, a brief starting, finishing, failing or being refused, a brief coming back with a mix of sound and speech that cannot be filmed, meeting the sign-up wall, running out of your allowance, going to checkout, changing or deleting a plan, and somebody opening a brief you shared a link to. These are how we tell whether the product works at all, and they are recorded whatever you answer about usage tracking. They never carry your IP address and never carry a word you wrote. They are labelled with your account id when you are signed in, and otherwise with a value that cannot be turned back into an address and that changes every day.
  • Session replay. Mixpanel’s script records how you move through the pages — where you click, scroll and pause — and lets us play that back to understand where the product is confusing.

Replay does not capture what you write. Text is masked before it is recorded, and two things are excluded outright: the box where you describe your video, and the finished brief. In a replay they appear as blank shapes. That is set explicitly by us rather than left to a default.

Your IP address. The events we send Mixpanel carry an instruction not to record your IP address or work out where you are from it. The screen recording does not: it is uploaded by a different part of Mixpanel’s script that takes no such setting, so we have no way to send that instruction with it. And once you allow the script at all, it runs in your own browser and talks to Mixpanel directly, so their servers see the address your connection comes from either way — the same as any site you visit.

Which label goes on what. Events sent by your browser carry the identifier Mixpanel keeps there; if you are signed in we also tell Mixpanel that identifier is your account. Events sent by our servers carry the labels described above. No event carries both.

Cookies and storage

Everything CubCuts stores in your browser is named below, with what it is for and how long it stays. The last two groups are set by other people’s software — our sign-in provider and, if you allow it, our analytics — and we have listed what we have seen them store; that set is theirs and can change when they update their software. You can delete any of it at any time by clearing your browser data. Doing that signs you out, asks you the usage-tracking question again, and forgets an unfinished request; nothing else here breaks.

What we store ourselves. None of it is shared with anyone, none of it is an advertising cookie, and none of it is used to follow you around other websites. Some are sent to us when you do something that needs them, and each one below says whether it is; the rest never leave your machine. They are written as you use the site, without waiting for your answer about usage tracking — that answer governs the analytics script further down, which is the thing that reports anything.

  • Your tracking answer. Your answer to the usage-tracking question — yes or no. It is kept so we stop asking, and it is never sent to us. Until you clear your browser data. cubcuts.analytics-consent.v1browser storage
  • How you got here. How you first arrived: any campaign tag in the web address, the site you came from (its name only, never the full address), the page you landed on, and any invite code the link carried. It stays on your device while you are only reading. It is sent to us the moment you ask for a sign-in link, and if that link creates your account it is kept against the account and goes to our analytics with the sign-up. If you are already signed in, an invite code is sent to us and saved on your account so it can be used when you subscribe; the invite code itself is never sent to our analytics. Ask for no link and stay signed out, and it never leaves your browser. Until you clear your browser data — except an invite code, which is dropped after 14 days. cubcuts_first_touchbrowser storage
  • Whether your invite code is still good. The answer we got back about an invite code you arrived with — whether it was still active, and when it runs out. It is kept so we ask once instead of on every page, and it is never sent anywhere; it only decides what the notice at the top of the page says. 14 days, or until the code is used, is found to be dead, or you clear your browser data — whichever comes first. cubcuts_promo_checkbrowser storage
  • Whether you have visited before. A single mark saying you have been here before, so we can tell a first visit from a return. It holds nothing else — no time, no page, no identifier. It is only reported to us if you agreed to usage tracking. Until you clear your browser data. cubcuts_seen_beforebrowser storage
  • Your unfinished request. What you typed, held while you go and create an account or pay, so you do not have to type it again. When you come back it is sent to us to build your brief and then cleared. If you have been away more than half an hour it is handed back to the form instead and waits for you to press the button. Until it is used, or you clear your browser data. cubcuts_pending_requestbrowser storage
  • What you were typing. What you had written in the brief form but not yet built, so following a link away from it and coming back does not lose it. This copy stays on your device and belongs to that one tab. If you are signed in, the same text is also saved to your account so it survives closing the tab and follows you to another device; signed out, it never leaves your browser. Pressing Build clears it, and so does emptying the form. On your device: until you close the tab, or you build the brief — and never more than 7 days. On your account: until you build the brief, empty the form, or delete your account. cubcuts_draft_requestbrowser storage, this tab only
  • A brief that was interrupted. A note that a brief was still being written when the tab closed or reloaded, so the page can tell you what happened instead of the work vanishing. It is never sent to us and it never starts anything by itself. Until you close the tab. cubcuts_generation_in_flightbrowser storage, this tab only

When you sign in. These are cookies, and they are the only cookies on the site.

  • Staying signed in. Keeps you signed in. It is set when you sign in and refreshed as you use the site, and is sometimes split across more than one cookie. Up to 400 days, or until you sign out. sb-…-auth-tokencookie
  • Finishing a sign-in. A one-time secret your browser keeps while a sign-in link is sitting in your inbox, so only the browser that asked for the link can complete the sign-in. It is written when you ask for the link, not when you sign in. Until the sign-in finishes. sb-…-code-verifiercookie

Only if you agree to usage tracking. Mixpanel’s script is the one third-party script that runs on these pages, and it does not load at all until you allow it: say no, or say nothing, and it never starts. If you do allow it, it stores these. It sets no cookies, unless your browser blocks ordinary storage, in which case it falls back to one.

  • An identifier for this browser. A random identifier for this browser, so separate page views can be joined into one visit. It is not your name or your email. Until you turn usage tracking off, or clear your browser data. mp_…_mixpanelbrowser storage
  • Things waiting to be sent. A few queues of events and profile updates waiting to go, so a moment is not lost if the connection drops. They empty as they send. If you turn usage tracking off while something is still queued, it stops being sent but stays where it is. Until they are sent, or you clear your browser data. __mpq_…browser storage
  • Your refusal, kept by their script. If you turn usage tracking off after having turned it on, Mixpanel's own script writes down that you said no. This one is meant to outlive the rest: it is what makes the refusal stick. Until you clear your browser data. __mp_opt_in_out_…browser storage
  • Which tab is which. Tells one tab from another when you have several open. Until you close the tab. mp_tab_id_… and mp_gen_new_tab_id_…browser storage, this tab only
  • The recording, before it is uploaded. Two databases in your browser. One holds the screen recording described above while it waits to be uploaded; the other holds settings the script fetches. Neither exists unless you said yes. Until the recording is uploaded, or you clear your browser data. mixpanelBrowserDb and mixpanelFlagsDbbrowser database

What the recording actually captures. Mixpanel records mouse movement, clicks and scrolling, so we can see where people get stuck. What you type into a brief is masked before it leaves your browser, and in a replay those fields appear as blank shapes. The sentence you type on the home page is carried to the next page in an encrypted form, so it does not appear in the web address and is not recorded by our analytics.

Changing your mind. The switch is on this page, just below, and this page is linked from the footer of every other one and from the notice that first asked you. Turning it off stops the script and the recording, and clears the identifier Mixpanel stored — it does not simply stop asking. Turning it back on starts it again. Signing in and creating briefs work exactly the same either way; nothing is withheld for saying no.

Usage tracking in this browser…

The setting belongs to this browser, because that is where the answer is kept — it is not attached to your account, so a different browser or device asks you again.

Two things the switch does not do, said plainly because a reader would otherwise assume them. It does not stop the events our own servers record, listed above. And a piece of recording still waiting on your device when you switch off is uploaded as part of shutting the recorder down, rather than thrown away — turning tracking off stops the next recording, it does not recall the last one.

How long we keep it

Briefs stay until you delete them or delete your account. Delete a brief and it is gone from the database immediately — there is no recycle bin and we cannot get it back for you.

When you delete your account, and only if you had used free trial briefs, we keep a one-way hash of your email address — a fingerprint that cannot be reversed into the original address — solely to prevent the same email from claiming another free trial. Delete without having used it and we keep nothing. Two things also stay outside our own database: your billing record remains with Stripe, because an invoice is a financial record they keep under their own rules, and past usage events remain with Mixpanel under theirs. Everything we hold ourselves is deleted.

Your rights

  • Take it with you. Every brief downloads as a Markdown file from its own page. No request needed.
  • Delete it. Your account page removes your account, every brief, and the billing reference we hold, and cancels any active subscription first. It happens immediately. Your invoices stay with Stripe — see How long we keep it above for the two things that outlive deletion and why.
  • Ask us anything else — access, correction, or a complaint — using the contact address below.

Contact

We are still setting up a support address. Until it is live, reach us through wherever you signed up and we will pick it up.