Legal
Privacy
CubCuts turns a sentence about your business into a shot list. This page says what we store to do that, who else sees it, and how to make us stop.
Last updated 13 August 2026
Contents
What we hold
- Your email address. It is how you sign in. There is no password.
- What you type into the form — your video goal and any brand context — and the brief we generate from it.
- How many briefs you have made in the current period, so the allowance works.
- A billing reference if you subscribe: identifiers from Stripe that let us tell whether your subscription is active.
We never see or store your card details. Those go directly to Stripe and are never sent to us.
Who else it reaches
- OpenAI — your goal and brand context are sent to generate the brief. There is no way to produce one without this.
- Supabase — hosts the database and the sign-in system. Servers are in the United States.
- Stripe — payments, if you subscribe.
- Mixpanel — product analytics and session replay. See below. It records how you move through the pages; it does not receive what you write.
- Vercel — runs the site itself, so every request you make passes through it on the way to us.
Analytics, specifically
We measure how the product is used, so we can see where it works and where people get stuck. Here is everything that does it:
- Events recorded by your browser. Opening a page, reaching or starting the form, copying or downloading a brief, clicking through to pricing — things you do on the page. On top of the ones we name, Mixpanel’s script records ordinary page views, clicks and form submissions by itself. All of this needs your permission and stops the moment you take it away.
- Events recorded by our own servers. Signing up, a brief starting, finishing, failing or being refused, a brief coming back with a mix of sound and speech that cannot be filmed, meeting the sign-up wall, running out of your allowance, going to checkout, changing or deleting a plan, and somebody opening a brief you shared a link to. These are how we tell whether the product works at all, and they are recorded whatever you answer about usage tracking. They never carry your IP address and never carry a word you wrote. They are labelled with your account id when you are signed in, and otherwise with a value that cannot be turned back into an address and that changes every day.
- Session replay. Mixpanel’s script records how you move through the pages — where you click, scroll and pause — and lets us play that back to understand where the product is confusing.
Replay does not capture what you write. Text is masked before it is recorded, and two things are excluded outright: the box where you describe your video, and the finished brief. In a replay they appear as blank shapes. That is set explicitly by us rather than left to a default.
Your IP address. The events we send Mixpanel carry an instruction not to record your IP address or work out where you are from it. The screen recording does not: it is uploaded by a different part of Mixpanel’s script that takes no such setting, so we have no way to send that instruction with it. And once you allow the script at all, it runs in your own browser and talks to Mixpanel directly, so their servers see the address your connection comes from either way — the same as any site you visit.
Which label goes on what. Events sent by your browser carry the identifier Mixpanel keeps there; if you are signed in we also tell Mixpanel that identifier is your account. Events sent by our servers carry the labels described above. No event carries both.
How long we keep it
Briefs stay until you delete them or delete your account. Delete a brief and it is gone from the database immediately — there is no recycle bin and we cannot get it back for you.
When you delete your account, and only if you had used free trial briefs, we keep a one-way hash of your email address — a fingerprint that cannot be reversed into the original address — solely to prevent the same email from claiming another free trial. Delete without having used it and we keep nothing. Two things also stay outside our own database: your billing record remains with Stripe, because an invoice is a financial record they keep under their own rules, and past usage events remain with Mixpanel under theirs. Everything we hold ourselves is deleted.
Your rights
- Take it with you. Every brief downloads as a Markdown file from its own page. No request needed.
- Delete it. Your account page removes your account, every brief, and the billing reference we hold, and cancels any active subscription first. It happens immediately. Your invoices stay with Stripe — see How long we keep it above for the two things that outlive deletion and why.
- Ask us anything else — access, correction, or a complaint — using the contact address below.
Contact
We are still setting up a support address. Until it is live, reach us through wherever you signed up and we will pick it up.