Privacy Policy

Last updated: 2 October 2026 · Burncaps is operated by Jordan Labs Ltd, a company registered in England and Wales (company no. 17358646).

The short version

We never see your videos. Your video is processed only on your device and is never uploaded. The sound stays on your device too, unless you choose our speech service (a phone offers it for speed; a computer for a language other than English, when it is listening slowly, or when you ask for a closer transcript): then only the sound, never the picture, goes through our server to Microsoft’s speech service in the EU, which by Microsoft’s terms for this service stores none of it, and we store none of it either.

What we process

Your video: processed entirely on your device. Never transmitted to us or anyone else.

Your sound: stays on your device, unless you choose our speech service (below).

Transcripts and captions: stored on your device only.

Our speech service (only when you choose it): on a phone, the page asks once whether to write the words with our speech service or on your device, and remembers your answer in your browser (change it under Listening settings). If you chose the phone and a video would take more than a minute more, it asks once again for that video. On a computer it asks when your video is in a language other than English (the same remembered answer), when the computer is listening slower than the video plays (asked every time for English), and it offers a button to listen again with the service for one video. With the service, the page cuts the sound into pieces of up to 30 seconds at the speaker’s pauses and sends each piece, as a 16 kHz mono recording with nothing from the picture, to our server, which passes it to Microsoft’s MAI-Transcribe (Azure AI Speech fast transcription, North Europe region, Ireland) and returns the words with their timings and the language heard. Microsoft states that for fast transcription it “does not retain or store the data provided by customers”. Our server keeps no sound and no words: it counts the seconds heard for a random ID for your browser (or your email when signed in) and for your connection, stored as salted one-way hashes for 30 days, so the allowance is fair (25 minutes a month without Pro, 5 hours with Pro; after that the words are written on your device). Tick “Keep everything on this device” and no sound is ever sent.

Carrying on after you close the page: your last file (up to 400 MB) and the script made from it are kept in your browser’s own storage on your device, so that closing the tab (or a phone closing it for you) loses nothing: the front page offers to carry on. They never leave the device. The next file replaces them, they are removed after three days, and “Start fresh” removes them at once.

AI model files: your browser downloads the open-source Whisper model from Hugging Face's content delivery network and, when a video is in one of twelve Indian languages (Hindi, Urdu, Bengali, Tamil, Telugu, Gujarati, Marathi, Kannada, Malayalam, Punjabi, Nepali or Odia), the open-source IndicConformer model made for that language, from the same network. The code that runs these models comes from the jsDelivr content delivery network. These downloads are normal file requests and include no data about your media.

Payments (Pro): handled by Stripe. We never see your card details. Stripe shares your email and payment status with us so we can switch Pro on for you. See Stripe's privacy policy for how they handle payment data.

Your Pro sign-in: Pro is tied to the email you paid with. Our server keeps that email, a record of the payment, and up to three signed-in devices (for each: a random identifier, a short label such as "Chrome on Mac", when it signed in and when it was last used). Each device holds a random sign-in token in its browser storage; our server keeps only a one-way hash of it. When you sign in on a new device we email you a six-digit code, sent through Resend, our email provider; the code is stored only as a hash and expires after 10 minutes. We also count sign-in attempts per internet address each day, stored as a salted hash, so nobody can guess codes. If you answer the one question on the page Stripe returns you to (where you first heard of Burncaps and, if you like, what you caption, each a tap on a short list, with up to 80 characters of your own words for “Somewhere else”), the answer is kept with this record. We use your email for nothing else: no newsletters, no marketing, unless you ask for our emails yourself (below). Ask us to delete it at any time.

The export check: before an export, the page asks our server for an export pass. For a free video it sends a random ID for your browser and a random ID for the file (made up on your device, derived from nothing in the video; your browser keeps it for that file for a day, filed under a scrambled form of the file’s name and size that never leaves the device, so exporting the same file again is never counted twice). When the export has finished, the page sends the same two IDs and the pass once more, and only then does our server count the free video: an export that stops or is abandoned is not counted (one a month; after that an unfinished export counts, so the check cannot be dodged). The count is kept against that browser and against your internet connection, stored as a salted one-way hash of your address (for an IPv6 address, of its network part) and kept for 30 days. Signed in, the count belongs to your email instead. After your two free videos, if you choose to keep going free, the page asks for a pass for a video that carries the burncaps.app mark: it sends the same two random IDs, and nothing is counted or kept. A Pro device receives a signed pass valid for seven days, renewed whenever it checks in. The pass carries the same random browser ID and an expiry, nothing else. This is what keeps the two free videos fair and Pro for the people who bought it.

The moment picker, the name check and the caption language: when you choose the best 30 or 60 seconds, type names to spell right, or choose a caption language other than the one spoken, the transcript text of your recording (the words and their timings, and the language they were heard in, never the video or the audio) is sent to our server and passed to Anthropic's Claude API to choose the strongest stretch, correct the spelling of the names you typed, write a line to post with the clip, or translate the lines into the caption language you chose (for a translation only the lines of text are sent, each word numbered and a mark after the words where the speaker paused, but no times). Anthropic processes API data under its commercial terms and does not train on it. We do not store the transcript. The only records our server keeps are counts: a daily count per address, and the number of AI picks used per random browser ID (or per email when signed in) and per connection over 30 days (a translation is free and uses none of the picks, only the daily count per address), each stored as a salted one-way hash, so the feature cannot be abused. With Pro, picks and translations are unlimited: the count is kept per account per day only as a safety limit against a misused sign-in. Tick "Keep everything on this device" and this request is never made; a local rule does the job instead.

Step counts: as you use the tool, the page sends our server one count for each step: arriving (with which of our pages you arrived on, for example the home page or a language page), starting, the language your recording was heard in (a short code such as "hi" for Hindi, never any of your words) and which speech model wrote it (the larger one, the model made for an Indian language, or our speech service, with the language you picked if the page asked), the caption language you choose and whether its translation came back, whether a video you export uses your own caption look (words appearing as they are said, or your own caption colours; once a visit each, never the colours themselves), each free video, reaching the free limit, the reason if you choose to tap one, choosing to keep going free with the mark, each video made with the mark, clicking Pro (and where: the offer under your video, or at the free limit), your script and result appearing on screen (once a visit), pressing Export (once a visit), a stretch of your recording that had sound but came back with no words (once a file, and whether listening to it again found them), a file turned away for being too big or too long (with its length rounded up to a band of minutes, such as up to 15 or up to 30), leaving your email on the Studio or Clips card (and where the card was: the home page, the Pro page or under your video), leaving your email for our emails (and where: under your video), sending yourself this page from a phone, whether an export or the moment picker finished or failed, a count if the editor could not load in your browser at all, and a count the first time in a visit you play with Wick, our mascot, in each way (a poke, a drag, feeding it a video, taking its offer to try the sample, its party, hiding it or bringing it back), and a count the first time in a visit you try the sample take from the button under the drop box. On a phone the page also counts each stage as it starts (the file chosen, with its size in megabytes, its width and height in pixels, its length in seconds and the phone's memory size; the speech model loading; listening; finished; and for an export, its size and length, whether a background was on, which video encoder the phone used, how long finding the face took, how far it had got each quarter and each minute, and at the end how many frames a second it wrote and how many milliseconds each stage of a frame took on average), because a phone can close a page without warning and the last count shows where it stopped. Each count carries only the kind of place your visit came from (for example ChatGPT, Google, Bing, a social site, or none), the kind of place your first ever visit came from and roughly how long ago that was (the same day, the next day, within a week, or longer: see “Where your first visit came from” below), whether you are on a phone or a computer, and the country your connection is in, which our host reads from the request (your internet address is not kept). There is no identifier of any kind and nothing links one count to another, so they are plain totals, not a record of you. They tell us where people come from and where the tool stops working for them.

Where your first visit came from: the first time you open Burncaps, your browser keeps a small note in its own storage on your device: the kind of place that visit came from (as for the step counts), our advert’s tag or a partner’s code if the link carried one, and the date, with no time. It leaves your device only as a short label (for example “org-chatgpt”) on the step counts and on a Pro payment, so we can see which places bring people who come back and buy. Clearing this site’s data in your browser removes it. A browser that used Burncaps before 2 October 2026 is labelled “earlier”, because its first visit is not known.

Studio and Clips (not open yet): if you leave your email on one of the “Tell me when it opens” cards, our server keeps the email, which card, where on the site the card was, the label of where your first visit came from (above), the country of your connection and the date. We use it for one email, when that product opens, and for nothing else; ask us to delete it at any time.

Emails from Burncaps (only if you ask): after an export you can leave your email for our emails. Our server then keeps the email, where on the site you left it, the label of where your first visit came from (above), the country of your connection, the date, and which of our emails it has been sent. You get one email when something big arrives and, unless you have Pro, three short emails over the next ten days on getting more from Burncaps (what Pro changes, how buyers use it, and its price against a year of monthly plans). Every email has a link at the bottom that stops them in one click; your mail app’s own Unsubscribe button works too. They are sent through Resend, our email provider, with no tracking of any kind: no pixel, and nothing that follows one person. A link back to burncaps.app carries only a label for which email it was (for example src=email-n1), the same for everyone who gets that email, so we can count which emails bring people back. We keep the email until you stop them or ask us to delete it; after a stop we keep only a note that the address stopped, filed under a scrambled form of it (a salted one-way hash), so you are not written to again; the email itself, and everything else above, is deleted.

If we emailed you about listing Burncaps: we sometimes write, one person at a time, to people who publish lists or reviews of caption tools, using the work address on their own site. We keep your address, the subject, the date and our email provider’s reference for what we sent in our operations log, and under a salted one-way hash the date, so we never write to the same address twice within 30 days. Reply “stop” and we never write again. The email is plain text, sent through Resend with no tracking of any kind. Ask us to delete it all at any time: the address, the log lines and the note go (and with them our record that you asked us to stop).

The price where you are: Pro is $49 in most countries, ₹998 in India (by UPI or card) and $10.40 in lower-income countries. When a page opens, it asks our server which of these applies. The request carries nothing about you: our host reads the country from it, as for the step counts, and nothing is kept. The answer stays in your browser’s session memory for that tab only.

What we do not do

Visit counting

We use Cloudflare Web Analytics, a cookieless page-view counter, to see how many people visit and which pages they read. It sets no cookies, does not fingerprint your device, and cannot identify you. It is the one small script from cloudflareinsights.com you will see in your browser's network tab alongside the AI model download. See Cloudflare's Web Analytics documentation for what they collect.

Our own adverts

A link from one of our own adverts carries a short source tag (for example src=rd-anchor) so we can count which advert brought visitors, how many of them tried the tool, and how many bought Pro. The tag is held in your browser's session memory for that tab only and is gone when you close it; if it brought your first ever visit, it is also part of the note described under “Where your first visit came from”. It is not a cookie, it contains nothing about you, and the counts are plain totals with no identifiers. A link from one of our partners carries a short code (ref=); your browser keeps the code and the date for 60 days so a purchase in that time can be credited to the partner, and nothing else. If you arrive without a tag, the step counts above are recorded as "organic". When you choose Pro, the label of where your first visit came from goes to Stripe with the payment and, if this visit came from somewhere else (an advert, a partner), that label too (for example “org-chatgpt” or “org-chatgpt_ms-cards”), so a sale can be credited to what brought it; it says nothing about you. No advertising network's tracking code runs on this site.

Hosting

The site's static files are served by Netlify, which may log IP addresses of requests for security and operations, as any web host does.

Your rights

Under UK GDPR you have rights over personal data we hold. Because we hold almost none (at most, your Pro sign-in record described above, an email you left on a Studio or Clips card, or an email you left for our emails), a single email to hello@burncaps.app is enough to exercise any of them.

Back to Burncaps · About Burncaps