Privacy Policy
Effective date: 1 May 2025
This Privacy Policy explains how Stitchr ("we", "us", "our") collects, uses, and protects your personal data when you use Stitchr ("the Service"). We are committed to handling your data responsibly and in compliance with the General Data Protection Regulation (GDPR).
1. Who We Are
Stitchr is operated from the Netherlands. For data protection matters, you can reach us at [email protected].
2. Data We Collect
Account data: When you sign up, we collect your name, email address, and any social login information you provide ( e.g. Google OAuth).
Usage data: We collect information about how you use the Service — pages visited, features used, videos created, and errors encountered. This helps us improve the product.
Content data: We store the scripts, voiceovers, images, and videos you create using Stitchr so we can deliver them back to you and publish them on your behalf.
Billing data: Payments are processed by Stripe. We store a reference to your subscription and plan, but we do not store full payment card details.
Technical data: We collect standard log data including IP addresses, browser type, and device information for security and diagnostic purposes.
3. How We Use Your Data
We use your data to:
- Provide and maintain the Service
- Process your subscription and manage billing
- Publish content to your connected YouTube channel
- Send you transactional emails (account activity, billing receipts, error alerts)
- Improve the Service through aggregated, anonymised usage analysis
- Respond to support requests
- Comply with legal obligations
We do not sell your data. We do not use your content to train AI models.
4. Legal Basis for Processing (GDPR)
- Contract: Processing necessary to provide the Service you signed up for
- Legitimate interests: Security, fraud prevention, service improvement
- Legal obligation: Compliance with applicable laws
- Consent: Where we ask for consent (e.g. optional marketing emails), you may withdraw it at any time
5. Third Parties We Share Data With
We share data only where necessary to provide the Service:
| Service | Purpose |
|---|---|
| Stripe | Subscription billing |
| YouTube (Google) | Publishing videos to your channel |
| ElevenLabs | Voiceover generation |
| AWS | File storage and video rendering |
| Plausible Analytics | Privacy-friendly usage analytics (no cookies, no personal data shared) |
| Sentry | Error monitoring |
All third parties are under contractual obligations to process your data securely and only for the purposes we specify.
6. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where retention is required by law (e.g. billing records, which we keep for 7 years).
Generated content (videos, voiceovers, images) stored on our infrastructure is deleted within 30 days of your account closure.
7. Your Rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing in certain circumstances
- Port your data to another service
- Object to processing based on legitimate interests
- Withdraw consent where processing is based on consent
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with your national data protection authority. In the Netherlands, that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
8. Cookies
We use a small number of essential cookies to keep you logged in and to protect against CSRF attacks. We do not use tracking or advertising cookies. Our analytics are handled by Plausible, which is cookie-free.
9. Data Security
We use industry-standard measures to protect your data, including encrypted connections (TLS), access controls, and regular security reviews. No system is perfectly secure — if you discover a vulnerability, please report it to [email protected].
10. International Transfers
Your data is primarily stored and processed in the EU (Ireland/Netherlands). If any processing occurs outside the EU, we ensure appropriate safeguards are in place (e.g. Standard Contractual Clauses).
11. Changes to This Policy
If we make material changes to this policy, we will notify you by email or in the app before they take effect. The effective date at the top of this page will be updated accordingly.
Questions about your privacy? Email us at [email protected].