SightScript

Privacy

What we collect, who else sees it, and how long we keep it. Written to describe what the software actually does.

Last updated 9 August 2026

The short version

SightScript turns a video into documents. To do that it sends the video to Google's Gemini API and stores the documents it gets back. It does not sell data, does not run advertising or third-party trackers, and sets no cookies.

If you use it without an account, nothing you produce is stored on our servers at all; your history stays in your own browser.

What we collect

Without an account: nothing that identifies you. Your results are kept in your browser's local storage (up to 20 entries) and never reach our database. We record your IP address transiently to enforce the hourly limit on free trial runs, and count anonymous usage as aggregate totals with no identifier attached.

With an account: your email address and a password hash, both held by our authentication provider; we never see your password. Plus the documents produced by each run, and your plan.

On Pro: a Stripe customer identifier so a subscription can be linked to your account. Card details go directly to Stripe and never touch our servers.

We do not collect your name, address, phone number, or location, and there is no analytics product, advertising pixel, or session recorder anywhere on the site.

The videos you submit

A YouTube link you paste is sent to Google's Gemini API for analysis. We do not download or store the video itself, only the documents produced from it.

A file you upload on Pro goes from your browser directly to temporary storage, is streamed to the Gemini API, and the temporary copy is deleted as soon as that finishes. If a transfer fails partway (a dropped connection, a closed tab), a leftover temporary copy can survive until it is next cleared. Gemini's own copy expires within 48 hours. We keep no copy of the video once processing completes.

Gemini runs on Google's paid API tier, under which Google states it does not use submitted content to train or improve its models. This is a deliberate choice and the reason the service is not run on the free tier.

Please do not upload recordings you do not have the right to process, or that contain information you would not want handled by a third-party AI provider.

How long things are kept

Documents saved to an account are kept until you delete them or delete your account. You can delete any individual result from your library at any time.

Uploaded video files: deleted from our transit storage within seconds of processing, and from Google's within 48 hours. An upload that fails mid-transfer may leave a temporary copy behind until it is cleared.

Anonymous browser history: until you clear it or your browser does.

Server logs, which may contain IP addresses and error details, are retained by our hosting provider on their standard schedule and are not used for anything other than diagnosing faults.

Aggregate usage counters are kept for about six months. They contain no identifiers and cannot be traced to a person.

Who else processes your data

Google (Gemini API): analyses the video and generates the documents. Also the YouTube Data API, to check a video's length before processing and to read its captions for timestamp accuracy.

Supabase: accounts, authentication, and the database holding your saved documents.

Stripe: subscription payments. Stripe receives your email address; we receive only a customer identifier and subscription status.

Vercel: hosting, plus temporary storage for uploaded files.

Upstash: the rate-limiting and usage counters described above.

Resend: sends account emails such as sign-up confirmation.

Each is used only for the purpose listed. We do not share your data with anyone else, and we do not sell it.

Sharing a result

You can create a share link for a saved document. Anyone holding that link can read that one document without signing in; the link itself is the only credential, so treat it as you would a password. It exposes only the document, never your account, your email, or anything else in your library. You can revoke it at any time, and revocation takes effect immediately.

Share links for uploaded videos deliberately omit the file reference, so a recipient cannot reach the underlying video.

Your rights

You can export any document from the app, delete individual results, or ask us to delete your account and everything attached to it. Deletion is permanent.

If you are in a jurisdiction that grants rights of access, correction, portability, or erasure (including the EEA, the UK, Canada, and several US states), those rights apply here, and you can exercise them by writing to the support address below. We will not charge you or make it difficult.

Security

Accounts are isolated at the database level, not merely in application code: the database refuses to return one user's rows to another. Uploaded files are tagged with their uploader and cannot be processed by anyone else. All traffic is encrypted in transit.

No system is perfectly secure. If you find a vulnerability, please write to the support address; reports are welcome and will be taken seriously.

Children

SightScript is not intended for children under 13, and we do not knowingly collect their information.

Changes

If this policy changes materially we will update the date at the top. Because the policy is generated from the same repository as the product, it changes when the product changes rather than drifting away from it.

Contact

Questions, deletion requests, or anything else: support@sightscript.io.