Privacy Policy
Established: October 12, 2024; last revised: September 6, 2026
The person or entity that operates Beutl ("we", "us", or "our") handles information about Users of Beutl accounts, the Store, cloud storage, paid AI features, APIs, and other online services (collectively, the "Service") as described in this Privacy Policy.
This Policy applies to beutl.beditor.net, APIs provided under that domain, and the rest of the Service. External sites and packages independently supplied by third parties may be governed by their own policies. For usage data optionally sent by the Beutl desktop application, also review the Telemetry Policy.
1. Information we collect
1.1 Account and authentication information
- Name or display name, email address, profile image, and User ID
- Profile biography, public username, and registered social links
- Connected services such as Google or GitHub, external account identifiers, authentication tokens, and authorized scopes
- Passkey public key, authenticator type, backup status, creation time, and last-used time
- Tokens and expiration times needed for sessions, desktop application authentication, and identity verification
The Service does not currently offer password authentication, so we do not collect a password for your Beutl account. We also do not receive your Google or GitHub password.
1.2 Profiles, storage, and published content
- Stored or published file contents, file name, type, size, hash, visibility, and creation and update times
- Package name, description, website, tags, price, currency, images, releases, supported versions, and publication status
- Packages acquired from the Store, additions to and removals from the library, and information required for downloads
- Upload progress, identifiers needed to resume or safely delete an upload, and processing records
1.3 AI input, output, and usage history
- Prompts, editing instructions, glossaries, subtitles, languages, styles, and other settings
- Reference images, images to edit, first and last video frames, and audio submitted for transcription
- Generated images and videos, transcriptions, translations, and other AI output
- Selected model, operation type, status, errors, timestamps, allowance consumed, retry data, and identifiers used to prevent duplicate charges
Images, audio, and subtitles may contain faces, voices, names, or other personal information relating to you or another person. Submit only information for which you have all required rights and individual consents.
1.4 Purchases, billing, and usage allowances
- Stripe customer, checkout, payment, invoice, subscription, refund, and dispute identifiers and statuses
- Purchased product, amount, currency, billing period, purchase time, entitlement, and payment history
- Monthly AI usage, additional credits, adjustments following refunds or reversals, and transaction history
Card numbers, security codes, and other complete card details are entered directly into Stripe and are not stored by us.
1.5 Inquiries and feedback
We collect your name, email address, inquiry category and message, response status, and communications with us.
1.6 Technical information and usage records
- IP address, source port, User-Agent, browser, operating system, device type, and approximate country or region
- Access time, requested destination, activity, referrer, response status, error information, and security audit logs
- Cookies, session identifiers, and settings and recovery information stored in the browser
1.7 Information received from external services
When you choose to use an integration, we receive your name, email address, profile image, external account identifier, and other authentication information from Google or GitHub; payment and contract status from Stripe; and results and usage information from AI providers. The exact information depends on your settings, each service's specifications, and the authorization screen.
2. Purposes of use
We use collected information to:
- Verify identity and manage authentication, accounts, and profiles
- Store, retrieve, publish, distribute, meter, and safely delete files
- Publish, review, search, acquire, purchase, manage, and redistribute packages
- Run AI operations, store results, display history, calculate usage, prevent duplicate execution, and recover from failures
- Process payments, invoices, subscriptions, refunds, reversals, fraud prevention, and accounting
- Answer inquiries, provide support, and send important notices
- Investigate failures, monitor security, prevent unauthorized access, maintain audit records, and respond to rights infringements
- Improve the Service's quality, performance, usability, and features
- Compile and analyze usage, cost, and operation statistics in a form that does not identify an individual
- Perform these Terms and other conditions, resolve disputes, and meet legal obligations
3. Information made public
If you choose to publish them, your public username, display name, biography, social links, profile image, published packages, descriptions, prices, screenshots, and release files become available to the public on the internet. Copies may remain in search engines or third-party storage after you stop publishing the information. Do not include confidential information or personal information that must not be made public.
4. Information handled by AI features
- AI input is sent to OpenRouter, Inc. for processing and is then sent to the business that operates the selected model. The model publisher and the provider that actually runs the model may differ.
- Retention, training use, and safety review of input and output by OpenRouter and each AI provider vary according to the selected model, processing route, and provider policies. The Service does not guarantee zero data retention or exclusion from training for every AI operation.
- We store results, job history, and information needed for billing and recovery. Unless you separately save them to storage, source images and audio are ordinarily processed temporarily for the AI operation and are not stored as Beutl job-history files. Retention by external AI providers remains subject to their terms.
- Do not submit confidential information, authentication information, sensitive personal information, medical or financial information, or another person's personal information unless you have lawful authority and a genuine need to transmit it.
For current information about OpenRouter's practices, review the OpenRouter Privacy Policy and Provider Logging.
5. Cookies and browser storage
- The Service uses necessary cookies to maintain sign-in state, protect security, and remember settings such as whether the sidebar is open. Disabling cookies may prevent sign-in or other features from working.
- The Service stores AI prompt templates, temporary handoff data from transcription to translation, recovery identifiers used to avoid duplicate operations, upload-completion recovery data, and similar information in local storage or session storage. This information ordinarily remains on your device, and only the portion required for a feature is sent to the Service when you use that feature.
- You can delete cookies and browser storage in your browser settings. Doing so may prevent automatic recovery of an incomplete upload or AI operation.
- The Service's web application currently does not embed cookies, advertising tags, or analytics SDKs for advertising or cross-site behavioral tracking.
6. Disclosures to and processing by external providers
To provide the Service, we engage the following providers to process information or disclose information at your direction. A provider's own policy may also apply when it independently collects information.
| Provider or service | Purpose | Main information processed |
|---|---|---|
| Cloudflare, Inc. | Delivery, server execution, caching, file storage, security, and operational monitoring | IP address, HTTP communications, technical logs, files, and Service data |
| Cockroach Labs, Inc. (CockroachDB) Data storage region: Singapore | Storage of accounts, history, entitlements, and processing state | Information recorded in the Service database |
| Stripe, Inc. | Payments, recurring purchases, invoices, refunds, and fraud prevention | Email address, customer and transaction identifiers, purchase details, amounts, card details, and billing information |
| Google LLC / GitHub, Inc. | Authentication through an external account and display of connected information | External account identifier, name, email address, profile image, authentication tokens, and authorized scopes |
| Plus Five Five, Inc. (Resend) | Sending sign-in links, identity-verification messages, and Service notices | Email address, message body, and delivery information |
| OpenRouter, Inc. and the provider of the selected AI model | AI processing, model routing, returning results, and usage management | AI input and output, model, processing identifiers, and technical usage information |
| IPinfo, Inc. | Estimating currency by country when the delivery platform does not supply country information | IP address |
| Raintank, Inc. (Grafana Labs / Grafana Cloud) | Optional desktop application telemetry | Error logs, performance and usage data, and other telemetry information described in the Telemetry Policy |
When a Google or GitHub profile image is displayed, the image host may receive your IP address, User-Agent, referrer information, and similar data. A third party may also collect information after you follow an external link.
We may also disclose information with your consent; where required by law; where necessary to protect life, physical safety, or property and consent is difficult to obtain; as part of a business transfer; or in another circumstance permitted by the Act on the Protection of Personal Information or other applicable law.
7. Processing outside Japan
Information recorded in the Service database is stored in the Singapore region of CockroachDB. Cockroach Labs, Inc. is located in the United States, and it or its subprocessors may process information from outside Singapore for service operation or support.
Many of the other providers listed above are also located in the United States, and their servers or subprocessors may be located in Japan, Singapore, the United States, Europe, or other countries or regions. The country in which an AI operation is processed varies according to the selected model, OpenRouter routing, availability, and the model provider's subprocessors, so it cannot be identified as a single country in advance. Potential providers and their locations are listed in the OpenRouter provider directory.
We review public information and contractual terms of these providers and apply safeguards such as limiting transmitted data, encrypting communications, and controlling access. Contact us if you need more information about processing countries or safeguards.
8. Retention and deletion
- Accounts, profiles, stored files, and published content are generally retained until you delete them or close your account.
- A web sign-in session is generally valid for no more than thirty days after its last update. It may be invalidated earlier by sign-out, expiration, or a security measure.
- Transcription and subtitle-translation result files are generally deleted thirty days after creation. Generated images and videos are generally retained until you delete the job or file or close your account. Job identifiers, status, input settings, and usage records are retained as necessary for billing, history, recovery, and fraud prevention.
- Incomplete file uploads generally become eligible for deletion after twenty-four hours. If a failure or uncertain response from external storage prevents safe deletion, recovery records may remain until deletion can be confirmed.
- Transaction, billing, refund, audit, and security records are retained as necessary for legal retention obligations, accounting, dispute resolution, fraud prevention, and protection of rights.
- Prompt-library data and similar browser data remains on your device until you remove it or clear browser storage. AI recovery information generally expires after thirty days.
- Information accepted for deletion may remain in an isolated or restricted state until backups are overwritten, an external provider completes deletion, or an in-progress payment, refund, or storage operation is resolved.
9. Security measures
We apply measures including the following according to the nature and risk of the information. Additional details are available on request to the extent disclosure would not compromise security.
- Separation of administrator and User permissions, per-User access controls, and authentication
- Encryption in transit and appropriate hashing or secret management of tokens and similar information
- Authorization checks for private files, unpredictable storage identifiers, and upload-size limits
- Audit records for important actions, logging of anomalies and errors, and controls for safe retries and duplicate-processing prevention
- Restricting access to personal data and reviewing the data-handling terms of external providers
- Investigation, containment, recovery, and legally required regulatory and individual notice if a data breach occurs
10. Access, correction, and deletion requests
- Account settings allow you to access, change, or delete profile data, your email address, connected accounts, passkeys, files, and AI jobs. You can also request account deletion from those settings.
- To request notice of the purpose of use; disclosure of retained personal data or third-party disclosure records; correction, addition, or deletion; cessation of use; erasure; or cessation of third-party disclosure, email contact@beditor.net from your registered address and identify the request and information concerned.
- We will verify that the requester is the individual or an authorized representative through account sign-in, a reply to the registered email address, or another reasonable method, and will respond without delay as required by law. If we cannot grant a request under applicable law, the reason will be explained.
- Save any files and AI results you need before deleting your account. They may not be recoverable afterward.
11. Sale of personal information and anonymous data
We do not sell personal information for consideration and do not disclose it to third parties for advertising. Statistics that have been aggregated or anonymized so that they do not identify an individual may be used to operate or improve the Service, manage costs, or publish information.
12. Minors
A minor must use the Service with the consent of a parent or other legal representative. If you learn that personal information was provided without the required consent, contact us. After verifying the circumstances, we will respond as required by law.
13. Changes to this Policy
We may amend this Policy in response to changes in the Service or applicable law. The amendment and its effective date will be published on this page. If an amendment materially affects Users, we will provide reasonable advance notice through the Service, by email to the registered address, or by another appropriate method. An amendment that legally requires individual consent applies only after that consent is obtained through the designated process.
14. Inquiries and complaints
Send inquiries and complaints concerning personal information, this Policy, security measures, or an individual-rights request to:
Privacy contact: Beutl privacy desk
Email: contact@beditor.net