Privacy
What we hold about you, why, and who else touches it. Short version: an email address, a licence, the machines it runs on, and what the tax office requires. Nothing else, and never your footage.
Who holds it
Cutsense Mateusz Jazowski, Beskidzka 25, 44-200 Rybnik, Poland (NIP 6423191192, REGON 362188813) is the controller of this data. Write to mj@cutsense.com about anything on this page.
Your footage never comes to us
The plugins do their work on your machine. No frame, no project, no still and no thumbnail is uploaded, sampled or analysed. There is no telemetry inside the plugins.
What we store, and why
- Your account. Email address, and a name if you give one. If you sign in with Google or Apple, we keep the identifier they return so the next sign-in finds the same account. Never your password, which we never see. If you use an email and password instead, the password is stored only as a hash.
- Your licence and its machines. Which products you own, and for each activated computer: a hashed fingerprint, the name the machine reports, which host it activated from, and when it was last seen. The hash is what enforces the seat limit; we cannot turn it back into your hardware. Releasing a seat deletes that record.
- Your purchase. Amount, currency, product, and what has to go on the invoice: your name and address, and for a company its name, address and tax number. Tax law puts the buyer on the document, so this is not optional for us either. We also record that you accepted these terms and asked for immediate access, and when. Payment itself happens at Stripe; card numbers never reach our servers.
- Where you bought from.The country your connection resolves to and the country that issued your card. VAT law makes the buyer's location the thing that decides the tax, and requires two independent pieces of evidence for it. That is what these are for, and the only thing they are used for.
- A session cookie. So you stay signed in. It holds a token and nothing else. See the cookies page.
No analytics, no advertising, no profiling, no cross-site tracking. We do not sell data and we do not have anyone to sell it to.
Who else processes it
- Stripe takes the payment and tells us it succeeded.
- inFakt issues and emails your invoice. Invoices to companies go on from there to KSeF, the Polish national e-invoicing system, because the law requires it.
- VIES (the EU register) and Brønnøysundregistrene (Norway) answer whether a tax number you enter is registered. Without that check we cannot let a business buy without VAT.
- Google and Apple, only if you choose to sign in with them.
- Resend sends the note confirming your purchase.
- Vercel and Turso host the site and the database.
Some of these run outside the European Economic Area. Where they do, the transfer rests on the European Commission's standard contractual clauses.
Why we are allowed to
Your account, your licence and your activations exist so we can give you what you bought, which is performance of our contract with you. Invoices, tax records and KSeF are a legal obligation. Seat limits, and looking at a sale whose location evidence disagrees with itself, are our legitimate interest in not being defrauded. We do not rely on consent for anything, because we send no marketing.
How long
Invoices and the records behind them: five years from the end of the tax year, which is what Polish tax law demands and is not ours to shorten. Your account and licence: until you ask us to delete them. A device record: until the seat is released. A session: thirty days, or until you log out.
What you can ask for
A copy of what we hold, a correction, deletion, a portable export, or that we stop a particular use. Write to us and you get an answer inside a month, usually the same week. Deletion has one limit: we cannot remove an invoice that tax law obliges us to keep, and we will tell you exactly what stays and why.
If we handle it badly you can complain to the Polish data protection authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, Warsaw), or to the authority where you live.
Keeping it safe
Everything travels over TLS. Passwords are hashed, machine fingerprints are hashed, session tokens are random and expire. Access to the database is limited to the people who build this, currently one person.
Children
This is professional software sold to adults. We do not knowingly hold data about anyone under sixteen.
Changes
If we add a processor or start collecting something new, this page changes first and says when it changed. We will not quietly widen what we do with what we already have.
Last updated 5 August 2026. Questions: mj@cutsense.com.