Legal Document

Privacy Policy

Last Updated: May 26, 2026

TL;DR — Key Points

  • We do not sell your data and we never will. We do not share it for cross-context behavioral advertising.
  • We do not collect biometric voiceprints. Audio is transcribed to text only; no speaker embeddings or voice identifiers are extracted or stored.
  • Named subprocessors only. Every third party that touches your data is listed by name in §5 (14 providers total).
  • Analytics is off by default. A consent banner appears on first visit; no analytics events are captured until you accept.
  • Broad regional coverage. This policy addresses rights under US state laws (CCPA/CPRA and 18 additional states), Canadian law (PIPEDA + Quebec Law 25), and GDPR-equivalent rights for EEA, UK, and Swiss users.

1. Introduction

Welcome to NeonCut ("we," "our," or "us"). NeonCut is operated by Asif Technologies Inc. and is an AI-powered video creation platform that transforms voiceover audio into polished videos with motion graphics and captions. We are committed to protecting your privacy and being transparent about how we collect, use, and share your personal information.

This Privacy Policy explains our practices regarding personal information we collect when you visit our website at neoncut.app, join our waitlist, complete surveys, or use our services (collectively, the "Services").

By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Services.

Quick Summary: We collect only what we need to provide our services, we never sell your data, and we give you control over your information. We are committed to applicable US and Canadian privacy laws, and we provide GDPR-equivalent rights for users in the EEA, UK, and Switzerland.

2. Information We Collect

We collect information in the following categories:

2.1 Information You Provide Directly

Data TypeDescriptionRequired/Optional
Email AddressYour email address when joining our waitlist or creating an accountRequired
Company URLYour company or personal website (from survey)Optional
RoleYour professional role or title (from survey)Optional
Primary GoalWhat you hope to achieve with NeonCut (from survey)Optional
Survey ResponsesAdditional feedback and preferences you shareOptional

2.2 Information Collected Automatically

When you visit our website or use our Services, we automatically collect certain technical information:

Data TypePurpose
IP AddressSecurity, fraud prevention, and approximate geographic location
User AgentBrowser type and operating system for compatibility
Device InformationDevice type, screen resolution, and hardware details
UTM ParametersMarketing attribution (source, medium, campaign)
Page Views & InteractionsUnderstanding how you use our Services
TimestampsWhen you accessed our Services

2.3 Content Data

When you use our video creation features, we also collect:

  • Audio Files: Voiceover recordings you upload for video generation
  • Generated Videos: Output videos created by our AI from your audio
  • Style Preferences: Your selected visual styles and customization choices
  • Project Metadata: Titles, descriptions, and organizational data for your projects

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Delivery

  • Managing your waitlist position and sending early access invitations
  • Processing your audio files and generating videos
  • Providing customer support and responding to your inquiries
  • Personalizing your experience based on your preferences

3.2 Communications

  • Sending waitlist updates and early access notifications
  • Providing important service announcements and updates
  • Responding to your questions and feedback
  • Marketing communications (with your consent, which you can withdraw at any time)

3.3 Improvement and Analytics

  • Understanding how users interact with our Services
  • Identifying and fixing technical issues
  • Improving our AI models and video generation quality
  • Developing new features based on user feedback

3.4 Legal Basis for Processing

We process your personal information under the following legal bases:

  • Contract performance: Processing your audio files, delivering generated videos, managing your account, and processing payments are necessary to perform our contract with you.
  • Consent: We rely on your consent for marketing communications and for optional product analytics. You may withdraw consent at any time.
  • Legitimate interests: We have a legitimate interest in operating, securing, and improving our Services — including error monitoring, fraud prevention, and aggregate analytics — provided those interests are not overridden by your rights and interests.
  • Legal obligation: We may process data where necessary to comply with applicable law, including retention of billing records and responses to lawful government requests.

4. AI Processing & Biometric Non-Extraction

NeonCut uses artificial intelligence to transform your audio into videos. This section explains exactly how your content is processed and what we do — and importantly, what we do not — extract from it.

4.1 How AI Processes Your Content

Your audio is transcribed to produce text and millisecond-level word timings; those outputs are passed to our AI scene-generation pipeline, which selects appropriate visuals. Processing runs on encrypted servers, and generated videos are stored privately and accessible only to you.

4.2 Biometric Non-Extraction

NeonCut does not collect, capture, store, or use voiceprints, speaker embeddings, or any other voice-derived biometric identifier. We use AssemblyAI's standard transcription endpoint with speaker diarization and speaker labels disabled. Audio is processed solely to produce text transcripts and millisecond-level word timings; no audio-derived feature vector is generated, retained, or shared. We do not use audio to identify a speaker. Google Gemini receives only the resulting transcript text and word timings — never the audio file itself.

This design is intentional and reflects our commitment to avoiding biometric data collection under Illinois BIPA, Texas CUBI, Washington MHMDA, and analogous state laws that regulate voiceprints and voice-derived identifiers.

4.3 Your Content is Not Used for Training

Our Commitment:We do not use your uploaded audio or generated videos to train AI models — ours or anyone else's. AssemblyAI, Google Gemini, and PostHog are engaged under no-training service tiers. A subprocessor DPA schedule will be published as part of our next policy revision.

4.4 Content Ownership

You retain all rights to your uploaded content and own the videos generated from it. We do not claim ownership of your creative work. See our Terms of Service for licensing details.

5. How We Share Your Information

We do not sell your personal information. We share your information only in the following circumstances:

5.1 Named Subprocessors

We work with the following named third-party service providers who process data on our behalf. All are contractually bound to protect your data and may only use it for the specified purposes.

ProviderPurposeData SharedLocation
VercelApp hosting and edge deliveryRequest/response data, logsUS
SupabaseDatabase, authentication, file storageAccount data, project metadata, audio file referencesUS (cloud)
AWS (S3 + CloudFront + SQS + Lambda)Media storage, CDN, video export renderingAudio files, generated videosUS (us-east-1)
StripePayment processingPayment method, billing address, subscription statusUS
ResendTransactional email deliveryEmail address, message bodyUS
AssemblyAIAudio transcription only (no diarization, no speaker labels)Audio file during processing; output is text onlyUS
Google GeminiAI scene generationTranscript text and word timings only — never the audio fileUS
Cloudflare TurnstilePrimary bot protectionIP address, user agent, challenge dataGlobal edge
hCaptchaFallback bot protectionIP address, user agentUS
InngestBackground job orchestrationJob metadata, internal IDsUS
PostHogProduct analytics (opt-in only)Internal account ID, schema-defined product events (no email, name, or audio)US
Upstash RedisRate limiting and throttlingIP address, throttling keysUS / Global
SentryError monitoring (PII scrubbed before transmission)Stack traces, request metadataUS
Pexels / Pixabay / CoverrStock media search for scene assetsText search queries onlyGlobal

5.2 Legal Requirements

We may disclose your information if required by law, legal process, or government request, or to:

  • Comply with legal obligations
  • Protect our rights, privacy, safety, or property
  • Enforce our Terms of Service
  • Protect against legal liability

5.3 Business Transfers

If NeonCut is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

6. Data Retention

We retain your information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

Data CategoryRetention PeriodReason
Account data (email, signup details, survey responses)Duration of account + 30 days after deletion requestService provision
Uploaded audio filesRetained for the life of the source project; deleted on account or project deletion. A 30-day post-export auto-deletion job is on our roadmap.Processing & support
Generated videosUntil you delete them or account closureService provision
Analytics data (identifiable)26 monthsService improvement
Technical logs90 daysSecurity & debugging
Legal/compliance recordsAs required by law (typically 7 years)Legal obligations

You can request deletion of your data at any time (see Your Rights). Anonymized or aggregated data that cannot be linked back to you may be retained indefinitely for statistical purposes.

7. Your Rights

Depending on your location, you have certain rights regarding your personal information. We honor rights requests from all users regardless of where they are located.

7.1 Universal Rights

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Withdraw Consent: Withdraw consent for marketing communications at any time

7.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of personal information collected, used, and shared
  • Right to Delete: Request deletion of personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights
  • Right to Limit Use of Sensitive Personal Information (SPI): You have the right to limit our use of sensitive personal information to purposes necessary to provide the Services. Note that NeonCut processes audio solely to produce text transcripts — we do not use audio for inferences beyond transcription, and we do not generate or retain voice-derived biometric identifiers. There is therefore no SPI use to limit with respect to audio; however, the right exists and you may exercise it at any time.
  • Right to Appeal: If we deny your rights request, you may appeal by emailing contact@neoncut.app with the subject line "Privacy Request Appeal." We will provide a substantive response within 45 days.

Important: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

7.3 Other US State Residents

If you reside in a US state with a comprehensive consumer privacy law (such as Colorado, Virginia, Connecticut, Texas, Utah, Oregon, Montana, and others), you have rights substantively similar to those described above for California: access, deletion, correction, portability, and the right to opt out of any sale or targeted advertising. We do not sell personal information and we do not engage in targeted advertising. To exercise your rights, email contact@neoncut.app with your state name in the subject line.

7.4 Canadian Residents (PIPEDA + Quebec Law 25)

If you are a resident of Canada, PIPEDA provides you with:

  • Right to Access: Information we hold about you
  • Right to Challenge Accuracy: Request correction of inaccurate information
  • Right to Withdraw Consent: Subject to legal restrictions
  • Right to Complain: To the Office of the Privacy Commissioner of Canada at www.priv.gc.ca

Contact: contact@neoncut.app with "PIPEDA Request" in the subject line. We respond within 30 days.

Quebec Law 25 (Act Respecting the Protection of Personal Information in the Private Sector)

If you are a Quebec resident, Law 25 provides additional rights effective September 2023:

  • Privacy Officer: A designated Privacy Officer is responsible for the protection of personal information at NeonCut. Privacy inquiries are currently handled by the NeonCut team at contact@neoncut.app.
  • Data Portability: You have the right to receive your personal information in a structured, commonly used technological format.
  • Automated Decision Notice: Where a decision based solely on automated processing produces effects concerning you, we will inform you and you may request human review.
  • Privacy Impact Assessment (PIA): We conduct PIAs for cross-border transfers of personal information. A summary PIA is available on request.

Contact: contact@neoncut.app with "Law 25 Request" in the subject line.

CASL (Canada's Anti-Spam Legislation)

Marketing emails from NeonCut comply with CASL. Every marketing email includes an unsubscribe link. You may withdraw consent for marketing communications at any time by clicking "Unsubscribe" in any email or by emailing us with "Unsubscribe" in the subject line. Withdrawal of marketing consent does not affect transactional emails necessary to provide the Services.

7.5 EEA, UK, and Swiss Users (GDPR-Equivalent Rights)

If you are in the EEA, the UK, or Switzerland and choose to sign up for NeonCut, we extend GDPR-equivalent rights: access, rectification, erasure, restriction of processing, data portability, objection to processing (including for direct marketing), and the right not to be subject to solely automated decisions with legal or similarly significant effects (Articles 15–22). Our lawful bases are described in §3.4 and data transfers to the United States in §8. To exercise these rights, email contact@neoncut.app with "GDPR Request" in the subject line.

7.6 How to Exercise Your Rights

To exercise any of these rights, email contact@neoncut.app. We respond within 30 days (or within the timeframe required by applicable law) and may need to verify your identity first. You may designate an Authorized Agent to submit a request on your behalf; we will require written authorization plus proof of the agent's identity and will independently verify your own identity at the email address on your account before fulfilling any deletion or access request.

If we deny a request in whole or in part, you may appeal by emailing the same address with the subject line "Privacy Request Appeal"; we will conduct a fresh review within 45 days.

8. International Data Transfers

Asif Technologies Inc. (operating as NeonCut) is based in Canada, and our infrastructure providers are primarily located in the United States. By using our Services, you acknowledge that your information may be processed in the United States, where data protection laws may differ from those in your country of residence. We take appropriate contractual and technical measures to ensure your information is protected regardless of where it is processed.

For EEA, UK, and Swiss users: transfers to the United States are made on the basis of our contractual commitments with subprocessors and, where available, Standard Contractual Clauses (SCCs) or equivalent mechanisms. See §5 for a full list of subprocessors and their locations.

9. Security

We protect your information with:

  • Encryption: TLS 1.3 in transit and at rest
  • Access Controls: Strict access limits to your data
  • Secure Infrastructure: Cloud providers with SOC 2 compliance
  • Regular Audits: Security assessments and code reviews
  • Bot Protection: Cloudflare Turnstile against automated attacks
  • Incident Response: Procedures to detect and respond to incidents

No method of transmission or storage is 100% secure, but we maintain reasonable safeguards.

9.1 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify affected users promptly upon becoming aware of a breach that poses a real risk of harm, as required by applicable law. Notification will be sent to the email address associated with your account and will include: a description of the breach, the types of data affected, steps we are taking in response, and recommendations for protecting yourself.

10. Children's Privacy

Our Services are not intended for children under 13 and we do not knowingly collect personal information from them. Under the expanded COPPA rule effective April 22, 2026, voiceprints are classified as children's personal information; as noted in §4.2, NeonCut does not collect or retain voiceprints from any user. If a parent or guardian believes their child has provided us with personal information, email contact@neoncut.app and we will delete it promptly.

11. Cookies, Tracking, and Analytics

We use cookies and similar technologies to operate our Services and improve your experience.

11.1 Types of Cookies We Use

Cookie NameTypePurposeDurationCan Opt Out?
sb-* (Supabase auth)EssentialSession management and authenticationSession / up to 1 yearNo (required for login)
nc_subFunctionalCaches subscription status for page loads24 hoursNo (required for access control)
nc_analytics_consentPreferenceStores your analytics consent choice (accepted / rejected)1 yearYes — change at /cookies

11.2 Managing Cookies

You may manage cookie preferences through your browser settings or on our Cookie Preferences page. Note that blocking essential cookies will prevent login and access to the Service.

11.3 Product Analytics

We use PostHog for first-party product analytics. Analytics is off by default. On first visit you will see a consent banner offering Accept or Reject; we capture no analytics events until you click Accept. You can change your decision any time from the Cookie Preferences page. When analytics is enabled, PostHog is configured so that we identify you only by your internal account ID (no email or name), capture only schema-defined product events (account creation, project creation, scene generation, video export, etc.), and do not track you across third-party websites.

Aggregated, non-identifying analytics data may be retained for product-improvement purposes as described in Data Retention. You can request deletion of analytics data tied to your account by contacting us.

11.4 Global Privacy Control

We honor the Global Privacy Control browser signal (Sec-GPC: 1). When your browser sends the GPC signal, we treat it as an opt-out of analytics and any future sale or sharing of personal information; the PostHog SDK is initialised with respect_dnt: true so capture is suppressed at the SDK level even if a preference cookie is later set, and the consent banner acknowledges the signal in its body copy so you can see that it has been processed. California regulations effective January 1, 2026 require that businesses provide visible confirmation that the GPC signal has been processed — this section, together with the on-page banner acknowledgement, is that confirmation.

12. Automated Decision-Making

Our AI selects video templates, captions, and pacing based on your audio transcript. These decisions are aesthetic recommendations only — they do not produce legal effects, financial decisions, or other significant decisions about you. You can regenerate any output, override stylistic choices, or contact us with concerns. We do not engage in profiling that produces legal or similarly significant effects within the meaning of GDPR Article 22 or analogous US state laws.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make changes:

  • We will update the "Last Updated" date at the top of this policy
  • For significant changes, we will notify you via email (if you are on our waitlist or have an account)
  • We may also post a notice on our website
  • Material changes will be communicated at least 30 days before taking effect

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Asif Technologies Inc. (operating as NeonCut)

Privacy Officer: Privacy inquiries are handled by the NeonCut team at the contact email above.

When contacting us, please include the applicable law in your subject line (e.g., "CCPA Request", "GDPR Request", "Law 25 Request", "PIPEDA Request") so we can route the request correctly. Appeals of denied requests should use "Privacy Request Appeal". We aim to respond to all inquiries within 30 days.

© 2026 Asif Technologies Inc. (NeonCut). All rights reserved.