Legal
/
Privacy Policy
Privacy Policy
last updated: 21.07.2026
About this policy
This policy applies to the Evercut website at https://www.evercut.app, the Evercut macOS app, and messages sent to us through the website (together, the “Services”).
It does not apply to third-party services you choose to use, or to content you choose to export, publish, send, upload, or share outside Evercut. Those services have their own privacy policies.
General information
Tolv.Studio Damian Jankowski, a sole trader registered in Poland, NIP 7831912730, is the controller of the personal data described in this policy. In this policy, “Evercut”, “we”, “us”, and “our” mean Tolv.Studio Damian Jankowski.
You can contact us about privacy at privacy@evercut.app
Privacy overview
Your recordings, screenshots, audio, video, project files, OCR text, transcript text, clipboard actions, and other creative work stay on your device. We do not upload them to Evercut or elsewhere.
If you create an account, we use Supabase to provide sign-in, synchronised presets, and limited account-linked feature-use totals.
We use Framer’s built-in, cookie-free analytics to understand overall website use. We do not use Google Analytics, advertising pixels, or behavioural advertising.
We use Cloudflare for domain name system (DNS) and app-storage infrastructure.
We use Resend to deliver sign-in emails (magic links).
We do not sell personal information or share it for cross-context behavioural advertising.
Data we process
4.1 Your Creative Work
Evercut processes recordings, screenshots, microphone and camera media, cursor activity, OCR text, transcripts, project files, imported media, exports, local preferences, selected device names, and clipboard actions on your device.
This material is not sent to Evercut or Supabase under the current product design. If you export, copy, share, or upload it to another service, that service—not Evercut—handles the data you choose to send.
Transcription also runs locally. When you first use transcription, the app may download the Parakeet speech-recognition model from a GitHub release. GitHub receives the technical information required to deliver that download, such as an IP address and request data. Your audio and generated transcript are not sent to GitHub or Evercut for transcription.
4.2 Website Visits
When you visit the website, Framer and its infrastructure providers may process technical data such as IP address, browser and device information, pages requested, timestamps, and security logs. This is used to deliver and secure the website, investigate faults, and prevent abuse.
We also use Framer’s built-in analytics to understand aggregated website use. Framer states that this analytics service does not use cookies or persistent identifiers. To count daily unique visitors, it creates a daily rotating hash from a visitor’s IP address and user agent. The analytics dashboard gives us aggregated trends, such as pages viewed, referrers, country, and device type. We do not maintain a separate IP-address analytics database.
4.3 Contact Messages
If you contact us through the website, we receive the name, email address, and message you provide. We use this information only to read, assess, and reply to your enquiry. We do not add you to a marketing list or newsletter unless you separately ask us to do so.
Please avoid sending sensitive, confidential, or unnecessary personal information through the contact form.
4.4 Account Information
If you create an Evercut account, we process your email address, Supabase user ID, sign-in provider, provider account identifier, access status, account timestamps, and authentication-session data.
You may sign in with an email magic link or, if you choose, Google. We use Resend to deliver magic-link sign-in emails; Resend processes the recipient email address and the email content needed to send those messages. Google sign-in may provide the basic profile information available through the configured sign-in scopes, such as email address, name, profile image, and Google account identifier. We use your email address to identify your account; we do not use Google profile information for advertising.
The app stores its authentication session on your device using macOS-secured storage where available.
4.5 Preset Sync
If you use synchronised presets, we process preset names, settings and configuration, selected-preset preferences, technical record identifiers, and timestamps so those presets are available to your account. Preset names may contain personal data if you put it there, so please avoid including unnecessary or sensitive information.
4.6 Product Insights
When you are signed in, the app sends account-linked, cumulative totals for completed product actions. These include the type and number of screen captures and recordings (full-screen, window, or area), copies and exports, transcript generations, and certain editing actions, such as adding a zoom, split, voice-over, blur, image, text, shape, annotation, crop, or filler block.
These are totals—not a record of every click and not a session recording. They do not include project content, file paths, media, transcripts, OCR text, keyboard input, cursor paths, or clipboard content. We use them to understand feature adoption and improve the app.
4.7 Connection Data
When the app connects to Supabase to sign in, refresh a session, synchronise presets, or send product-insight totals, Supabase may process network and security data such as IP address, user-agent or app/device information, request timestamps, request path and status, and authentication audit information. Google processes the technical and authentication information needed when you choose Google sign-in.
We do not currently use a separate crash-reporting service or third-party app-analytics SDK.
4.8 Where It Comes From
Most of this data comes directly from you or your device when you visit the website, use the app, create an account, submit a message, or choose a feature. Google provides the account information made available when you choose Google sign-in. Framer, Supabase, GitHub, and our business-inbox provider generate the technical and service information described above while providing their services. We do not buy personal data or obtain it from data brokers.
How we use data
We use personal data only to:
provide and operate the website and app;
create, secure, and administer accounts;
synchronise presets and provide account-linked features;
understand aggregate website use and account-linked feature adoption;
respond to genuine enquiries;
protect the Services, prevent abuse, troubleshoot problems, and defend or establish legal claims; and
comply with applicable legal obligations.
For people in the EEA and UK, our legal bases are:
Contract: where processing is needed to provide an account, sign-in, synchronised presets, or another account-linked feature you request.
Legitimate interests: where needed to run and secure the website and app, reply to enquiries, understand feature adoption, improve the Services, prevent abuse, and protect or defend our rights. We consider the impact on your privacy and use only the data reasonably needed for these purposes.
Legal obligation: where we must keep or disclose information to comply with applicable law.
Consent: if we introduce a processing activity that relies on consent, we will ask for it at the relevant time and explain how to withdraw it.
You do not need to provide personal data simply to browse the website or use local-only app features. An email address and account-authentication information are needed for an Evercut account and account-linked features; without them, those features cannot work. Google sign-in is optional. Screen recording, microphone, camera, and accessibility permissions are optional, but the relevant feature cannot work without the relevant macOS permission. A contact email or other reply method is needed if you want us to respond to an enquiry.
Our providers
We use providers only where they help us run the Services. They receive only the information needed for their role.
Framer hosts the website, provides the contact form, and provides built-in website analytics.
Cloudflare provides domain name system (DNS) and app-storage infrastructure, including delivery of app updates. Cloudflare does not currently store or process personal data through this infrastructure, but may process standard network and security data (such as IP address and request metadata) while routing and securing traffic.
Supabase provides account authentication and EU-hosted database services for account data, synchronised presets, and product-insight totals.
Google provides Google sign-in when you choose it. Google is responsible for its own processing of your Google account under its privacy documentation.
GitHub delivers the optional transcription-model download.
Resend delivers transactional emails on our behalf, including sign-in magic links. Resend processes the recipient email address and the email content needed to send those messages.
We may also disclose personal data where reasonably necessary to comply with law, respond to a valid legal process, protect the rights, safety, or security of Evercut or others, or deal with a merger, sale, financing, or transfer of all or part of our business. If we do, we will do so only as permitted by applicable law.
We may use or share aggregated information that does not identify you.
Data retention
We keep personal data only for as long as reasonably needed for the purpose for which it was collected, unless a longer period is required or permitted by law. We do not keep personal data indefinitely, and we periodically review what we hold and delete or anonymise data we no longer need.
Account data, synchronised presets, and product-insight totals: kept while your account is active, then deleted or anonymised within a reasonable period after the account is closed or deletion is requested.
Local authentication session: kept until you sign out, it expires, you remove it, or you delete the app or account.
Contact messages: kept only for as long as needed to handle your enquiry and for a reasonable period afterward in case you follow up, unless we need to keep them longer for a legal claim or obligation.
Privacy requests: kept for a reasonable period after completion, so we can demonstrate that we handled the request correctly.
Framer technical logs and analytics: kept under Framer’s standard service configuration for operating, securing, and analysing use of the website.
Cloudflare technical and security logs: kept under Cloudflare’s standard service configuration for routing and securing traffic and delivering app updates.
Supabase API and authentication logs: kept under our Supabase project’s standard configuration, including any configured log-drain destination.
Resend delivery logs: kept under Resend’s standard service configuration for sending and troubleshooting sign-in emails.
Encrypted Supabase backups may retain account data for a limited rotation period after deletion before being overwritten, consistent with our backup provider’s standard configuration. Your local project files and downloaded transcription model remain on your device and are controlled by you.
Your privacy rights
If the GDPR or UK GDPR applies, you may have the right to:
ask for access to your personal data;
ask us to correct inaccurate or incomplete data;
ask us to delete personal data in certain circumstances;
ask us to restrict processing in certain circumstances;
receive a portable copy of data you provided where the right applies;
object to processing based on legitimate interests; and
withdraw consent where we rely on it. Withdrawal does not affect processing that took place before withdrawal.
We do not make decisions about you solely by automated means that produce legal or similarly significant effects.
To exercise a right, email privacy@evercut.app with the subject line Privacy request and tell us the right you wish to use. We may ask for information reasonably needed to verify your identity and authority before acting on a request. We normally respond within one month under the GDPR and UK GDPR, or explain any lawful extension or limitation.
Evercut does not currently offer self-service account deletion. To request deletion, email privacy@evercut.app from your account email address with the subject line Delete my Evercut account. After verification, we revoke active sessions and delete the account and associated Evercut account data, subject to the retention and backup limits described above and any legal exception.
You may complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or to the authority where you live or work, or where you believe an infringement occurred. UK users may complain to the Information Commissioner’s Office.
Cookies & analytics
Our website uses Framer’s built-in, cookie-free analytics and any essential technologies needed to deliver and secure the website. It does not use Google Analytics, advertising pixels, social-media pixels, or behavioural-advertising cookies.
Our Cookie Policy at cookies policy page provides more detail. Before we add a non-essential cookie, embedded service, or third-party script, we will review whether consent is required and update the Cookie Policy before it runs.
Recording responsibly
The app asks macOS for Screen Recording, Microphone, Camera, or Accessibility permission only when a relevant feature needs it. You can decline, revoke, or change permissions in macOS settings; the corresponding feature may stop working.
You are responsible for obtaining any notice, permission, or consent required from people whose voices, images, communications, personal data, or confidential information are captured in your content.
Children’s privacy
Evercut is not intended for anyone under 16. Please do not use the Services or send us personal data if you are under 16. If you believe a child has provided us personal data, contact us at privacy@evercut.app
U.S. privacy rights
This section applies only where a U.S. state privacy law applies to Evercut and you. Under the current product design, the categories of personal information we may collect are:
identifiers, such as name, email address, account or provider identifiers, and IP address;
internet or electronic network activity, such as website technical information, Framer Analytics information, app connection data, and account-linked product-insight totals; and
contact-message content.
We collect this information from you, your device or browser, your selected sign-in provider, and our providers. We disclose it to the providers described in section 6 only as needed to run the Services.
We do not sell personal information or share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information to infer characteristics about you.
Depending on applicable law, you may have rights to know or access, correct, delete, obtain a portable copy of, or opt out of certain processing of personal information. You may make a request using the contact details in section 9. An authorised agent may make a request where allowed by law; we will verify the agent’s authority and may ask you to verify your identity directly. We will not discriminate against you for exercising an applicable right.
Where an applicable state law gives you a right to appeal our decision, email privacy@evercut.app with the subject line Privacy appeal. We will explain the outcome and any available external appeal route.
Keeping data secure
We use reasonable technical and organisational measures designed to protect personal data, including access controls and encrypted local storage for app authentication sessions where supported by macOS. No system or transmission is completely secure; please protect your devices, account access, and exported files.