Privacy Policy — CUTFORGE
Last updated: 2026-06-02
Version: 1.0
Notice: This document is a template for review. It is not legal advice. Have it reviewed by a qualified lawyer, especially if you target the EU/EEA, UK, or Switzerland (GDPR / FADP).
1. Introduction
This Privacy Policy explains how CUTFORGE (“we”, “us”) collects, uses, and protects personal data when you:
- visit https://cutforge.app (the “Site”);
- download or use the CUTFORGE desktop application (the “Software”); or
- purchase or manage a PRO subscription or license.
Data controller:
CUTFORGE
Switzerland
Contact (privacy): info@cutforge.app
We aim to comply with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) where it applies, and comparable laws in other regions.
2. Summary (plain language)
| Topic | What we do |
|---|---|
| Your videos & projects | Stay on your device by default; we do not upload them to our servers for editing |
| Payment | Handled by Paddle (Merchant of Record); we receive order metadata, not your full card number |
| PRO license | We process email, plan, expiry, and machine ID to issue and validate licenses |
| Site | Minimal technical logs (hosting); optional analytics only if you enable them later |
| Marketing | We do not sell your personal data |
3. Personal data we collect
3.1 Data you provide
- Email address — when you purchase PRO, contact support, or request a license
- Machine ID — a technical identifier generated on your computer to bind a PRO license to one device
- Support messages — content you send us voluntarily
- Language preference — if you choose a language on the Site
We do not require an account to use the FREE tier.
3.2 Data collected automatically
On the Site (cutforge.app):
- Server logs from our host (e.g. IP address, browser type, pages requested, timestamp) — typical for security and operations
- Cookies / local storage — see Section 8
In the Software:
- Machine ID (stored locally and used for licensing)
- Optional log files on your device if you enable diagnostic logging (if offered)
- Update checks (if implemented) — may send Software version and OS type to check for updates
We do not routinely collect the contents of your timeline, media files, or exports on our servers.
3.3 Payment data (Paddle)
When you pay for PRO, Paddle processes payment. They may collect:
- name, email, billing address, tax ID (if applicable)
- payment method details (handled by their payment providers)
- order history and subscription status
We receive limited order information (e.g. email, product, amount, subscription status, custom fields such as machine ID) to fulfill licenses and support.
Paddle’s privacy practices are described in their policy:
https://www.paddle.com/legal/privacy
4. Purposes and legal bases (GDPR)
Where GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Provide FREE Software | Legitimate interests / contract preparation |
| Sell and validate PRO licenses | Contract performance |
| Process payments via Paddle | Contract / legal obligation (tax, accounting) |
| Support and respond to inquiries | Legitimate interests / contract |
| Security, fraud prevention, abuse | Legitimate interests |
| Comply with law | Legal obligation |
| Improve Site and Software | Legitimate interests (minimal data) |
| Marketing emails (if any, opt-in) | Consent |
You may object to processing based on legitimate interests as described in Section 9.
5. How we use personal data
We use personal data to:
- deliver and validate PRO licenses;
- manage subscriptions and renewal status (via Paddle webhooks or exports);
- provide customer support;
- send transactional emails (receipts are typically from Paddle; license delivery may be from us);
- maintain security of the Site and licensing systems;
- comply with legal and tax obligations;
- improve documentation and fix bugs (aggregated or anonymized where possible).
We do not use your video content for advertising or AI training.
6. Sharing and recipients
We may share personal data with:
| Recipient | Role |
|---|---|
| Paddle | Payment processing, Merchant of Record, subscriptions |
| Hosting provider (e.g. Vercel) | Site hosting and serverless functions (checkout redirect API) |
| Email provider (if used) | Sending license files or support replies |
| Professional advisers | Legal, accounting — under confidentiality |
| Authorities | When required by law |
We require processors to protect data under appropriate agreements where required by law.
We do not sell personal data.
7. International transfers
If you are in the EU/EEA, UK, or Switzerland, your data may be processed in countries outside your region (e.g. United States) by our hosting or payment partners.
Where required, we rely on appropriate safeguards such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission; and/or
- adequacy decisions, where applicable.
You may request details about safeguards by contacting us.
8. Cookies and similar technologies
8.1 Site
We aim to keep cookies minimal. The Site may use:
- Strictly necessary storage — e.g. language preference (`lang`)
- Hosting / security cookies from our CDN or host
If we add analytics (e.g. privacy-friendly statistics), we will update this policy and, where required, ask for consent.
8.2 Software
The desktop application does not use advertising cookies. Local settings are stored on your device.
8.3 Managing cookies
You can control cookies through your browser settings. Blocking necessary cookies may affect Site functionality.
9. Retention
We keep personal data only as long as needed for the purposes above:
| Data | Typical retention |
|---|---|
| License and purchase records | Duration of license + legal/tax retention (often 5–10 years, depending on country) |
| Support emails | Up to 24 months after resolution, unless needed for disputes |
| Server logs | 30–90 days (host-dependent) |
| Marketing consent | Until you withdraw consent |
We delete or anonymize data when it is no longer required, subject to legal holds.
10. Your rights
Depending on your location, you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”) in certain cases
- Restrict processing
- Object to processing based on legitimate interests
- Data portability (structured, machine-readable format) where applicable
- Withdraw consent at any time (for consent-based processing)
- Lodge a complaint with a supervisory authority
EU/EEA: Find your authority at https://edpb.europa.eu/about-edpb/about-edpb/members_en
Switzerland: FDPIC — https://www.edoeb.admin.ch
UK: ICO — https://ico.org.uk
To exercise rights, email info@cutforge.app. We may need to verify your identity. We respond within one month (GDPR), possibly extended for complex requests.
11. Children
The Software and Site are not directed at children under 16 (or the applicable age in your country). We do not knowingly collect children’s data. Contact us if you believe we have done so; we will delete it promptly.
12. Security
We use reasonable technical and organizational measures, including:
- HTTPS for the Site
- signed license files (cryptographic verification in the Software)
- restricted access to signing keys and production secrets
No method of transmission or storage is 100% secure. You are responsible for securing your device and license files.
13. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects solely by automated means. License validation is a technical check (signature + machine ID + expiry), not profiling.
14. Changes to this policy
We may update this Privacy Policy. We will post the new version on the Site with an updated date. Material changes will be communicated by reasonable means where required by law.
15. Contact
Privacy inquiries: info@cutforge.app
Postal address:
CUTFORGE
Switzerland
_If you are a California resident, additional disclosures under CCPA/CPRA may apply once we meet applicable thresholds; contact us for a supplemental notice if needed._