Skip to main content

Legal

Privacy Policy

Videorc is built local-first: your recordings live on your computer, accounts deliver signed app downloads and online features, and we don't run advertising or cross-site tracking.

Last updated: October 4, 2026

The short version

  • Recordings, scenes, notes, settings, and Orcle's stream reports stay on your computer. Nothing is uploaded unless you explicitly use a cloud feature.
  • A Videorc account is required to obtain signed desktop downloads and is also used for sign-in and Premium features. Windows Alpha testing itself is free.
  • Payments are handled by Creem, our merchant of record. We never see or store card numbers.
  • AI features only process content you explicitly submit, after you consent to the upload.
  • Signing in uses one cookie — the session cookie that keeps you signed in. Creating an account with email and password also sets security cookies from Vercel BotID that tell people apart from bots. No ad or tracking cookies, which is why there is no cookie banner.

Who we are

Videorc is operated by OrcDev ("we", "us"). For anything privacy-related, contact us at orc@videorc.com. This policy covers the Videorc website (videorc.com), the account service, and the online features of the Videorc desktop app.

What we collect and why

Account data. When you create an account: your name, email address, and a hashed password — or your Google account identifier if you sign in with Google. Used to sign you in, send you login links and password resets, and attach your Premium subscription to you.

Billing data. Payments are processed by Creem as merchant of record. Creem handles your payment details under its own privacy policy; we store only your subscription state — plan, billing interval, status, and renewal date — so the product knows what you paid for.

AI content (opt-in). Premium AI features, such as Orcle Live, Clean cut, and live captions (early alpha), only process chat, audio, or text that you explicitly choose to submit. We ask for consent before anything is uploaded. We also keep usage counts (number of AI runs, processing volume) to enforce fair monthly quotas. Older versions of the app also offer AI publishing tools (transcripts, titles, summaries, chapters), which process a recording's audio when you run them. Orcle Live, the optional AI producer for your streams (Premium, off by default), sends public live-chat messages from your own broadcast (author name, message text, platform) to the AI provider in short batches while you stream, only while you have enabled it and given consent; replies are never posted without your explicit approval, and chat batches are not retained after the response is produced. Listening comes on with Orcle Live, and you can turn it off. While it is on (or while live captions are on), Orcle also receives what you say on your microphone while you are live, as text (never audio), in short windows: the speech-to-text provider turns each short stretch of microphone audio into text, and only that text reaches Orcle, together with a few recent chat messages, so it can tell what you are talking about, keep a short summary of the stream and remind you of what you promised your viewers. Videorc servers do not keep the audio or the transcript. If you record, the transcript is saved on your own computer with your recording.

Orcle voice commands and removing chat messages. You can ask Orcle out loud to put a chat message on your stream, take it down, or remove it from your live chat. The app understands these commands on your computer, from the same text Orcle already receives; nothing extra is uploaded for that. If Orcle hears its name but cannot work out a command on your computer, it may send that sentence, together with up to 20 recent chat messages (author name, message text, time), to Videorc's cloud AI to work out what you meant; like chat batches, they are not retained after the response is produced, and we keep only a usage count. A message is removed only when you ask, and the app shows it to you first. When you remove a message, by voice or from its menu, your computer asks the platform (YouTube, Twitch, Kick, or X) to delete it using your own connected account; the request does not go through Videorc servers. A record of each removal (the platform, the author's name, a short excerpt of the message, the reason you gave, and the result) is kept on your computer and is not sent to Videorc.

Orcle stream reports. After each stream, Orcle saves a short report on your computer: counts of what happened (questions, flags, promises, greetings, alerts, voice commands), the questions it caught with the names of the viewers who asked them, and any promises still open. The report is not sent to Videorc, and it is deleted when you delete that session in Videorc.

Clean cut (opt-in).Clean cut (Premium) edits a copy of a recording for you, and runs only when you start it or turn on automatic clean cuts. It works in two steps, after you consent. First, the app uploads the recording's audio, never the video, in short chunks, and a speech-to-text provider turns each chunk into a word-by-word transcript with timings that goes back to your computer. Videorc servers keep neither that audio nor the timed transcript; we only count the minutes used, for your monthly allowance. Second, to find retakes and false starts, the app sends the transcript's sentences (text only) to Videorc's cloud AI as an AI job. Those sentences are deleted from Videorc servers as soon as the job finishes; only the result (which sentence ranges to cut) is kept with your account (see "Retention and deletion" below). The cutting happens on your computer, and your original recording is never changed.

X live chat relay. X delivers the live chat of a broadcast only to a server, not to a desktop app. If you go live on X from Videorc while signed in, X sends the public chat messages of your own broadcast to our servers and the app collects them from there to show in your Chat window. For each message we briefly hold the text, the message and broadcast identifiers, whether the author subscribes to you, and the author's public X profile details (id, handle, display name, avatar link, verification type). X also tells us when someone follows you, so the app can name them; for each follow we briefly hold the follower's public X profile details (id, handle, display name, avatar link). We use this only to deliver your chat and follows to your app: we do not analyze it, share it, or use it for anything else, and each message or follow is deleted within 24 hours. To route chat to the right account we also store your X user id and handle next to your Videorc account until you disconnect X or delete your account. Your X access tokens are never sent to us.

Kick live chat relay. Kick delivers the live chat of a channel only to a server, not to a desktop app. If you connect Kick in Videorc while signed in, Kick sends the public chat messages, follows, subscriptions, gifted subscriptions, KICKs gifts, bans and live status of your own channel to our servers and the app collects them from there to show in your Chat window and Stream Manager. For each event we briefly hold only what is needed to show it: the message text and identifiers, emote positions, the message it replies to, the public Kick profile details (id, username, avatar link, name colour, badges) of the people involved, gifted subscription recipients, subscription length, the KICKs amount, gift and message, and a ban's reason and expiry. Anonymous gifters stay anonymous. We use this only to deliver your chat to your app: we do not analyze it, share it, or use it for anything else, and each event is deleted within 24 hours. To route chat to the right account we also store your Kick user id and username next to your Videorc account until you disconnect Kick or delete your account. Your Kick access token is used once to confirm your account and is never stored.

Emails. We send transactional email only: login links, password resets, and subscription confirmations, delivered via Resend.

Technical data. Our hosting provider (Vercel) collects aggregate, privacy-friendly analytics and standard server logs. This does not use cookies and does not track you across sites.

What stays on your computer

The Videorc recorder is local-first. Your recordings, scene layouts, local library, session notes, Orcle stream reports, and app settings are stored on your computer. Stream keys and connected-platform credentials are stored in your per-user app data, protected by your operating-system account permissions. None of this is transmitted to us unless you explicitly submit specific content to a cloud AI feature.

7TV emotes.While “Show 7TV emotes in chat” is on (Settings, General; on by default), the app asks 7TV (7tv.app) for the public emote set linked to the Twitch, Kick or YouTube channel you connected, and downloads emote images from 7TV's servers. This goes straight from your computer to 7TV, never through us. 7TV receives your IP address and those public channel ids, and nothing else. Turning the setting off stops it.

YouTube API Services

Videorc uses YouTube API Services when you choose to connect a YouTube account. By using that connection, you are also subject to the YouTube Terms of Service and the Google Privacy Policy.

With your permission, Videorc accesses your YouTube channel identity (channel ID, name, handle, and avatar), live-broadcast and live-stream identifiers and status, and live-chat messages needed to prepare, manage, and display your broadcast and chat inside the app, and to remove a message from your live chat when you ask and confirm. OAuth tokens and connected-channel metadata are stored locally on your computer, protected by the safeguards described in "How we protect your data" below. Videorc does not sell this data. OAuth tokens and connected-channel credentials stay on your device. If you enable Orcle and consent to cloud processing, limited public messages from your own YouTube live chat are processed by Videorc's cloud service and its AI provider to provide the assistance you requested, as described under "AI content (opt-in)" above.

Videorc's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Purpose limitation. Google and YouTube user data obtained through YouTube API Services (including the sensitive scope youtube.force-ssl) is used only to provide and improve Videorc's user-facing YouTube features: connecting your channel, preparing and managing live broadcasts, displaying your live chat inside the app, and removing a chat message when you ask. We do not use this data for advertising, personalized or interest-based ads, creditworthiness or lending decisions, selling to data brokers or information resellers, or training generalized AI/ML models.

Sharing and transfer. We do not sell Google or YouTube user data. We do not share, transfer, or disclose that data to third parties for purposes other than providing the YouTube features you request. API calls to Google and YouTube are made from your device over encrypted connections; OAuth tokens and connected-channel metadata are not sent to Videorc servers.

Protection of sensitive Google and YouTube data. Security procedures are in place to protect the confidentiality of Google user data obtained through YouTube API Services. We use encryption to protect this information in transit (TLS / HTTPS). Sensitive OAuth tokens and connected-channel metadata remain on your computer under operating-system account protections, as detailed in "How we protect your data" below.

You can remove access at any time with Disconnect in Videorc. This asks Google to revoke the authorization and deletes the locally stored tokens and connected-channel data. You can also revoke Videorc from Google's third-party access settings. YouTube API data is refreshed when needed to provide the connected feature; it is not retained after you disconnect. If revocation is detected, Videorc stops using the authorization and prompts you to reconnect.

How we protect your data

We take the security and protection of sensitive data seriously — including personal account data and Google user data obtained through YouTube API Services. Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information, restrict who can access production systems, and keep connected-platform OAuth tokens on your device rather than on our servers.

Encryption in transit. All communication between your browser or the Videorc app and our services — and between Videorc and third-party APIs, including Google and YouTube API Services — is encrypted with TLS (HTTPS). We never transmit your data over unencrypted connections.

Encryption at rest. Account and subscription data lives in our managed database (Neon), which encrypts all data at rest. Passwords are never stored in readable form — only as salted cryptographic hashes — and sign-in sessions use secure, HTTP-only cookies.

Sensitive tokens stay on your device. OAuth tokens and credentials for connected platforms — including Google user data obtained through YouTube API Services — are stored only in your per-user app data on your own computer, protected by your operating-system account permissions. They are never transmitted to or stored on our servers, which means a breach of our infrastructure cannot expose your connected-platform tokens.

Access control. Production infrastructure access is restricted to the operator, protected by strong authentication. Application secrets are kept in managed environment configuration, never in source code, and service integrations run with the minimum scopes they need.

Incident response. If we become aware of a security breach affecting your personal data, we will notify affected users and the relevant authorities as required by applicable law, and publish what happened and what we did about it.

Service providers

We use a small set of processors to run the service: Vercel (hosting, analytics, and bot protection on sign-up through Vercel BotID), Neon (database), Creem (payments, as merchant of record), Resend (transactional email), and, only for content you submit to AI features, AI model providers reached through Vercel's AI Gateway, plus OpenAI and Deepgram for transcription. We do not sell your data, and we do not use your content to train our own models.

Retention and deletion

Account and subscription data is kept while your account exists. Billing and webhook records are retained as needed for accounting and dispute handling. AI job inputs and outputs are kept so the app can collect and show your results, and are removed when you delete your account. Clean cut is stricter: the transcript sentences it sends are deleted as soon as its job finishes, and only the cut result is kept. Clean cut audio, and the timed word-by-word transcripts made from it, are not stored on Videorc servers; only the minutes used are counted. Orcle stream reports exist only on your computer. X and Kick live chat messages relayed to your app are deleted within 24 hours. Google and YouTube API data stored on your computer (OAuth tokens and connected-channel metadata) is deleted when you disconnect YouTube in Videorc or revoke access in Google's settings; it is not retained on Videorc servers. To delete your account and its data, email us at orc@videorc.com.

Your rights

Depending on where you live (including under the GDPR), you can ask for access to, correction of, deletion of, or a copy of your personal data, and you can object to or restrict certain processing. Email us and we will handle it — no forms, no runaround.

Changes

If this policy changes in a way that matters, we will update this page and adjust the date above. Significant changes will be called out on the website or by email. See also our Terms of Service.