Privacy Policy
Last updated: September 4, 2026
The short version
Bling edits on your computer, not on our servers. Your video files, your transcripts and your edit decisions stay on your machine. We never receive them, so we cannot read them, store them, sell them or train on them.
One step can leave your machine, and only if you let it. With cloud transcription on, Bling sends the audio track of the file you are editing to Deepgram, our speech-to-text provider, and Deepgram returns the words. Deepgram processes that audio for the one request and does not keep it or train on it. We never see it either. Turn cloud transcription off in Settings and Bling transcribes on your own machine instead. See §2.
What we do hold is the small amount of account and billing information it takes to sign you in and to know which plan you are on. The rest of this page says exactly what that is, who else touches it, and how to get rid of it.
1. Who we are
Bling ("Bling", "we", "us") makes a macOS desktop application that transcribes your footage and removes silences, filler words and bad takes, plus the website at blingai.org. This policy covers both.
For any privacy question, or to exercise any right described below, email liuwilliam12@gmail.com. We are the data controller for the information described here.
2. What stays on your computer
This is the part that matters most, so it comes first. The following never leaves your computer and is never transmitted to Bling:
- Your video files. You point Bling at a file on your disk. It is read from there and stays there. There is no upload path for video in the app at all.
- Your transcripts. The transcript is written to a project file on your disk. Nobody, including us, receives a copy.
- Your edits. Cuts, keeps, deletions, chapter marks, b-roll placements and every other timeline decision are stored in local project files.
- Your exports. MP4, MP3, SRT, VTT, CapCut kits, Premiere XML and Resolve EDL files are written straight to a folder you choose.
We have no upload endpoint for media and no copy of your footage to lose, hand over or breach. If you delete a project from your computer, it is gone, and there is nothing for us to delete on our side.
2.1 The one exception: cloud transcription
Turning speech into words is the one step Bling can send off your machine, and it is a setting you control. Cloud transcription is on by default for signed-in accounts and is never used when you are signed out.
- What is sent. Bling extracts the audio track of the file you are transcribing into a compact 16 kHz mono copy and sends that, and only that, to Deepgram. The video is not sent. The filename is not sent. Your email, your user ID and your project are not sent.
- Who receives it. Deepgram, a US speech-to-text provider (SOC 2 Type II, GDPR, HIPAA-capable). See §5.
- What they do with it. They transcribe it and return words with timings. Every request Bling makes is marked as opted out of Deepgram's model improvement programme, which means the audio is used for that one request and is not retained and not used to train models. Deepgram does not store transcripts.
- What we keep. We record the number of minutes your account sent, so plan limits can be enforced and so we can pay the bill. We do not receive the audio, the transcript or any text from it.
- How to switch it off. Settings, then turn off Cloud transcription. Bling then transcribes on your own machine using the models that shipped with the app, and no audio and no video is uploaded. Your account, plan and billing still talk to our server, as described in §3.
Two smaller clarifications, so this promise is not broader than the truth. First, the app downloads its AI model weights from Hugging Face the first time it needs them; that is a download to you, and none of your content is sent in the request. Second, if you use the optional stock footage picker, the words you type into its search box go to Pexels using an API key you supply. Both are covered in §5.
3. What we collect
3.1 Account information
When you create an account we store your email address and an internal user ID. If you sign in with Google, we receive the basic profile Google returns for that sign-in (your email address, and your name if your Google account publishes one). If you sign in with a password, authentication is handled by our authentication provider, which stores a salted hash; we never see or store your password in readable form.
3.2 Billing information
If you buy Pro or Lifetime, checkout happens on Stripe. We never receive your card number, CVC or full billing address. Stripe collects those directly and we cannot see them.
What we do store, so the app knows what you are entitled to, is:
- your plan (free, pro or lifetime) and its status;
- your Stripe customer ID and, for Pro, your Stripe subscription ID;
- which price you bought, when the current period ends, and whether you have asked to cancel;
- the charge ID of a Lifetime purchase, so a refund or dispute can be matched to it;
- a log of the billing events Stripe has sent us, which is what support reads when something goes wrong with a payment.
3.3 Website measurement and advertising
Every page on this website loads the Google Ads tag, so we can tell which advertisements lead to a download or a purchase. It sets cookies and reports to Google that a visit, a download or a purchase happened. For a purchase it also reports the plan bought, its list price and currency, and the Stripe checkout reference, never your name, email address or card details. The tag is not present in the Mac app at all.
3.4 Service logs
Our backend keeps ordinary server logs for the requests it serves (sign-in, checkout, entitlement checks). These contain an IP address, a timestamp, the request path and an outcome. We use them for security, abuse prevention and debugging.
3.5 Transcription usage
When you transcribe with cloud transcription on, we record the length in minutes of the audio, the date, and your user ID, so that plan limits can be enforced and the provider bill can be reconciled. We do not record the filename, the audio, the transcript, or any word of what was said.
3.6 What we do not collect
The desktop app contains no analytics SDK, no telemetry, no crash reporter and no session recorder. We do not track what you edit, which features you use, or which files you open. Beyond the minute count in §3.5 we hold nothing about your transcriptions. We do not build advertising profiles from your content, and we do not sell personal information.
4. Why we use it
| What | Why | Legal basis (UK/EU) |
|---|---|---|
| Email and user ID | Create and secure your account, sign you in, send account and transactional email | Performance of a contract |
| Billing state | Take payment, unlock the plan you bought, handle cancellations, refunds and disputes, meet tax and accounting duties | Contract, and legal obligation |
| Service logs | Keep the service up, investigate faults, prevent abuse and fraud | Legitimate interests |
| Transcription minutes | Enforce the free plan's monthly cloud transcription limit and reconcile what our provider bills us | Performance of a contract |
| Advertising cookies | Measure which ads bring people to Bling | Consent, where required |
5. Who we share it with
We do not sell your personal information and we do not share it for cross-context behavioural advertising. We use the following service providers, and nothing beyond what each one needs:
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Authentication and database hosting | Email address, user ID, billing state, service logs |
| Stripe | Payments and subscription management | Payment details you enter on Stripe, your email, purchase history |
| Vercel | Hosts blingai.org | Standard web request logs |
| Cloudflare R2 | Serves the Mac app download | Standard download request logs |
| Google Sign-In, and ad measurement on the marketing pages | Sign-in profile if you use it; ad interaction data | |
| Discord | Notifies our team that a new account was created | The new account's email address and sign-in method |
| Hugging Face | Hosts the AI model weights the app downloads on first run | The download request only. No user content. |
| Deepgram | Cloud speech-to-text, when cloud transcription is on | The audio track of the file being transcribed, for that request only. Opted out of model training. No video, no filename, no account identifier. |
| Pexels | Optional stock footage search, only if you enable it with your own API key | Your search terms. No user content. |
We may also disclose information if the law requires it, to enforce our Terms of Service, or to protect the rights and safety of our users. If Bling is ever acquired or merged, account and billing information may transfer as part of that transaction, and this policy will continue to apply to it until you are told otherwise.
6. Cookies and advertising
This website uses cookies set by the Google Ads tag described in §3.3, for conversion measurement. The app uses local storage on your own machine to keep you signed in and to remember your preferences; that is not shared with anyone.
You can block or clear cookies in your browser at any time. Doing so does not affect the Mac app or your ability to use Bling. You can also opt out of Google's personalised advertising at adssettings.google.com.
7. How long we keep it
- Account information: until you delete your account.
- Billing records: retained after account deletion, in a reduced form, for as long as tax, accounting and dispute rules require (generally up to seven years). This is what lets us explain or process a refund for someone whose account is already gone.
- Service logs: a short rolling window, typically not more than 90 days.
- Transcription minute counts: kept for the current and previous billing period so a limit can be enforced and a bill checked, then aggregated away. The audio itself is never in our hands to keep.
8. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct it if it is wrong;
- delete it (see §9);
- receive a copy in a portable format;
- object to or restrict certain processing;
- withdraw consent you previously gave, without affecting what was done beforehand;
- not be discriminated against for exercising any of these rights.
To exercise any of them, email liuwilliam12@gmail.com from the address on your account. We will respond within 30 days. If you are in the UK or EEA and you are unhappy with our answer, you may complain to your local data protection authority.
California residents: we do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. The categories we collect, the purposes, and the recipients are the ones listed in §3, §4 and §5.
9. Deleting your account
You can delete your account from inside the app, under Account settings. It takes effect immediately: your sign-in record and profile are removed and you can no longer sign in. As noted in §7, a reduced billing record is kept for the legally required period, holding your plan history and Stripe identifiers so that refunds and disputes remain traceable.
Deleting your account does not touch your projects, footage or exports, because those are on your computer and always were. Remove them the way you remove any other file. Deleting the account also ends cloud transcription for it; there is no audio held anywhere to delete, because none was retained.
If you have an active Pro subscription, cancel it before deleting your account, or email us and we will make sure it is cancelled.
10. Security
Traffic to our services is encrypted in transit with TLS. Passwords are stored only as salted hashes. Access to production data is limited to those who need it. Payment details are handled entirely by Stripe, a PCI Service Provider Level 1, and never touch our systems.
The strongest security property Bling has is structural rather than procedural: your video is not on a server we operate, so there is no repository of customer video to breach. The audio sent for cloud transcription is held by Deepgram only for the length of the request and is transmitted over TLS with a short-lived token that is minted per job and expires within the hour. No system is perfectly secure, but the standing pile of customer footage that is normally the risk simply does not exist here.
11. International transfers
Our providers are based in the United States and may process the information in §3 there and in other countries. Where we transfer personal information out of the UK or EEA, we rely on the European Commission's Standard Contractual Clauses or another approved safeguard.
12. Children
Bling is not directed at children. You must be at least 13 years old to use it, and at least 16 if you are in the EEA or UK. We do not knowingly collect information from children below those ages. If you believe a child has given us information, email us and we will delete it.
13. Changes to this policy
If we change this policy we will update the date at the top of the page. If a change materially affects how we handle your information, we will tell you by email or in the app before it takes effect. Continuing to use Bling after that means you accept the updated policy.
14. Contact
Questions, requests or complaints: liuwilliam12@gmail.com. A real person reads it, and we aim to answer within a few days.
See also the Terms of Service.