Version 1 · English · Effective 2026-10-05T07:55:34Z

SubLunio Privacy Policy

This Privacy Policy explains how Gatsbi AI Limited handles personal information when you browse SubLunio at sublunio.com, generate or translate subtitles, use your SubLunio account, make a payment or contact support. It covers the website, official desktop application and subtitle-processing service. It should be read alongside our Terms of Service; it is a notice about data handling, not a request to waive your rights.

Data user, controller and contact

Gatsbi AI Limited, a Hong Kong company operating SubLunio at sublunio.com, is the data user responsible for personal information under Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486), and the controller where applicable data-protection law uses that term. References to we, us and our mean Gatsbi AI Limited. This policy covers personal information processed for SubLunio accounts, subtitle tasks, billing and support on the website and the official desktop application. A hosting or model provider may also have its own responsibilities for the information it receives.

Our company contact address is RM 2502B Floor 25, 148 ELECTRIC ROAD, NORTH POINT, HK. Send privacy requests and service enquiries to our contact email, listed in the Contact section at the end of this policy. You do not need a paid account to make a privacy request.

Information you provide

Account information includes your email, chosen interface language, sign-in method, creation date, preferences and notification choices. If you choose password sign-in, we store a salted password hash to verify your password, not the password in plain text. Google sign-in provides a verified identity identifier and email; the application does not request your Google password, contacts, Drive files or mailbox. Email codes expire after ten minutes.

Task information includes the task name, source and target languages, selected audio stream, glossary, duration, limited file metadata, subtitle text and timestamps. Server-side source metadata does not contain a local path. A filename used as a task name can itself identify a person, so avoid unnecessary personal information in it. Contact messages include the email and information you choose to send.

Providing information is voluntary, but some information is necessary for the feature you request. An email address is required for an account; without it, you cannot use account-based features, although an eligible guest preview remains available. Processing a recording requires its extracted audio and the task settings needed to produce subtitles; without them, we cannot process that recording. A password is required only if you choose password sign-in. Stripe requires payment information to complete a purchase. Glossary entries and consent to optional analytics are optional; omitting them does not prevent core subtitle generation. To answer a support or privacy request, we need enough information to locate the issue and, where necessary, verify your authority; without it, we may be unable to fulfil that request.

Local video and audio processing

The browser reads a selected file in portions, extracts the chosen audio stream and creates MP3 on the device. Only the prepared audio is uploaded. The original video and its picture frames are not sent by this workflow. A server receives the full prepared audio even for the trial so it can measure duration and locate speech; before continuation, recognition and translation process the excerpts needed to produce the preview.

The local player uses the original file or a cached MP3 and the task’s subtitle text. Browser site-private storage may cache prepared audio with a reuse period of up to 7 days; actual removal depends on cache cleanup as explained below. File fingerprints and optional Chromium file handles help reconnect a task to a local video; these handles remain on the device and require the browser’s permission when reopened. Your desktop queue stores local paths and settings on your computer, while the API receives a task name and permitted metadata only. Desktop video preview, subtitle styling and video export run locally. Source videos, preview frames and exported videos are not uploaded by these operations. Local records can include source and output paths, subtitle copies, export settings and temporary preview or conversion files; downloaded and exported files remain under your control.

Security, device and payment records

We process session identifiers, request identifiers, limited IP information, device name, platform, client version, token-family status and activity timestamps to authenticate requests, prevent abuse and support recovery. Access and refresh tokens are stored as hashes on the server. The desktop saves refresh credentials in the operating-system credential store when available. If that store is unavailable, credentials are held in memory for the current session and you may need to sign in again after restarting. Credentials are not exposed to the web interface or stored in the local queue database.

Stripe receives payment details through its checkout page. Our records include the USD amount, balance movements, payment and customer identifiers, payment status, limited method details such as brand and last four digits, invoice references, refunds and disputes. We do not receive or store full card numbers or card security codes. A payment record is not made public in a sitemap or an indexable page.

Why information is used and the relevant grounds

We use task data to carry out the transcription and translation you request, provide previews and downloads, recover interrupted work, and associate eligible guest tasks with your account. Under Hong Kong's Personal Data (Privacy) Ordinance, personal information is collected for lawful purposes directly related to our activities and used for the stated purposes or directly related purposes; a new purpose requires the prescribed consent unless an applicable exemption permits it. Where applicable law requires a specific legal basis, we rely on performance of a contract or steps you request before entering it for processing necessary to provide the service. Optional email sign-in is needed only if you choose account-based access.

We use proportionate security and operational information to protect accounts, prevent abuse, control service capacity, investigate faults and resolve payment disputes. Where applicable law permits reliance on legitimate interests, we rely on our interests in protecting and operating the service, taking account of the impact on individuals and the need to minimise data. Compliance with a specific legal duty, such as an applicable accounting obligation or valid legal order, may require processing on the basis of that obligation. Where consent is required for an additional purpose, it must be obtained separately; this notice is not blanket consent for unrelated uses.

Our subtitle service is not designed to identify speakers biometrically, determine sexual preferences or build advertising profiles. Audio or text may nevertheless disclose sensitive information about identifiable people. Applicable law may impose additional conditions on processing sensitive information. A request to provide the service does not, by itself, establish every permission or condition required for that processing. Do not submit such material unless the processing is lawful, including any additional condition that applies; write to our contact email before using the service for private or sensitive recordings.

Browser storage and optional technologies

Necessary storage supports sign-in, request security, selected language, theme, task recovery and the local media operation you request. See the cookie inventory for individual names and lifetimes. Clearing it may sign you out or require you to reselect a local video; it does not itself delete your server account.

To protect the free preview service against repeated automated submissions, we use a first-party cookie named sl_preview_browser containing a random, signed identifier. It is separate from sign-in and remains after sign-out, with a maximum browser lifetime of 400 days renewed when your session is read. We use it only for the cumulative free-preview allowance, not for advertising, analytics or tracking activity on other websites. We do not use IP addresses, network prefixes, user-agent strings or video fingerprints to infer that separate browsers belong to the same person for this allowance. If the browser identifier and session are both unavailable, we do not attempt to reconstruct them from device characteristics.

When you request a new free preview, we load Cloudflare Turnstile within a dialog to check automated abuse. Cloudflare receives browser network and device signals as described in its Turnstile Privacy Addendum. We do not send video, extracted audio, filenames or subtitles to Turnstile. This check is separate from optional analytics. Our configured widget does not request Cloudflare pre-clearance for the website.

For a short-lived sign-in prompt, we also count accepted guest previews from an exact public IP within a time window, normally ten minutes. We store a keyed, window-specific digest for this rule, not its raw IP. A busy shared connection can require a guest to verify their email and sign in; it does not merge accounts or prevent signed-in users from continuing within their own allowance. Private or unavailable addresses are skipped. These counters become eligible for maintenance deletion one day after expiry.

To accommodate long local audio extraction, a successful check issues a one-use verification receipt bound to the requesting account or guest session and browser. It normally lasts six hours. We store a keyed digest of the verification token, the binding, expiry and task use, not the original token. Receipts become eligible for maintenance deletion one day after expiry. Routine maintenance and the backup retention rules below apply. These proportionate security measures help prevent automated resource abuse and keep the requested service available.

The allowance record contains the submission time and random task, browser, session and, when known, account identifiers. It does not contain recordings, subtitles, filenames, email addresses or IP addresses. Signing in or using a valid recovery key can associate your guest submissions with your account. These minimal records remain while the cumulative allowance is operated, including after a task is cancelled, deleted or expires or a session ends; otherwise repeated deletion could reset the abuse protection. Account deletion does not itself reset a browser's allowance. This limited retention is separate from the shorter operational-log and audio-retention periods below. You may write to our contact email about an incorrect association or a data-protection request; we do not treat this mechanism as proof that multiple people are the same person.

Optional functional consent enables Google One Tap. A Google button is loaded when you explicitly request Google sign-in even if One Tap is off. When configured, Google Analytics 4 loads only after you separately accept analytics. It sends Google a simplified page address, referring site, browser/device information and selected product actions; Google receives the network request, including the visitor’s IP address, and processes usage data and pseudonymous browser/session identifiers. This is third-party analytics, not a claim of fully anonymous processing. Our event payloads exclude recordings, subtitle text, filenames, email addresses, account/task/payment IDs, URL queries and fragments. Advertising personalization, Google signals and User-ID are not enabled. Browser privacy signals (Global Privacy Control or Do Not Track) disable analytics. You can withdraw consent through Cookie settings; this stops further collection and clears this site’s analytics cookies, without affecting core subtitle functionality. Accept and reject controls have equal prominence. Consent choices and versions are retained for two years.

Service providers and recipients

Depending on the configured processing route, Groq receives necessary audio segments and language parameters for speech recognition, or OpenRouter receives audio segments and recognition instructions and routes them to Google's Gemini models. Groq may also receive segments requiring fallback transcription. OpenRouter receives subtitle text, neighbouring context, instructions and glossary terms for translation and routes them to the configured model provider. Alibaba Cloud provides the service's hosting and data-storage infrastructure in Singapore. Delivery, database and email suppliers also support the application. Stripe processes payments; Google processes identity requests when you choose that method. Support personnel receive contact requests and restricted operational records.

The default OpenRouter configuration requests no data collection and zero-data-retention routing. This is an application routing choice, not a blanket claim about every vendor’s systems or usage metadata. Groq organisation-level data controls must be configured separately by the operator. Provider data practices and transfer arrangements are distinct from deletion of audio on our server. We do not use user recordings to train our own models, publish private subtitle records or sell audio and subtitle text for advertising.

Limited information may be disclosed to professional advisers, competent authorities or a successor operator when a lawful reason applies. Any necessary disclosure should be proportionate. Naming a provider in this policy does not imply that a particular optional integration is enabled for every account.

International processing

Our service hosting and data-storage infrastructure is provided by Alibaba Cloud in Singapore, outside Hong Kong. Third-party providers, including Groq, OpenRouter and downstream model providers, Stripe, Google and email suppliers, may process information in other jurisdictions under their own arrangements. The location of Gatsbi AI Limited and our Singapore hosting does not mean that all processing occurs in Hong Kong or Singapore. Provider retention and operational metadata are also distinct from the lifetime of files on our own server.

We remain responsible for meeting applicable data-protection requirements when using providers outside Hong Kong. Where a transfer is restricted by applicable law, the required transfer mechanism, safeguards and assessment must be established before that transfer. Write to our contact email for details of current suppliers, processing locations and applicable safeguards. We do not represent that a particular agreement has been signed, or a particular transfer mechanism verified, merely by naming a provider in this policy.

Task and local-cache retention

Server audio normally expires 24 hours after task creation and is removed after the full result is completed, or earlier when it is no longer needed for processing or recovery. Starting full generation, including with existing account credit, or awaiting payment confirmation may extend this window so the task can continue; the task displays its actual deadline. Guest task records expire after 7 days. Signed-in subtitle history remains until you delete a task or account. We do not keep the original video.

Browser MP3 caches are eligible for reuse for up to 7 days and may be evicted sooner. Expired audio is no longer reused and is removed when the website next runs its cache cleanup. Files may remain on disk longer while the website is closed or cleanup cannot complete. You can clear them from account settings or browser site-data controls. Deleting a task from the current browser removes its registered audio cache. Other devices cannot be remotely guaranteed to erase local files; clear their site or application data as needed. The desktop application may also keep local playback caches, subtitle caches and recovery copies created when replacing a video during export. Deleting a server task or account does not itself erase those desktop files. Downloaded subtitles, exported videos and recovery copies remain on your device until you remove them; the browser's 7-day audio-cache period does not apply to these files.

Account deletion, finance, logs and backups

Self-service account deletion requires renewed verification, your account email and an explicit acknowledgement. It immediately invalidates sessions, device credentials and sign-in identities, cancels unfinished work, and schedules removal of account personal information, audio and subtitles within five minutes. A deletion notice is the final permitted account email. Pending refunds or payments under review must be resolved first; write to our contact email to request a refund of unused credit before confirming deletion.

Necessary financial records and supporting contract records are retained for at least seven years after completion of the relevant transaction, rather than from account closure. To preserve verifiable accounting history, linked records may be kept together until the retention period measured from the latest relevant transaction or supporting record ends. Records needed to substantiate active account balances or unresolved payments, refunds and disputes are retained as necessary; a longer period applies where required by law. We limit retained information to what is necessary for these purposes. Account deletion still clears account profile information, audio and subtitles on the schedule above, while necessary payment, account and agreement identifiers may remain in retained financial and contract records.

Routine maintenance clears a device credential’s last recorded IP after 90 days without use, and the requesting IP for a browser-confirmed device sign-in code once that code record is more than 90 days old. Device names, platforms, client versions, authorisation and revocation status, and activity timestamps may remain while the account exists so you can review connected devices and we can protect account access; device credentials and their associated records are removed on account deletion. The 90-day IP cleanup does not mean that all device history is deleted after 90 days. Consent records, including limited IP information recorded with a consent choice, are retained for two years. Expired codes and short-lived idempotency records are periodically removed. A hashed abuse-prevention identifier can be retained after a suspended account is deleted when necessary to enforce a proportionate restriction; it is not used for marketing.

Encrypted backups are isolated from routine use and expire within 30 days. A separate deletion log ensures account deletion is replayed before a restored backup returns to service. Backup retention does not authorise further use of deleted recordings. Where a specific legal hold requires different retention, we explain its scope when lawful to do so.

Security and access

The service is designed to use HTTPS in production, account or guest-session ownership checks, restricted administrative functions and server-side payment verification. Administrators should access information only when necessary for operations, support or a lawful investigation. These measures reduce risk but cannot eliminate every possibility of loss, unauthorised access or transmission failure.

Keep your password, email account, session cookies and recovery key private. A guest recovery key can confer access to an eligible unclaimed task. Avoid putting credentials, private correspondence or sensitive identifiers into the glossary or filename. If you believe that access has been compromised, write to our contact email promptly and include an order or task identifier rather than reposting the full recording.

Your rights and requests

Under Hong Kong's Personal Data (Privacy) Ordinance, you may request access to personal information we hold about you and correction of inaccurate information, subject to the Ordinance's conditions and exceptions. Depending on other applicable law and circumstances, you may also have rights to request erasure or restriction, receive portable information or object to certain processing. You may withdraw consent where it is the basis of processing. These rights have conditions and exceptions; a withdrawal does not retrospectively make earlier lawful processing unlawful.

Send privacy requests to our contact email with enough information to locate the relevant account or task. We may ask for proportionate verification to avoid disclosing someone else's information. We aim to respond without undue delay and within the period required by applicable law. Hong Kong data access and correction requests are generally subject to a 40-day response period. Where a different mandatory deadline applies, we will follow that deadline. Applicable exceptions, extensions or other timing rules will be explained where relevant. Necessary legal or financial retention does not justify denying every part of a request.

You may complain to Hong Kong's Office of the Privacy Commissioner for Personal Data (PCPD), or another competent data-protection authority where applicable. You do not have to obtain our permission before doing so. If you write to our contact email first, we will investigate the issue and explain the outcome, without limiting your right to seek other remedies.

Third-party information and children

The service is intended for adults. Do not upload recordings that unlawfully disclose information about another person, including a child. Your authority to possess a recording may differ from authority to send it to transcription and translation providers. Obtain the permissions and lawful basis required for your intended processing.

If you believe your information was submitted without appropriate authority, write to our contact email with enough detail to locate the task while avoiding unnecessary repetition of sensitive material. We will assess the request and take appropriate action. Private task records are not a public video or title library.

We will update this notice when material processing practices change. The date at the top identifies this version. A new purpose that needs a different legal ground or a separate choice will not be justified solely by silently changing this page. Relevant information should be provided before the new processing begins.

Provider documentation describes those providers' practices and may change independently of this notice. It does not replace the operator's responsibility to explain its own service accurately. The following links provide information about those providers' data practices and our Terms of Service.

Groq: your data in GroqCloud

OpenRouter Privacy Policy

SubLunio Terms of Service

Google Analytics data and retention

Analytics is optional and uses consent as its basis. Our tag requests host-only sl_ga / sl_ga_* cookies for up to one year without renewing their expiry on each visit; withdrawing consent clears them. The operator must configure a two-month event-data retention period in GA4 and disable enhanced measurement and user-provided data collection before enabling this integration. Aggregated reports can be retained separately under Google’s service settings.

Google may process analytics information outside your country, including in the United States. Google’s applicable data-processing terms and transfer arrangements must be assessed by the operator. The international-processing and rights sections of this notice also apply to this optional provider.

How Google uses information from sites that use its services

Agreement confirmation records

We retain the English Terms and Privacy Policy versions shown for a payment, their permanent URLs and integrity hashes, the confirmation notice, account and payment identifiers, and server verification records. For Stripe payments, the corresponding version URLs and verification information are also attached to the payment records in Stripe. These records support contract administration, refunds and payment disputes and follow the financial-record retention rules described above. Server verification times are not represented as the exact time you clicked a checkbox. Public agreement texts do not contain individual account or payment details.

Contact

Contact email: [email protected]. Use this address for privacy questions, access or correction requests, other data-protection requests and service enquiries. You do not need a paid account to contact us.

Download this version as Markdown