Privacy policy
Last updated October 2, 2026
In short
- The editor works without an account. Your songs, images, clips and fonts stay on your device.
- An account stores your email address, your name and your project layouts. It does not store your media.
- Media is uploaded only when you choose a cloud render. The uploaded files are deleted when that render ends, and the finished video is deleted after 7 days.
- We don't show ads, sell data or set tracking cookies.
Who runs Undertow
Undertow is made and run by Subcult. In this policy, "we" means Subcult. To ask a question or make a request about your data, write to [email protected].
Using the editor without an account
You can edit and export videos without signing in. In that case:
- The files you add (songs, images, video clips, fonts and lyrics) are kept in your browser's storage on your device. They are not sent to us.
- Your project layouts and your defaults are saved in the same browser. Clearing the site's data in your browser removes them.
- "Export on this computer" analyses, renders and encodes the video in your browser. Nothing is uploaded.
What an account stores
An account is optional. If you create one, we store the following on our servers.
| What | What it holds |
|---|---|
| Profile | Your email address, the name you give, whether you confirmed the address, and a profile picture address if your sign-in provider supplies one. |
| Password | Stored only as a hash. We cannot read it. |
| Sign-in sessions | A session identifier, plus the IP address and browser description recorded when you signed in. |
| Google sign-in | If you sign in with Google or connect it: your Google account identifier and the tokens Google issues, stored encrypted. If you connect YouTube, we ask for read-only access and use it only to read your channel name so it can fill your socials. |
| Projects | The layout: layer settings, the text you typed, the names and sizes of the files the project uses, and a small preview image. The files themselves stay on your devices. |
| Templates, palettes and defaults | What you save: template layouts, color palettes, and defaults such as artist name, website and social handles. |
| API keys | Each key's name, a short prefix that identifies it, and when it was created and last used. For requests made with your account we log the route, method, response status and time. |
| Billing | If you subscribe: your Stripe customer and subscription identifiers, the subscription's status and the end of the paid period. We never receive your card details. |
| Cloud renders | Each job's settings, length, status and times. See the next section for the files. |
Cloud rendering
When you choose "In the cloud" in the export dialog, the files that project needs are uploaded to our server so it can render the video. Those uploaded files are deleted when the job finishes, fails or is cancelled. The finished video is kept for 7 days so you can download it, then deleted. You can delete it sooner from Cloud renders.
Payments
Subscriptions are sold through Stripe. You enter your payment details on Stripe's pages, and Stripe processes the payment and keeps its own records. Stripe tells us whether your subscription is active. Receipts and payment emails come from Stripe.
We send account email only: the link that confirms your address and the link that resets your password. These are delivered through Brevo, which receives your email address to deliver them. We do not send marketing email.
Visit statistics
We count page views with Umami, an analytics tool we host ourselves. It sets no cookies. Before a page view is recorded, the query string is removed from the page address and the referring address is cut down to the site it came from. The record also includes general details about the browser and device. We use it to see how many people visit, not to follow individuals.
If your browser sends a Do Not Track or Global Privacy Control signal, no page view is recorded.
Cookies and browser storage
- When you sign in, we set a session cookie that keeps you signed in. Signing in with Google also sets short-lived cookies that protect the sign-in exchange.
- The editor uses your browser's storage for your files, projects and defaults, as described above.
- We set no advertising or cross-site tracking cookies.
Who else handles your data
We do not sell your data or share it for advertising. These companies process data for us, each only for the job named:
- Cloudflare sits in front of the site and passes requests to our server. It sees your IP address and the requests your browser makes.
- Stripe processes payments.
- Brevo delivers account email.
- Google handles sign-in if you choose Google, and tells us the name, email address and picture on that account.
We may disclose information when the law requires it.
Where data is kept
Accounts, projects and render files are kept on servers that Subcult operates in the United States. If you use Undertow from another country, your data is processed there.
How long we keep it
- Account data is kept until you delete your account.
- Deleting your account removes your profile, sign-in sessions, connected accounts, projects, templates, palettes, defaults, API keys, request log and render jobs.
- Files uploaded for a cloud render are deleted when the job ends. Finished videos are deleted after 7 days.
- Database backups are kept for about 30 days, so deleted data can remain in a backup for up to that long.
- Stripe keeps payment records under its own policy and legal duties.
Your choices and rights
- Change your name under Account, Profile.
- Disconnect Google under Account, Connected accounts.
- Download any project's layout with Project, Download layout.
- Delete your account under Account, Delete account. If you have a subscription, cancel it first under Billing.
Depending on where you live, the law may give you rights to see, correct, export or delete your data, to object to how it is used, and to complain to a data protection authority. To use any of these, write to [email protected]. We answer within 30 days.
Children
Undertow is not meant for children under 13, and we do not knowingly keep accounts for them. If you believe a child has created an account, write to us and we will delete it.
Changes to this policy
When this policy changes, we update the date at the top. If a change affects how your existing data is used, we will also tell account holders by email or in the editor before it takes effect.