Privacy Policy
What we collect, where it lives, who else touches it, and how to get it deleted. No tracking pixels and no ad networks.
LAST UPDATED 2026-08-16
1. Who is responsible for your data
The data controller is [MILLIMETERS LEGAL ENTITY + ADDRESS — MIKA TO FILL], operating millimeters.cc. Privacy questions and requests go through the contact page’s form — leave your email there so we can verify the request and reply.
2. What we collect
Data you give us
- Account details — your name, email address, and a bcrypt hash of your password (never the password itself). If you sign in with Google or GitHub we store the provider name and the profile name, email and avatar URL it returns.
- The date and time you accepted these policies, recorded on your account when you sign up.
- Your content — the video, audio, images, project files, comments, annotations, transcripts and file names you upload or create, plus the technical metadata we read out of them (duration, resolution, codec, frame rate, timecode, camera metadata where the file carries it).
- Workspace details — workspace name, the people you invite and their roles, and share-link settings such as passwords and expiry dates.
- Support correspondence — including anything you send through the in-app “Report an issue” form, which attaches the page you were on and your browser’s user-agent string so we can reproduce the problem.
Data we generate or collect automatically
- Derived media — proxies, thumbnails, waveforms, transcripts and analysis reports produced from your uploads.
- Usage and billing counters — storage used, processing jobs run, AI tokens spent against your workspace allowance.
- Server logs — IP address, user agent, request path, timestamp and error detail, written by our API and CDN. We use them to operate the service, debug faults, and rate-limit abuse.
We do not run advertising trackers, third-party analytics scripts, session recording, or social pixels on millimeters.cc.
3. Cookies and browser storage
We use no advertising or tracking cookies, so there is no consent banner. What we do set:
- mm_access / mm_refresh
- HttpOnly, Secure, SameSite cookies that hold your session tokens. Strictly necessary — without them you cannot stay signed in. Set on sign-in, cleared on sign-out.
- localStorage
- Your access token (for the desktop app and API calls), your selected workspace, and your light/dark theme choice. Local to your browser; clearing site data removes them.
Clients opening a share link get no cookie from us at all unless they sign in — a share link is a URL, not an account.
4. Why we use it
- To provide the Service — store your files, generate proxies and transcripts, serve share links, run review workflows.
- To bill you and to keep your plan limits honest.
- To keep the platform secure — rate limiting, abuse detection, fraud prevention.
- To email you about your account: a welcome message when you sign up, password resets, workspace invitations, replies to support requests, billing receipts from Stripe, and material changes to these policies. We do not send marketing email to customers who have not asked for it.
- To fix bugs and improve the product, using aggregate usage counters and error logs — not by watching your footage.
We do not sell your personal information.
5. Where your data lives
Millimeters runs on Amazon Web Services in the Asia Pacific (Sydney) region, ap-southeast-2. Your account records live in DynamoDB; your files live in S3, encrypted at rest; media processing runs on our own containers in the same region. Files are delivered to browsers through Amazon CloudFront, which caches and serves them from edge locations worldwide — so content you share travels to whichever country your viewer is in.
Some sub-processors (below) process data outside Australia. By using the Service you consent to that transfer.
6. Who else touches your data (sub-processors)
- Amazon Web Services
- Hosting, storage, database, email delivery and CDN. Sydney (ap-southeast-2) for storage and compute; CloudFront edge locations globally.
- Stripe
- Payments. Stripe receives your email address, billing details and the card data you enter directly into their checkout — we never see or store your full card number. Processed in the United States and elsewhere under Stripe’s own terms.
Managed-mode AI (the AI editor, AI cut assistance and parts of Analyze) runs on inference infrastructure we operate, not a third-party model provider — see section 7. In bring-your-own-key mode, the provider you configure is your own sub-processor under your agreement with them.
Transcription and media analysis run on our own infrastructure inside AWS — audio is not sent to a third-party transcription service.
7. AI features and what leaves the platform
Each workspace picks one of three AI modes in its settings:
- Managed — your prompts, the conversation history, and metadata describing your media (file names, durations, timecodes, transcript text, clip and timeline structure, and where you ask for it, sampled still frames) are processed by AI inference infrastructure we operate to generate the response. Usage is metered against your workspace allowance.
- Bring your own key — requests go to the provider and endpoint you configure, authenticated with your key. What that provider does with the data is governed by your agreement with them, not by this policy.
- Disabled — no AI feature sends anything to any model provider.
We store the resulting conversations against your workspace so you can reopen them, and you can delete a thread at any time.
8. How long we keep things
- Your content
- Until you delete it, or until your account is deleted. Deleting a video, file or project removes the original and its derived proxies and thumbnails.
- Deleted accounts
- Content and account records are removed within 30 days of the deletion request.
- Database backups
- Point-in-time recovery snapshots roll forward on a 35-day window. Deleted data can survive in those snapshots until it ages out; they are only ever used to restore the platform after a failure.
- Server and access logs
- Up to 30 days.
- Billing records
- Kept for as long as Australian tax and record-keeping law requires, even after an account closes.
9. Your rights
You can ask us to:
- Access the personal information we hold about you, and get a copy of it.
- Correct anything inaccurate — name, email and avatar you can change yourself in your profile settings.
- Delete your account and its content yourself, from your account settings. Deletion runs immediately and is irreversible. If you would rather we do it, or you cannot sign in, ask via the contact page, including the email address on the account — we will verify and confirm before anything is destroyed.
- Export your data. Your account settings include a one-click export that downloads a machine-readable copy of the personal information and account records we hold about you, and you can download your original files from the app at any time. Ask us if you need a bulk export of media.
- Complain. If you are unhappy with how we handled your data, write to us first — we will respond within 30 days. You can then escalate to the Office of the Australian Information Commissioner (oaic.gov.au).
We will ask you to verify you control the account before acting on an access or deletion request, and we respond within 30 days.
If you are in the European Economic Area or the United Kingdom, the GDPR (or UK GDPR) gives you these rights in largely the same shape: access and portability (the account-settings export is a machine-readable copy), rectification, erasure (the self-serve delete runs immediately), restriction, and objection. We rely on performance of our contract with you to process account and content data, and on legitimate interests for service security and operations. You can also lodge a complaint with your local supervisory authority.
10. Children
Millimeters does not set a minimum age. If you believe a child holds an account without their guardian’s knowledge, tell us through the contact page and we will help sort it out.
11. Security
Passwords are hashed with bcrypt. Data is encrypted in transit (TLS) and at rest. Session cookies are HttpOnly and Secure. Access to production systems is limited to the people who operate the platform. No system is perfect: if a breach affects your personal information we will notify you and the OAIC as the Notifiable Data Breaches scheme requires.
12. Changes
We will update this page as the product changes, and the “last updated” date at the top always reflects the current version. If a change materially affects how we handle your personal information, we will email account holders before it takes effect.
See also the Terms of Service and the Refunds & Cancellation Policy.