Privacy Policy
Last updated: August 18, 2026
Overview
1 Tap Cut and 1tapcut.com are operated by Louperkos Investments Ltd (Cyprus company number HE 451009). Louperkos Investments Ltd (“Louperkos,” “we,” “us,” or “our”) is the controller responsible for the processing described in this Privacy Policy. Our registered address is 9 Efesou, Paralimni 5280, Famagusta, Cyprus.
This Privacy Policy explains how we handle information when you use the 1 Tap Cut iOS app, Android app, or this website. The current mobile apps have no email, password, or social sign-in and do not create a profile tied to your name. They create a pseudonymous Firebase identity so private-cloud requests can be authenticated and service usage can be associated with that app installation.
1 Tap Cut is local-first in ownership and control: your device owns your project state, editing decisions, validation, preview, and final render. Some heavyweight features use private-cloud processing as described below. We do not sell personal information. Louperkos does not use your footage, audio, transcripts, or projects to train its models or intentionally submit that content to a provider for model training.
By using 1 Tap Cut, you acknowledge that you have read this policy. That acknowledgement is not blanket consent to optional processing. Before the app sends media to our private-cloud service, it presents a separate disclosure and asks you to choose Agree & continue or Not now. Choosing Not now sends nothing to that service and leaves supported on-device features available.
Information the mobile apps handle
- Your media and edits: video, audio, photos, project structure, subtitles, transcripts, analysis results, and exports you create or import.
- Pseudonymous installation identity: a randomly generated Firebase user ID and short-lived authentication tokens. We do not ask Firebase for your email address, name, contacts, or Google account.
- Usage and technical information: app version, device model, operating-system version, pseudonymous Firebase, app-instance, and installation identifiers, IP address and ordinary network metadata, feature and control events, operation and download status and timing, crashes, hangs, and performance information. On Android, Firebase Analytics may also receive an advertising or measurement identifier when Android makes one available. The iOS app uses Firebase's no-IDFA Analytics integration and does not link an advertising SDK.
- Optional information you provide: support emails and a project file or backup you explicitly export or save. The Android app can also store a Gemini API key when you choose its bring-your-own-key route; the current iOS release does not include that route.
What stays on your device
Ordinary editing, timeline and project state, local analysis results, preview, and export are stored and controlled on your device. Final video rendering also runs on the device. Export requires 1 Tap Cut to remain open; if the app leaves the foreground, the render is stopped safely and no partial result is offered for sharing. Imported media and generated working files remain in app-owned storage unless you explicitly start a feature that discloses a cloud route or export/share a file yourself.
Both mobile apps use system-provided pickers and receive access only to the videos, photos, audio, or project files you select. They do not scan the rest of your media library. On iOS, import uses Apple's Photos picker and document picker without requesting broad Photos-library access. Saving an export uses add-only Photos permission, which allows 1 Tap Cut to add the video without reading your library. Android uses its system photo and document pickers, and picker access to an imported item may be retained so the app can reopen that item in your project.
On Android, 1 Tap Cut asks the operating system not to include its app-owned databases, preferences, API keys, imported media, generated files, or usage ledger in cloud backup or device-to-device transfer. On iOS, downloaded speech models and reproducible working files are excluded from iCloud backup; other app-owned project data may be included in an encrypted Apple device or iCloud backup according to your Apple backup settings. Normal app updates preserve local data. Clearing app data where the platform offers that control, or uninstalling the app, removes its local container and resets the local Firebase identity and usage counters. Restoring an eligible device backup may restore data included in that backup. Files you exported elsewhere are controlled by that destination and are not removed when the app is uninstalled.
Model and editing-asset downloads
1 Tap Cut may download optional on-device AI models, editing assets you choose, catalog metadata, and an updated copy of the small branded end-credit card used during export. Android's managed model set includes YAMNet (sound events), MobileFaceNet (recognising the same person across clips), Beat This (beat tracking), MoViNet (action recognition), DINOv2 (subject and scene grouping), Whisper Base (speech transcription), and wav2vec2 (word timing). Those runtime files are served from models.1tapcut.com and Android's system Download Manager may continue the transfer outside the app and show its own notification.
On iOS, an on-device speech workflow may ask for permission to download the approximately 600 MB Distil-Whisper Core ML model used by WhisperKit. It is fetched only after the workflow discloses the network action, stored in the app's Application Support area, excluded from iCloud backup, and removable from the app's project settings. The current iOS release does not silently download that model at launch.
A download request exposes the requested file address and ordinary network metadata, such as IP address, to the relevant host. The platform and 1 Tap Cut process download progress, status, file size, and integrity information as needed to complete the transfer. These downloads do not upload your imported media, projects, transcripts, prompts, or exports. Downloaded models remain in app-owned storage until you remove them in the app, clear app storage where available, or uninstall the app.
Private-cloud AI processing
Private-cloud processing is used only for the feature you start and only after the relevant in-app disclosure or setting. Depending on the feature and mobile platform, 1 Tap Cut may upload:
- a 16 kHz audio extract for transcription and word timing;
- a bounded story, transcript, and analysis-evidence catalog for automatic Find Shorts, plus the audio extract if speech must first be transcribed; or
- sampled 512-pixel frames and up to 30 seconds of audio when you enable private-cloud video understanding.
Transfers use encrypted HTTPS connections to Louperkos's private processing service. The normal AI processing path does not upload the full raw video. Temporary media files are stored under generated job and file identifiers rather than a named user profile. Most are scheduled for removal within 6 hours, and some short-lived artifacts within 1 hour. The client job record, including its pseudonymous Firebase installation identifier, is scheduled for hard deletion after 24 hours. Successful results needed by the editor are downloaded and stored in the local project.
Media is not associated with an email address or named 1 Tap Cut profile. It is nevertheless pseudonymous, not guaranteed to be absolutely anonymous: while a job exists, it is scoped to the app's randomly generated Firebase installation identifier, and ordinary network logs may include an IP address. Access is restricted to authorised operators and processing providers that need it to operate, secure, or troubleshoot the service. We do not offer third parties an on-demand way to obtain your media, and we do not sell it, share it for advertising, or use it for model training.
Media-free worker-attempt records containing a generated job ID, worker name, timestamps, outcome, and an error message may be retained for up to 14 days for reliability, security, and incident investigation. They are designed not to contain the uploaded media or a named-account identity.
Pseudonymous identity and private-cloud minutes
The app uses its randomly generated Firebase ID to authenticate private-cloud requests. The current release also keeps daily and tracked Transcription and automatic Find Shorts usage on the device. The free allowance is configured remotely and currently defaults to 30 combined source-media minutes per local day. On-device work does not consume that allowance; on Android, supported Gemini-with-your-key work does not consume it either. These controls are an initial client-side limit rather than a fraud-resistant billing system, so clearing app data or reinstalling can reset the local counter and create a new local pseudonymous credential. The corresponding Firebase record and already-created cloud job records follow their own service retention rather than the local uninstall.
Project files and backups
Where available, project-file export and import work without Louperkos cloud storage. The current mobile apps do not automatically upload complete project backups or private project revisions to Louperkos. A project file, source file, or exported video leaves the app only when you choose a system share, save, or export destination, or when you explicitly start a disclosed private-cloud processing feature described above.
Firebase and diagnostics
We use the following Firebase services:
- Authentication creates the pseudonymous installation identity used for private-cloud requests.
- Remote Config supplies availability flags, processing endpoints, model locations, and the current free-minute allowance.
- Analytics records basic lifecycle events and app-specific actions such as feature starts, control interactions, workflow outcomes, and export outcomes. Firebase Analytics may process an Android advertising or measurement identifier when Android makes one available, together with app-instance and installation identifiers, for measurement and attribution. The iOS app uses Firebase's no-IDFA product and does not link an advertising SDK. Louperkos does not use this information to serve ads. Event parameters are designed not to include filenames, project titles, transcripts, or media content.
- Crashlytics records crashes, hangs or ANRs, build and device context, and redacted diagnostic breadcrumbs. When optional diagnostics are enabled, it also records sanitised handled failures.
- Performance Monitoring measures app start, screen performance, and the duration and outcome of heavy operations.
- Firestore (Android only) may receive redacted model and media-processing failure reports and retry historical diagnostic reports that were already queued on an older Android installation. The current iOS app does not link Firebase Firestore.
The app's privacy or About & Legal settings include a Share diagnostics control, which is on by default unless the remotely configured default changes. Turning it off stops additional media-processing performance and handled-failure reporting and disables Firebase Performance collection from the next launch. Basic Analytics and automatic crash reporting are separate and are not disabled by that switch. Additional reports are designed to contain model name, device specifications, media format such as codec, resolution, or duration, failure class, and timing—never the media itself, its URI or filename, a transcript, prompt, frame, or model response.
The private-cloud retention periods above do not apply to Firebase analytics and diagnostics, website access logs, or support correspondence. Those records are kept only for as long as reasonably needed for measurement, security, reliability, troubleshooting, responding to you, and applicable legal obligations, using the retention controls and deletion processes available from the relevant provider. Access is limited to authorised personnel and service providers. Where an exact period is controlled by a provider, that provider's published retention terms and our configured service settings apply.
Android-only Gemini and public-cloud routes
The Android app can optionally save a Google Gemini API key for features that support that route. The key is kept in app-owned storage on that device, excluded from Android backup and device transfer, and sent only to Google when you start a supported Gemini feature. Google's own quota, billing, data handling, and terms apply. Louperkos does not receive the key, and Gemini work does not consume the private-cloud minute allowance. The current iOS release does not include a bring-your-own-key route.
A supported Android feature may instead disclose and use a configured public-cloud processing fallback. In that case, the inputs required for that feature are sent to the named provider and are handled under that provider's terms and privacy policy. Louperkos uses these routes to provide the requested result and does not intentionally submit user content for provider model training. The current iOS release ships only its on-device and private-cloud processing routes, not this public-cloud fallback.
How we use and share information
We use information to provide the requested editing and AI features, authenticate and protect our private services, apply usage limits, diagnose failures, measure reliability, prevent abuse, and respond to support requests. We share information only with service providers needed for those purposes, including Google Firebase, Cloudflare infrastructure, Louperkos's private processing providers, and—only when an Android user chooses a disclosed route—Google Gemini or another configured public processing provider. We do not sell your data or share your footage for advertising. Louperkos does not train its models on your content or intentionally submit it for provider model training.
We may disclose the minimum information reasonably necessary to comply with applicable law or valid legal process, or to protect the rights, safety, and security of users, Louperkos, and the service. This is not routine sharing and does not mean that media is handed over merely because someone asks for it. If 1 Tap Cut or the relevant business assets are involved in a merger, acquisition, reorganisation, or sale, data may transfer to the successor subject to applicable law and the commitments in this policy. We will give notice if such a change materially affects how personal data is handled.
Legal bases and your privacy rights
Depending on the processing, we rely on providing the service you request, our legitimate interests in operating a secure and reliable service, your consent or affirmative choice where required, and compliance with legal obligations. Where processing is based on consent, you may withdraw it without affecting processing that occurred before withdrawal.
Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability of personal data connected to you. Because the app uses a pseudonymous installation identity, we may need technical information from your device to locate and verify the relevant records. You may also lodge a complaint with your local data-protection authority or the Cyprus Office of the Commissioner for Personal Data Protection.
Your choices and data deletion
- You can keep supported processing on-device by enabling available local models and routes.
- You can leave optional private-cloud video understanding off.
- You can turn off additional model/media diagnostics in Settings.
- On Android, you can clear the optional Gemini key in Settings.
- You can remove downloaded and partial managed-model files using the controls available in the app.
- You can delete projects and imported media from this device in Settings. This does not delete app preferences, the pseudonymous Firebase identity, local usage limits, downloaded models, or a separately exported file.
- You can clear all app-owned local data by clearing app storage where the platform offers that control, or by uninstalling. Android's excluded app data is not restored automatically; eligible iOS project data may be restored later if it was included in an Apple device or iCloud backup.
The current releases have no named user account and therefore no in-app account-deletion control. For questions or a request concerning information held by Louperkos or its providers, email us. We may need enough technical information to locate and verify the relevant pseudonymous data, and legal or security obligations may limit what can be accessed or deleted.
Possible future Android fraud-prevention changes
The current Android release does not send Louperkos a hardware serial number, IMEI, or a hash derived from Android ID for minute-limit enforcement. It does not use an advertising identifier for minute enforcement or to serve ads; as described above, Firebase Analytics may process an advertising or measurement identifier for measurement and attribution when Android makes one available. A future release may add a server-keyed hash of the app-and-signing-scoped Android ID, together with Play Integrity signals, to reduce reinstall-based abuse. If we introduce that processing, we will update this policy before or when collection begins.
Security and international processing
We use access controls, encryption in transit, scoped service credentials, redaction, and isolated storage boundaries. No storage or transmission method is completely secure. Service providers and private-cloud workers may process data in countries other than your own, subject to their safeguards and applicable law.
Website and support
If you email us, we receive the address, message, and attachments you choose to send. Our website host may process ordinary request information such as IP address, browser type, requested page, and timestamps for delivery, security, and operational logging. The website does not create the mobile apps' pseudonymous Firebase identity.
Links to other services
The app and website may link to services we do not operate, including Google services, app stores, and social-media sites such as Instagram. Their own terms and privacy policies govern information you provide to them. We are not responsible for the content or privacy practices of third-party sites merely because 1 Tap Cut links to them.
Children’s privacy
1 Tap Cut is not directed at children under 13, or the higher minimum age required in their country, and we do not knowingly collect personal data from children below that age.
Changes to this policy
We may update this policy when the app, service providers, or legal requirements change. Material changes will be reflected by an updated “Last updated” date and, when appropriate, an in-app notice.
Contact
Privacy questions, requests, and general app support can be sent to kallossoft@gmail.com.