Privacy policy

Version dated 4 August 2026

Account deletion

You can delete your account directly from My account, or submit a request without signing in from the public Tidecut account deletion page.

The procedure, the data deleted, organisation-owned media and legal exceptions are explained in section 12.

1. Scope and roles

This policy explains processing carried out through the Tidecut website, web platform and mobile application.

SARL RIOU STICHELBAUT (trading as Polaryse), French company registration number 844 114 942, 40 avenue de la Perrière, 56100 Lorient, France, contact@polaryse.com, acts as controller for account creation and security, billing, support, communications and service administration.

For professional media uploaded by a company or other organisation, that organisation generally determines the purposes and essential means of processing and acts as controller. Polaryse then processes the content on its behalf as processor. The organisation must inform people appearing in the content and establish an appropriate legal basis.

2. Data we process

  • Account and identity: first and last name, email address, identifier, hashed password, profile picture, preferences, role, accessible companies and projects.
  • Professional and contractual data: company, members, invitations, access rights, subscription, Stripe identifiers, invoices and contractual history.
  • Content: photographs, videos, audio files, other files, thumbnails, subtitles, transcripts, translations, metadata, keywords and classification or sharing information.
  • Results of AI-assisted processing: transcripts, corrections, translations, synchronisation results, descriptions, keywords and analysis results. The feature called “AI search” queries stored names, metadata and keywords, some of which were previously generated by AI; the query and ranking are processed locally by Tidecut without calling an AI provider.
  • Technical data: IP address, date and time, URL or action, access and audit logs, browser or User-Agent, app version, errors and technical identifiers required for security.

3. Mobile app and device access

  • The authentication token is kept in the phone’s secure storage provided by the operating system.
  • The camera and microphone are used only during a capture initiated by the user, after the operating system has granted permission.
  • To import existing content, the app uses the system picker and receives only the media selected by the user.
  • Selected original files may contain EXIF or IPTC metadata — for example the capture date, device, rights holder and, where present in the file, precise GPS coordinates. This metadata remains embedded in the file that is transmitted and stored. Tidecut does not access the device’s live location, and the app requests no location permission.
  • Downloaded content may be stored locally in the app’s storage or, with permission, in the media library. These local copies remain under the control of the user and their device.

4. Purposes and legal bases

  • Performance of a contract: create the account, authenticate the user, store, organise, search, download and share content, and manage rights, subscriptions and support requests.
  • Legitimate interests: secure the platform, prevent abuse, diagnose errors, measure feature usage, improve the service, ensure its continuity and establish or defend legal claims, after balancing those interests against individual rights.
  • Legal obligation: retain accounting documents, respond to competent authorities and handle data-subject requests.
  • Consent: optional operations that legally rely on this basis, including permissions requested by the operating system and, if it is reintroduced, certain biometric processing. Consent may be withdrawn for future processing.
  • Customer instructions: where Polaryse acts as processor for professional media.

5. Artificial intelligence processing

Tidecut can analyse content to generate keywords, transcribe audio or video files, and correct, translate and synchronise subtitles. Correction may be requested by the user or take place as post-processing of a requested transcription.

Indexing and search: the company owner, a company super-administrator or a project administrator may authorise analysis of a folder. The authorisation extends to child folders, remains effective until withdrawn and causes new media added while it is active to be analysed. After withdrawal, no new analysis is started; previously generated keywords remain stored until an authorised user edits or deletes them. The feature called “AI search” does not reanalyse media: it selects and ranks results locally using names, metadata and stored keywords, some of which were previously generated by AI. No AI provider is called during a search, and neither the search text nor the media is sent to one. To measure usage and improve the service, Tidecut records the search query and its usage context, including the user where identified, the search scope, date, duration and number of results.

Data sent: Tidecut generally uses a reduced version of an image but does not guarantee this for every configuration. For video analysed by local models, approximately one frame per second may be extracted; the audio track may be processed separately for transcription. Gladia receives the audio track needed for transcription, after which the transcript is stored in Tidecut. To correct subtitles, the text of the relevant segments, their timecodes and any information strictly necessary for the correction may be sent to the configured provider; the media file itself is not sent solely for that correction.

Providers: the provider is determined by the company’s subscription, the feature and the technical configuration. Gladia currently provides transcription. OpenAI is used for subtitle translation and synchronisation and may be used for subtitle correction. Mistral AI may be used for subtitle correction, with a possible fallback to OpenAI if it is unavailable. Depending on the configuration, content analysis and keyword generation may use OpenAI, Mistral AI, Google/Gemini or a model hosted by Tidecut. With a local model, processing remains on Tidecut’s Node infrastructure. With a third-party provider, only the data strictly required for the requested feature may be disclosed to that provider.

Folder authorisation is an instruction from the customer organisation for processing carried out on its behalf. Where the law requires separate consent, particularly for any future biometric processing, this general authorisation does not replace it. Retention, secondary use and transfer terms depend on the applicable service and contract; Tidecut does not promise zero retention or exclusion from model training unless those safeguards have been verified for the relevant account and provider.

Results are probabilistic and may be inaccurate. They must be checked before being used for any consequential purpose.

6. Facial recognition feature disabled

As of the date of this policy, facial recognition is not offered to users and no new facial detection or recognition processing is carried out.

Facial data resulting from earlier tests was deleted from the active system on 3 August 2026. It may remain in recovery backups for no more than seven days before those backups expire.

Any reactivation for customers will require specific information and an authorisation separate from the general AI authorisation. The customer organisation must establish an Article 6 legal basis and an applicable Article 9 condition, inform the individuals concerned and, where that condition is consent, be able to demonstrate explicit consent.

7. Recipients and service providers

Data is accessible to authorised Polaryse personnel, authorised members of the customer organisation and, where necessary, the following providers:

  • AWS, eu-west-1 (Ireland): website and PostgreSQL database hosting, transcoding capacity, the backup Node server and backups.
  • Tidecut infrastructure connected through Free Pro (France): local hosting of the primary media API and Tidecut’s local models.
  • Wasabi, eu-west-2 (Paris): multimedia file storage.
  • Amazon CloudFront: accelerated media delivery through a global network.
  • Stripe: payments, subscriptions and billing.
  • Gandi: domain name and services connected with email sent from the domain.
  • Gladia: transcription of the audio track.
  • OpenAI: subtitle translation and synchronisation, and other possible processing depending on the subscription.
  • Mistral AI and Google/Gemini: possible providers for certain processing depending on the subscription.
  • Models hosted by Tidecut: local processing where the configuration permits.
  • Google Fonts and public content-delivery networks such as cdnjs or jsDelivr: fonts or libraries loaded on certain pages; these services receive at least the technical information needed for the connection, including the IP address and User-Agent.

This list describes the configurations identified during the audit. Activating a new recipient that materially changes processing will result in an updated policy and, where required, new information or consent.

8. Location and international transfers

The configured Wasabi storage is in Paris and the primary AWS hosting is in Ireland. This does not mean all data remains in the European Union: CloudFront uses a global network, and some providers, affiliates or subprocessors may process data from third countries.

Where a provider processes data from a third country, the transfer must be covered by an adequacy decision, European Commission standard contractual clauses accompanied where necessary by an assessment and supplementary measures, or another GDPR mechanism. Server location alone does not prove that no transfer occurs.

For the services used by Tidecut, any transfers are governed by the mechanisms in the relevant provider’s data-processing terms, including an adequacy decision or standard contractual clauses where required. Information about the mechanism applicable to a specific processing operation may be requested through contact@polaryse.com.

9. Retention periods

  • Account data is retained for the contractual relationship and deleted when the account is closed, subject to the exceptions below.
  • Media and associated data is retained while the organisation or authorised user keeps it in Tidecut. An organisation’s content is not deleted merely because one member leaves.
  • Search queries and their associated usage information are retained for internal statistics and service improvement during the contractual relationship. At its end, data directly linked to an account is deleted or anonymised; aggregated statistics that no longer identify a user may be retained.
  • Accounting records and information needed to meet tax obligations may be retained for the applicable statutory period, which may be up to ten years.
  • Navigation actions recorded in Django are deleted after forty days. The Node API writes its technical logs to the standard output of the process launched directly with Node.js; Tidecut does not save them to a file or persistent logging service. No Amazon CloudWatch Logs group is configured.
  • PostgreSQL backups are retained for up to seven days in AWS eu-west-1. Data deleted from the active system may therefore remain in a backup until that backup expires.
  • The Tidecut organisations on OpenAI and Mistral AI do not currently have a zero-data-retention mode. For the stateless API calls used by Tidecut, those providers may retain inputs and outputs for up to thirty days for abuse monitoring. Voluntary settings allowing use for model training are disabled, and Tidecut does not use Mistral Labs models. Retention periods applying to other providers depend on the relevant service and agreement.
  • A minimal record of public deletion requests and their handling is retained for three years.

10. Security

Polaryse applies access controls, logical segregation by organisation, logging of sensitive actions and safeguards proportionate to risk. No Internet transmission or computer infrastructure can, however, be guaranteed as absolutely secure.

Security descriptions are limited to demonstrable measures. An incident likely to create a risk for individuals is handled in accordance with applicable notification and information obligations.

11. Your rights

Depending on the processing and legal basis, you may request access, rectification, erasure, restriction, objection and portability, withdraw consent for future processing, and provide instructions for your personal data after death where French law applies.

Send requests to contact@polaryse.com. Strictly necessary identity evidence may be requested where there is reasonable doubt. You may also lodge a complaint with the French data protection authority (CNIL) or your local supervisory authority.

Where data originates from a customer organisation, Polaryse may forward the request to that organisation for consideration as controller.

12. Account deletion

A signed-in user can initiate actual deletion from their account. The mobile app also lets the user initiate an authenticated request; Tidecut then sends a verification link valid for forty-eight hours to the account email address. An external request may be submitted at any time through the public account deletion page, including after uninstalling the app. The email address is first verified through a single-use link; additional information is requested only where there is reasonable doubt about identity. Tidecut handles the request within one month, unless an extension permitted by law is necessary and notified to the requester.

  • Personal account: the profile, access rights, server-side sessions and tokens, and personal workspace relationships are deleted.
  • Organisation member: the member’s access is deleted, but media owned by the organisation remains available to it.
  • Owner: a decision is required for each company owned. It must be transferred to a direct member offered by Tidecut as a successor or deleted together with its projects and media after confirmation.
  • Company deletion: remote media and projects are deleted and the company’s Stripe subscriptions are cancelled. Previously issued billing records may remain with Stripe and Tidecut for the legally required period.
  • Exceptions: invoices, minimal contractual archives, evidence of the request and data needed to meet a legal obligation, prevent fraud or defend legal claims may be retained for the justified period.

Uninstalling the mobile app does not delete the account. Deleting the account does not automatically delete copies downloaded to the user’s device. Data removed from the active system may remain in recovery backups for up to seven days before expiry.

13. Cookies and external website services

The website uses cookies needed for authentication, security, shared links, language and preferences. Certain pages load Stripe, Google Fonts or libraries from cdnjs or jsDelivr; these services receive the IP address and technical information needed to establish the connection. See the cookie policy.

14. Changes and contact

This policy may be updated when processing, providers or legal requirements change. Material changes will be brought to users’ attention through an appropriate channel.

For questions, email contact@polaryse.com.