Draft – requires legal review before launch.

Privacy Policy

Last updated: 6 October 2026

This policy explains how CutMeme handles personal data when you use our website and app. It is written for the EU General Data Protection Regulation (GDPR).

Who is responsible

The controller of your data is Baseflow Technology OÜ, registry code 17438321, Tallinn, Estonia (“we”). Write to us at privacy@cutmeme.com for anything about your data, or at support@cutmeme.com for everything else.

What we collect, why and on which basis

Data Why we use it Legal basis
Account: your name, email address, password (stored only as a one-way hash) or the account you sign in with (Google, Facebook or Microsoft: your name, email address and that account’s id), your language, and which version of the terms you accepted and when To create your account, sign you in and send you the emails the service needs (verifying your address, resetting your password, changes to your account) Contract: GDPR art. 6(1)(b)
Your content: the videos, images and captions you upload, the people you select in them and the files we make from them To do what you ask: cut people out, put them on a new background and export your video Contract: GDPR art. 6(1)(b)
Use of your plan: your projects, the jobs we ran for them, and how much of your plan’s memes, selection time, exports and library you used To apply your plan’s limits and show you what is left Contract: GDPR art. 6(1)(b)
Billing: your customer number at Stripe and your subscription’s plan, status, currency and dates. We never see your card details To run your subscription Contract and our legal duty to keep accounting records: GDPR art. 6(1)(b) and (c)
How you found us: if you came from a campaign link, its parameters (such as utm values or an ad click id), the website you came from and the first page you opened, saved with your account when you sign up To understand which pages and campaigns bring people to CutMeme Our legitimate interest in measuring our marketing: GDPR art. 6(1)(f)
Product events: that you signed up, uploaded your first video, exported your first video, started a checkout or a subscription; each once, with your account. A copy goes to our own statistics without your name, email address or account id To see how people use the product and fix where they get stuck Legitimate interest: GDPR art. 6(1)(f)
Security and abuse prevention: a security check when you sign up or sign in (Cloudflare Turnstile, which looks at your browser and IP address), the number of requests you send, a check that your email address is not a throwaway one, and, if you used the free meme and deleted your account, a keyed one-way fingerprint of your email address To keep the service safe and to stop one person from taking the free meme again and again Legitimate interest in security and preventing abuse: GDPR art. 6(1)(f)
Technical records: each request’s random id, method, address without its parameters, result and time. Our own logs do not record your IP address. Unexpected errors go to Sentry without your name, email address, cookies or what you sent To run the service and find errors Legitimate interest: GDPR art. 6(1)(f)
Optional permissions: whether you allowed emails about new features and offers, and ad measurement, and when Emails about new features and offers, only if you allowed them. Ad measurement, only if you allowed it: telling the ad platform whose ad brought you (Google or Meta) that you signed up or subscribed, with the click id of that ad, so we can see which ads work. We do not do this yet; we will update this policy before we do Your consent: GDPR art. 6(1)(a). Turn either off at any time on the account page; every email also has a link to stop them
Messages to us: what you write to support and our answers To answer you Contract or legitimate interest, depending on the question: GDPR art. 6(1)(b) or (f)

You give us your account data and content yourself; without them we cannot provide the service. The optional permissions are up to you and change nothing else. The rest comes from your use of the service.

We do not sell your data, we do not show ads, and we do not use your videos to train AI models. We make no decisions about you by automated means that have legal or similarly significant effects.

People in your videos. Your videos may show other people. When you upload them for your own use, you decide what happens to them and we process them only on your behalf, to make your video. Please only upload videos you have the right to use (see the Terms of Service).

Subscriptions are sold through Link, Stripe’s checkout, as the seller of record (Stripe’s “Managed Payments”). Link collects your payment details, billing address and email address at checkout, sends your receipts and handles payment questions and refunds together with us. For that it is a separate controller, and the Link Privacy Policy applies. We receive only what is listed under “Billing” above.

Who else processes your data

We use these providers to run the service. They process your data on our instructions under data processing agreements, except where noted.

Provider What for Where
Hetzner Online GmbH Our server: the database, the app’s backend and our statistics Germany (EU)
Cloudflare, Inc. Website hosting, network security, the sign-up check (Turnstile) and file storage Files stored in the EU; the network is worldwide
Modal Labs, Inc. The GPU computers that cut people out of your videos USA
Resend, Inc. Sending the service’s emails EU (Ireland)
Functional Software, Inc. (Sentry) Error reports EU (Germany)
Stripe and Link Payments; Link as the seller (see above) EU and USA
Google, Meta (Facebook), Microsoft Signing you in, only if you choose that account USA and others

Transfers outside the EU. When a provider processes data in a country without an EU adequacy decision, the transfer is covered by the European Commission’s standard contractual clauses, or by the EU–US Data Privacy Framework where the provider is certified. You can ask us for a copy of the safeguards at privacy@cutmeme.com.

We may also share data when the law requires it, for example with a court or an authority, and with professional advisers (such as our accountant) bound by confidentiality.

How long we keep it

Data Kept
Working files of a project (the uploaded video, the cut-out, previews) Deleted automatically 24 hours after the last job
Uploads no project uses 1 day
Your finished videos and saved people Until you delete them, the project or your account. If your paid subscription ends: 90 days after it ends, then deleted; we email you 30 and 7 days before. A video you made on the free plan stays
Account data, plan use and product events Until you delete your account
The fingerprint of a deleted account’s email address that used the free meme As long as the free meme is offered
Messages to support 3 years after the matter is closed
Records of what our team changed on your account 3 years, for disputes and our own accountability
Error reports (Sentry) Up to 90 days
Server logs Until they are overwritten: the server keeps only a fixed amount of them
Encrypted database backups 14 days, so deleted data leaves them within 14 days
Accounting records of payments 7 years, as Estonian accounting law requires; Link keeps its own records of the sale

Deleting your account removes your account data at once and your files within hours.

Your rights

Under the GDPR you have the right to:

  • access your data and get a copy of it,
  • have it corrected if it is wrong,
  • have it erased,
  • restrict how we use it,
  • receive it in a machine-readable format and have it sent to someone else (portability),
  • object at any time to uses based on our legitimate interest,
  • withdraw any consent you gave, without affecting what was done before.

Most of this you can do yourself on the account page: change your name and email address, download a copy of your data (JSON) and delete your account. For anything else write to privacy@cutmeme.com; we answer within one month, free of charge. We may ask you to confirm your identity first.

If you think we handle your data unlawfully, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or to the authority of the EU country where you live or work.

Age

CutMeme is not for children under 16, and we do not knowingly collect their data. If you believe a child under 16 has an account, tell us and we will delete it.

Security

Everything travels over HTTPS. Your files are stored privately and reached only through short-lived signed links. Database backups are encrypted with a key that is not kept on our server. Only the people who run the service can reach the systems, and every change they make to an account is recorded.

Changes

If we change this policy in a way that matters, we tell you by email or in the app before the change takes effect. The date at the top shows the latest version.