Privacy Policy
Last updated · August 21, 2026
This policy explains what Dubsmith collects when you use our video-localization service, why, where it goes, and how to get it deleted. We are based in Singapore and this policy is written primarily around Singapore’s Personal Data Protection Act 2012 (PDPA), with the additional disclosures and rights that the GDPR, UK GDPR, and US state privacy laws require for people covered by them.
1. Who we are, and the two roles we play
Dubsmith operates the Dubsmith web app and website. For questions about this policy, to exercise a right, or to reach the person responsible for data protection, contact contact@dubsmith.io. We treat that address as the business contact for data protection matters, including for the purposes of section 11 of the PDPA and, where the GDPR applies to us, as the point of contact for data subjects.
Your own data. For your account, billing and support data, we decide why and how it is processed. Under the PDPA we are the organisation; under the GDPR we are the controller.
The media you upload. For the video, audio and derived content you put through the service, we act on your instructions and for your purposes. Under the PDPA we are a data intermediary; under the GDPR we are a processor and you are the controller. That means you decide what is uploaded and why, you are responsible for having a lawful basis and the necessary consents, and we process it only to produce the localizations you ask for. The Data Processing Addendum sets out the terms of that role.
2. What we collect
Account data. Your name, email address, and authentication credentials — or, if you sign in with Google or Apple, the identity details that provider shares with us. Passwords are stored only as salted hashes.
Your media and everything derived from it. The video and audio files you upload, and what we generate from them: transcripts, speaker diarization, translations, emotion and on-screen text analysis, synthesized and cloned voices, inpainted frames, lip-synced video, subtitles, and rendered dubs. Where you use voice matching or cloning, this includes reference audio of the speaker’s voice.
Usage and billing data. Processing metadata (job durations, languages, stages completed, amounts metered), your plan and balance, invoices and transaction records. Payment card details are collected and processed directly by our payment provider and never reach our servers.
Technical data. IP address, browser and device type, and server and application logs generated when you use the site and app. We use these to keep the service running and secure, and to investigate faults and abuse.
Communications. What you send us when you email us or contact support, and our replies.
Please do not upload restricted data
The service is not built for sensitive or special-category personal data. Unless we have agreed otherwise in writing, do not upload content containing government identification numbers, financial account or payment card data, health or medical information, biometric identifiers used for identification, or personal data of children under 16. If you do, you do so on your own responsibility and warrant that you have the legal basis for it.
3. Why we use it, and our legal basis
We use personal data only for the purposes below. Under the PDPA we rely on your consent, on deemed consent for what is reasonably necessary to provide a service you asked for, and on the legitimate interests exception where it applies. Where the GDPR applies, the basis is set out in the right-hand column.
| Purpose | Data used | GDPR legal basis |
|---|---|---|
| Delivering the service — processing your media into the deliverables you request, running the review and approval flow | Account data, your media and derived content, technical data | Performance of a contract |
| Running your account, support, and service notices | Account data, communications | Performance of a contract |
| Metering, invoicing, collections, and tax records | Usage and billing data, account data | Performance of a contract; legal obligation |
| Security, abuse prevention, fault diagnosis, and service reliability | Technical data, usage data, account data | Legitimate interests — keeping the service secure and working |
| Enforcing our terms, establishing or defending legal claims, and responding to lawful requests | Any data relevant in the circumstances | Legitimate interests; legal obligation |
| Service updates and, if you opt in, occasional product email | Account data, communications | Legitimate interests; consent for marketing where required |
Aggregate statistics. We produce aggregate operational statistics — job volumes, stage durations, error rates — that do not identify you or any individual, and use them to run and improve the service.
4. What we do not do
- We do not train AI models on your content. Not our own, not anyone else’s. We contractually require our processing vendors not to use your content for their model training either.
- We do not sell or share personal data for money or for cross-context behavioural advertising.
- We do not run advertising, ad networks, or cross-site tracking.
- We do not use your personal data for profiling or automated decision-making that produces legal or similarly significant effects. The localization pipeline is automated, but it acts on the media you submit, not on decisions about you.
5. Cookies and similar technologies
We use essential cookies only — the ones that keep you signed in and keep the session secure. We set no advertising, analytics, or cross-site tracking cookies, so there is nothing to consent to and no cookie banner to click through.
| What | Purpose | Type |
|---|---|---|
| Session cookie | Keeps you signed in and authenticates your requests | Essential · first-party · expires when the session ends or you sign out |
| Browser storage | Remembers interface preferences such as theme and panel layout | Essential · first-party · stays until you clear site data |
You can block or delete cookies in your browser settings, but the app cannot keep you signed in without the session cookie. Because we do not track across sites, there is nothing for a “Do Not Track” or Global Privacy Control signal to switch off — but if we ever introduce non-essential tracking, we will honour those signals and ask for consent first, and this section will say so before it happens.
6. Who we share it with
We do not sell your data. We share it only with the service providers we need to run the service, and only for that purpose. Each of them is bound by a written contract that limits them to our instructions, requires appropriate security, and prohibits using your content for their own model training.
The full list — provider, what it does, what it receives, and where it operates — is published at Subprocessors and kept current.
Other disclosures. We may also disclose personal data to professional advisers under duties of confidence; to law enforcement, regulators or courts where we reasonably believe we are legally required to or where it is necessary to protect our rights, your safety, or the safety of others; and to a buyer or successor in connection with a merger, acquisition, financing, insolvency, or sale of assets, subject to this policy continuing to apply.
7. Where your data goes
Application data (projects, transcripts, review state, account records) lives in Convex. Uploads and finished renders are stored with Cloudflare (R2). During processing, working copies pass through our pipeline on Amazon Web Services and are cleaned up after the job completes. Speech synthesis, lip-sync, and on-screen text removal are performed by specialised vendors that receive only the segments required for their step.
Transfers out of Singapore. Most of these providers operate outside Singapore, principally in the United States and the European Union. Before transferring personal data overseas we take reasonable steps, as section 26 of the PDPA requires, to satisfy ourselves that the recipient is bound by legally enforceable obligations to protect it to a standard comparable to the PDPA — in practice, through the data-protection terms in our contracts with them.
Transfers out of the EEA and the UK. Where the GDPR or UK GDPR applies, transfers to countries without an adequacy decision are made under the European Commission’s Standard Contractual Clauses, as varied by the UK International Data Transfer Addendum where relevant, together with supplementary measures where they are needed. You can request details of the mechanism used for a particular transfer at contact@dubsmith.io.
8. How long we keep it
Your media stays in your workspace until you delete it. Deleting a project or video removes its uploads and generated assets from active storage; residual copies in routine backups are isolated from further processing and cycle out on the normal backup schedule.
- Media and derived content: until you delete it, or until your account is closed.
- Account records: for as long as your account is open, then deleted on request within 30 days.
- Billing and tax records: retained for as long as accounting and tax law requires, which in Singapore is five years.
- Security and application logs: retained for a limited period for fault diagnosis and abuse investigation, then discarded.
To delete your account and everything associated with it, email contact@dubsmith.io. We complete account deletions within 30 days, except for data we are required to keep by law and copies isolated in backups pending their normal expiry.
9. Security
We apply technical and organisational measures appropriate to the risk: encryption in transit and at rest, access restricted on a need-to-know basis, authenticated and signed server-to-server calls between our services, secrets held in a managed secret store, and confidentiality obligations on everyone with access.
No system is perfectly secure and we cannot guarantee the security of your data. You are responsible for keeping your credentials safe and for the security of the devices you use to reach the service.
If something goes wrong. If a data breach occurs we assess it promptly. Where it is notifiable under the PDPA we notify the Personal Data Protection Commission within three calendar days of concluding that it is notifiable, and affected individuals where the breach is likely to result in significant harm. Where the GDPR applies we notify the competent supervisory authority within 72 hours and affected individuals where required. Where you are a business customer and the affected data is your customers’, we notify you without undue delay so you can meet your own obligations.
10. Your rights
Everyone. You can ask us for a copy of the personal data we hold about you and information about how it has been used, ask us to correct anything inaccurate, ask us to delete your account and data, and withdraw any consent you have given. Under the PDPA we will respond to an access or correction request as soon as reasonably possible and in any case within 30 days, and will tell you if we need longer and why. Withdrawing consent may mean we can no longer provide the service.
If the GDPR or UK GDPR applies to you. You additionally have the right to restrict processing, to object to processing based on legitimate interests, to receive your data in a portable machine-readable format, and to lodge a complaint with your supervisory authority — in the UK, the Information Commissioner’s Office. We would appreciate the chance to address your concern first.
If you are a resident of a US state with a privacy law. You may have rights to know, access, correct, delete, obtain a portable copy, appeal a refusal, and opt out of sale, sharing, targeted advertising and certain profiling. We do not sell or share personal data, do not run targeted advertising, and do not carry out profiling of the kind those laws address, so those opt-outs have nothing to act on. We do not discriminate against anyone for exercising a right.
How to exercise a right. Email contact@dubsmith.io. We will verify your identity, usually by confirming control of the account email, before acting — this protects you as much as us. If a request concerns media a business customer uploaded, we will refer you to that customer, who controls it, and assist them in responding.
Complaints. If you are not satisfied with our response, you may complain to the Personal Data Protection Commission of Singapore, or to the data protection authority where you live.
11. Marketing and email
We send service email — sign-in and password messages, job notifications, billing and security notices — because they are part of providing the service, and you cannot opt out of them while you hold an account. Any marketing email carries an unsubscribe link and honours it. We do not send marketing by text message, and we comply with the Spam Control Act 2007 and the Do Not Call provisions of the PDPA.
12. Children
The service is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact contact@dubsmith.io and we will delete it.
13. Changes and contact
If this policy changes materially we will note it here with a new date and, where the change significantly affects you, tell you by email before it takes effect. Questions, requests, or complaints: contact@dubsmith.io.

