This Privacy Policy explains how SinCap (“we”, “us”, “our”) collects, uses, and protects your information when you use the SinCap web, iOS, and Android applications and the website at sinhalacaptions.com (collectively, the “Service”).
1. Who we are
SinCap is a personal project operated by Thilina Pathirage, an individual developer based in Sri Lanka. SinCap is not a registered company. For any privacy questions or requests, contact thilinap.me@gmail.com.
2. Information we collect
To create and maintain your account, we collect only the following:
- Name — first and last name you provide on signup.
- Email address — used for account login, OTP verification, and service emails.
- Password — stored only as a salted hash using bcrypt (cost factor 12). We never store or have access to your plaintext password.
- Credit balance — the number of caption-generation credits associated with your account, updated when you make an in-app purchase or use a credit.
We also automatically collect basic technical data when you use the app or website:
- Cookies and analytics identifiers (see Section 7).
- Standard server logs (IP address, browser/device type, timestamps) for security and abuse prevention.
- On Android, Google Play Services may collect device identifiers and usage data under Google's own privacy policy.
3. Media you upload (videos and audio)
We do not store your videos or audio on our servers or databases. Media is processed transiently to generate captions and is discarded immediately after processing. Generated captions/subtitles remain in your local project on your device and are not retained by SinCap.
For speech-to-text transcription, the extracted audio is sent for processing to AI services provided by Microsoft and Google. The media is not retained by SinCap after the transcription response is returned. Each provider’s handling of the data is governed by its respective terms and privacy policy.
Only the audio track is uploaded. The app extracts the audio from the video you select and sends only that; the video file itself never leaves your device. We do not send your name, email address, password, or payment details to any AI provider.
AI editing tools. The optional AI editing features — word emphasis, text hooks, video descriptions, and B-roll placement — send your caption text, and any B-roll images you choose to add, to the AI services named above to produce the suggestion. These features run only when you tap the button that requests them, and the submitted text and images are not retained by SinCap afterwards.
Your permission. Before anything is sent to these AI providers, the app shows you a disclosure naming what is sent and who receives it, and asks you to agree. Nothing is sent to an AI provider until you do. You can review that disclosure or withdraw your permission at any time from Profile → AI data sharing; withdrawing it stops the AI features until you agree again.
4. How we use your information
- To create, authenticate, and secure your account.
- To send one-time-password (OTP) codes for signup verification, password reset, password change, and account deletion.
- To process the media you choose to caption.
- To generate the AI editing suggestions you request (word emphasis, text hooks, video descriptions, and B-roll placement).
- To manage your credit balance and verify in-app purchases made through Google Play.
- To respond to your support requests.
- To prevent fraud, abuse, and security incidents.
5. Legal bases for processing
Where the EU/UK GDPR applies, we process your data on the basis of (a) performance of a contract with you (operating your account), (b) your consent (analytics, optional features), and (c) our legitimate interests (security and service improvement).
6. Service providers we use
We share limited data with the following third-party processors strictly to operate the Service:
- Microsoft Azure AI services — transient processing of audio, caption text, and any B-roll images you add, for captions and the AI editing tools.
- Microsoft Azure Communication Services — sending transactional and OTP emails.
- Google AI / Gemini API — transient processing of audio, caption text, and any B-roll images you add, for captions and the AI editing tools.
- Google Play Billing — payment processing for in-app credit purchases on Android. SinCap receives only a purchase token to verify the transaction; full payment details are handled solely by Google.
- Google Play Services — Android platform services. Subject to Google's own privacy policy.
- Apple App Store (StoreKit / In-App Purchase) — payment processing for in-app credit purchases on iOS. SinCap receives only a transaction identifier to verify the purchase; full payment details are handled solely by Apple.
- RevenueCat — in-app purchase infrastructure that validates and manages credit purchases across the App Store and Google Play. Receives your app user identifier and purchase/transaction data to confirm purchases and relay them to SinCap. Subject to RevenueCat's own privacy policy.
- MongoDB Atlas — storage of account records (name, email, password hash, credit balance).
- Vercel — hosting for the SinCap website and API.
- Google Analytics (GA4) and Google AdSense — analytics and advertising on the website only (not the mobile apps).
We share data with each processor above only to operate the Service, and only the minimum needed for that purpose. Each processor is bound by its own data-processing terms and privacy commitments, which we require to provide protection equivalent to that described in this policy.
We do not sell your personal information. We do not share your data with any party outside the list above except where required by law.
7. Cookies and analytics
The SinCap website uses Google Analytics (GA4) to understand basic usage patterns and Google AdSense to display ads. These services may set cookies and collect device and usage information. You can disable cookies in your browser at any time. The mobile apps do not use Google Analytics or AdSense.
8. In-app purchases and billing
The SinCap app offers optional credit purchases via Google Play Billing on Android and the Apple App Store on iOS, managed through RevenueCat. All payment processing is handled by Google or Apple; SinCap never receives or stores your credit card number or full payment details. Upon a successful purchase, we receive only a purchase token or transaction identifier, which we use solely to credit your account. Your credit balance is stored in our database and updated as credits are consumed or purchased.
Purchase history is managed by Google Play or the Apple App Store and is subject to their respective privacy and refund policies. For billing disputes or refund requests, contact Google Play or Apple support.
9. Device permissions
The SinCap mobile app may request the following device permissions to enable its features:
- Photos / Media library — to access video files you choose to caption, to attach images to community posts, and to save exported videos back to your library.
Permissions are requested only when a relevant feature is used and can be revoked at any time from your device settings. Revoking a permission disables the corresponding feature but does not affect your account.
10. Account deletion
You can delete your account at any time from Profile → Delete account in the app. We will email a 6-digit OTP code to your registered email address to confirm the request, and you must enter your password before account deletion is confirmed. Once confirmed:
- Account deletion will permanently delete your account within 90 days.
- After deleting, you cannot access your account.
- You may recover the account before deletion is completed by signing up again with the same email and verifying the OTP.
- When deletion is completed, your account record, transcription jobs, and associated metadata are permanently deleted.
Encrypted database backups may retain residual data for a short period after permanent deletion before being overwritten, after which all traces are removed.
11. Data retention
We keep your account data for as long as your account is active. Deleted account data is removed within 90 days as described in Section 10. Server logs are retained for a limited period for security purposes.
12. Security
All network traffic uses TLS encryption in transit. Passwords are stored only as bcrypt hashes (never plaintext). Access to the production database is restricted to the operator. While we take reasonable steps to protect your data, no system is 100% secure — if you discover a vulnerability, please report it to the contact email below.
13. Children’s privacy
SinCap is not directed to children under 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (you can edit your name and email from the app).
- Delete your data (see Section 10).
- Object to or restrict processing.
- Request a copy of your data in a portable format.
To exercise any of these rights, email thilinap.me@gmail.com. We will respond within a reasonable timeframe.
15. International data transfers
SinCap is operated from Sri Lanka and uses service providers (Microsoft Azure, MongoDB Atlas, Vercel, Google) whose infrastructure may process data in regions outside your country, including the United States and the European Union. By using the Service, you understand that your data may be processed in those regions under the terms of each provider.
16. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app or via email to your registered address. The “Effective” date at the top of this page indicates when the latest version took effect.
17. Contact
For any questions about this policy or your data, contact: thilinap.me@gmail.com.