Customer information
Privacy Notice
This notice explains what information Millwards Studio handles when you edit, analyse or export clips, manage a subscription, or contact support.
Last updated: 22 July 2026
1. Who we are
Millwards Studio is operated by Mackenzie Millward, a sole trader trading as Millwards Studio, whose business address is 698 Harvey Road, Derby, DE24 0EG, United Kingdom (referred to as “Millwards Studio,” “we,” “us,” or “our”).
For data-protection questions or to exercise a privacy right, contact support@millwards.website. We have not appointed a data protection officer. Paid Pro subscriptions are currently limited to UK customers. Before selling in another market, we will assess and publish any additional privacy requirements.
2. Information we handle
Account and contact information
To create an account, we require an email address and password. We store a password hash rather than the password itself, together with authentication identifiers, verification status, security records, and records of Terms and Privacy Notice acceptance. Payment information is required only for Pro.
Video and project information
The editor processes previews, edits, and Free 720p exports locally in your browser. Project names and settings, editing choices, captions, brand-kit defaults, content-planner entries, and performance figures you enter manually may be stored on your device using browser storage. Saving those browser-local details does not by itself send them to us. Clearing site data or changing devices may remove them.
If a signed-in, verified customer deliberately chooses Save project, we upload the selected source in integrity-checked chunks and store it with the project's edit settings in private, account-owned storage. The current allowance is 1 GiB in total on Free and 5 GiB on Pro, with a 1 GiB maximum source file and up to 50 saved projects. Opening or editing a local file does not trigger this upload. A saved source is available only through an authenticated owner request and may be reused for an AI analysis or Pro export that you request without another browser upload. You can delete an individual saved project in the Projects workspace. This feature is for continuing work, not a backup service, so keep your original files and finished exports.
If you deliberately request a Pro 1080p export from a local source that has not been saved, we upload it temporarily in integrity-checked chunks together with the selected trim, layout, framing, and caption instructions. If the source is already saved, the service makes a temporary private rendering copy instead. We use that information only to validate and create the requested MP4, make it available to your authenticated account for a short time, enforce limits, diagnose failures, and protect the service. The interface shows when an upload begins.
If a verified customer imports a direct media-file URL, our private German server requests the HTTPS URL, validates the resulting MP4, MOV, or WebM file in an isolated media sandbox, and transfers it once to the customer's browser. The source host receives our server address rather than the customer's browser address. The temporary import copy is deleted after transfer; if a web process is interrupted, an automatic cleanup normally removes the abandoned copy within one hour. We keep no import project backup.
Pro AI analysis information
When you request Pro AI analysis, we temporarily process the selected local or saved source, extracted audio, and video frames on our private German server to create an editable transcription draft, transcript timestamps and highlight suggestions, and subject-following crop suggestions. Analysis working copies are separate from any source you chose to keep as a saved project. Subject tracking estimates the position of a visible subject; it does not identify people or create biometric templates. We also keep pseudonymous account and billing-period usage totals to enforce the included allowance. Full media and transcripts are not sent to a hosted generative-AI service while that separate provider gate remains disabled, and we do not use customer content to train our own models.
Subscription and transaction information
Stripe handles checkout and payment-card information. We may receive your Stripe customer and subscription identifiers, plan, subscription status, renewal dates, billing address, the UK customer address collected to enforce current UK-only availability, tax status, limited payment-method details, invoices, and payment outcomes. We do not need to receive your complete card number.
Support, email, and technical information
If you contact us, we handle your message, attachments, and our response. Our email-delivery service may process recipient addresses and delivery events. Our servers may also record IP address, user agent, timestamps, route requested, errors, and security events to operate and protect the service.
The site uses browser-local storage for project settings, brand preferences, planning entries, manually entered performance figures, and related workspace choices, plus a first-party security cookie for account sessions and request protection. The cookie is session-only before sign-in and may persist for up to 30 days after account authentication. It is not used for advertising or cross-site tracking.
Connected TikTok, Instagram, and YouTube accounts
When connected-account publishing is enabled and you choose to connect a platform, we receive the platform-scoped account identifier, account or channel display information needed to show the destination, permissions granted, access-token information, and connection status. We encrypt provider credentials at rest. For a publishing action you expressly request, we also handle the finished clip, the title or caption and settings you approve, transfer and processing identifiers, and the provider’s result. We do not use connected-account data for advertising, profiling, or AI-model training, and we do not publish silently.
3. How and why we use information
We use information to:
- create and secure accounts, remember preferences, privately store projects you choose to save, provide the editor, perform AI analysis you request, and create exports you request;
- connect a TikTok, Instagram, or YouTube account you authorise, display the selected destination, carry out a publishing action you expressly confirm, report its status, and disconnect or delete the connection when requested;
- check UK eligibility and start, administer, and support subscriptions and trials;
- send service messages such as verification, billing, security, and support emails;
- diagnose faults, prevent fraud and abuse, enforce usage limits, and improve reliability;
- meet accounting, tax, dispute, and other legal obligations.
We rely on contract where processing is necessary to create and secure an account, store and retrieve a project you deliberately save, provide requested editor, AI-analysis, and export features (including a requested Pro analysis or render), administer a trial or subscription, provide support, and send essential service messages. We rely on our legitimate interests to prevent fraud and abuse, protect accounts and the service, diagnose faults, maintain limited operational records, and establish or defend legal claims, after considering the effect on your rights. We rely on legal obligation where information is needed for tax, accounting, regulatory, court, or data-protection duties. We do not currently use account information for optional marketing.
4. Who receives information
We do not sell your personal information. We disclose only what is reasonably needed to:
- Stripe, for checkout, recurring billing, fraud prevention, tax features, and the customer billing portal;
- Resend and our email provider, for transactional email delivery and support correspondence;
- TikTok, Meta/Instagram, or Google/YouTube, only when you choose to connect the relevant account or expressly request a platform publishing action;
- hosting, database, monitoring, and security providers, to operate and protect the service; and
- professional advisers, authorities, or a successor operator, when required for legal claims, compliance, a business transaction, or protection against harm.
Production hosting and Pro AI analysis are provided on our server with netcup GmbH in Germany (EEA). We rely on the United Kingdom’s adequacy regulations for this EEA hosting. Stripe may process payment and fraud information in several countries under its own privacy terms. Resend’s primary processing operations are in the United States. TikTok, Meta/Instagram, and Google/YouTube may process an authorised connection or requested publishing transfer in countries described in their own privacy information. The separate hosted generative-AI provider gate remains disabled and receives no full media or transcripts.
For a restricted transfer by Stripe or Resend, we rely on the transfer terms in the relevant supplier data-processing agreement, including the EU standard contractual clauses together with the UK International Data Transfer Addendum where applicable, plus the supplier’s technical and organisational safeguards. You may ask us for more information or a copy of the relevant safeguards, subject to necessary redactions, by emailing support@millwards.website.
Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. Google’s own handling is described in the Google Privacy Policy.
5. How long we keep information
The editor stores recent browser-local project details and preferences until you clear its site data or the browser removes them. A source and edit settings that you explicitly save to your account are kept until you delete that saved project or your account is deleted. Incomplete saved-project uploads and failed saved-project media are normally removed within 24 hours. Deleting a saved project frees its storage allowance immediately. If Pro ends while stored use exceeds the Free allowance, existing saved projects remain available to open or delete, but new source uploads are blocked until use is within the current allowance. Saved projects are not a backup: keep your original files and finished exports.
A temporary direct-link import copy is deleted after its one-time transfer to the browser; an interrupted copy is normally removed within one hour. For a requested Pro render from an unsaved local source, an incomplete upload normally expires within six hours; temporary source chunks and the assembled rendering source are deleted after successful processing; a failed job’s media is normally deleted within 24 hours; and a completed MP4 is normally available for no more than 24 hours. A saved source remains until you delete its project, while the separate temporary render copy follows those render periods. Minimal render-job metadata, such as account, status, size, timestamps, and integrity hashes, is normally removed within 30 days after expiry.
For successful Pro AI analysis, the analysis copy of the source and its extracted audio and frame working files are deleted immediately after results are returned. Abandoned or failed AI jobs and any residual result artifacts are deleted within 24 hours. Results used in a saved project remain with that project's edit settings until the project is deleted; otherwise they remain in your browser. Pseudonymous, content-free AI usage totals are kept for up to 12 months to enforce and audit allowances.
Account and authentication information is kept while an account remains open. Unverified abandoned accounts are removed after 30 days. Following a verified deletion request, account information is deleted or anonymised within 30 days, except limited subscription, payment, policy-acceptance, tax, accounting, dispute, and legal records that may be retained for up to six years after the relevant accounting period, or longer where law or an active claim requires it. Verification links expire after 24 hours and password-reset links after one hour; their records are removed within 30 days after expiry or use. Pseudonymous rate-limit records and routine server logs are normally kept for no more than seven days. Support correspondence is normally retained for 24 months after the last meaningful contact. Local backups are replaced within 31 days. Suppliers apply their own disclosed retention periods.
Connected-platform tokens and ordinary account data are kept only while needed to provide an authorised connection. Using Disconnect removes the local connection and requests provider revocation; a verified connected-platform deletion request is normally completed within seven days. We refresh or delete stored non-statistical YouTube API data within 30 days where YouTube’s rules require it, and delete remaining local YouTube data within 30 days after we learn that access was revoked at Google. A video already published remains in the platform account until the account holder removes it there. See our Data Deletion Instructions.
6. Your choices and rights
You can manage billing and cancel a subscription through the customer portal. Saving a project and requesting AI analysis are optional and happen only when you choose them. You can delete an account-stored project from the Projects workspace. You can remove browser-local project settings, AI results, brand defaults, planning entries, performance figures, and preferences through your browser’s site-data settings; planner and performance entries can also be removed in the workspace. When connected-account publishing is available, you can use Disconnect and can also remove Google access through your Google Account’s third-party connections. Follow our Data Deletion Instructions for a connected-platform or complete account deletion request. Use the contact details below for account correction, deletion, or other privacy requests.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, withdraw consent, or complain to a regulator. These rights can have legal exceptions. Send requests to support@millwards.website; we may need to verify your identity.
You have a specific right to object to processing based on our legitimate interests. If you object, we will stop the relevant processing unless we demonstrate compelling legitimate grounds or need it for legal claims.
Privacy complaints
Email support@millwards.website with the subject “Privacy complaint.” Include the account email, a clear description of your concern, the outcome you want, and any relevant dates or references; do not send passwords, complete card details, or unnecessary identity documents. Mackenzie Millward handles the complaint as data controller. We aim to acknowledge it within two business days and will investigate impartially.
We will respond without undue delay and normally within one month after receiving a privacy rights request. If a request is complex or you make several requests, the law may allow up to two additional months; if so, we will explain the extension within the first month. You may reply to ask for an internal reconsideration of the response.
If you are in the United Kingdom, you may complain to the Information Commissioner’s Office (ICO) at any time. You do not have to complete our complaints process first. Details are available at ico.org.uk/make-a-complaint/. If you live elsewhere, you may also have the right to complain to your local data-protection authority.
7. Security and age limits
We use technical and organisational safeguards intended to protect information, but no internet service is completely secure. Keep your sign-in details confidential and tell us promptly if you suspect unauthorised access.
The service is not directed to children below 18. If a parent or guardian believes a child supplied information contrary to the applicable requirements, they should contact us.
8. Changes and contact
We may update this notice as the service or law changes. We will post the revised version here and provide additional notice where appropriate. The “last updated” date identifies the current version.
Privacy contact
Mackenzie Millwardtrading as Millwards Studio
698 Harvey Road, Derby, DE24 0EG, United Kingdom
Email: support@millwards.website