Last updated 26 August 2026

Privacy Policy

KinoPipe processes the media you send it and the account data needed to run jobs and bill for them, nothing more. This page says exactly what is collected, how long it stays, who processes it and how to exercise your rights.

Who we are

KinoPipe (kinopipe.com) is FFmpeg as a service for AI agents and developers. It is built and operated by Nicolas Coutureau, an independent developer based in France, who is the data controller for the personal data described here.

This policy covers the website, the dashboard and playground, the REST API and the hosted MCP server. It applies whether you use KinoPipe directly or through an AI client such as Claude, Cursor or n8n. Questions or requests go to support@kinopipe.com.

What we collect

Account data. Your email address, a password (stored hashed by our authentication provider; we never see it), an optional display name, and sign-in events with the IP address and browser used. Sign-in by magic link sends a one-time code to your email.

Media you send. Files you upload directly, the URLs you pass as inputs (our workers fetch them to run the job), and the outputs produced. For each file we record its filename, MIME type, size, duration and dimensions.

Job data. The recipe of each job (operations, parameters and input URLs), its status and progress, error messages, the credits it consumed, and timestamps.

Edit descriptions. Text you type in "Describe the edit" or send to the recipe suggestion endpoint. The text is sent to Google's Gemini API to be turned into a recipe. Your media is not sent with it.

API keys and connected clients. API key secrets are stored hashed and shown to you once; we keep the key name, prefix, creation, expiry and last-used times. When an AI client connects through OAuth, our authorization server records the client you approved and the tokens issued to it.

Billing. Your plan, subscription status and the customer and subscription identifiers assigned by Polar, our payment provider. Card details are entered on Polar's checkout and never reach KinoPipe.

Usage and technical data. Request logs (IP address, user agent, path, status, timing) kept by our hosting provider for security and debugging, per-account rate-limit counters, and analytics events described under cookies and analytics.

Support. What you write in the support chat, plus your account email when you are signed in so we can find your jobs.

How we use it

  • To run the service: accept your inputs, execute the job you asked for, store the output and serve its download link. Legal basis: performance of our contract with you.
  • To keep accounts safe: authentication, abuse prevention, rate limiting, fraud detection, and blocking requests to private networks from our workers. Legal basis: legitimate interest in a secure service.
  • To bill you: credit accounting, subscriptions, and automatic refunds of failed jobs. Legal basis: contract and legal obligations.
  • To help you: answering support requests. Legal basis: contract and legitimate interest.
  • To improve KinoPipe: aggregated usage statistics and error rates. Analytics cookies are used only with your consent where the law requires it. Legal basis: consent or legitimate interest, depending on your location.

We do not sell personal data. We do not use your media or outputs to train machine-learning models, and we do not look at them except to debug a job you have reported or when the law requires it.

Where it lives and how long

  • Direct uploads are deleted automatically 24 hours after upload.
  • Inputs passed by URL are fetched onto a worker for the duration of the job and discarded when it ends. We do not keep a durable copy.
  • Outputs are stored in Cloudflare R2 and served through cdn.kinopipe.com. Download links work for up to 12 months, and outputs are retained no longer than that. Ask us to remove an output sooner and we will.
  • Worker scratch files are ephemeral: the worker's disk is wiped when the job finishes.
  • Job records and file metadata are kept for as long as your account exists so your job history and billing stay consistent, then deleted with the account.
  • Account, billing and API key records are kept for the life of the account, plus what tax and accounting law requires for invoices.
  • Request logs are held briefly by our hosting provider; support conversations are kept in the support tool until we close them out.

Media is stored in Cloudflare R2 in North America. Jobs run on GPU and CPU workers operated by RunPod and Google Cloud, in the United States and the European Union. Account data lives in Supabase. Where data leaves the European Economic Area, our providers rely on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.

Who processes it for us

KinoPipe runs on a small set of providers, each acting on our instructions:

ProviderWhat it doesData involved
SupabaseAuthentication, OAuth authorization server, databaseAccount data, job records, API key hashes, connected clients
CloudflareR2 object storage, CDN, DNSUploaded inputs, outputs
VercelHosting of the website, API and MCP serverRequest logs, job payloads in transit
RunPodFFmpeg workers (GPU and CPU)Inputs and outputs during a job
Google CloudFallback FFmpeg workers; Gemini API for edit suggestionsInputs and outputs during a job; edit description text
PolarPayments, invoicing and subscriptions (merchant of record)Email, billing details, plan
CrispSupport chat, loaded only when you open itMessages, email when signed in
Google AnalyticsUsage analytics, subject to consentPseudonymous usage events

Beyond these providers we disclose data only when the law requires it, to protect the service or its users from abuse, or to a successor if KinoPipe changes hands, in which case you will be told first.

Output links. A download link is unguessable but not private: anyone who has it can download the file until it expires. Treat links to sensitive outputs accordingly.

Cookies and analytics

KinoPipe sets the cookies needed to keep you signed in and to remember your analytics choice. Nothing else is strictly necessary.

We use Google Analytics 4 in consent mode to understand which pages and tools are used. In the EEA, the UK and Switzerland no analytics cookie is set until you accept the banner; without consent Google receives only cookieless, aggregated pings. Elsewhere analytics is on by default. In every case you can change your choice at any time with "Analytics preferences" in the footer. We do not use advertising cookies.

AI agents and MCP connections

When you connect KinoPipe to an AI client (Claude, Cursor, n8n and others) over MCP, the client registers as an OAuth application with our authorization server and you approve it on a consent screen signed in to your KinoPipe account. The tokens issued let that client create and read jobs on your account; the jobs stay attached to you, not to the client.

We do not receive your conversation with the AI. We receive the tool calls the client sends: the operation, its parameters and the media URLs. To disconnect, remove the connector on the client's side, or ask us at support@kinopipe.com to revoke its access. See the connection guide for the clients we support.

Your rights

Under the GDPR and similar laws you can ask to access, correct, export or delete your personal data, object to or restrict certain processing, and withdraw consent at any time. You can revoke API keys yourself from the dashboard. To delete your account and everything attached to it, email support@kinopipe.com from the address on the account; we confirm once it is done.

If you believe we handle your data unlawfully you can complain to the CNIL (cnil.fr) in France or to the supervisory authority where you live.

Security

All traffic uses TLS. Passwords and API key secrets are stored hashed. Uploads and downloads use signed, expiring URLs. KinoPipe never runs shell commands from user input: every request is a typed operation validated before it reaches a worker, and workers cannot reach private networks. No system is perfectly secure; if you find a problem, please report it to support@kinopipe.com and we will respond quickly.

Children

KinoPipe is not directed at children and we do not knowingly collect data from anyone under 16. If you think a child has created an account, tell us and we will delete it.

Changes to this policy

When this policy changes we update the date at the top of the page. For material changes, such as a new provider handling your media, we also notify you by email or in the dashboard before they take effect.

Contact

Nicolas Coutureau, operating KinoPipe, France. Email: support@kinopipe.com. The in-app support chat reaches the same person.