Privacy policy
Duxo is designed so that your recordings never have to reach us. This page explains exactly what we hold, what we do not, and what happens the moment you choose to publish something.
Last updated 24 August 2026
01
The short version
Duxo is built so that your video never has to reach us. Recording, editing and encoding all happen inside your browser on your own machine. We hold the small amount of data needed to run an account and a subscription, plus anything you explicitly choose to publish.
- Your screen recordings are not uploaded to us, and we cannot watch them.
- We store your email address, a hashed password, and your plan status.
- We never see or store your card details — Stripe and Paystack handle payment.
- If you use the AI copilot, still frames from your recording are sent for processing.
- If you publish a how-to, that article and its screenshots are stored and served by us.
- If you publish to YouTube, the video goes from your browser straight to Google.
- We run no advertising trackers and no third-party analytics.
The sections below explain each of these precisely. This summary is for orientation; the detail is what governs.
02
Who this policy covers
This policy applies to Duxo at https://demo-studio-ten.vercel.app — the marketing site, the account system and the studio application. It describes what we collect, why, and what you can do about it.
For questions or requests, contact hello@duxo.app.
03
What we collect
We collect only what a given feature needs in order to work.
- Account details
- Your email address, an optional display name, and a one-way bcrypt hash of your password. We cannot read your password.
- Subscription status
- Your plan, billing interval, currency, renewal date, and a reference to the checkout that created it.
- Copilot inputs
- When you run the AI copilot, still frames extracted from your recording and any context note you type are sent to our server and passed to Anthropic's API to generate the article.
- Published how-tos
- If you publish a how-to guide, its text and the screenshots it uses are stored in our database and served at a public link so your blog can embed it.
- YouTube connection
- If you connect a channel, we store the access and refresh tokens Google issues, plus the channel name so we can show you which account is connected.
- Server logs
- Standard request logs from our hosting provider, including IP address and user agent, used for security and debugging.
04
What we do not collect
These are worth stating explicitly, because they are the things people reasonably assume a screen recorder would take.
- Your screen recordings. Capture, editing and encoding run entirely in your browser. Unless you publish a how-to or upload to YouTube, no video or audio ever leaves your machine.
- Your project files. Saving a project writes a file to a folder you pick on your own computer, using your browser's file access permission. We never receive it.
- Your card number, CVV or bank details. Payment pages are hosted by Stripe and Paystack; we receive only the outcome.
- Anything else on your Google account. The YouTube permission we request is upload-only, so we cannot read, edit or delete your existing videos, playlists or subscriptions.
- Advertising identifiers, cross-site tracking data, or third-party analytics profiles.
05
Google and YouTube data
Publishing to YouTube uses the YouTube Data API. By connecting a channel you are also agreeing to the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We request a single scope, youtube.upload, which permits uploading videos and nothing else.
- Tokens are used only to start an upload you have asked for. We do not use them for advertising, we do not sell them, and no human at Duxo reads them.
- The video file itself is transferred directly from your browser to Google. It does not pass through, and is not stored on, our servers.
- You can disconnect the channel at any time from the Publish menu in the studio, which deletes the stored tokens.
You can also revoke our access independently at myaccount.google.com/permissions.
06
The AI copilot
The copilot turns a recording into a written guide. To do that, it needs to see the recording — so when you run it, Duxo extracts still frames from your video in the browser and sends those frames, together with any context you typed, to our server, which forwards them to Anthropic's API.
- This only happens when you press the copilot button. Simply recording or editing sends nothing.
- Only still frames are sent — not the video file and not your audio.
- We do not retain the frames after the article is generated; they are held in memory for the duration of the request.
- Anthropic processes the frames as our service provider under its own commercial terms and does not use them to train models.
If a recording shows information you would not want processed by a third party, do not run the copilot on it.
07
How-tos you publish
Publishing a how-to is what makes it embeddable, and that necessarily means we host it. When you publish:
- The article text and its screenshots are stored in our database.
- They become available at a public URL, so any site you paste the embed into can load them.
- The link is unguessable but not secret — anyone who has it can view the guide.
- The embed page is marked noindex, so it does not compete with your own post in search results.
Do not publish a guide containing confidential material. If you need a published guide removed, email us and we will delete it.
08
How we use what we collect
- To create and authenticate your account.
- To apply your plan's limits and to process and renew your subscription.
- To generate and host the content you explicitly ask us to generate or host.
- To upload a video to your YouTube channel when you ask us to.
- To keep the service secure, diagnose faults and prevent abuse.
- To send you service messages about your account or a payment. We do not send marketing email.
We do not sell personal data, and we do not share it for advertising. Where the GDPR applies, our legal bases are performance of a contract (running your account and subscription), legitimate interests (security and fault diagnosis), and consent (optional features such as the copilot and YouTube publishing, which you initiate).
09
Who processes data on our behalf
We keep the list short, and every entry is here because a feature needs it.
- Vercel
- Hosting and server logs for the website and API.
- MongoDB Atlas
- Database for accounts, subscriptions and published how-tos.
- Stripe
- Card payments in USD, GBP and EUR.
- Paystack
- Card and bank payments in NGN, GHS, KES and ZAR.
- Anthropic
- Processes the still frames sent to the AI copilot.
- Google / YouTube
- Receives a video only when you publish one to your own channel.
10
How long we keep it
- Account details
- Until you delete your account.
- Subscription records
- Retained after cancellation where needed for tax and accounting.
- Copilot frames
- Not retained — held only for the duration of the request.
- Published how-tos
- Until you or we delete them.
- YouTube tokens
- Until you disconnect the channel or delete your account.
- Server logs
- Short-term, per our hosting provider's retention window.
11
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict what we do with it. Email hello@duxo.app and we will respond within 30 days.
Deleting your account removes your account record, your YouTube tokens and your published how-tos. It does not affect anything already saved on your own computer, or any video you already uploaded to your own YouTube channel — those are yours and remain under your control.
If you are in the UK, EU or another region with a data protection authority, you also have the right to complain to it.
12
Security
- Passwords are stored as bcrypt hashes and are never recoverable in plain text.
- All traffic runs over HTTPS.
- Sessions use signed JSON Web Tokens in an HTTP-only cookie.
- Payment provider webhooks are verified by signature before we act on them.
- The architecture itself limits exposure: because your recordings stay on your machine, a breach of our systems could not expose them.
No system is perfectly secure. If you find a vulnerability, please report it to hello@duxo.app rather than disclosing it publicly.
14
International transfers
Our providers operate globally, so your data may be processed outside your country, including in the United States and the European Union. Where required, transfers rely on Standard Contractual Clauses or an equivalent safeguard offered by the provider.
15
Children
Duxo is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
16
Changes to this policy
If we change how we handle data, we will update this page and the date at the top. Material changes will also be sent to the email address on your account. Continuing to use Duxo after a change means you accept the updated policy. This version is dated 24 August 2026. See also our terms of service.
Questions about this document? hello@duxo.app