Privacy Policy
Last updated:
1. Summary
There are two ways to compress a video here, and both keep it private.
- In your browser (the default when your device can do it): your video never leaves your device.
- On our server: your video is uploaded, or downloaded from a link you give us, only to be compressed. The original and the result are deleted 2 hours after compressing.
The same goes for the other tools (cutting, cropping, and converting to MP3 or GIF): wherever this page says “compress”, it covers them too.
Video to text always runs on our server: the video’s sound is sent to Cloudflare Workers AI, which turns the speech into text. The transcript is kept and deleted like any other result, 2 hours after it’s done.
You don’t need an account. We don’t sell data, show ads or track you across sites.
2. Who we are
Video Compressor (videocompressor.xyz) decides how the data described here is processed. Write to feedback@videocompressor.xyz about anything on this page.
3. Compressing in your browser
Your browser compresses the video on your device. Nothing about the video reaches us or anyone else.
- The video is not uploaded. We create no job record, it doesn’t count toward the daily limit, and no human verification runs.
- The result is kept temporarily in storage your browser sets aside for this site (the Origin Private File System). It is deleted when you cancel, start over or choose another video; anything left behind, older than 1 day, is cleaned up the next time you open the site.
- While it compresses, your browser’s session storage holds the file name, only to explain what happened if the page reloads unexpectedly. It is removed when compressing ends.
- The page and the compression code load from our site. Those requests show up in server logs and page statistics like any visit (see below), but they never contain your video or its name.
- If your browser can’t compress a video, we suggest our server instead. Nothing is uploaded until you press the button.
4. Videos from Google Drive or Dropbox
You can pick a video in Google Drive or Dropbox instead of on your device. Your browser then downloads it straight from Google or Dropbox and handles it like a video from your device: it is compressed in your browser or uploaded to our server as described in sections 3 and 6.
- The Google or Dropbox code loads only when you point at, tap or tab to one of their buttons. From then on, Google’s or Dropbox’s own privacy policy applies to what you do in their window.
- Google Drive: Google asks you to give this site access to only the files you pick (the
drive.filepermission, nothing else in your Drive); we only read them. The access token Google gives your browser stays in the page’s memory until you leave it; it is never stored or sent to our server. We use it only to download the video you picked. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. - Dropbox: Dropbox gives your browser a temporary link to the video you picked, which it downloads right away. We don’t keep the link and need no access to your account.
- We don’t save anything back to your Drive or Dropbox.
5. Videos from a link
You can paste an https link to a video file instead of uploading it. Your browser sends only the link. Our server then downloads the file from that address and handles it like an uploaded video, as described in section 6:
- We store the downloaded video and delete it like an uploaded one, and keep the link with the job record for as long as the record.
- The site behind the link sees a request from our server, not from you: our server’s IP address and a user agent naming this service. We send no cookies and nothing about you, and the site’s own privacy policy applies to what it logs.
- We only download what the link points to, once, and never follow it again for another compression.
6. What we process on the server, and why
We only process what we need to compress your video, keep the service working and stop abuse. The legal bases are Article 6(1)(b) GDPR (providing the service you ask for) and Article 6(1)(f) GDPR (our legitimate interest in security and preventing abuse).
Your video and the compressed result
- Why
- Compressing the video you upload or link to. Only when you compress on our server.
- Legal basis
- 6(1)(b)
- Kept for
- The original until 2 hours after its last compression ended (so you can try other settings), the result for 2 hours. A storage rule deletes anything left after 1 day.
The sound of a video you turn into text
Our server takes the sound out of the video, cuts it into pieces of a few minutes and sends them to Cloudflare Workers AI, which runs the Whisper speech recognition model and sends back the text. Nothing else about you or the video goes with it.
- Why
- Transcribing it, only when you use video to text.
- Legal basis
- 6(1)(b)
- Kept for
- We keep only the transcript, for 2 hours, like any result. The sound is deleted from our server when the job ends.
Job records
For each server compression: the id from your vc_owner cookie, the file name, size, type and length, the link you pasted (only for a video from a link), the settings you chose, the status and error code, and the times.
- Why
- Showing you your jobs, finding problems and counting jobs in total.
- Legal basis
- 6(1)(b) and 6(1)(f)
- Kept for
- 30 days. Database backups are deleted after 30 days too.
The vc_owner cookie
A random id, set only when you use our server. It is not linked to who you are.
- Why
- So only you can see your jobs, and to count your 5 videos a day.
- Legal basis
- 6(1)(b)
- Kept for
- 1 year in your browser.
Your IP address
Cloudflare passes it to us with each request, and Turnstile sends it to Cloudflare to check you’re human. We never store it in our database: each job keeps an HMAC-SHA256 hash made with a secret key on our server, which can’t be turned back into the address without that key.
- Why
- Human verification (Cloudflare Turnstile), limiting requests, and a cap of 20 server compressions per network a day.
- Legal basis
- 6(1)(f)
- Kept for
- Only as a keyed hash, with the job record, for 30 days.
Server logs
- Website logs (Cloudflare Workers Logs): the address, time and status of each request, the request details Cloudflare adds (which may include your IP address), and error messages.
- Compression server logs: the job id, the video’s technical details (resolution, length, codecs) and error messages. No IP address or file name. Once the job record is deleted after 30 days, they can’t be linked to anyone.
- Why
- Security and fixing errors.
- Legal basis
- 6(1)(f)
- Kept for
- Up to 7 days for website logs; compression server logs are rotated by size.
Page statistics
Plausible Analytics, which we run ourselves on our server in Germany, counts page views, the links you follow to other sites, and the steps of using a tool: adding a video, starting, finishing or failing, and downloading. For these it records only the tool, whether it ran on your device or our server, the kind of setting, the error code and roughly how much smaller the result is, never the file’s name, size or content. It works without cookies and without identifying you. It sees the page address, the referring site, your browser, operating system and country. Your IP address is only used, together with a secret that changes every day, to tell visits apart, and is never stored.
- Why
- Counting visits and uses to see which pages and tools work.
- Legal basis
- 6(1)(f)
- Kept for
- As counts on our own server; no profile of you is built.
Your browser also keeps three things in its local storage that are never sent to us: theme (light or dark mode), vc:jobs (the ids of your server jobs, so they continue after a reload; each is removed once the page sees it failed, was canceled or expired) and vc:locale-hint (that you dismissed the offer to show the site in your browser’s language). The site’s language comes from the address alone, like /es for Spanish; no cookie is set for it.
7. Download links
Only your browser, the one holding your vc_owner cookie, can ask for a result’s download link. The link itself works for anyone who has it for 1 hour, so please don’t share it.
9. Who processes data for us
- Cloudflare (United States): delivers the site, runs the website and its logs, stores uploads in its R2 storage in the European Union, runs Turnstile, and turns speech into text for video to text with Workers AI. Cloudflare’s privacy policy.
- Hetzner (Germany): the compression, database and page statistics servers, in Germany or Finland. Hetzner’s privacy policy.
Transfers outside the European Union rely on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework, which Cloudflare is certified under.
10. What we don’t do
- We don’t look at your videos, unless you report a problem with one and agree that we look.
- We don’t use your videos to train models, make them public or share them with anyone except the processors below, only to do what you asked.
- Compressed videos carry no metadata from the original: no location, camera or date.
11. Your rights
You can ask to see, correct or delete your data, and object to or restrict how we process it. Since there are no accounts, we can only find your data by its job id: the “Report this problem” link on a failed job includes it. Write to feedback@videocompressor.xyz. You can also complain to your data protection authority.
12. Children
The service is meant for people aged 16 and over.
13. Changes
When this policy changes, the date at the top changes too. We point out important changes on the home page.