Trust & data handling
A plain-English system boundary you can hand to your security team. Editing and export run on your device; we control the software you run, not your footage.
AetherCut is a browser application. When you import, cut, caption, and export a video, that work runs locally on your machine via the Web Audio and WebCodecs APIs. Your source media, project files, and rendered output are not transmitted to or stored by AetherCut for the core editing and export workflow. You can verify this yourself: open your browser's DevTools, switch to the Network tab, and edit — no outbound request carries your frames.
We want to be precise rather than market-y, because security reviewers will test the claim. "No cloud" would be imprecise — we serve the app from a CDN, and we run small optional services for accounts, licensing, and billing. What is true, in writing and in architecture, is this: no customer media is stored in our cloud for the core editor, and our telemetry never contains file contents or frames.
The honest exception is our optional AI tools. A few features — transcription, lip-sync, AI reshoot, and upscaling — genuinely need server-side inference, so when you choose to run one, the specific clip or audio you selected is sent to a named subprocessor (OpenAI/Whisper, fal.ai) for processing. These are opt-in, per-action, and never run on your media automatically. Privacy Mode disables every cloud AI tool in one click, giving you a verifiably zero-upload editor.
What stays on your device
All core editing operations — trimming, splitting, transitions, filters, text and titles, the audio mixer (gain, pan, compression, LUFS loudness), and the final export — execute in your browser. The media never leaves your machine for any of these.
Local project save/resume uses your browser's IndexedDB. Your timeline and media references live in your own browser storage, not on our servers.
What is in scope for a security review
The system we operate and audit is: distribution of the application (static hosting, CDN, DNS, TLS); optional account, license, and billing services; authentication for unlocking export; privacy-safe, event-level analytics and error reporting; and the corporate and vendor systems (source control, CI/CD, release publishing, identity provider) that can change what you execute.
The threat model for a zero-upload tool is supply chain and publish-access — i.e. us shipping a compromised build — not a video bucket. Our controls focus there: protected release path, required review, pinned dependencies, SSO + MFA on every system that can publish or change DNS, and a code-review rule that telemetry may never attach media.
Optional AI tools and Privacy Mode
Transcription (Whisper), lip-sync and reshoot (fal.ai), and upscaling are cloud-AI features. Running one uploads only the specific media you selected, only when you trigger it, to the named subprocessor for that feature. We do not retain that media beyond the processing call.
Privacy Mode is a one-click kill switch in the editor that disables every cloud-AI tool. With it on, AetherCut makes no outbound request carrying any media — the core editor is fully local.
Telemetry: what we measure
Our analytics are event-level only: an allowlisted event name (e.g. a funnel step or feature open) and a few short, opaque tags (tool ids, experiment variant labels). Both the client and the server strip and reject anything resembling an inline media payload, so file bytes and frame buffers can never ride along with a metric.
We do not collect your video, audio, transcripts, or project contents in analytics or crash reports.
Subprocessors
We rely on a small set of vendors, each with their own compliance posture: a CDN and DNS provider (app delivery), a payments processor (Stripe) for billing, an email provider (Resend) for transactional mail, an error/analytics tracker for privacy-safe telemetry, and the AI inference providers (OpenAI, fal.ai) used only by the opt-in AI tools.
We collect each subprocessor's SOC 2 or equivalent report annually and carve them out as subservice organizations rather than claiming their controls as our own.
Frequently asked questions
Is my video uploaded when I edit or export?
No. Core editing and export run in your browser; your media is not transmitted to or stored by AetherCut. You can confirm it in DevTools → Network: no request carries your frames. The only exception is the opt-in AI tools, which upload only the clip you select, only when you run them.
What if I never want anything to leave my machine?
Turn on Privacy Mode. It disables every cloud-AI tool in one click, leaving a fully local editor that makes no outbound request carrying any media.
Do your analytics or crash reports contain my footage?
No. Telemetry is limited to allowlisted event names and short opaque tags. Both the browser and our server reject anything that looks like media, so file contents and frames never travel with a metric.
Can I get your SOC 2 report?
We scope a Security-criteria SOC 2 around the software we ship and who can change it. Enterprise buyers can request the current report or our system description through our contact channels.
Try AetherCut now — no signup required.
Open the editor and verify the no-upload claim yourself in Chrome DevTools.
Free tier · Pro $14.95/mo · $129.88/yr · Lifetime Pro one-time
Other comparisons + resources
Related searches
AetherCut answers for all of these search intents — pick the one closest to what you're looking for:
No signup. No upload. Verify privacy in DevTools in 30 seconds.