Privacy Policy
Last updated: 13 August 2026
The short version
Your video never reaches us, and neither do your recordings. Both stay in your browser and travel directly to the other players in your room. There is no database table for them, because there is nothing to put in it.
The exception is the audio, and we want to be precise about it. To work out which lines are worth dubbing, the audio track alone is extracted in your browser, downmixed to mono at low quality, and sent for analysis. It passes through our server in memory for the length of a single request, is never written to disk by us and never logged. The video is not sent anywhere.
That audio reaches two specialist processors under contract to us: a speaker-diarisation provider, which works out who is speaking and when, and a speech-to-text provider, which supplies word timings. A third, a large language model provider, reviews the result and decides which lines belong together — it is sent the text of those lines and never the audio. All three are established commercial API vendors, bound by their own data-processing terms, and none of them is sent anything identifying you or your room. We will name any of them on request — write to us at the address at the bottom of this page.
We do keep two things derived from that audio, so the same clip does not have to be analysed twice. The first is a one-way fingerprintof the low-quality audio — a SHA-256 digest, from which the audio cannot be reconstructed and which tells us nothing about what was said. The second is the result: the line timings, and any dialogue text the analysis transcribed. Together they let a clip somebody has already played start immediately instead of being scanned again.
These are kept for three days, extended to 90 days if a round is played through to the end, and then deleted automatically. They are keyed by the fingerprint alone — not to you, your account, or your room. The analysis audio itself is still never stored, and neither is the video.
Background audio, if your room uses it
A round can play the clip's soundtrackunderneath the new dialogue instead of turning it down. Producing that means sending the clip's audio track to a separation service, which returns the same soundtrack with the original speech removed— the music, the effects, the room tone, and no voices.
We store that dialogue-removed audio for 90 days, so the next room to play the same clip does not have to wait for it to be produced again. This is the one thing derived from your media that we keep as audio rather than as a description of it, and we want to be exact about what it is and is not:
- It is the clip's background with the spoken dialogue taken out. It is not the video, not your microphone, and not the dub your room recorded.
- It is filed under a one-way fingerprint of the audio it came from, not under your name, your account, or your room. We cannot look up what a given person separated.
- Its address is unguessable but it is not password-protected, because every player's browser has to fetch it directly. Anyone holding the link can play it until it expires.
- It is deleted automatically after 90 days. If your room does not use background separation, none of this happens at all.
Without this, the same audio would still be sent for separation — it would simply sit on the separation service's own servers instead, where we could not control how long it lasted or when it went.
What we actually store
- Account details — your email address and display name, and the identifier from whichever sign-in provider you used. Only for people who create an account.
- Billing records — subscription status and identifiers from our payment processor. We never see or store card numbers.
- Compliance records — copyright notices, abuse reports, and enforcement decisions, including a timestamped record that a host confirmed they had the rights to a clip. That record contains the confirmation and the room reference. It does not contain the file, its name, or any fingerprint of it.
- Operational logs — IP addresses and request metadata for rate limiting and abuse prevention, retained briefly.
- Analysis results — a one-way fingerprint of the analysed audio, together with the line timings and transcribed dialogue it produced. Kept so a clip is not scanned twice: three days, or 90 days if a round was played through. Not linked to you.
- Background audio— for rounds that use background separation, the clip's soundtrack with the spoken dialogue removed, filed under a one-way fingerprint of the audio it came from. Kept 90 days so the same clip is not separated twice, then deleted. Not linked to you. See above for the detail.
- Scene library — when you open a clip, a one-way fingerprint of the video file is sent so we can show you markings other people have shared for that same file. A marking is a list of line timings and which character speaks each one. It contains no dialogue: any text you typed on a line is removed before a marking is shared, and the video itself is never sent.
The fingerprint is a SHA-256 digest. The file cannot be reconstructed from it, but it does identify that file — it is what tells us which markings belong to the clip you have open. If you publish a marking it is stored with your account so it can be attributed to you and counted; simply opening a clip stores nothing. - Published clips — if you choose to publish a clip to the scene library, that video file is uploaded and stored so other people can play the same scene. This is the only video we ever hold, it happens only when you publish, and it never happens for an ordinary round.
It is stored against your account, so it can be attributed to you and so a takedown can be acted on. Delete it, or ask us to, and the file is removed from our storage; copies may persist briefly in caches and backups until they expire. Your recordings and the finished dub are never uploaded, published or not.
What we never store
- Video from an ordinary round, in any form. The single exception is a clip you deliberately publish to the scene library — see above. If you never publish, we never hold a frame.
- The audio sent for analysis. It exists in memory for one request and is discarded.
- Any recording of the original speech in your clip. Separation keeps the soundtrack and discards the voices; the dialogue is the part that is thrown away, not the part that is kept.
- Microphone recordings, or any part of them.
- Mixed or dubbed results.
- File names, or the contents of any file.
Your microphone
Your browser will ask permission before the microphone is used. Audio is captured only during the recording phase of a round, only for the lines assigned to you, and is held in your device's memory. It is sent directly to the other players in your room so the result can be played back, and it is discarded when the session ends. It is never sent to us.
Session data
Room state — who is in a room, whose turn it is, the timestamps of the marked lines, and vote tallies — is held in temporary storage with an expiry and is deleted when the room ends. The timestamps describe when speech occurs in a clip; they contain no audio and nothing identifying the source material.
Clip analysis
When a host chooses a clip, its audio is analysed so the game knows who speaks and when. We send only mono, low-sample-rate audio — never the video, and never anything identifying you or the room. While it is being processed it is subject to each provider's handling of API data.
- A speaker-diarisation provider — separates the clip into who is speaking and between which moments. This is the part the round is built on. It receives the mono audio.
- A speech-to-text provider — supplies word-level timings so the lines can carry captions. It receives the mono audio.
- A large language model provider — reviews the finished lines and suggests which to merge or drop. It receives the text, not the audio.
- An audio source-separation provider — only for rooms using background separation, and only then. It receives the mono audio. Described above.
These are categories rather than company names. Every one is a contracted commercial API vendor operating under its own data-processing terms, and none receives your account, your email, your room code, or anything else that identifies you. If you want to know exactly which companies these are — because you are assessing us for a business, or because you simply want to know where your voice went — ask and we will tell you.
Hosts can skip analysis entirely and mark the lines by hand, in which case no audio leaves the device at all.
Connection relays
When two players cannot connect directly, their connection may be routed through a third-party relay. This is automatic and transient. The relay does not inspect, log, or retain what passes through it.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold. Because we hold so little, this is usually your account record and any compliance records. Contact us at support@postemply.com. Deleting your account removes your account and billing records; compliance records may be retained where we are required to keep them.
Children
PartyDub is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect their data.