Toast is an AI-powered video and audio editor, operated by Arnanda Technologies Private Limited ("we", "us", "our"), a company registered in India and the data controller for the information described below. We are committed to protecting your privacy, especially when it comes to your content.
Privacy Policy
Last updated: September 7, 2026
1. Overview
2. Video Privacy — Our Core Principle
Your video never leaves your device. Every frame is decoded, edited and exported in your browser using WebCodecs, FFmpeg.wasm and MediaPipe. Video files live in your browser's Origin Private File System (OPFS) and are never uploaded to Toast's servers or to any third party.
Audio is the deliberate exception. Turning speech into words with timings cannot happen on your device, so we extract the audio track and send it to the providers named below — and for a video built from a voiceover, the file you upload is audio, so that file is what gets sent. Section 3 lists everything that leaves and why.
3. What Data We Process
- Audio for transcription and noise removal: To transcribe your recording and optionally remove background noise, we extract the audio track and send it to our transcription and audio-isolation providers. Only the audio is transmitted — never the video.
- Transcript text for AI editing: The transcript produced from your audio (text and timestamps, plus the editing instructions you provide) is sent to our AI language-model providers so Toast can suggest cuts, captions, and effects, and so it can plan the graphics, zooms and on-screen words that change every few seconds. For that plan your browser also sends the timing of each spoken word to Toast's own server, which uses it to time each graphic to the word it lands on; the word timings are not passed on to the AI providers. Nor are the times of your edit's cuts: so a transition can be placed on a cut, the providers are shown only which words are said just before and just after each one — words already in the transcript. If you enter a speaker name and role on a project, that name and role are sent with the transcript for the same plan, so a lower third can show them; leave them empty and no name is sent or shown. This is text only — no video or audio frames are sent to these providers.
- Transcript text for planning a faceless video: For a video built from a voiceover, the same transcript is used for two further purposes, and both send it to the same AI language-model providers. First, to work out who and what recurs in your script, so the same person or object can be drawn consistently. Second, to plan the picture for every moment of the video — which means the transcript is sentwith its sentence timings, because every scene boundary is derived from when a line is actually spoken. Still text and timestamps; still no audio or video. When your script was a production document, both steps also send the notes you wrote in it about the pictures — the style note, the image notes and any cast descriptions — so that a place, a thing or a person is described in your words rather than guessed. Those notes are text you wrote, and they go to the same providers. What is kept with your project is what Toast writes from them — the descriptions of your cast and of each scene — not the document.
- The words on a graphics card: When Toast puts a designed card on screen — a statistic, a label, a title — the card is drawn on our own servers and sent back to your browser as a small transparent clip, which your browser lays over your footage. Your video is not involved: the renderer never receives a frame of it, and could not, because it never leaves your device. What we send to that renderer is the text that appears on the card — usually a few words taken from your own script — along with which card design to use and how big to draw it. It goes to Toast's own render service and to no third party. We deliberately do not send where the card will sit or where your face is in the frame: your browser works that out itself, and the renderer has no use for it. The finished card is stored with your project (see section 4) so that re-editing your video does not redraw it.
- One frame’s description, when you ask Toast to improve it: On the review screen you can ask Toast to rewrite the description of a single picture. That sends the description and the one line of narration it illustrates to the same AI language-model providers — one sentence of your script, not the script. It happens only when you press the button, and the suggestion is handed back to you and stored nowhere.
- A script document you ask Toast to read: If you write or load a script that is a production document — with a title block, image notes, music cues or stage directions in it — Toast sorts it into what should be spoken and what should not. It does that in your browser, and nothing is sent. If that split is wrong, you can ask Toast to read the document properly, and only then is it sent to our AI language-model providers. What is sent is the whole document — not just the part you marked as narration — because deciding which part that is is the thing being asked for. We do not store it: it is processed, cached for a week so re-reading the same file costs nothing, and not used for training. Loading a
.txt,.mdor.pdffrom your computer still happens entirely in your browser; the file itself is never uploaded. - Stock and generated media: When you add B-roll or background media, we send your text search query (or a text prompt for AI-generated images) to the corresponding media providers. We never send your footage.
- How much of this a faceless video involves: Worth stating plainly, because the scale is different from adding a piece of B-roll by hand. A faceless video is illustrated end to end at roughly ten pictures per minute — about a hundred images for a ten-minute video — and each one is a separate request to the image provider carrying a description built from your script, including the narration line that picture illustrates. You approve the plan before any of it runs, and you can stop the run at any point.
- Generated images, stored on our servers: When you use Toast to generate images — for B-roll, or for a faceless video built from a voiceover — the resulting images are stored in our own cloud storage, together with the prompt that produced them, so you can reuse them instead of paying to generate the same picture twice. This is the one category of media Toast does keep. They are private to your account, served over expiring signed links, and deleted when you delete them. If the prompt was derived from your script, that line of your script is stored alongside the image and is sent to the image provider as part of the prompt.
- Pictures Toast drew are sent back to a model to be checked: Every picture Toast generates for a faceless video is checked against what you asked for — does it match the look you chose, does it show the moment it was meant to show, and is the character in it still the same character. That check is another AI model, so each generated picture is sent to it over an expiring link, together with the description that asked for it. This includes the reference picture Toast draws of each character, which is also read back to tell you what it actually drew. Each picture is sent more than once: a separate check looks for lettering, a signature or a printed border the image model added on its own, and a picture that fails it is drawn again and the new one checked too — so pictures you never see, because they were thrown away and redrawn, are sent to the model as well. A picture from your library that was made before this check existed is sent once before it is reused. A third check compares each picture with the facts its description states — the right things, where they are, who is not in it — and a picture that gets one wrong is drawn again from a rewritten description, up to twice, and the new picture is checked too. To write and rewrite that description, the scene description (built from a line of your script and the descriptions of your characters) is sent to the language model as well. These are pictures Toast made — never a photo you uploaded, and never a frame of your own video.
- Reference photos you upload: If you upload a photo to lock what a person, animal, object or place in your video should look like, that photo is stored on our servers and sent once to our vision model, which reads it and writes a description. That description — not your photo — is what gets sent to the image provider for every picture it draws. Your uploaded photo is never sent to an image generator, cannot be used as the basis for an AI edit, and is never offered back to you as stock imagery in another video. It stays as the picture we compare the generated frames against.
- Pictures you put on a frame yourself: If you replace a frame of a faceless video with a picture of your own, or use your own photo or logo for a person or company in it, that picture is stored on our servers with the rest of your images. It is not sent to any AI model or any other company, it is not checked or described, and it is never offered back to you as stock imagery in another video.
- Real people and companies your script or video names: When a faceless script names a real person or company, or the speaker in a talking-head video says one, Toast sends that name — just the name, never your script or transcript — to Wikidata and Wikimedia Commons to find a freely licensed photograph or logo, and, only when none exists, sends the company's web address to Brandfetch for its logo. For a talking-head video the name sent is the full name our AI model identified from your transcript, with a short description of who or what it is that we compare on our servers and do not send to Wikidata. The picture found is stored with your images, placed into your video instead of being drawn by an AI, never sent to an AI model, and credited so you can list it in your video's description. When no freely licensed photograph of a person exists, that moment gets no picture rather than a stand-in.
- Uploading a photo of a person: Before you can upload a photo of a person, we ask you to confirm that it is you, or that you have that person's permission. We also check the photo, and we will not generate images from a photo of a child unless you have told us it is a photo of you. If we refuse it, the upload is deleted rather than kept.
- Editing a generated image sends that image to the provider: When you ask Toast to change something about a picture it made for you — “keep everything the same, just change her expression” — the only way to keep the rest of the picture is to give the provider the picture. So that request sends a temporary, expiring link to that stored image along with your instruction. It is always an image Toast generated for you: never a photo you uploaded, and never a frame of your video.
- Account data: Email address and authentication tokens (via Clerk) for account management.
- Payment data: When you buy credits you are sent to Razorpay's own hosted checkout page and enter your payment details there. Toast never receives, sees or stores your card, UPI or bank details. What we keep is the payment identifier, the amount and the time, which is what lets us credit your account, show you a receipt and refuse to charge you twice for the same purchase.
- Project metadata: Project names, edit manifests, and version history are stored on our servers. These contain text and timestamps — never video or audio content.
- Feedback attachments: If you attach a file to a feedback or suggestion form, it is emailed to our team via our email provider. We accept images and text files only; video attachments are rejected.
- Analytics: We collect product-usage analytics (page views, feature usage) via PostHog. Events are tied to a pseudonymous account identifier (your Clerk user ID) so we can understand feature adoption; we do not send your name or email address to PostHog.
4. Sub-processors and Third-Party Services
We use the following sub-processors. Each receives only the data described above for the stated purpose; none receive your video.
AI editing
- Anthropic (Claude) — AI editing decisions (transcript text + prompts)
- OpenAI — AI editing fallback (transcript text + prompts)
- OpenRouter — AI model routing for the above, configured to deny provider data retention/training (transcript text + prompts). Also routes the vision model that checks generated pictures and reads uploaded reference photos, so images reach it too, not text alone
Audio
- ElevenLabs — Transcription, audio noise removal, and — if you type a script instead of uploading a voiceover — speaking that script aloud. In that case the words you wrote are sent to ElevenLabs, which is the same kind of content as your transcript.
- CleanVoice — Audio noise removal (audio only)
Media
- Replicate (running Black Forest Labs' Flux models, and ByteDance's Seedream model when you choose “Best” picture quality for a faceless video) — AI image generation and editing. Text prompt for a new image; for a faceless video that prompt is derived from your script, so it can contain lines of your narration. On a “Standard” video, a picture our own check finds wrong is redrawn once with Seedream too, so its prompt goes there as well. Editing an existing image also sends that image (an expiring link to a picture Toast generated for you) — never your video, never an upload
- Pexels, Pixabay — Stock footage and images (the text search query only — what you typed into the search box)
- Jamendo — Background music search and download. Usually a few words Toast worked out from your video. But if your script document has a music cue sheet in it, what we search for is the cue you wrote — the keywords out of your own sheet, sent without you pressing search. A few words of your document, never the document, and only when you put a cue sheet in it
Platform
- Clerk — Authentication (Google OAuth, magic links)
- PostHog — Product analytics (pseudonymous account ID; no name/email)
- Sentry — Error tracking (with PII redaction)
- Razorpay — Payment processing for credit purchases. You are sent to Razorpay's own hosted checkout page and enter your payment details there; Toast never sees or stores your card, UPI or bank details. We keep the payment identifier and the amount so we can credit your account and show you a receipt
- Resend — Transactional and feedback email delivery
- Vercel — Frontend hosting
- Railway — API hosting, and hosting for the service that draws graphics cards. That service receives the text that goes on a card and returns a transparent clip; it never receives your video, and it is ours, not a third party that gets to keep anything
- Supabase — Database (project metadata only)
- Cloudflare R2 — Storage for images Toast generated for you, for graphics cards it drew for you, and for reference photos you upload. Never video.
5. Data Retention
Project metadata is retained as long as your account is active. You can delete any project at any time, which removes all associated metadata from our servers. Browser-local data (OPFS files) is managed entirely by your browser.
A reference photo you upload is kept until you delete it or delete the subject it describes, for the same reason: it is what later videos compare their frames against. Deleting it removes it from your library immediately.
Generated images are kept until you delete them, and deliberately outlive the project they were first made for — that is what lets a later video reuse them rather than regenerate them. Deleting one removes it from your library immediately, and the file itself is erased from our storage within 30 days. We keep a record that the image existed after that, with no picture attached, because an image you later edited from it has to remain explicable. We do not control how long the image provider retains a prompt or its output on their side; see Replicate's own policy for that.
Deleting your account erases the files too. Everything we have stored for you — every generated image and every reference photo — is removed from our storage along with your records, whether you delete the account yourself or it is removed on the sign-in provider's side.
A faceless video contains no camera footage at all. The rule above is not weakened by any of this — for that kind of project it is not even engaged.
6. Your Rights
You may request deletion of your account and all associated data by contacting us at gopikrishna@toast.video.
7. Changes
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice.
8. Contact
Arnanda Technologies Private Limited. Questions? Reach us at gopikrishna@toast.video.