Privacy Policy

Last updated: September 23, 2026

1. Who We Are and What This Covers

DISKO is made by Smith Robinson Multimedia LLC, a New Hampshire limited liability company in Portsmouth, New Hampshire, United States ("DISKO," "we," "us"). We are the data controller for the personal information described in this policy. It covers:

  • our websites at disko.media and diskolabs.org;
  • DISKO Cloud — the hosted library, review, collaboration, client-portal, showcase and site features;
  • the public pages you create with DISKO Cloud (review links, showcases, client portals, portfolio pages, embedded players and sites) and the people who visit them;
  • the online features of the DISKO desktop application (licensing, updates, model downloads, Cloud Sync, and the optional connected services described below); and
  • our integrations, such as Google Drive and our tools for third-party editing applications.

Our Terms of Service and, for the desktop application, the EULA govern your use of DISKO. If you disagree with this policy, please do not use the Service.

2. The Short Version

  • Your library lives on your computer. The desktop app tags, transcribes and recognizes faces on your own hardware. Nothing is uploaded unless you sign in and choose to sync, share or upload it.
  • We do not sell your information, we do not show ads, and we do not use advertising trackers.
  • What you share is yours to control. Public pages are visible to anyone with the link unless you protect them, and you see who visited them (country and source, never names or addresses).
  • Face recognition is your decision. It is a tool you apply to your own media; you are responsible for the people in it, and you can turn it off or delete a person at any time.
  • Some features use your own AI account. If you connect an API key from Anthropic, OpenAI or Google, the content you select goes to that provider under its rules, not ours.
  • Ask us anything at support@disko.media; to close your account, email us from the address on the account.

3. Information We Collect

3.1 Account and billing

  • Account: your name, email address and a password (stored as a one-way hash by our authentication provider), plus an optional username and profile details you choose to add.
  • Billing: when you buy a license or subscribe, Stripe processes the payment. We receive and keep your Stripe customer and subscription identifiers, plan and payment status, the last four digits and brand of your card, and your billing country; we never see or store your full card number.
  • Desktop license: a license key, the account or email it is tied to, and a machine fingerprint for each activated computer — a SHA-256 hash of hardware identifiers (hostname, platform, architecture, CPU model, total memory and a network adapter address) that cannot be reversed to recover those details. It is used only to enforce the activation limit.

3.2 Content you sync, upload or create

Only what you choose to sync, upload or create in DISKO Cloud reaches our servers. Depending on what you use, that can include: media files and the thumbnails, proxies, filmstrips and waveforms generated from them; file names, technical metadata, capture dates and GPS locations; tags, AI descriptions, notes and ratings; transcripts, including the names of speakers you have identified; the people you have identified in your media — their names, face thumbnail crops and the face embeddings (numeric representations) used to recognize them — and which files they appear in; clients, projects and folder structure; screenplays, shot lists, production notes and story scripts; comments, annotations and approvals; branding, brand kits and site configurations; and the file names, links and metadata of Google Drive items you connect. Voice embeddings created by speaker identification stay on your computer and are not synced.

3.3 Sign-up protection

To keep automated sign-ups out we use Cloudflare Turnstile, which analyses browser signals and your IP address under Cloudflare's privacy policy; a hidden form field that only bots fill in; a check that your email address's domain can receive mail, performed by looking up the domain (not your address) through Cloudflare's DNS resolver; and short-lived per-IP-address limits on how many attempts can be made. The email address you sign up with is checked against lists of disposable-address services.

3.4 Technical and usage information

Like any online service we receive your IP address, browser and device type, operating system, language, referring page, the pages and features you use, and timestamps when you use the Service. Our hosting and infrastructure providers keep standard access logs of this information for a short period. For abuse prevention and to count unique visitors we store a salted hash of the IP address rather than the address itself where we can.

3.5 Visitors to public pages

When someone opens a page you shared (a review link, showcase, client portal, portfolio page, embedded player or site) we record, and show to the page owner, the visitor's country (for sites, also region and city where available), the referring website and any campaign ("utm") codes in the link, the path viewed, playback events such as play, pause, seek, quality changes and seconds watched, a random per-session identifier, and a hashed IP address. Visitors who comment, annotate, approve or request changes provide a display name (and, for review links, optionally an email address) and the content they post; the page owner sees all of this. Passwords for protected pages are checked on our servers and never stored in the visitor's browser — a short-lived signed cookie remembers that access was granted.

3.6 The desktop application

The desktop application has no telemetry, usage analytics or automatic crash reporting. It connects to the internet for these purposes only:

  • Licensing: activating, validating and deactivating your license (account identifier, license key, machine fingerprint).
  • Updates and models: checking for updates and downloading them, and downloading the AI models it needs on first use, from our own download mirror hosted on Cloudflare; a few models fall back to their original hosts (Hugging Face or GitHub) if our mirror is unavailable. Those hosts see your IP address as with any download.
  • Cloud Sync: off by default; when you turn it on and sync a project, the content described in 3.2 is uploaded (Section 7.3).
  • Bug reports: sent only when you submit one. A report contains the description you write, recent application logs, your app version, operating system version, and a summary of library statistics (counts, not file names or media). Reports are tied to your account.
  • Online place-name lookup (off by default): if you turn it on, the location text you type is sent to OpenStreetMap's Nominatim service and GPS coordinates from your media are sent to Komoot's Photon service to look up place names. Only the text or coordinates are sent — never file names or media.
  • Google Drive libraries: if you connect a Google account (Section 6).
  • Your own AI provider: if you connect an API key for the Story Generator (Section 5.3).

3.7 When you contact us

Messages sent through our support form, support email, bug reports and any surveys are kept so we can respond and improve the product.

4. How We Use Information

  • to provide the Service: store, process, deliver and display your content to you and to the people you share it with;
  • to run the AI features you use and show you their results;
  • to license the desktop application and deliver updates;
  • to process payments, send receipts and manage subscriptions;
  • to send service emails — sign-up confirmation, password resets, security alerts, comment and review notifications, and emails you ask us to send on your behalf (for example an invitation to review or to upload files, which carries your name);
  • to show page owners how their shared pages are performing, and to understand in aggregate how DISKO is used so we can improve it;
  • to protect the Service — preventing abuse, bots, fraud and unauthorized access, and enforcing our Terms; and
  • to comply with the law and to establish, exercise or defend legal claims.

We do not currently send marketing newsletters. If we start, you will be able to opt out in every email, and opting out never affects service emails you need.

Legal bases (EEA, UK and Switzerland). We process your information to perform our contract with you (providing the Service you signed up for), for our legitimate interests (securing and improving the Service, understanding usage, communicating with you), to comply with legal obligations (tax and accounting records, responding to lawful requests), and with your consent where we ask for it (for example when you connect Google Drive or turn on an optional feature). You can withdraw consent at any time by disconnecting or turning off the feature.

5. Who We Share Information With

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share it only as follows.

5.1 Service providers that process data for us

  • Supabase (USA) — database and authentication for DISKO Cloud.
  • Cloudflare (global) — hosting and edge delivery of our websites and APIs, R2 object storage for media, the content delivery network, Turnstile bot protection, the DNS resolver used for sign-up checks, and the containers that run our own FFmpeg-based transcoder, which converts media you upload into streaming proxies.
  • Stripe (USA) — payments, subscriptions and invoices.
  • Resend (USA) — delivery of the emails described in Section 4.
  • IONOS (Germany/USA) — hosts diskolabs.org, our own site for DISKO's free tools, where we also keep a simple internal dashboard. When you create a DISKO Cloud account, your name and email address are recorded there so we can see account growth in one place; and marketing page views on disko.media (not the signed-in dashboard, sign-in or sign-up pages) are counted there by a tracking pixel that records the page viewed and the site you came from.

These providers act on our instructions under contracts that restrict their use of your information. Where they are outside your country, see Section 11.

5.2 People you share with

Team members, collaborators, clients and visitors see the content you share with them, along with your name and any comments or notes on it. Page owners see visitor analytics and everything visitors post (Section 3.5). If you share a library with a teammate, they see what you have shared and the comments on it.

5.3 Your own AI provider

The Story Generator in the desktop application and the screenplay co-writer in DISKO Cloud work with an API key that you obtain from a third-party AI provider (Anthropic, OpenAI or Google) and enter yourself. When you run one of these features, the content you select — which may include transcripts, speaker names, file names, AI descriptions, script excerpts and your instructions — is sent directly from your computer or browser to that provider, under your account and that provider's privacy terms. We are not a party to that transfer and do not receive its results. Your key is stored on your own device or in your browser's local storage, never on our servers.

5.4 Google

If you connect Google Drive, information flows to and from Google as described in Section 6.

5.5 Legal, safety and business transfers

We may disclose information if required by law, subpoena or other legal process; to protect the rights, property or safety of DISKO, our users or the public, including to report unlawful content to the authorities; to enforce our Terms; and, in connection with a merger, acquisition, reorganization or sale of assets, to the successor business, which will be bound by this policy for the information it receives.

6. Google Drive and Google API Services

DISKO can index a Google Drive folder as a library without copying your files. When you connect Google Drive you sign in with Google and grant DISKO read-only access to your Drive (the drive.readonly scope). With that access, DISKO:

  • reads the names, folder structure, sizes, dates and technical metadata of the files in the folders you select, and Google's thumbnails of them, to build your library;
  • streams or downloads a file's contents only when you open it, ask for a preview, save a copy, or enable deep indexing for a folder (which fetches the file to generate a real thumbnail, metadata, a proxy and a transcript, then discards the copy); downloaded copies are kept in a cache on your computer that you control and can clear;
  • if you sync a Drive library to DISKO Cloud, sends the file names, Drive links, folder path and metadata to DISKO Cloud so you and the people you share with can find the files and open them in Drive — the files themselves are never uploaded from Drive to DISKO Cloud; and
  • in DISKO Cloud, lets a viewer connect their own Google account to play a Drive video inside DISKO; that viewer's Google access token is held in a short-lived (at most one hour) encrypted, HTTP-only cookie in their browser and used only to relay the video from Google to their player. We do not store it.

Google access tokens for the desktop application are stored encrypted on your computer, in the library that uses them, and can be revoked by disconnecting Google Drive in DISKO or at myaccount.google.com/permissions.

Limited Use. DISKO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google user data only to provide and improve the Drive features you see in DISKO; we do not use it for advertising; we do not sell it; we do not use it to train generalized AI or machine-learning models; and humans do not read it except with your consent, for security or legal reasons, or in aggregated, anonymized form.

7. AI Processing and Biometric Data

7.1 Where AI processing happens

The desktop application performs its AI processing on your own hardware (on Apple silicon, using the Neural Engine and GPU) with models that run on your device: automatic tagging and descriptions of images and video, face detection and recognition, speech transcription, speaker identification, visual similarity and duplicate detection, product recognition, and multi-camera synchronization. The exceptions are the features that use your own AI provider account (Section 5.3), which you must configure yourself. DISKO Cloud runs no AI processing of its own on your media; it stores and displays the results produced on your computer, and its search ranks those results.

7.2 Face recognition and voice identification

Face recognition creates mathematical representations of facial geometry ("embeddings") so that photos and clips of the same person can be grouped; speaker identification does the same for voices. Under some laws — including the Illinois Biometric Information Privacy Act, the Texas and Washington biometric laws, and the GDPR's rules on special-category data — this can be biometric data, and the person who decides to collect it may need to give notice, obtain consent, and publish a retention policy.

  • Who decides: you do. These features act on your media at your direction. You are responsible for any notices and consents the people in your media are owed, and for complying with the laws that apply to you.
  • Purpose: face and voice embeddings are used only to find and group the same person within your own library and to label your transcripts. We never use them for any other purpose, never compare them across customers, and never use them to identify people for anyone else.
  • Where it is stored: on your computer, in your library. If you enable Cloud Sync, the names, face thumbnail crops and face embeddings of the people you have identified, and the speaker names on transcripts, are stored in DISKO Cloud (Supabase database and Cloudflare R2 storage) so your synced library, portals and search work; voice embeddings are never uploaded.
  • Retention: until you delete the person, the media they appear in, the library, or your account. Deleting a person in the desktop application also removes their cloud data on the next sync; you can also ask us to delete it.
  • Your controls: face recognition and speaker identification can be turned off; any person can be deleted at any time; a whole library can be deleted.
  • No sale or disclosure: we never sell, lease, trade or otherwise disclose biometric data to anyone, and we do not profit from it, except to the service providers that store it for us (Section 5.1) and where the law requires.

7.3 Cloud Sync

Cloud Sync is off by default and starts only when you sign in and choose to sync. Ordinary sync uploads the content described in Section 3.2 in the form of metadata, thumbnails and reduced-size proxies; original full-resolution files are uploaded only when you explicitly send them. You can stop syncing at any time in the desktop application; stopping does not delete what was already synced, which you can remove by un-syncing a project, deleting content, or asking us.

7.4 No training on your content

We do not use your media, transcripts, faces, voices or other content to train AI models that serve other customers. Models you train yourself — for example teaching DISKO to recognize a product — are built from your own labels, stored in your library, and used only for you.

8. Cookies and Browser Storage

We keep cookies to the minimum the Service needs. We use no advertising cookies and no third-party analytics scripts.

  • Sign-in session: your DISKO Cloud sign-in token is kept in your browser's local storage by our authentication library so you stay signed in.
  • Access cookies for protected pages: when you unlock a password-protected showcase, portal or screenplay, or connect Google to play a Drive video, we set a short-lived, signed, HTTP-only cookie scoped to that page so you are not asked again during the session. It contains no password.
  • Cloudflare security cookies: Cloudflare may set its own cookies to distinguish people from bots and to protect the Service; these are described in Cloudflare's privacy policy.
  • Preferences and drafts: we use local storage for conveniences such as the name you gave when commenting as a guest, unsent drafts, recent searches, offline copies of screenplays you have opened, and your own AI provider key; and session storage for the random identifier that groups playback events in an embedded player. These stay in your browser and are not sent to us except where this policy describes.
  • Our own analytics pixel: public marketing pages load a one-pixel image from diskolabs.org that records the page category and referring site (Section 5.1). It sets no cookie.

You can clear or block cookies and site data in your browser; blocking the sign-in and access cookies will stop the corresponding features from working. Because we do not sell or share personal information for advertising, there is no advertising opt-out to signal; we treat Global Privacy Control and Do Not Track signals as a request not to be tracked, which is already how the Service behaves.

9. How Long We Keep Information

  • Account and content: for as long as your account exists. When you ask us to close your account we delete your account data and content from our live systems within 30 days, and from backups within 90 days after that, except for information we must keep by law (for example billing records for tax purposes) or to resolve disputes.
  • Content you delete: removed from our live systems when you delete it or un-sync it, and from backups within 90 days. Content on public pages may persist in content-delivery caches and in visitors' browsers for a short time.
  • Visitor analytics and comments: kept with the page they belong to and deleted with it, or when the account that owns it is closed.
  • Free and inactive accounts: we may delete content in accounts that have been inactive for an extended period, after notice to the account email address.
  • Logs and security data: access logs, hashed IP addresses and rate-limit counters are kept for short periods needed to run and protect the Service, typically days to a few weeks.
  • Support and bug reports: kept while we need them to help you and improve the product.

10. Security

We take reasonable measures to protect your information, including:

  • encryption in transit (TLS) for every connection, and encryption at rest for stored media and database data at our providers;
  • private media that is served only through short-lived signed links, and access tokens for protected pages that are signed and HTTP-only;
  • database rules that restrict every record to its owner and the people it was shared with, plus server-side checks on every public page;
  • rate limiting, bot protection and abuse monitoring on sign-up and on every public endpoint;
  • desktop credentials and tokens stored encrypted using your operating system's keychain; and
  • limited, logged access to production systems.

No system is perfectly secure. If you believe your account has been compromised, or you have found a vulnerability, please contact security@disko.media (see also our security.txt). If a breach affecting your personal information occurs, we will notify you and the relevant authorities as the law requires.

11. International Transfers

We are based in the United States and our service providers operate there and, in Cloudflare's case, at edge locations around the world; your information may be transferred to and processed in the United States and other countries whose data-protection laws differ from yours. Where we transfer personal information from the EEA, the United Kingdom or Switzerland, we rely on our providers' data-processing agreements, which incorporate the European Commission's Standard Contractual Clauses and the UK addendum, together with appropriate safeguards.

12. Your Rights and Choices

Wherever you live, you can access and update your account details in the Service, export the content you created, turn optional features on and off, and ask us to correct or delete your information or close your account. To make a request, email support@disko.media from the address on your account; we will verify that the request comes from you, and respond within 30 days (or the time the law allows). We will not treat you differently for exercising your rights.

12.1 European Economic Area, United Kingdom and Switzerland

You have the right to access your personal data and receive a copy; to have it corrected; to have it erased; to receive it in a portable format; to restrict or object to processing based on our legitimate interests; to withdraw consent at any time where processing is based on consent; and to lodge a complaint with your local data-protection authority. Where you have connected Google Drive or enabled an optional feature, withdrawing consent means disconnecting or turning it off.

12.2 California and other U.S. states

If you live in California or another state with a consumer-privacy law, you have the right to know what personal information we collect, use and disclose and for what purposes (this policy is that disclosure); to access it; to correct it; to delete it; and to not be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising, and we have not done so in the past twelve months, so there is no sale or sharing to opt out of; we do not use or disclose sensitive personal information for purposes that require a right to limit. You may designate an authorized agent to make a request for you; we will still verify the request with you directly.

12.3 People who appear in a DISKO user's media

If you appear in media that a DISKO user has processed or shared, the DISKO user is responsible for that media and is the person to contact about it. If you cannot reach them, or you believe content on a public DISKO page violates your rights, contact support@disko.media and we will help as the law allows.

13. Children

The Service is not intended for anyone under 16, and we do not knowingly collect personal information from children under 16. If you believe we have, please contact us and we will delete it. (Media that a DISKO user processes may of course depict minors; the user is responsible for having the right to do so — see Section 7.2.)

14. Changes to This Policy

We update this policy when our practices change. We will post the new version here with a new "Last updated" date, and for material changes we will also notify you by email or within the Service before they take effect. Your continued use after a change takes effect means you accept it.

15. Contact Us

Questions, requests or concerns about privacy:

Smith Robinson Multimedia LLC

Portsmouth, New Hampshire, United States

Privacy and general: support@disko.media

Security: security@disko.media