Privacy Policy
Last updated: July 5, 2026
This policy explains what information Highlightly ("we", "us") collects through this website and the Highlightly desktop application (the "App"), how it's used, and who it's shared with.
1. Who we are
Highlightly is operated by Hasan Raza Rawjani, contactable at rawjanihasan@gmail.com. This policy covers this website and the Highlightly desktop app for Windows (the "App").
2. What we collect
Account information. When you create an account we use Supabase to store your email address, a hashed password (or your Google account identifier if you sign in with Google), your account ID, and your subscription plan/status. If you sign in with Google, Google shares your name, email address, and profile photo with us via OAuth — we don't receive your Google password.
Payment information. Subscription payments are handled entirely by Stripe. We never see or store your full card number, CVC, or bank credentials — Stripe's checkout page collects that directly. We do receive limited billing metadata from Stripe (such as your subscription status, plan, and renewal date) so we can unlock the right features on your account.
Local browser storage. The Site caches your signed-in email and plan in your browser's local storage so the page doesn't flash a signed-out state on reload. This data stays on your device and is not a tracking cookie.
Video, audio, and gameplay content. The App is designed to process your clips locally on your own computer — your video files are never uploaded to our servers. The one exception is captions: to generate word-level captions, the App extracts just the audio track from your clip and sends it to Groq's Whisper transcription API so it can be converted to text. That audio is used only to produce your transcript and is governed by Groq's own privacy terms. If you don't configure a Groq API key, the App instead runs transcription fully offline on your machine using a local Whisper model, and no audio ever leaves your computer.
3. How we use this information
- To create and authenticate your account
- To process payments and manage your subscription
- To generate captions for clips you choose to process with a cloud API key configured
- To provide customer support if you contact us
- To keep the Site and App secure and working correctly
We do not sell your personal information, and we do not use your gameplay clips or audio to train any AI models.
4. Who we share data with
- Supabase — authentication and account database hosting
- Stripe — payment processing and subscription billing
- Google — optional Google Sign-In (OAuth)
- Groq — optional cloud audio transcription, only for clips you process with a Groq API key configured
Each of these providers has its own privacy policy governing how they handle data on our behalf.
5. Data retention
We keep your account information for as long as your account is active. If you delete your account or ask us to remove your data, we will delete your account record from Supabase and stop billing you through Stripe within 30 business days. Local video files, exports, and cache files created by the App live only on your own computer and are entirely under your control — we have no copy of them.
6. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to certain processing. To exercise any of these rights, email us at rawjanihasan@gmail.com.
7. Children's privacy
Highlightly is not directed at children under 13, and we do not knowingly collect personal information from children.
8. Security
Account data is stored with Supabase using industry-standard encryption in transit and at rest. Payment data never touches our servers at all — it's handled entirely within Stripe's PCI-compliant infrastructure. No method of transmission or storage is 100% secure, but we work to protect your information using reasonable administrative and technical safeguards.
9. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date above and, where required, notify you directly.
10. Contact us
Questions about this policy? Email rawjanihasan@gmail.com.