LEGAL
Privacy Policy
What data Takeline processes, why, with whom and for how long, and how you exercise your rights under the LGPD.
Last updated: October 2, 2026
Draft pending legal review
This text describes what Takeline does today and is still being reviewed by a lawyer. It may change before the final version; the date above shows when it last changed.
Who we are
Takeline is a video editing and content creation service for TikTok, Reels and Shorts, operated by NZK TECNOLOGIA LTDA ("NZK", "we"). This policy covers the takeline.com.br website, the web app and the Mac app.
For your account and usage data, NZK is the controller under Brazil's General Data Protection Law (Law 13,709/2018, LGPD). For the content you upload, such as videos showing other people, NZK processes the data only to provide the service to you, as set out in the Terms of Service.
Data we process
- Account: name, email and, if you sign in with Google or Apple, the identifier and photo those accounts send us. We never receive your Google or Apple password.
- Sessions and security: when you signed in, the IP address and browser or device of each session, and a log of important actions in the workspace (such as invitations and role changes), with the IP of whoever acted.
- Workspace and team: the workspace name, its members, their roles and invitations, with the invitee's email and the inviter's optional message.
- Brand profile: name, description, segment, phone number, the social handles you enter, colour and logo.
- Scripts: the topic, type and settings of each request, and the hooks, bodies and calls to action generated.
- Media: the videos, images, audio and documents you upload, the derived versions we make for the editor (thumbnail, lightweight copy and waveform) and the transcript of each video's speech, with the timing of every word.
- Edited videos: the editing request, its settings, the caption with hashtags and the final video.
- Credits and payment: credit balance and usage, plan, subscription status and your Stripe customer identifier. Card and Pix details stay with Stripe; we never receive them.
- Website and app usage: pages viewed and events such as signing up and creating a workspace, linked to an identifier, unless you turn analytics cookies off (see Cookies).
Why we use it and on what legal basis
- Providing the service you signed up for: signing in, storing and editing your media, transcribing, generating scripts, delivering videos and tracking credits. Basis: performance of a contract (LGPD art. 7, V).
- Billing subscriptions and credit packs and issuing receipts. Basis: performance of a contract and legal obligation (art. 7, II and V).
- Protecting accounts and the service: limiting attempts, investigating abuse and keeping access records. Basis: legal obligation (Brazil's Marco Civil da Internet) and legitimate interest (art. 7, II and IX).
- Sending emails the service needs: sign-in links, invitations, receipts and payment notices. Basis: performance of a contract.
- Understanding and improving the product with usage data. Basis: legitimate interest, which you can turn off at any time in the cookie settings.
We do not sell personal data and we do not use your videos for advertising.
Artificial intelligence
Your videos are transcribed with whisper.cpp, an open model running on our own servers. Cuts, captions, zoom and music are applied by our software, also on our servers. Scripts are written by our own generator, with no third-party model.
Today none of your videos, audio, transcripts or scripts is sent to an outside AI provider. Your data does not train AI models, ours or anyone else's. We do not use your face or voice for biometrics or cloning.
If we ever start using an outside AI provider, this policy will name it before any of your data is sent, and our contract with it will forbid using your data to train models.
Who we share it with
We share data only with the providers that make the service work, each with the minimum it needs:
- Server provider: hosts the app, the database and video processing.
- Cloudflare (R2): stores media files; you reach them through signed links that expire in one hour.
- Email provider (Resend or our own SMTP server): delivers the service's emails.
- Stripe: processes card and Pix payments.
- PostHog: measures website and app usage, without recording the screen; the data passes through our server first, which strips cookies before sending it on.
- Google and Apple: only when you choose to sign in with them.
We may also share data when the law or an authority requires it, or to defend rights in legal proceedings.
International transfers
Some of these providers, such as PostHog, Stripe, Cloudflare, Google and Apple, process data outside Brazil, including in the United States. These transfers follow LGPD art. 33, with contractual clauses and safeguards equivalent to Brazil's.
Cookies
We use few cookies, and you choose the analytics ones in the cookie notice or, at any time, under "Cookies" in the site's footer.
takeline.session_token(__Secure-takeline.session_tokenin production): keeps you signed in to the app. Necessary.takeline_ephemeral: keeps your first workspace's draft for 15 minutes while you sign up. Necessary.analytics_consent: keeps your choice about analytics cookies for 180 days. Necessary.NEXT_LOCALE: remembers the language you chose. Necessary.ph_takeline_ph(cookie and local storage): identifies the browser for usage analytics in PostHog. Analytics: on by default and you can turn it off; if your browser sends "Do Not Track", it stays off.
When the website and the app share a domain, your cookie choice and the analytics identifier apply to both.
How long we keep it
- Account, workspace, scripts and media: for as long as the account exists. When you delete a file, it and its derived versions leave storage at once.
- Closing your account: ask at contato@takeline.com.br; we delete the account and its content within 30 days, except what the law requires us to keep.
- Payments: for as long as tax law requires.
- Access records: for as long as the Marco Civil da Internet requires, and the workspace's action log for as long as security needs.
- Sign-in links sent by email expire in 15 minutes; file links, in one hour.
Security
Data travels encrypted (HTTPS). Each workspace sees only its own data, files open only through signed, temporary links, and the service's credentials live in a secrets vault, outside the code. No system is infallible: if an incident may affect you, we will tell you and the ANPD as the LGPD requires.
Your rights
Under the LGPD (art. 18), you may ask at any time for:
- confirmation that we process your data, and access to it;
- correction of incomplete or wrong data;
- anonymisation, blocking or deletion of data that is unnecessary or processed unlawfully;
- portability of your data;
- deletion of data processed with your consent, and withdrawal of that consent;
- information about whom we share your data with.
Write to contato@takeline.com.br. We answer within 15 days. You may also complain to Brazil's National Data Protection Authority (ANPD).
Children and teenagers
Takeline is not meant for anyone under 18, and we do not knowingly collect children's data. If an uploaded video shows children or teenagers, whoever uploads it is responsible for having their guardians' permission.
Changes to this policy
When Takeline starts collecting, keeping or sharing data differently, this policy changes with it, with a new date at the top. Significant changes are announced by email or in the app before they apply. See also the Terms of Service.
Contact
NZK TECNOLOGIA LTDA, which runs Takeline. Email: contato@takeline.com.br. Requests about personal data, including to the data protection officer, go to the same address.