Skip to content

Draft for review — not yet effective. Replace every [VERIFY: ...] item before publication, confirm that production systems match this draft, and have the final policy reviewed by a privacy lawyer for the countries where the Services will be offered.

Proposed effective date: [VERIFY: EFFECTIVE DATE]

Draft updated: September 14, 2026

Items to verify before publication

  • The Company's registered or public privacy address and privacy contact telephone number.
  • Whether the Company is covered by the Australian Privacy Act 1988, including whether it has opted in if the small-business exemption might otherwise apply.
  • Which additional regional notices are needed for worldwide sales, including any EEA, UK, Californian, or other US state disclosures.
  • Whether an EEA or UK representative or data-protection officer must be appointed.
  • Every remaining production provider: email/OTP delivery, support tools, logging, monitoring, crash reporting, and analytics.
  • Every country in which those providers may store or access personal information.
  • Whether any telemetry, analytics, or automatic crash reporting will be enabled. None was identified in the audited Showcase, account, API, or Site code.
  • Implementation and testing of the retention and deletion schedule in section 6, including provider settings and the raw Stripe webhook purge.
  • Clear marketing-consent wording beside each Site feedback and launch-list form.
  • Confirmation that production entitlement, payment-grace, account-deletion, and human-review behaviour matches section 10.

Who we are and what this policy covers

120.DEV PTY LTD (ACN 702 182 545, ABN 59 702 182 545) (120.dev, we, us, or our) [VERIFY: REGISTERED OR PUBLIC PRIVACY ADDRESS] is responsible for the personal information described in this Privacy Policy. For privacy laws that use the terms controller or business, 120.DEV PTY LTD acts in that role for personal information it determines how and why to handle.

This policy applies to:

  • 120.dev and related websites (the Site);
  • 120.dev account, authentication, billing, entitlement, download, update, and support services; and
  • software and services we make available under the 120.dev brand, including Showcase, 120 AI Chat, and 120 HN,

together, the Services.

In this policy, personal information includes information or an opinion about an identified individual or an individual who is reasonably identifiable. Some laws use the term personal data for a similar concept.

This policy describes information handled by 120.dev. It does not make us responsible for information that remains only on your device or for a third party's independent privacy practices.

The Services may be offered worldwide. Mandatory privacy rights in your location continue to apply.

Summary of the design

  • Showcase's standard recording, transcription, editing, project, and export workflows run locally. Under the current design, your project media, transcripts, captions, and editing data are not uploaded to 120.dev.
  • Account creation, sign-in, Google identity linking, purchases, subscription management, entitlement checks, software delivery, and support use online systems and involve the information described below.
  • We do not sell personal information or use it for third-party targeted advertising.
  • We do not currently include product analytics, advertising trackers, or automatic crash reporting in the audited code. [VERIFY BEFORE PUBLICATION AND AFTER EACH MATERIAL SYSTEM CHANGE.]
  • If you enable global input-event recording in Showcase, the resulting pointer and keyboard-event metadata is stored locally with the recording. This feature is off by default in the audited code.

1. Information We Collect

1.1 Account and identity information

When you create or use an account, we may handle:

  • your email address;
  • an internal user identifier;
  • your authentication method and linked identities;
  • if you choose Google sign-in, profile information Google makes available, such as your name, email address, profile image, and Google account identifier;
  • authentication, session, token, sign-in, consent, and security-event metadata;
  • the version and time of your acceptance of our Terms; and
  • OAuth applications you have authorised and grants you have revoked.

Email sign-in uses a one-time code. Google sign-in is optional. We do not receive your Google password.

1.2 Subscription, purchase, and entitlement information

We and our providers may handle:

  • the product, offer, billing interval, price, amount, currency, and tax information;
  • purchase-intent and checkout references;
  • Stripe customer, checkout-session, payment, invoice, subscription, refund, dispute, and event identifiers and statuses;
  • subscription dates, renewal state, cancellation state, and payment outcomes;
  • billing name, address, contact, and tax information included in Stripe events where configured;
  • account, product, entitlement, installation, lease, and licence-verification identifiers; and
  • records of when an entitlement was issued, refreshed, expired, suspended, or revoked.

Stripe collects payment-card or other payment-method details directly. We do not intentionally receive or store a complete card number or card security code. Stripe may send us limited payment and billing information, and verified webhook event bodies may temporarily contain more detailed transaction or customer fields. See section 6 for retention.

1.3 Technical, security, and online activity information

When you visit the Site or use an online function, we or our hosting, content-delivery, authentication, and security providers may automatically process:

  • IP address and approximate location derived from it;
  • browser, operating-system, device, and app-version information;
  • requested hostname, URL, endpoint, and HTTP metadata;
  • request, session, installation, and correlation identifiers;
  • access, authentication, entitlement, rate-limit, security, and error events; and
  • timestamps, response status, and diagnostic information.

We use this information to deliver online functions, authenticate users, prevent abuse, investigate errors, and protect the Services. [VERIFY: EXACT VERCEL, CLOUDFLARE, SUPABASE, AND APPLICATION LOG FIELDS AND RETENTION.]

1.4 Messages, feedback, and marketing information

If you contact us, request support, join a launch or product mailing list, or submit a Site form, we may handle your email address, name if provided, message, feedback, attachments, preferences, and related submission metadata.

The current Site sends launch-list and feedback-form submissions to Zoho. Submitting either form also subscribes the email address to product news and launch marketing. Marketing messages will include a way to unsubscribe. Service messages about security, billing, Terms, or account operation are not marketing and may still be sent while relevant.

[VERIFY: ENSURE EACH FORM CLEARLY DISCLOSES MARKETING SIGN-UP AT COLLECTION AND CONFIRM THE EXACT ZOHO PRODUCTS AND ANY PROCESSING OUTSIDE AUSTRALIA.]

1.5 Showcase content kept on your device

Depending on the features you use, Showcase may locally access or create:

  • imported video, audio, and image files;
  • a screen, application window, or selected screen area;
  • system audio and, when selected, microphone audio;
  • when selected, video from one or more cameras;
  • transcripts, captions, edits, effects, thumbnails, project metadata, temporary working files, and exports; and
  • when you separately enable input-event recording, timestamped global pointer positions, mouse buttons, scroll amounts, keyboard key codes, and modifier changes.

Input-event metadata does not store the text value of a field as text, but key codes and timing may reveal or help reconstruct what was typed. It can include activity outside the captured screen area while recording. Avoid entering passwords or other sensitive information while this feature is enabled.

This content is stored locally under the current Showcase design. 120.dev does not collect or receive it through the standard local workflow. It may contain personal or sensitive information about you or other people, but we do not hold that information unless you choose to send it to us—for example, in a support request—or a future online feature clearly tells you it will upload the content.

You control local retention by managing projects and files on your devices. Deleting your 120.dev account does not delete this local content.

1.6 Local credentials and settings

The Services may store information on your device, including:

  • Site appearance preferences in browser storage;
  • account session information in browser storage;
  • rotating authentication credentials, an installation identifier, product identifiers, and signed entitlement information in operating-system-protected credential storage; and
  • app preferences and local databases in app storage.

The installation identifier is randomly generated and is not intended to be derived from hardware identifiers. Access tokens used by the audited desktop authentication flow are held in memory, while longer-lived rotating credentials and entitlement records use protected credential storage.

Signing out removes locally stored authentication material where supported. Uninstalling an app may not remove files or credentials retained separately by the operating system; you can use the app's controls or operating-system tools to remove them.

1.7 Content sent to third-party services at your direction

Some 120.dev products may let you connect a third-party AI or content provider using your own account or API key. When you choose that feature, your device may send prompts, content, identifiers, or requests directly to that provider. Under the audited local design, 120.dev does not receive that content merely because you use the connection.

The provider handles the information under its own privacy policy. Review that policy, including its retention and model-training terms, before sending personal or confidential information.

2. How we collect information

We collect personal information:

  • directly from you when you create an account, subscribe, submit a form, or contact us;
  • from providers you choose to use, such as Google for sign-in and Stripe for billing;
  • automatically from your device or browser when it communicates with our online systems; and
  • from security, fraud-prevention, support, or legal sources where permitted by law.

You can browse public parts of the Site without an account. An email address or supported external identity is required for account functions because we need to authenticate you and associate your subscription and entitlement with you. If you do not provide required information, we may be unable to provide those functions.

3. Why we use personal information

We use personal information to:

  • create, secure, and administer accounts;
  • authenticate you and link or unlink identities at your request;
  • process purchases, administer subscriptions, and keep financial records;
  • grant, verify, refresh, suspend, or revoke product entitlements;
  • provide downloads, updates, support, and requested communications;
  • maintain, troubleshoot, secure, and prevent misuse of the Services;
  • investigate fraud, disputes, incidents, and violations of our Terms;
  • send product news or launch messages when you have requested them;
  • understand and respond to feedback you submit;
  • comply with tax, accounting, consumer, privacy, sanctions, court, and other legal obligations; and
  • establish, exercise, or defend legal claims.

We do not use locally stored Showcase content to train AI models because that content is not uploaded to us in the standard workflow.

Australian privacy law does not use the same “legal basis” framework as some other laws. Where the EEA, UK, or another law requires a legal ground, we generally rely on:

  • contract, to create your account, process your subscription, and provide the Services you request;
  • legitimate interests, to secure, maintain, troubleshoot, and improve the Services, prevent fraud, and manage our business, where those interests are not overridden by your rights;
  • legal obligations, for tax, accounting, consumer, law-enforcement, and compliance requirements; and
  • consent, where required, including for optional marketing or optional device permissions. You may withdraw consent prospectively, but that does not make earlier processing unlawful.

[VERIFY WITH COUNSEL: EEA AND UK REPRESENTATIVE DETAILS, WHETHER A DATA-PROTECTION OFFICER IS REQUIRED, AND ANY ADDITIONAL LEGAL-BASE DETAIL FOR WORLDWIDE SALES.]

5. When we disclose information

We disclose only what is reasonably necessary for the relevant purpose. Current or intended provider categories are listed below; production configuration must be confirmed before publication.

RecipientPurpose and information involved
SupabaseAccount authentication, sessions, linked identities, account database, subscription projections, entitlements, and related security records. The primary production project region is Australia. [VERIFY: EMAIL/OTP CONFIGURATION AND ANY PROCESSING OUTSIDE THE PRIMARY REGION.]
GoogleGoogle sign-in and identity linking when you choose it. Google receives the authentication request and provides approved profile fields.
StripeCheckout, payment processing, invoices, subscriptions, billing portal, refunds, disputes, fraud prevention, and related customer support.
VercelHosting and delivery of the Site, account service, and API, including request and technical data. The audited deployment configuration selects Vercel's sfo1 region in the United States. [VERIFY: PRODUCTION CONFIGURATION AND ANY OTHER PROCESSING LOCATIONS.]
CloudflareDelivery and protection of assets and related request, network, and security data. Processing may occur through Cloudflare's global network.
ZohoSite feedback, launch-list, and marketing-list processing, including submitted email addresses and messages. The configured region is Australia. [VERIFY: EXACT ZOHO PRODUCTS AND ANY PROCESSING OUTSIDE THE PRIMARY REGION.]
Email/OTP providerDelivery of sign-in codes, account messages, and service or marketing emails. [VERIFY: PROVIDER, DATA HANDLED, AND REGION.]
Support, monitoring, and professional providersSupport tools, incident response, legal, accounting, insurance, and similar services, but only if used and subject to appropriate duties. [VERIFY: ACTUAL PROVIDERS.]

We may also disclose personal information:

  • when you direct or authorise us to do so;
  • to regulators, courts, law enforcement, or others where reasonably necessary to comply with law, protect rights and safety, investigate wrongdoing, or establish or defend legal claims; and
  • in connection with a proposed or completed financing, merger, restructuring, or sale of all or part of our business, subject to confidentiality and applicable law.

If a third-party AI or content service receives information directly from your device at your direction, see section 1.7.

6. Retention and deletion

We retain personal information only for as long as reasonably needed for the purposes in this policy, including legal, accounting, security, fraud-prevention, dispute, and backup requirements. We then delete or de-identify it where required and reasonably practicable.

The following schedule is a draft and must be aligned with production systems before publication:

InformationDraft retention approach
Local Showcase projects and mediaUntil you delete them from your device or storage. We cannot delete content we do not hold.
Browser and desktop authentication materialUntil sign-out, revocation, expiry, account deletion, or local removal, subject to how the browser or operating system manages storage.
Account and identity recordsWhile the account exists, then deleted or de-identified. Residual backup copies are deleted within 30 days, unless isolation or restoration makes a shorter period impracticable and access remains restricted.
OAuth grantsUntil you revoke the grant, it expires, or the account is deleted; shorter-lived codes and tokens expire earlier.
Purchase, subscription, tax, and accounting recordsFor 7 years after the relevant transaction or the end of the subscription, whichever is later, or longer if a dispute or law requires it. This includes records of affirmative subscription consent and purchase acknowledgements. Operational entitlement records not needed for those purposes are deleted with the account.
Verified raw Stripe webhook bodiesDeleted within 30 days. We retain limited event identifiers, hashes, processing outcomes, and billing facts under the longer billing-record period where needed.
Routine security and audit events30 days. An event needed for an active security incident, fraud investigation, billing dispute, legal claim, or mandatory record may be retained until that matter ends or for the applicable 7-year billing-record period.
Site, CDN, account, and API logs30 days, subject to shorter technical caches and any longer period strictly required for an active incident or by law.
Support and general correspondence2 years after the matter closes, or longer while reasonably needed for a dispute or legal obligation.
Marketing recordsUntil you unsubscribe or we discontinue the list. We retain a minimal suppression record for as long as reasonably needed to honour the opt-out.

Account deletion may be delayed while an active subscription, open checkout, refund, dispute, or other billing state must be resolved. Deleting your account does not itself cancel a Stripe subscription, erase records Stripe independently must retain, or remove files stored locally on your devices.

7. Security

We use technical and organisational safeguards designed to protect personal information. The audited design includes encrypted network transport, short-lived authorisation codes, PKCE for desktop sign-in, rotating credentials, protected operating-system credential storage, signed time-limited product entitlements, access controls, bounded request bodies, and Stripe-hosted payment collection.

No method of storage or transmission is completely secure. You should protect your email account, devices, one-time codes, and recovery methods; install security updates; and contact us promptly if you suspect unauthorised account access.

If a data breach occurs, we will investigate and notify affected people and regulators where required by applicable law.

8. Cookies and similar local technologies

The audited Site and account application do not include advertising cookies or third-party analytics scripts. [VERIFY: PRODUCTION DEPLOYMENT.]

We use or permit strictly necessary local technologies for functions such as:

  • remembering Site appearance preferences;
  • keeping you signed in and refreshing an account session;
  • protecting authentication and checkout flows; and
  • storing app settings, credentials, and entitlements on your device.

These technologies may include browser local storage and provider cookies on a provider's own domain. Stripe, Google, Supabase, Vercel, Cloudflare, and Zoho may use their own necessary technologies when you interact with their services. Blocking required storage may prevent sign-in, checkout, or other functions.

Because we do not currently use personal information for cross-site targeted advertising, we do not respond differently to browser “Do Not Track” signals. [VERIFY IF ANALYTICS OR ADVERTISING PRACTICES CHANGE.]

9. International disclosures

Some providers store or access personal information outside Australia. Primary Supabase and Zoho regions are configured in Australia. The audited Vercel deployment selects its sfo1 region in the United States. Cloudflare uses a global network, and Stripe, Google, and other providers may process information through their international operations.

[VERIFY: LIST EACH PRACTICABLE RECIPIENT COUNTRY, ESPECIALLY THE SUPABASE, STRIPE, VERCEL, CLOUDFLARE, ZOHO, EMAIL, SUPPORT, AND MONITORING LOCATIONS.]

Privacy protections in another country may differ from those in your country. Where required, we take reasonable steps to select suitable providers, use contractual and security safeguards, and comply with rules governing overseas disclosures or transfers.

10. Automated decisions about access

Our systems use rules to reconcile account and Stripe information and decide whether to grant, continue, expire, suspend, or revoke access to a paid product. They may also prevent account deletion while billing is active or unresolved.

The personal information used for these rules may include your account identifier, product and offer, purchase-intent and Stripe identifiers, payment or subscription status, paid-through and cancellation dates, refunds, disputes, and entitlement history. For example, an active paid subscription may grant access, while an expired, fully refunded, or terminal subscription state may end access. After a failed renewal payment, rules may preserve access during the 14-day grace period while Stripe makes up to eight retry attempts, then end access if payment remains unresolved.

These are rules-based access and billing decisions, not behavioural advertising or AI profiling. If you believe a status is wrong or want a person to review it, contact hello@120.dev.

[VERIFY: PRODUCTION RULES, WHETHER FRAUD OR CHARGEBACK SIGNALS AFFECT ACCESS, AND THE HUMAN-REVIEW PROCESS MUST MATCH THIS SECTION. This section is drafted with the Australian automated-decision privacy-policy requirements commencing on December 10, 2026 in mind.]

11. Your choices and rights

Depending on where you live and which law applies, you may have rights to:

  • ask whether we hold personal information about you and request access to it;
  • request correction of inaccurate or incomplete information;
  • request deletion or de-identification;
  • object to or restrict certain processing;
  • receive certain information in a portable form;
  • withdraw consent where processing depends on consent;
  • opt out of marketing; and
  • complain to us or a privacy regulator.

Where applicable, you may use an authorised agent, appeal our refusal of a request, and exercise privacy rights without unlawful discrimination. We do not sell personal information or share it for cross-context behavioural advertising, so we do not offer a sale or targeted-advertising opt-out.

You can manage linked identities, authorised applications, billing, and account deletion through your 120.dev account where those controls are available. Use the unsubscribe link in a marketing email to opt out of marketing.

To exercise another right, email hello@120.dev. Describe your request and the account email involved. We may need to verify your identity. We will respond within the period required by applicable law and explain any lawful reason we cannot fulfil all or part of a request. We do not charge for a request unless applicable law permits a reasonable charge and we tell you first.

Some information cannot be deleted immediately because it is stored only on your device, needed to complete billing or prevent fraud, or must be retained for legal, tax, accounting, security, or dispute purposes.

If you have a privacy concern, contact us first so we can investigate. [VERIFY: INTERNAL COMPLAINT PROCESS AND TARGET RESPONSE TIME.] If the Australian Privacy Act applies and you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.

12. Children

The Services are not directed to children, and a person must be at least 18 to create an account. We do not knowingly collect online account information from a younger person. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.

Showcase content stored only on a user's device may depict children, but 120.dev does not receive that content through the standard local workflow.

13. Third-party sites and services

The Site and apps may link to third-party sites or services. When you leave our Services or direct your device to communicate with a third party, that party's privacy policy applies. We do not control its independent practices. This includes Google, Stripe, AI providers, social networks, app-distribution channels, and linked content sources.

14. Changes to this policy

We may update this policy when our practices, providers, Services, or legal obligations change. We will post the revised policy and update its effective date. If a change is material, we will provide reasonable notice by email, in-product notice, account notice, or a prominent Site notice, as appropriate.

We will ask for consent before using personal information for a materially different purpose where applicable law requires it.

15. Contact us

For privacy questions, access or correction requests, deletion requests, and complaints, contact:

  • Entity: 120.DEV PTY LTD
  • Attention: Privacy Officer
  • ACN: 702 182 545
  • ABN: 59 702 182 545
  • Address: [VERIFY: REGISTERED OR PRIVACY NOTICE ADDRESS]
  • Telephone: [VERIFY: PRIVACY CONTACT TELEPHONE]
  • Email: hello@120.dev
  • Website: 120.dev
  • EEA representative: [VERIFY WITH COUNSEL: NAME AND CONTACT DETAILS IF REQUIRED]
  • UK representative: [VERIFY WITH COUNSEL: NAME AND CONTACT DETAILS IF REQUIRED]