What we collect
Account data. Your email address, display name, and the authentication identifiers our auth partner issues. We never see or store your password.
Session media. The camera and microphone you record, and the source video you react to. On iPhone and iPad, the app uses your camera and microphone with your permission and saves recording segments and recovery information in its local storage. On the web, media is captured in your browser. Recording segments are uploaded to our object storage and processed by our render workers to produce your exports. In guest sessions, LiveKit carries the live audio and video shared with the participants you join.
Local files and permissions. The app accesses source files you select through Photos or Files and copies them into its own storage so uploads can resume. Save to Photos requests permission to add a finished export to your library. Share opens the device share sheet for the destination you choose. Local segments, imported files and recovery records may remain after upload; cloud retention does not automatically remove these local copies. Removing the app can erase recordings that have not uploaded.
Session metadata. The timeline of your recording — when you played, paused and seeked the source — plus layout, resolution and export choices. This is what makes a take reproducible in a different layout later, so it lives as long as the session does.
Transcripts. Automatic transcription is switched off by default and is not running for anyone today, so no audio leaves our storage for speech-to-text. If we turn it on, the recorded audio of a session is sent to Deepgram (listed below) to produce a transcript the host can download, and this policy is updated before that happens.
Usage and device data. Standard web logs — IP address, user agent, timestamps, pages viewed — and product analytics about which parts of the studio you use.
Billing data. Our payment processor handles the card. We store your customer ID, plan tier and subscription status. We never receive your card number. Apple handles purchases made through the iPhone and iPad app. OverReact receives signed transaction information, including the product, transaction identifier, subscription expiry, trial and revocation status, and an identifier linking the purchase to your OverReact account. We use this information to verify and restore access. Existing web subscriptions continue to use Stripe.
How we use it
To run the service: authenticate you, record and render your sessions, send transactional email such as receipts and service notices, enforce plan limits, prevent abuse, and work out which parts of the product are broken.
We do not sell your data, we do not use your recordings to train models, and we do not share media with anyone except the subprocessors listed below, each of which needs it to deliver a specific part of the service.
How long we keep your media
This is the part of the policy most likely to actually affect you, so it is stated plainly rather than buried.
On Free, recordings and exports are permanently deleted 24 hours after they are created. Download them before then, or upgrade to keep them.
Persistent storage is a paid feature. That is not a dark pattern hidden in a policy — the 24-hour countdown is shown on the storage meter and on every asset in your dashboard, and the download button is right next to it.
| Plan | What happens to your recordings and exports |
|---|---|
| Free | Permanently deleted 24 hours after they are created. Storage quota 2 GB. |
| Pro trial (3 days) | An eligible Pro trial provides Pro access during the trial. Web trials are processed by Stripe; app subscriptions and eligible introductory trials are processed by Apple. Eligibility and renewal terms are shown before purchase. Retention follows your effective entitlement, including existing paid or lifetime access. When access becomes Free, the 24-hour rule applies to new media. |
| Pro (and legacy paid tiers) | Kept until you delete them. Nothing is auto-deleted while you are subscribed. Storage quota 50 GB. |
| After a paid plan ends | Kept for 7 days, then deleted. |
Hitting a storage quota does not delete anything. It pauses new uploads and renders until you clear space. We do not free up room by removing a paying customer’s media.
If a paid subscription ends, When a paid plan ends, your recordings and exports are kept for 7 days and then deleted. Download anything you want to keep within that window; the dashboard shows your plan status.
When you delete something, it disappears from the app immediately and is purged from object storage and from our backups within 30 days. Deleting your account does the same for everything in it.
Everything else. Server logs are kept for 30 days. Billing records are kept for as long as tax and accounting law requires, which is longer than any of the above and is not something we can shorten on request.
Who else touches your data
These are the companies that process data on our behalf to deliver OverReact. Each one handles it under its own terms and privacy policy.
| Subprocessor | What it does for us |
|---|---|
| Clerk | Authentication, sessions and account identity |
| LiveKit | Real-time media transport for guests and AirCam |
| Amazon Web Services (S3) | Object storage for raw chunks, renders and exports |
| Hostinger | The servers that run OverReact — API, database and render workers |
| Stripe | Web payments, subscriptions and the billing portal |
| Apple | App Store distribution, in-app purchases, purchase restoration and subscription transaction notifications |
| Resend | Transactional email — guest invite links and waitlist confirmations |
| Sentry | Error monitoring — receives the stack trace, IP address and account ID when something breaks |
| PostHog | Product analytics — which parts of the studio are used, when enabled |
| Deepgram | Speech-to-text, only if transcription is switched on (it is off today) |
| OpenRouter | AI highlight suggestions from a transcript, only if transcription is switched on |
If we add a subprocessor that processes session media, we will update this list before it starts processing anything.
Your rights
You can access, export, correct or delete your personal data at any time. Sessions and exports can be downloaded and deleted from your dashboard without asking us. For anything that is not a button in the product, email hello@overreact.tv from the address on the account.
Account deletion in the app. Open Account and choose Delete account. The iOS app clears local files associated with the signed-in account before sending the deletion request. Files belonging to another account and unrecognized older files are preserved. The service disables the account and queues identity, media and applicable web-subscription cleanup; failed provider actions are retried. Deleting your OverReact account does not cancel an Apple subscription. Cancel it separately in Apple Account subscription settings. Apple and payment providers may retain transaction records under their own policies and legal obligations.
If you are in the EEA, the UK or California you also have rights under the GDPR, the UK GDPR and the CCPA/CPRA respectively — including the right to object to processing, the right to data portability, and the right not to be discriminated against for exercising them.
Children
OverReact is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, tell us and we will remove it.
Where your data lives
Storage and processing happen primarily in the United States. If you use OverReact from outside the US, your data is transferred there.
Changes to this policy
The September 26, 2026 update clarifies how the iPhone and iPad app handles local recording files, permissions, Apple purchases and account deletion. It describes existing app behavior and does not change our data practices.
If we make a material change we will email you at least 7 days before it takes effect. The effective date at the top of this page always reflects the current version.
Contact
OverReact.tv · hello@overreact.tv. Privacy questions are answered by a person, not a ticket macro.
Related: how we protect it, the terms you agreed to, and which plan keeps your media.