Legal

Privacy Policy

Solar Sailer is a video editor that runs on your own computer. This page explains what stays there, what leaves, and who receives it.

Effective 8 August 2026. Last updated 30 September 2026.

We have written this to be read, not to be survived. If anything here is unclear, write to us and we will fix the wording.

Who we are

Solar Sailer is made by Little Bang, 8963 Complex Dr., Suite B, San Diego, CA 92123. You can reach us at operations@proko.com.

The short version

  • Your video files stay on your computer. Solar Sailer reads them where they already live. It reads your footage, project and caches locally. The AI features and optional crash dumps described below can send content from them.
  • Some things derived from your footage do leave when you use a feature that needs an AI service: an audio track for transcription, transcript text, small sample frames, short audio excerpts, and cropped faces. Which of those depends on which features you use. The list further down is exact.
  • Those go straight from your computer to that AI company, on your own account with them. They do not pass through us. These AI requests go to the provider. Optional desktop crash dumps can separately include content held in memory, as described below.
  • Solar Sailer does send us crash reports and usage data so we can find what breaks, what is slow and what goes unused, and fix it quickly. You can switch both off in Preferences. Ordinary reports and usage events exclude your content. Internal desktop builds and customers who turn on Contributor Mode can also send native crash dumps, which may contain transcripts or other content held in memory.

What stays on your computer

These files are stored on your own drive. The flows below describe when features send content derived from them; optional native crash dumps may also include content held in memory:

  • Your video, audio and image files.
  • Your project file, which holds the timeline, your cuts, markers and settings.
  • Working files Solar Sailer generates as you edit: audio conforms, preview proxies, waveforms, thumbnails and poster frames. They live in a cache folder you can move or clear at any time.
  • Transcripts and analysis results, stored beside your project.
  • Diagnostic logs, written once per session into Solar Sailer's application data folder. These do contain your project and file names. There is no feature that uploads them. If we ever ask you for a log to chase a bug, you will be sending it to us deliberately, by hand.
  • Your API keys, encrypted at rest using Windows' own credential protection.

What leaves your computer

Solar Sailer contacts an outside service only when a feature needs it. Below is every one of them.

Features that use your own AI accounts

These run on API keys you supply. The data travels from your computer directly to that provider. It never touches our servers, and we never see it or hold a copy. Once it arrives, that provider's own privacy terms and retention rules apply, not ours. Today those providers are AssemblyAI, OpenAI, Google and Anthropic. We may add others in the future, and this page will name them when we do. By using a feature that sends data to one of these providers, you agree to that provider's privacy policy and terms of service.

Transcription
A speech quality audio track extracted from your clip, in mono. The picture is stripped out first and is never sent.
AssemblyAI
Transcript review, Rough Cut, retake detection
The text of your transcript.
OpenAI or Google, depending on the feature
Automatic clip labeling
A handful of still frames sampled through each clip, shrunk to 384 pixels on the long edge. For audio files, a few short excerpts instead. This runs on import unless you switch it off.
Google
Character and face recognition
Cropped images of faces from your footage.
Google
The AI editing agent
Whatever the agent reads to answer you, which is typically your timeline structure, clip and file names, and transcript text.
Anthropic, through the Claude Code tool on your machine, logged in with your own account

Automatic clip labeling is on by default. When you import media, Solar Sailer samples a few frames and sends them to Google to work out what each clip is. Those frames are small and few, so this is not the same as uploading your video, but they are pictures out of your footage and you should know it happens. You can switch it off in Preferences before you import.

We set no retention instructions on your behalf. When your audio goes to AssemblyAI or your transcript goes to OpenAI, how long they keep it is governed by your account with them, not by anything Solar Sailer asks for. If retention matters to you, set it on your own provider account.

What Solar Sailer sends to us

Crash reports
From the desktop app and from the phone companion app, technical details about an error, such as its category, where in our code it happened, your operating system version and the Solar Sailer version. Desktop JavaScript reports and phone JavaScript reports discard ordinary free-text messages, request data and add-on metadata before upload. The phone also reports uncaught Android Java crashes. Those native reports can include a library's Java exception message, Java thread stacks, app permission states, device details and a random id for that app installation. Android release-health session pings carry the same random id. They do not include the user-assigned device name, footage, chat, screenshots, a view of the screen, web requests or breadcrumb trails. Android freeze reports and NDK or tombstone reports stay off. Like any web request, delivery carries an IP address, and Sentry works out a rough location from it, such as the country, region and city. From the desktop, we also send diagnostic log records from a short approved list of events, such as the audio output device disconnecting; any file name in those records is replaced with an anonymous token before it leaves your machine. Contributor Mode adds a yes-or-no marker and enables native desktop crash dumps while crash reporting is allowed. Internal desktop builds also enable these dumps. A dump is a snapshot of parts of app memory when it crashes and can include transcripts, file paths, project names, credentials or other content held in memory. Before a dump is queued or uploaded, the app removes recognized credentials, such as passwords and API keys, from the text, memory and processor data it can read in the dump. The details needed to diagnose the crash stay intact. Unrecognized, fragmented or differently encoded secrets may remain, including older credentials the app no longer knows about. When a crash happens, the crash handler first saves an unfiltered copy on your computer, before the app can clean it. Dumps stay off for customers who have not enabled Contributor Mode. Handled by Sentry on our behalf.
On by default. Preferences, Diagnostics on the desktop. Settings, Diagnostics on the phone
Usage data
How Solar Sailer is used: that the app launched, that a project was opened or created, which processing modules ran, which agent commands ran, and similar usage events as the product grows. The phone companion app sends the same kind of events for what it does: that it launched, that it paired with a desktop, that a message was sent to the agent and roughly how long that message was, and that an approval was approved or rejected. Never the message itself, and never what the approval was about. We collect this to see what is slow, what fails and what goes unused, so we can improve Solar Sailer quickly. Like any web request, each of these events carries your IP address. PostHog uses it to work out roughly where in the world our users are, such as the country, region and city. We do not use it to identify you. Handled by PostHog on our behalf.
On by default. Preferences, Diagnostics on the desktop. Settings, Diagnostics on the phone
Problem reports
Only when you choose to send one: the words you type into the report form, and your email address only if you enter it. A report sent from an error message is attached to that error's crash report; one sent from the Help menu travels on its own. Handled by Sentry on our behalf.
Only when you press Send. Available while crash reports are on.

Ordinary automatic reports exclude your media, transcripts, file contents, project names and file paths. Native desktop crash dumps are an exception for internal builds and customers who enable Contributor Mode: they may contain any of that information if it was in app memory. A problem report includes the words you choose to send; the desktop app removes recognized credentials, such as a pasted API key, first. We filter ordinary crash reports before sending them, and usage events describe what the app did, never the content you did it to. If you log in to your Solar Sailer account inside the app, crash reports and usage events carry your account id, so we can tell how many people hit one problem and follow one person's path through a feature. Ordinary automatic events exclude your email address and name, and logging out ends the account link. Native desktop dumps can still contain personal information held in memory. A logged-out Android native crash or release-health ping can still carry Sentry's random id for that app installation, which is not an account id, name, email address or hardware serial number. After you switch Diagnostics off and next open the app, it sends none of these records.

The desktop app also removes recognized credentials from its diagnostic logs before saving them. This does not rewrite older local logs or touch your documents, and it cannot recognize every possible secret.

Desktop JavaScript crash reports and phone JavaScript crash reports use an approved list of fields. Free-text fields that a dependency or the operating system could fill are discarded. Native desktop dump attachments bypass those field filters and can include app memory. Phone native Java crash reports keep the exception message and device facts described above because those fields do not pass through the JavaScript filter. A problem report is different again: it includes the words you choose to send and an email address only if you enter one.

Update checks

The installed app asks our update server whether a newer version exists. That request tells us an app version and, like any web request, carries your IP address. It contains nothing about you or your work, and an update is never installed without you choosing to download it.

Your account

Solar Sailer accounts live at account.solarsailer.com. An account is optional for editing: the app works fully without one, and today it logs you in to the desktop app and to the phone companion app. Crash reports and usage events from the phone carry the same account id as the ones from your desktop, and the same Diagnostics opt-out sits in the phone's Settings. When you create one we store your email address, your name, a scrambled form of your password that cannot be turned back into it, and, if you turn on two-factor log-in, the secret that makes your codes work. Each place you log in gets a session record with a device label, the IP address it came from and the browser or app that made it, so you can see and end them from the Devices page. We also keep a log of security events on your account, such as log-ins and password changes, for at least twelve months. All of this is held on our own server in Google Cloud, in the United States, and never sold or shared.

You can download everything we hold about your account, and you can ask us to delete it, both from the account site. Deletion starts a 30-day waiting period you can cancel, and then the account and its records are removed.

Paying for Solar Sailer

Solar Sailer is not on sale yet. When subscriptions open, payments will be handled by Stripe. Stripe collects your card details directly and we never see or store a full card number. What reaches us is the information needed to run a subscription: your email address, your billing country for tax, and whether your subscription is active.

Subscriptions are planned to include AI use without your own API keys. When that ships, some of the AI features listed above will be able to run on our accounts with those providers instead of yours, and we will keep a usage record for your subscription, measured in minutes of footage processed, to run your plan's included allowance. Using your own keys will remain supported. Today, none of that exists: every AI feature runs on keys you supply, exactly as described above.

Team plans are planned as well. When they ship, crash reports and usage data will be off by default for team accounts. Personal accounts keep them on by default, and anyone, on any plan, can switch them off in Preferences.

We will update this page when any of that goes live, rather than leaving you to discover it.

What we do not do

  • We will not train generative AI image or video models on your media. Your footage is your work, not our training data.
  • We do not sell your data. There is very little to sell, because we do not hold your work.
  • We show no advertising and run no social media pixels.
  • We do not build a profile of you to sell or to target you. Your account id groups your usage events so we can find what is slow or broken, and that is all it is used for.
  • We do not record your screen or your editing sessions.

This website

solarsailer.com uses PostHog Web Analytics to measure visits: which pages are viewed, how visitors arrive, and roughly where in the world they come from, worked out from your IP address. What is stored depends on where you are. For visitors in Europe, nothing is stored until you accept the cookie banner, and declining keeps it that way: we count visits rather than recognizing returning visitors. We tell Europe apart by your device's time zone, checked on your device itself, so nothing is sent anywhere to decide it. Everywhere else, a small identifier is stored in your browser from your first visit so we can recognize you when you return, and the Cookie settings link in the footer lets anyone, anywhere, turn that off at any time. Declining removes the identifier, and your choice itself is remembered in your browser. Analytics here measures visits to the site, nothing more. Your footage and your projects never touch this website at all.

If you join the waiting list you give us your email address and, optionally, three one click answers about how you work: whether you film long form video, roughly how much footage you shoot a month, and which machine you use. We use it only to tell you when Solar Sailer is available and to understand who is waiting. We do not sell it or pass it on. Ask us and we will delete it.

Your choices

  • Switch off crash reports and usage analytics. Preferences, Diagnostics. Takes effect at the next launch.
  • Switch off automatic clip labeling. Preferences, before you import. Nothing goes to Google for labeling once it is off.
  • Do not use the AI features. Transcription, Rough Cut, retakes, face recognition and the agent all run only when you ask for them. Solar Sailer is a working editor without them, and used that way it makes no outbound connection except the update check.
  • Remove your API keys. Preferences, API Keys. With no keys, the AI features cannot send anything anywhere.

Your rights

Depending on where you live, you may have the right to ask what personal information we hold about you, to have it corrected, or to have it deleted. In practice this includes the account and waiting-list information described above, plus crash and usage records linked to your account. App records carry your account id while you are logged in. Logging out ends that link. Logged-out Android records carry only Sentry's random installation id, so we cannot locate them from an account request. Write to operations@proko.com and we will act on any such request.

Children

Solar Sailer is a professional tool and is not directed at children under 13. We do not knowingly collect information from them.

Changes to this policy

If we change what Solar Sailer collects, we change this page and the date at the top. When a change is significant, such as a new service receiving your data or a new category of information, we will say so here rather than quietly editing a line.

Contact

operations@proko.com
Little Bang, 8963 Complex Dr., Suite B, San Diego, CA 92123.