Cardinal Editor
Effective 27 July 2026 · Last updated 27 July 2026
Cardinal Editor (“Cardinal”, “the app”, “we”, “us”) is a mobile video editor for short-form creators. It imports a video you already have, analyses it for likely audience engagement, suggests edits, and lets you finish the edit on your device.
This policy explains what the app processes, what leaves your device, who else is involved, and
how to delete anything we hold. It applies to the Cardinal mobile app and the Cardinal backend
service at api.kordiko.com.
Cardinal has no sign‑up. There is no email address, password, or database of users.
When the app first needs to talk to the connected‑accounts service, our server generates a random device identifier (a UUID) and returns it in a signed token. The app stores that token on your device and presents it on later requests. The signature exists so that one device cannot read another device’s connected‑account data. The identifier is random and is not derived from your phone, your SIM, an advertising ID, or anything about you.
| Data | Why | Where it goes | Kept for |
|---|---|---|---|
| Sampled video frames (still images, up to 24 per analysis) | So the AI model can see what is in your video and suggest edits | Our server, then our AI provider | Not stored. Held in memory during the analysis only |
| Extracted audio — only if you generate captions | To transcribe speech into timed captions | Our server, then our AI provider | Not stored. Held in memory for that request only |
| Your projects, clips, edits and media files | To let you keep working on an edit | Stays on your device. Never uploaded | Until you delete the project or uninstall |
| Connected‑account access tokens | To read your own channel statistics on your behalf | Our server, encrypted at rest | Until you disconnect or request deletion |
| Channel statistics (followers, views, post count) | To show your Dashboard | Fetched from the platform when you open the app | Not retained as a historical record |
| IP address and basic request metadata | Rate limiting, abuse prevention, diagnosing errors | Our server logs | Short‑lived operational logs |
This is worth stating plainly because it is unusual. Cardinal analyses your clip by sampling a handful of still frames from it and sending those, rather than the video itself. The video file never leaves your device. All trimming, filtering, caption burning and exporting happens locally on your phone.
To produce analysis, suggestions and captions we send the sampled frames (and, for captions, extracted audio) to OpenRouter, which routes the request to Google’s Gemini model. We send only that media and the instructions needed to analyse it. We do not send your device identifier, your connected‑account tokens, or any information about who you are, because the model does not need it.
Those providers process the content to return a result. Their handling of it is governed by their own terms and privacy policies. We do not use your content to train any model, and we do not retain it after the request completes.
You may optionally connect a YouTube, TikTok or Instagram account so the Dashboard can show your statistics in one place. This is entirely optional; the editor works fully without it.
When you connect an account you are taken to that platform’s own login page. We never see your username or password. The platform returns an access token to us.
Cardinal is currently free, and paid tiers are planned. When they arrive, purchases will be handled by the app store you installed Cardinal from — currently Google Play — which acts as the payment processor.
We never receive or store your card number, billing address or any other payment details. The store tells us only whether a given installation holds an active entitlement, which is what unlocks the paid features. That check involves no personal information and does not create an account.
We do not share your information with anyone else, except where we are legally required to.
Because there is no account, most of your data is already only on your phone.
/api/social/data-deletion.Traffic between the app and our server is encrypted in transit with HTTPS. Access tokens are encrypted at rest. Device tokens are cryptographically signed so they cannot be forged or guessed, and are sent in a request header rather than a URL, so they do not end up in logs or browser history.
No system is perfectly secure, and we do not claim otherwise. We keep the amount of data we hold deliberately small, which is the most effective protection available to us.
Cardinal is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has provided information to us, contact us and we will delete it.
Our server and our providers may process data in the United States and other countries. By using Cardinal you understand that your content may be processed in a country other than your own.
Depending on where you live, you may have rights to access, correct, export or delete your personal information, and to object to certain processing. Contact us and we will honour any such request. In practice, we hold very little: a random device identifier and, if you connected one, an encrypted access token.
If we change this policy we will update the date at the top of this page. Material changes will be announced in the app before they take effect.
Questions, requests or complaints: support@kordiko.com