Practical guide

Video subtitle privacy starts with the data flow

A local file picker says where a file is selected, not where it is processed. To compare subtitle workflows, ask what crosses the device boundary: the entire video, extracted audio, subtitle text, account data, or none of the media. ClipLocale keeps video local but uses online audio transcription and text translation.

Open the example workspace

Three workflows have different boundaries

Local extraction reduces the input sent upstream by separating audio from the video on your device. It is useful when the picture contains private material that the speech service does not need. The audio can still identify speakers, reveal private conversations, or contain sensitive facts, so removing the picture is not complete anonymization.

A full-video upload workflow sends the video to a remote service before or during processing. An offline workflow performs both speech recognition and translation on the device, provided its models and runtime truly operate without remote processing. Offline tools may still contact servers for downloads, updates, or analytics; inspect the specific setup rather than trusting a category name.

WorkflowMedia sent for processingWhat to check
Local audio extraction + online modelsExtracted audio and subtitle textAudio/text provider policy and request payloads
Remote video processingFull video and derived contentUpload storage, deletion, processing and sharing terms
Offline recognition + translationNo media for remote model processing if genuinely offlineModel availability, runtime requests, device resources

ClipLocale’s processing boundary

Your browser reads the selected video and extracts bounded audio chunks with MediaBunny and WebCodecs. The audio is sent to the same-origin ClipLocale Worker, which forwards it to OpenRouter for speech recognition. Timed subtitle text is then sent for translation. The browser receives cues for preview, editing, and SRT/VTT download.

Video, audio, and subtitle text are not saved as a project library in the ClipLocale application. Account sessions, processing balance, and necessary billing records are stored separately. That application design does not establish how an upstream provider handles request retention. Read the relevant provider policies before submitting material with confidentiality requirements.

ClipLocale processing flow (diagram)
  1. On device: videoBrowser reads video and extracts audio; video remains local
  2. Online: audio → transcriptSame-origin Worker → OpenRouter transcription
  3. Online: transcript → translationSubtitle text is sent to a text model
  4. On device: review and downloadOriginal, translated or bilingual SRT/VTT

Inspect requests with a harmless test clip

Use a short recording made specifically for testing, with no private names, faces, or conversations. Open browser developer tools, select Network, clear the log, and choose the video. Selection should inspect media locally; pressing Generate is the point where authorized processing requests begin. Do not use a real confidential file to test a privacy claim.

Filter for /api/transcribe and /api/translate. The transcription request carries extracted audio rather than the original MP4/MOV/WebM; the translation request carries caption text. Inspect whether unexpected third-party hosts receive media payloads. A browser inspection shows browser-to-service traffic, not every server-to-provider hop or the provider’s retention behavior.

  1. Prepare harmless sample media and start a fresh Network log.
  2. Select the file and observe local inspection before recognition.
  3. If authorized to incur processing cost, start a short range and inspect the request types.
  4. Check destinations and payload categories without sharing a raw network archive.

Do not mistake analytics for media processing

ClipLocale analytics records bounded categories such as a page view, processing outcome, subtitle download format, and checkout action, with anonymous visitor/session identifiers. It does not send subtitle lines, uploaded file names, account identifiers, or arbitrary query strings as analytics properties. Analytics traffic is separate from the audio and text requests needed for transcription and translation.

Inspecting a Network request can expose account cookies, tokens, payment metadata, or private payloads. Do not publish a HAR file or screenshot of request bodies from a real session. Share a redacted description of destination and data category when asking for help.

Choose according to your confidentiality requirement

If your requirement is that no audio or transcript leaves the device, ClipLocale’s online model workflow does not meet it. Choose an appropriately verified offline setup and check whether its language models are installed locally. If your requirement is that the video image not be sent to a speech service, local audio extraction can be relevant, while audio/text processing policies remain part of the decision.

This is a comparison of processing methods, not a claim that a named competitor has been tested or that one category guarantees a retention policy. Consult the privacy policy and current terms of each service. For public or permitted material, use the short review workflow and export the result before leaving the page.