Your words stay your words.
Studio cuts the recording you send. A card on screen can only use a word you said. If it cannot, that card is dropped before the video is drawn.
No card shows a word nobody said.
The rule is checked at plan time, before anything is drawn. A card containing a word that is not in your transcript is dropped, and that sentence is planned again on your face — as a shot of you talking, with captions, instead of a card.
Where the rule came from
A 54-minute talk rendered for three hours and then failed its last check. The planner had made a number card reading “11 / th grade” from the sentence “10th and 11th grade” — the recogniser had split an ordinal into a number and a stray word, and the card took both.
Three hours of work, lost at the final gate, for a reason the plan already contained. Two things changed and neither of them is a promise:
- An ordinal is not a number card. “10th”, “11th grade”, “21st” count nothing, so they produce no counting card at all.
- The check moved into the plan. The same test that failed the finished file now runs when the plan is made, so a long job can never again fail at the end for something its plan already had.
The run above is the shape of the real output; the live job's own record reads
unspoken_shots -> [('119', 2194.9, ['th'])] before the fix and 5 number cards, 0 unspoken
words after it. Source: gate O-17, in full.
If this, then that — every decision the Studio takes, in one place.
The decisions column of your video is not a log file. Each row states what happened, at the timecode where it happened, and the reason it happened — in the same words the rulebook uses.
The rulebook itself is public in the product: one row per situation, with what the Studio does and the rule id that holds it. When a rule changes, the row changes, and the reason a video was cut a particular way can be read months later.
Every row is recorded in the order it happened, with the words heard, the cards planned and the pieces cut. Source: the decisions column, as it runs.
Five gates, and the exact output each one produced.
These are reproduced character for character. Every one of them runs against the deployed Studio on its own URL — not in a lab, and not on a copy of the code.
Six gates can block a finished video: S1 a finished file exists and plays · S2 the length matches the plan · S3 captions match the speech · S4 no card covers a face (may warn) · S5 no card shows a word nobody said · S6 the audio is not clipped or silent. S7 (black edges) and S8 (the comparison) are reported as well.
Every gate is re-run against the live URL by a check that reads the access code from the environment and behaves as a customer's browser does. A gate that cannot be produced as output does not go in the list.
Three families: S for the live server, V for multi-file jobs and O for honesty — all five above, reproduced in full.
The time left is measured, and it rounds late on purpose.
Studio fits each stage to seconds = a + b × minutes of footage, using the finished jobs on this server rather than a benchmark. Talking videos and montages are fitted apart, because a montage's stages scale with its clips, not with speech.
A queued job adds the work of the jobs ahead of it in its own lane. A stage that is already running beats the history once it reports its own progress. And when a stage runs past its usual time the clock never falls to zero: it keeps a minimum of its own estimate, or twenty seconds.
A job survives the server that started it.
Editing runs in its own process, one job at a time, and every stage saves its work as it goes. That is what makes the promises below mechanical rather than hopeful.
| What happens | What Studio does | Where it is proved |
|---|---|---|
| The server restarts mid-job | The job continues from its last saved stage or piece, up to five times. An update restart does not use up one of those attempts — only a crash counts as one. | DS2 · the decision log |
| A stage stalls | No progress for 45 minutes and the stage is stopped and continued from its last saved piece, up to three times. Memory trouble waits a minute and continues from saved work. | the job's own stalled-stage record |
| An upload's connection drops | Files are sent in 4 MB chunks, up to five in parallel; a chunk arriving out of order waits its turn. The upload continues by itself, and after a refresh, choosing the same files continues from where it stopped. | uploads resume by themselves |
| A job runs and runs | No job may run longer than 24 hours. If one ever does, it stops as failed, and you get the full error report with a button to continue from the last saved piece. | the 24-hour limit, in the honest limits table |
| You press Stop | Everything already done is kept, nothing is deleted, and no minutes are charged. “Try again from where it stopped” continues it later. | “no minutes are charged” — what is never charged |
Your footage stays on Studio's own server.
It is not sent to a third-party generation API. The edit is drawn and encoded on the same machine that received the files, which is also why the render times on this site are as long as they are.
- IP addresses are hashed and never stored raw. Telemetry keeps a hash for counting, not an address.
- Footage is kept for your plan's retention window — 7 days on Free, 30 on Creator, 90 on Pro, 365 on Studio Business. The server's own knob is
STUDIO_KEEP_DAYS, where 0 means keep forever. - Delete footage at any time. Uploads, every version and every short go, and the page tells you the bytes freed.
- The notes stay. The editing notes, the chat, the transcript and what the Studio learned are what make your next video better, so deleting footage removes the media and keeps the record.
Deleting is blocked while a job is uploading, queued or running. The eighteen files that survive it are listed beside this, and IP addresses are hashed, never stored raw — accounts and access.
Eighteen files, an explicit allow-list. Nothing outside this list survives the delete.
Four lines it will not cross, and four things it cannot do at all.
Every product has a boundary. These are ours, written down here rather than discovered by you halfway through a project.
| Not possible | What that means for you |
|---|---|
| Generative footage | No AI-shot clips, no invented b-roll. Everything on screen was filmed or uploaded by you. |
| Frame-by-frame manual editing | You cannot drag a clip edge or nudge a cut by two frames. You ask in words; if a change cannot be expressed that way, it cannot be made. |
| Motion graphics authoring | No keyframe timeline, no custom animation build. Cards and captions are drawn from a fixed, tested set of layouts. |
| Multi-cam switching | There is no angle switcher. Side-by-side call panels are handled by layout rules, not by you cutting between cameras. |
If your job needs one of those four, Studio is the wrong tool and we would rather say so here. The comparison page names the tools that do those things well.
The four line-crossings above are rules the Studio applies to every job; the four “cannot” rows are gaps it has today, and we would rather list them than let you find them.
How signing in works, and what is not built yet.
These are the mechanics, including the parts that are less convenient than they could be. Anything not in this list does not exist.
| What | How it works | Where |
|---|---|---|
| Session cookie | A 30-day studio_sid cookie: HttpOnly, SameSite=Lax, Secure behind HTTPS, scoped to path=/studio. It is not readable by page scripts. |
your sessions, in security settings |
| Passwords | Salted and hashed with werkzeug's scrypt/pbkdf2. The plain password is never stored. Minimum 8 characters, and changing it deletes every existing session of that account. | change it in security settings |
| Sessions per login | Each login writes its own session row with the IP and the browser, kept for support — so “where was I signed in from” has an answer. | every sign-in is listed there |
| Disabling an account | Disabling takes effect at once and kicks every session of that account. | account settings |
| Rate limits | Sign-up: 5 new accounts per IP per hour, then “too many new accounts from here - try again later”. Log-in: 12 tries per IP per 10 minutes, then “too many tries - wait ten minutes”. | shown on the sign-in page |
| Scripts and API access | Authorization: Basic base64(email:password) is accepted instead of the cookie — over HTTPS only. There is no key management, so this is a password in a header. |
the legacy tools, and their API |
| Telemetry | Auth events (signup, signup_refused, login, login_refused, logout) are recorded, and IP addresses are hashed, never stored raw. | privacy and data handling |
Check it on your own footage.
The first 30 minutes are free, and the word check runs on a free job exactly as it runs on a paid one. If the edit is not right, say so in the chat — revisions cost nothing.
Already have an account? Sign in.