Skip to content
Skip to content
Safety

Your words stay your words.

Studio cuts the recording you send. A card on screen can only use a word you said. If it cannot, that card is dropped before the video is drawn.

Every claim names where it is checked Warnings are published, not hidden A limits list, not a feature list
The rule for this page A card can only show a word you said. The check runs before a frame is drawn. A card that fails is removed and that sentence stays on your face, with captions.
The word check No card will ever show a word you did not say. It is not a review step and it is not a promise. It runs at plan time, before a single frame is drawn, and a card that fails it is dropped and its sentence is planned again on your face.
The word check

No card shows a word nobody said.

The rule is checked at plan time, before anything is drawn. A card containing a word that is not in your transcript is dropped, and that sentence is planned again on your face — as a shot of you talking, with captions, instead of a card.

Where the rule came from

A 54-minute talk rendered for three hours and then failed its last check. The planner had made a number card reading “11 / th grade” from the sentence “10th and 11th grade” — the recogniser had split an ordinal into a number and a stray word, and the card took both.

Three hours of work, lost at the final gate, for a reason the plan already contained. Two things changed and neither of them is a promise:

  • An ordinal is not a number card. “10th”, “11th grade”, “21st” count nothing, so they produce no counting card at all.
  • The check moved into the plan. The same test that failed the finished file now runs when the plan is made, so a long job can never again fail at the end for something its plan already had.

What you see while it cuts

The video was planned again and drawn again
The friend's video did not stay failed. With the rule in place the transcript was planned again: five number cards, zero unspoken words, and the finished file passed S5 — “every drawn word was spoken”.
The checks behind the gate run on the unit suite and on the live job
S5No card shows a word nobody saidpass
PL5The check runs at plan time, before anything is drawnpass
F22An ordinal (“11th grade”) is not a number cardpass
NW1Number words are shown honestly, with their unitpass
S3Captions match the speechpass
$ honesty check — the five rules, run before anything is drawn PASS no unspoken word PASS ordinal rule: "10th and 11th grade" is not a number card PASS a card's words do not end mid-thought PASS a number card carries its unit PASS a year is a date, not a counting card dropped 1 card ("almost there") — sentence replanned on the face honesty: 5 of 5 pass

The run above is the shape of the real output; the live job's own record reads unspoken_shots -> [('119', 2194.9, ['th'])] before the fix and 5 number cards, 0 unspoken words after it. Source: gate O-17, in full.

Every decision, written down

If this, then that — every decision the Studio takes, in one place.

The decisions column of your video is not a log file. Each row states what happened, at the timecode where it happened, and the reason it happened — in the same words the rulebook uses.

The rulebook itself is public in the product: one row per situation, with what the Studio does and the rule id that holds it. When a rule changes, the row changes, and the reason a video was cut a particular way can be read months later.

Chapters of the rulebook: what came in (probe) · what kind of footage · sound · words · pictures on screen · when things go wrong · feedback, versions, learning.
Three rows from a finished job read before you watch
00:02:14 Two people in side-by-side call panels — this is a conversation The picture, after the black bars come off, is 3.6 : 1. A conversation is cut and planned differently from one person reading a script. rule FK2 · footage kind F1
00:09:41 Kept a sentence that was said twice In a conversation only stutter restarts are removed; the repeats stay. The retake rules for one person re-reading a script removed 112 of 278 sentences here before the conversation rule existed. rule KC
00:12:02 No card for “11th grade” — an ordinal counts nothing A number that is an ordinal is not a counting card. The sentence stayed on the faces with captions. rule F22

Every row is recorded in the order it happened, with the words heard, the cards planned and the pieces cut. Source: the decisions column, as it runs.

Gates with evidence

Five gates, and the exact output each one produced.

These are reproduced character for character. Every one of them runs against the deployed Studio on its own URL — not in a lab, and not on a copy of the code.

Run against the live server reproduced in full
S-1The Studio page answers on the live server with the access code, and refuses without itpass
S-3All ten test clips went through the live URL; every one passed gates S1–S6pass
S-4The deployed code is main's HEAD — what is live is what is committedpass
V-1Three multi-file sets passed S1–S6 and S8 on the live URL, and one carries the comparisonpass
O-17No card shows a word nobody said; ordinals are not number cards; the test runs at plan timepass

Six gates can block a finished video: S1 a finished file exists and plays · S2 the length matches the plan · S3 captions match the speech · S4 no card covers a face (may warn) · S5 no card shows a word nobody said · S6 the audio is not clipped or silent. S7 (black edges) and S8 (the comparison) are reported as well.

- [x] O-17: No card shows a word nobody said - ordinals are not number cards (F22) and the S5 test runs at plan time (PL5) CHECK: the honesty check EXPECT: /honesty: (\d+) of \1 pass/ EVIDENCE: 2026-10-02 ~14:20 IST "honesty: 5 of 5 pass"; the live spec of the friend's video: unspoken_shots -> [('119', 2194.9, ['th'])]; their transcript planned again with the fix -> 5 number cards, 0 unspoken words
- [x] S-3: All ten test clips went through the live URL and every one passed gates S1-S6 CHECK: the live round of ten test clips EXPECT: /round: 10 of 10 done, 10 of 10 pass S1-S6/ EVIDENCE: n2_horizontal_bakery: done {'S1': 'PASS', 'S2': 'PASS', 'S3': 'PASS', 'S4': 'PASS', 'S5': 'PASS', 'S6': 'PASS', 'S7': 'PASS'} | round: 10 of 10 done, 10 of 10 pass S1-S6

Every gate is re-run against the live URL by a check that reads the access code from the environment and behaves as a customer's browser does. A gate that cannot be produced as output does not go in the list.

Three families: S for the live server, V for multi-file jobs and O for honesty — all five above, reproduced in full.

An honest clock

The time left is measured, and it rounds late on purpose.

Studio fits each stage to seconds = a + b × minutes of footage, using the finished jobs on this server rather than a benchmark. Talking videos and montages are fitted apart, because a montage's stages scale with its clips, not with speech.

# fitted per step and per mode, from finished jobs, refreshed every 10 minutes talk probe (20, 1) transcribe (30, 12) cut (25, 50) plan (5, 1) render (60, 87) check (10, 10) montage probe (40, 110) transcribe (0, 0) cut (0, 0) plan (0, 0) render (100, 110) check (15, 5) MB_PER_MIN = 60.0 # before the footage is read, length is guessed from the upload size MARGIN = 1.15 # better a little late than early: the measured spread was -15 % to +40 %

A queued job adds the work of the jobs ahead of it in its own lane. A stage that is already running beats the history once it reports its own progress. And when a stage runs past its usual time the clock never falls to zero: it keeps a minimum of its own estimate, or twenty seconds.

The deliberate 15 % “Better a little late than early.” This server's own predictions landed between 15 % early and 40 % late. When a number has to be wrong the owner chose the direction that does not leave you refreshing a page, so the estimate carries a 15 % margin by design.
Why it exists The owner waited an hour with “working…” and no idea when the video would be ready. That sentence opens the file that now does the arithmetic. The honest clock was not a marketing idea — it was the fix for a page that went silent during a long job.
Nothing is lost quietly

A job survives the server that started it.

Editing runs in its own process, one job at a time, and every stage saves its work as it goes. That is what makes the promises below mechanical rather than hopeful.

What happens to a job or an upload when something goes wrong
What happensWhat Studio doesWhere it is proved
The server restarts mid-job The job continues from its last saved stage or piece, up to five times. An update restart does not use up one of those attempts — only a crash counts as one. DS2 · the decision log
A stage stalls No progress for 45 minutes and the stage is stopped and continued from its last saved piece, up to three times. Memory trouble waits a minute and continues from saved work. the job's own stalled-stage record
An upload's connection drops Files are sent in 4 MB chunks, up to five in parallel; a chunk arriving out of order waits its turn. The upload continues by itself, and after a refresh, choosing the same files continues from where it stopped. uploads resume by themselves
A job runs and runs No job may run longer than 24 hours. If one ever does, it stops as failed, and you get the full error report with a button to continue from the last saved piece. the 24-hour limit, in the honest limits table
You press Stop Everything already done is kept, nothing is deleted, and no minutes are charged. “Try again from where it stopped” continues it later. “no minutes are charged” — what is never charged
Where your footage goes

Your footage stays on Studio's own server.

It is not sent to a third-party generation API. The edit is drawn and encoded on the same machine that received the files, which is also why the render times on this site are as long as they are.

  • IP addresses are hashed and never stored raw. Telemetry keeps a hash for counting, not an address.
  • Footage is kept for your plan's retention window — 7 days on Free, 30 on Creator, 90 on Pro, 365 on Studio Business. The server's own knob is STUDIO_KEEP_DAYS, where 0 means keep forever.
  • Delete footage at any time. Uploads, every version and every short go, and the page tells you the bytes freed.
  • The notes stay. The editing notes, the chat, the transcript and what the Studio learned are what make your next video better, so deleting footage removes the media and keeps the record.

Deleting is blocked while a job is uploading, queued or running. The eighteen files that survive it are listed beside this, and IP addresses are hashed, never stored raw — accounts and access.

What is kept when the footage is deleted
state.json options.json upload.json chat.jsonl children.json rating.json spec.json transcript.json transcript.raw.json ctx.json assets.json style.json report.json probe.json edl.json words.json pipeline.log render.json

Eighteen files, an explicit allow-list. Nothing outside this list survives the delete.

The record, in your hands The edit decision list is yours to read. The pieces that were kept, the words that were heard and every card with its reason live in plain files on the server, and are readable from the video's own page without asking us for anything.
What Studio will not do

Four lines it will not cross, and four things it cannot do at all.

Every product has a boundary. These are ours, written down here rather than discovered by you halfway through a project.

It will not invent a shot you did not film. There is no generative footage in Studio. If the video needs a picture of something you never recorded, it will ask on the page rather than make one up.
It will not write a claim you did not make. Cards are made from your words. A correction to a name is only made where it sounds like what was actually said, and a script can only fix spellings.
It will not put a number on screen that nobody said. That is the word check, and it is the one rule with a test guarding it on every release.
It will not fake a render. If a job fails, the page shows the plain reason, the full error report and a button to continue — never a placeholder video, and never a silent retry that pretends the first one worked.
And what it cannot do at all, today
Things Studio cannot do, and what to use instead
Not possibleWhat that means for you
Generative footageNo AI-shot clips, no invented b-roll. Everything on screen was filmed or uploaded by you.
Frame-by-frame manual editingYou cannot drag a clip edge or nudge a cut by two frames. You ask in words; if a change cannot be expressed that way, it cannot be made.
Motion graphics authoringNo keyframe timeline, no custom animation build. Cards and captions are drawn from a fixed, tested set of layouts.
Multi-cam switchingThere is no angle switcher. Side-by-side call panels are handled by layout rules, not by you cutting between cameras.

If your job needs one of those four, Studio is the wrong tool and we would rather say so here. The comparison page names the tools that do those things well.

The four line-crossings above are rules the Studio applies to every job; the four “cannot” rows are gaps it has today, and we would rather list them than let you find them.

Accounts and access

How signing in works, and what is not built yet.

These are the mechanics, including the parts that are less convenient than they could be. Anything not in this list does not exist.

Sessions, passwords, rate limits and script access
WhatHow it worksWhere
Session cookie A 30-day studio_sid cookie: HttpOnly, SameSite=Lax, Secure behind HTTPS, scoped to path=/studio. It is not readable by page scripts. your sessions, in security settings
Passwords Salted and hashed with werkzeug's scrypt/pbkdf2. The plain password is never stored. Minimum 8 characters, and changing it deletes every existing session of that account. change it in security settings
Sessions per login Each login writes its own session row with the IP and the browser, kept for support — so “where was I signed in from” has an answer. every sign-in is listed there
Disabling an account Disabling takes effect at once and kicks every session of that account. account settings
Rate limits Sign-up: 5 new accounts per IP per hour, then “too many new accounts from here - try again later”. Log-in: 12 tries per IP per 10 minutes, then “too many tries - wait ten minutes”. shown on the sign-in page
Scripts and API access Authorization: Basic base64(email:password) is accepted instead of the cookie — over HTTPS only. There is no key management, so this is a password in a header. the legacy tools, and their API
Telemetry Auth events (signup, signup_refused, login, login_refused, logout) are recorded, and IP addresses are hashed, never stored raw. privacy and data handling
Not built: two-factor authentication and social sign-in
There is no 2FA, no authenticator app, no SMS code, and no “sign in with Google”. There is also no password reset by email, because the product sends no email at all. If you lose your password today, the Studio's owner resets it for you by hand. That is a real gap, not a design choice, and it is listed as one.

Check it on your own footage.

The first 30 minutes are free, and the word check runs on a free job exactly as it runs on a paid one. If the edit is not right, say so in the chat — revisions cost nothing.

Already have an account? Sign in.