Professional grade security, no matter the project

Nice Touch is built for professional post-production teams who work with sensitive, embargoed, and pre-release material. We treat your content the way you would. No training, ever.

Data isolation

Your footage is processed in isolated, ephemeral environments that spin up per job and are destroyed after completion. Media files are never stored longer than needed and are never used for model training.

Encryption everywhere

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Transcripts and project metadata are kept only for the duration you configure, then permanently deleted.

Local tool execution

NLE operations execute locally inside the desktop app. Your project files and media never leave your machine for editing purposes. Large files move via pre-signed URLs, not through cloud servers.

No model training

Customer data remains private and is not used to train external models. Your briefs, transcripts, and project context are yours alone.

Authentication and access

Firebase (Google sign-in), local email/password, and JWT authentication. Admin access is restricted to verified organisation domains.

Technical architecture

01On your machine

The app and your NLE

The Nice Touch desktop app runs locally. All editing operations — building timelines, reading project files, executing cuts — happen inside your open NLE session. Your media never moves.

  • Electron desktop app with local NLE bridge
  • DaVinci Resolve via Lua scripting
  • Adobe Premiere Pro via CEP panel
  • Project files and media stay on disk
  • No footage is uploaded to any server
Your project files and media never leave your machine.
02Our servers

What we store and why

Our backend stores only what is necessary to run your projects: transcripts, briefs, metadata, and account data. Nothing is retained beyond your configured period, and nothing is used for model training.

  • NestJS API, MySQL via Prisma, hosted on Sevalla
  • Data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Transcripts and metadata deleted after retention period
  • Isolated processing environments per job
  • Firebase authentication, JWT access control
We store only what your project needs. Never for training.
03External APIs

Inference only — no storage

We use Anthropic Claude for AI reasoning and AssemblyAI for audio transcription. Both are used for inference only. No customer data is stored at rest by these providers, and neither is used to train any model.

  • Anthropic Claude — AI chat, tool use, edit reasoning
  • AssemblyAI — audio transcription and speaker detection
  • Data passed for inference only, not retained
  • No training on customer content by either provider
  • Contractual data processing agreements in place
Inference only. Your content is never used to train external models.

Questions about security or compliance? Get in touch.

Contact Us