Video & subtitles · Subtitle Toolkit
Why subtitle files should never be uploaded to a random online converter
· Why it matters
subtitles privacy browser-processing
A subtitle file is the entire spoken content of a video in plain text. This post explains what that means when you upload it to a converter, who might keep it and why processing it in your own browser removes the question entirely.
A .srt is a script — how a small text file contains everything anyone said, timestamped
A caption file is not a settings file. It is a complete record of everything said, in order, with a timestamp against each line. Anyone holding it can reconstruct the dialogue of an unreleased film, the contents of an internal meeting or the testimony in a deposition, and they can do it by opening the file in a text editor. The format is plain text precisely so that any program can read it.
That is worth stating plainly because the conversion being requested is usually trivial. Changing a comma to a full stop and adding a header line is a punctuation change. Handing over a full transcript to have punctuation changed is a poor trade, and it is easy to make without noticing because the file is small and the form is convenient.
What an upload means — a copy on someone else's server, under someone else's retention policy
Uploading means a copy exists on hardware you do not control, governed by a retention policy you did not write and cannot audit. The transfer is the disclosure; everything after it is someone else’s decision. Whether the copy is deleted, how quickly, from how many systems and whether anything derived from it survives are all outside your visibility from the moment the request completes.
This is a different question from whether the operator is trustworthy. A careful operator with good intentions still creates a copy, still writes logs, and still has backups. The exposure comes from the copy existing, not from anyone behaving badly.
Who is exposed — unreleased films, internal meetings, legal proceedings, medical and educational recordings
The material most likely to be run through a quick converter is often the material least suited to it. Unreleased productions have embargo obligations. Recordings of internal meetings contain candid discussion never intended to circulate. Legal proceedings carry confidentiality that attaches to the content regardless of format. Medical and educational recordings are frequently subject to specific regulation that does not make an exception for file conversion.
In each case the caption file is the most quotable artefact the project produces. It is already text, already segmented into lines and already timestamped for citation.
Why 'we delete files after an hour' is not the same as never having them — logs, backups and breaches
A deletion promise is a commitment about the future, made after the file has arrived. It does not withdraw the upload. Even honoured exactly, it usually applies to the primary copy rather than to request logs, error reports that captured a payload, caches, or backup snapshots taken on their own schedule and retained on their own timetable.
And the promise only binds as long as the operator controls the system. A breach, an acquisition or a change of policy all happen to data that was uploaded earlier under different terms. The one state that cannot be breached is the state where no copy was ever made.
The browser-only alternative — reading, converting and writing the file inside the tab, with nothing to delete afterwards
A browser-based tool removes the question rather than answering it. The page receives a handle to the file when you choose it, reads the text into memory, parses it into cues, transforms those objects and serialises the result back out as a download. The bytes never leave the tab, so there is no copy to retain, no policy to rely on and nothing to delete afterwards.
The claim is also structurally different from a promise, because it is checkable by the person making the decision rather than asserted by the party receiving the file. That is the part that matters for confidential material.
Worked example: converting a confidential interview's captions — a network panel that stays quiet from start to finish
To check it, open the network panel before choosing the file and leave it open for the whole job. Load the interview captions, convert them, retime them if needed, download the result. Requests for the page and its scripts appear at load; what should not appear is any request whose payload is the transcript. Preserve the log across the session so nothing is missed between steps.
Two honest qualifications. Analytics or advertising scripts may load from other origins and will appear in the same panel; they are a separate matter from whether your file was transmitted, and the distinction is visible in the request itself. And the guarantee stops at the tab: a tool that converts locally cannot protect the file once you email it, sync it to cloud storage or paste it into a service that does upload.
Takeaway: the safest server is no server — how the Subtitle Toolkit keeps the transcript on your device
The safest server is the one that never receives the file. For a punctuation-level conversion there is no reason to transmit a complete transcript to anyone, and for embargoed, privileged or regulated material there is a strong reason not to.
Do the conversion in the tab and verify it once. A minute with the network panel open gives a stronger assurance than any privacy policy, because it is evidence rather than a commitment, and it is evidence you gathered yourself.