Keeping Your Source Files Private When an AI Tool Processes Them in the Cloud
Embargoed footage, NDAs, and unreleased cuts don't mix well with upload-first AI tools — here's how to use them without leaking your material.
Most of the interesting AI features in an editor's kit right now run in the cloud. Transcription, object removal, upscaling, generative b-roll, dialogue enhancement — a lot of it uploads your footage to someone else's servers, processes it there, and sends a result back. That's fine when you're cutting a personal project. It is a genuine problem when the material is embargoed, under NDA, contains a person who hasn't signed a release, or is an unreleased cut of something a studio will sue over if it leaks.
I'm not a lawyer and this isn't legal advice — when a contract governs the footage, the contract and your client's security team are the authority, not me. What I can give you is how a working editor thinks about this practically, so you can use these tools without turning your project into a breach.
Start by reading what you actually agreed to
Before any of the technical stuff, the governing document is usually your own contract or NDA. A lot of media NDAs in 2026 have explicit clauses about third-party cloud processing and AI services, precisely because this became a problem. Some forbid uploading material to any third-party service. Some require the service to be named and approved. Some are silent, which is not the same as permission. If you don't know what your NDA says about cloud tools, that's the first thing to fix, not the tool settings.
The same goes for the people in your footage. A subject who signed a release for your documentary did not necessarily consent to their face being uploaded to a generative AI service. That's an ethical line as much as a legal one, and it's yours to hold.
Know what "processed in the cloud" really involves
There are three separate questions to ask about any tool, and vendors often answer only the flattering one:
- Is my footage uploaded at all, or does it run on my machine? Some features are fully local. Resolve's transcription and Voice Isolation, Topaz Video AI's upscaling, and a growing set of on-device features never send your media anywhere. This is the cleanest answer to the whole problem: if the file never leaves your drive, there's nothing to leak.
- If it's uploaded, how long is it kept, and where? "We process in the cloud" can mean the file is deleted seconds after processing, or that it sits in a bucket for thirty days. These are very different risk profiles.
- Is my content used to train their models? This is the one that ends careers. A training-retention default means your unreleased footage becomes part of a model's weights, and there's no getting it back.
The answers live in the terms of service and the privacy policy, not the marketing page. I keep a short document per tool with these three answers written down, because they change with version updates and I'd rather check my note than re-read a policy under deadline.
The settings that actually matter
For the cloud tools I do use on sensitive work, these are the things I check every time:
- Turn off model-training / content-improvement toggles. Many pro tools now offer a setting that keeps your content out of training. It is frequently on by default. Adobe, for instance, has account-level content-analysis controls; turn the training contribution off for client work. Assume the default is the one that benefits the vendor, not you.
- Look for a business or enterprise tier with a no-training commitment. The paid professional tiers of most 2026 AI tools carry stronger data commitments than the free tier — often an explicit "we don't train on your data" term. If you're handling other people's IP, the free tier is usually the wrong tool regardless of budget.
- Prefer tools that publish a retention window and a deletion path. A vendor that will tell you "files deleted within 24 hours" and lets you delete manually is categorically better than one that's vague about it.
Practical habits that lower the stakes
Beyond settings, the way you prepare the material changes how much a leak would even matter:
- Upload the least revealing thing that gets the job done. If you need a transcript, you may be able to upload extracted audio rather than the picture. Faces and locations are what make footage sensitive; audio-only cuts the exposure. For a color or upscale test, a short representative clip beats the whole reel.
- Do generative and identity-sensitive work on proxies or stand-ins where possible. Not always feasible, but worth asking whether the actual sensitive frames need to touch the cloud at all.
- Default to local tools for the crown-jewel material. On the truly protected stuff — the unreleased feature, the confidential interview — I use the on-device options even when a cloud tool would be marginally better. The quality difference is rarely worth the exposure.
- Keep a shot log of what went where. If a client ever asks "was any of this processed by a third party," you want to answer from a record, not from memory.
When the answer is just "no"
Sometimes the right call is that a piece of footage doesn't go into a cloud tool at all, and you either use a local alternative or do the work by hand. Embargoed news material, anything under a strict studio NDA, footage of a vulnerable subject who hasn't been told about AI processing — for these, the convenience of a cloud feature is not worth the risk, and no toggle makes it worth it. Part of being trusted with people's material is knowing where the tools stop.
A short checklist to keep by the desk
- What does my contract or NDA say about third-party and AI cloud processing?
- Have the people in this footage consented to this kind of processing?
- Does this feature run locally, or upload? If it uploads — retained how long, and used for training?
- Is the training toggle off, and am I on a tier with a no-training commitment?
- Can I upload less — audio only, a proxy, a short clip — and still get what I need?
- For the crown jewels, is there a local tool that gets me close enough?
None of this means avoiding cloud AI. It means using it like a professional who's responsible for someone else's material — which, most of the time, is exactly what an editor is. The tools are good. The discipline around them is what keeps them from becoming the reason a client never hires you again.
Put this into practice
Paste any text to estimate how many tokens it uses, and see what that text would cost to send to each major model.
Open the Token Estimator →A note on shelf life. AI products change fast. This guide deliberately focuses on the parts that stay true — how to judge a tool, what the trade-offs are — rather than ranking products that will have changed by the time you read it. Prices and feature claims should always be checked against the provider before you rely on them.