Privacy Policy
We store your email, your billing reference, the videos you process and the clips they produce — nothing beyond what the service needs.
Source files, audio and transcripts are deleted about an hour after a job finishes. Finished clips live in a private bucket while your account exists, and deleting your account erases them immediately.
Sub-processors are named one by one: Google Gemini, ElevenLabs, fal.ai, Upload-Post, Cloudflare (email, storage and network), Stripe and — only if you accept it on the cookie banner — Google Analytics. Your content is never used to train AI models and never sold.
Where the law requires us to ask — the European Economic Area, the United Kingdom, Switzerland and every country we have not specifically reviewed — Google Analytics loads only after you press Accept, and before that no script is fetched and no analytics cookie is set. In the United States, Canada, Australia and New Zealand, where the law asks for notice rather than permission, it is on by default.
Refusing works everywhere and is the same one click: “Cookie settings” in the footer stops the tag and deletes its cookies whether or not you were ever shown a banner, and we honour the Global Privacy Control signal as a refusal. The country comes from the Cloudflare header on your own request; if we cannot tell, you get the banner.
1. Who is responsible
The data controller for clippen.app is FLISTONE TECHNOLOGIES - FZCO, trade licence number 68171, IFZA Business Park, Building 2, DDP 68171-001, Dubai Silicon Oasis (DSO), Dubai, United Arab Emirates — the company behind Clippen. For anything about your data, write to [email protected]. We have not appointed a representative under Article 27 GDPR or under the UK GDPR; contact us directly.
2. What we process, why, and on what legal basis
Legal bases are cited under the GDPR for readers to whom it applies; the same processing is carried out in accordance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection.
Your account
Your email address, and — if you sign in with Google — your Google account identifier, name and profile picture. We use passwordless magic links, so we never store a password. We keep the sign-up and last sign-in dates, and the IP address a sign-in link was requested from, which is also what lets us rate-limit abuse of the sign-in form. Basis: performance of the contract (Art. 6.1.b GDPR) and legitimate interest in securing accounts (Art. 6.1.f).
Billing
Payments run entirely on Stripe: we store your Stripe customer reference, your plan, subscription state and purchase history, never your card number. Invoicing data is kept because tax law requires it. Basis: contract (Art. 6.1.b) and legal obligation (Art. 6.1.c).
The videos you process
The videos you upload or instruct us to fetch, the audio and frames taken from them, their transcripts, and the clips, thumbnails and subtitle files generated from them, are processed to deliver exactly the job you requested, together with the technical metadata the library needs (title, duration, dimensions, file size, the model's own score for a moment). Basis: contract (Art. 6.1.b). Where a video contains personal data of other people — their image, their voice — you are the controller of that data and we act as your processor on your instructions; see Section 6 of the Terms of Service.
Usage and metering
Minutes consumed per job, credit reservations and balances, job outcomes and error diagnostics. This is how the meter can be audited and how a failed job can be refunded or retried. Basis: contract (Art. 6.1.b).
How you found us
On your first sign-in we record the referring page, the landing path and any UTM campaign parameters that were in the URL. Basis: legitimate interest in knowing which channels work (Art. 6.1.f); you can object at any time.
Connected services
If you connect social accounts for publishing, we store the publishing profile identifier that our partner allocates to you. If you create API keys for agent access, we store only a SHA-256 hash of each key, its first few characters, and when it was last used. Basis: contract (Art. 6.1.b).
Service emails
We email you sign-in links, receipts, renewal reminders, clips-ready notices and quota warnings. These are part of the service, not marketing. Basis: contract (Art. 6.1.b). If we ever send commercial newsletters we will ask for your consent first and every message will carry an unsubscribe link.
Product analytics
We measure how the product is used with two tools, and they are on different legal footings because they work differently.
Google Analytics 4 — only if you agree, in every country whose law
requires us to ask first. It stores cookies on your device
(_ga and _ga_<stream>) and sends Google your IP
address, the pages you view and a handful of product events — which pricing
screen you saw, whether a checkout was started, whether it reached Stripe. It
runs under one of two regimes, decided by where you are, and both are described
here because both are true of this site.
Where we ask first, and load nothing until you answer. In the European Economic Area (the 27 EU member states plus Iceland, Liechtenstein and Norway), the United Kingdom, Switzerland, Gibraltar, the Channel Islands and the Isle of Man, and in every other country we have not specifically reviewed: nothing of it loads until you press “Accept analytics” on our cookie banner — no script is fetched from Google, no cookie is set and no request leaves your browser for it. Basis: your consent (Art. 6.1.a GDPR and Art. 5(3) of the ePrivacy Directive as transposed locally; reg. 6 PECR in the United Kingdom).
Where the law asks us to tell you instead of asking you. In the United States, Canada, Australia and New Zealand there is no rule requiring permission in advance for first-party measurement; what those laws require is that you are told and that refusing actually works. There, Google Analytics is on by default and no banner interrupts you. Basis: our legitimate interest in knowing whether the product works and how much it is used (Art. 6.1.f GDPR, where that Regulation applies to you at all), together with PIPEDA Principle 4.3 in Canada, APP 3 and APP 5 in Australia and IPP 3 in New Zealand. We do not sell personal information and do not share it for cross-context behavioural advertising anywhere — that is the thing the US state privacy statutes give you a right to opt out of, and we do not do it.
Refusing works everywhere, and it is the same one click.
“Cookie settings” in the footer of every page stops the tag and
deletes the _ga cookies, whether or not a banner was ever shown to
you; withdrawing is as easy as consenting was and does not affect the lawfulness
of what was collected before. We also honour the Global Privacy
Control signal, if your browser or extension sends one: where it is
present we treat it as a refusal and load nothing, even in the four countries
above.
How we know which of the two applies to you. Cloudflare, whose network this site sits behind, derives a two-letter country code from the IP address your request already carries and passes it to our server in a header. We use it for this one decision and for nothing else. It is not stored against you, not written into any cookie and not combined with anything else about you. Our server keeps a line recording which country code it saw and which of the two outcomes followed — and nothing else: no IP address, no session, no account, no page. Two such lines from two different people in the same country are identical, so the record cannot be traced back to anyone. If we cannot tell where you are — no header, an anonymising proxy, a Tor exit node, or a request that did not pass through Cloudflare — you are treated as being in the first group and you get the banner.
Cloudflare Web Analytics — always on, and cookieless. It counts page views and page-load timings without storing anything on your device and without any identifier that follows you between sites, so it needs no consent and it is not on the banner. It does see the IP address and user agent that any web request carries, which Cloudflare uses to derive a country and does not retain against you. Basis: legitimate interest in knowing whether the service works and how much it is used (Art. 6.1.f) — you can object at any time by emailing [email protected].
Neither is an advertising product. There are no advertising pixels, no ad networks, no remarketing and no cross-site tracking anywhere on this site, and no data is sold or shared for anyone else's purposes. The product events we record are not linked to your email address at either provider.
Security, operations and anti-abuse
Server logs, IP-based rate limits and fraud signals, kept to protect the service and its users. Our own operational alerting channel receives short notifications about significant events (for example that a job finished or failed), and those notifications can include the account's email address. Basis: legitimate interest (Art. 6.1.f).
We do not process special categories of data (Art. 9 GDPR) as a designed part of the service — although a video you submit may contain such data, in which case you are the controller of it — we make no automated decisions producing legal effects on you (Art. 22 GDPR), and we do not use your content or your data to train AI models, ours or anyone else's, and we do not sell it.
3. Cookies, local storage and third-party requests
We set no advertising cookies and run no cross-site tracking. Cookies here fall into exactly two groups.
Strictly necessary — set without asking, because the site cannot work otherwise
- A session token so you stay signed in, valid for 30 days.
- Sign-in and anti-forgery tokens used while you are logging in. Sign-in links expire 15 minutes after they are issued.
clippen_consent— the record of the answer you gave our cookie banner, kept for six months. It holds one yes/no value and the date you answered, nothing that identifies you, and it exists so that a refusal is remembered and we do not ask you again tomorrow. We keep no server-side log of your answer and do not record your IP address against it.
Your interface preferences, and — where you use bring-your-own-key features such as dubbing or the AI-actor generator — the provider API keys you paste, are held in your browser's local storage rather than in cookies. Those keys are stored encrypted in your own browser, sent only to run your jobs, and never stored on our servers.
Analytics — the two regimes
Google Analytics sets _ga and _ga_<stream> on
this device, typically for up to two years, to recognise a returning browser.
Where we ask first — the European Economic Area, the United
Kingdom, Switzerland and everywhere we have not reviewed, as listed in Section 2
— those cookies do not exist until you accept, and the script that would set them
is never requested. Where the law asks for notice instead — the
United States, Canada, Australia and New Zealand — they are set from your first
page view unless you refuse. Either way, refusing stops the tag and deletes
them.
Changing your mind
“Cookie settings” in the footer of every page reopens the banner and lets you switch either way, as many times as you like. It is there on every page in every country, including the ones where the banner never appeared on its own — a country where we are not required to ask is not a country where you cannot refuse. We also ask again from scratch if the list of who receives analytics data ever changes, because consent to one list is not consent to a longer one.
Third-party requests
Loading a page of this site makes these requests to someone other than us, and no others:
- Google Fonts — the typefaces are downloaded at build time and served from our own domain, so no request is made to Google for them and Google learns nothing from your visit.
- Cloudflare Web Analytics — a small cookieless script, loaded on every page, as described in Section 2.
- Google Analytics — where we ask first, loaded only after you accept and never before; in the United States, Canada, Australia and New Zealand, loaded by default until you refuse. Section 2 has the full rule.
- Stripe — no Stripe script runs on our pages at all; starting a checkout redirects you to Stripe's own hosted page, and what happens there is covered by Stripe's notice.
4. Who receives data (sub-processors) and where
We use a short list of providers, each bound by a data processing agreement and each used only for the purpose stated:
- Google (Gemini API) — AI analysis. Receives the video file, sampled frames and the transcript, to select moments, write titles, pick a vertical layout and generate thumbnails. Google's paid API terms prohibit using customer content to train models. USA.
- Google (Sign in with Google) — optional sign-in, if you use it. USA.
- Google (Google Analytics 4) — measurement of page views and product events. Only if you accepted analytics on our cookie banner in the countries where we ask first, and by default until you refuse in the United States, Canada, Australia and New Zealand — see Section 2. Receives your IP address, the pages you view on this site and the product events listed in Section 2. Not linked to your email address, and not used by us for advertising. USA.
- Cloudflare (network, email, storage and Web Analytics) — every request to this site passes through Cloudflare's network, which receives the IP address and user agent that any request carries and derives from the address the two-letter country code our cookie banner logic reads (Section 2). Cloudflare also delivers our service emails — the sign-in link and job notifications — and stores your finished clips in R2, its S3-compatible object storage, in a private bucket with no public objects. Its Web Analytics additionally counts page views and page-load timings, cookielessly, on every page. Stores nothing on your device. USA.
- ElevenLabs — AI dubbing and AI voice generation, only when you request them. Receives the audio or video to be dubbed. USA.
- fal.ai — image and video generation for the optional AI-actor generator, only when you use it. USA.
- Upload-Post — publishing finished clips to the social accounts you connect, only on your instruction. USA.
- Amazon Web Services (S3) — the same clip, thumbnail and subtitle storage, for deployments of Clippen that point it at AWS instead. clippen.app itself uses Cloudflare R2, named above.
- Stripe — payments, invoicing and the customer portal. USA/EU.
- OpenPanel — product analytics, and only where a deployment of Clippen has installed it. It is not installed on clippen.app, receives nothing from this site, and is named here solely so the list stays complete for anyone running the software elsewhere. Where it is installed it sits behind the same consent banner as Google Analytics.
- Telegram — our internal operational alert channel, which receives short event notifications that can contain the account email address.
- Our hosting and rendering infrastructure provider — the servers the service runs on. Named on request at [email protected].
When you paste your own provider key for an optional feature, the request is made under your own account with that provider and their terms apply to it in addition to this policy.
Personal data is processed in the United Arab Emirates and in the countries listed above. For transfers out of the European Economic Area or the United Kingdom, we rely on the EU–US Data Privacy Framework where the provider is certified and, in any case, on the European Commission's Standard Contractual Clauses (Art. 46.2.c GDPR) together with the provider's technical safeguards. We prefer EU regions where a provider offers them.
5. How long we keep things
- Source videos, audio, transcripts and working files: kept only while the job needs them and deleted about an hour after it finishes, and sooner when the render disk is under pressure.
- Finished clips, thumbnails and subtitle files: stored while your account exists, until you delete them. They move to colder storage after 30 days, which changes their price and not their availability. Download links are signed and expire after 7 days; new ones are issued on request.
- Account data: while your account exists. Deleting your account from the dashboard deletes your stored objects and your database records immediately.
- Sign-in tokens: 15 minutes. Sessions: 30 days.
- Invoicing and payment records: 7 years, as required by applicable tax and accounting law.
- Server and security logs: up to 12 months.
- Google Analytics data, where you accepted it: as configured
in the property, and no longer than 14 months. The
_gacookies it sets on your device last up to two years, or until you withdraw consent, which deletes them. - Cloudflare Web Analytics: aggregate page-view counts only, retained by Cloudflare for up to six months. There is nothing device-specific in it to delete.
- Your cookie-consent answer: six months, in your own browser, after which we ask again.
- The country-and-decision line described in Section 2: up to 12 months, with the rest of our server logs. It holds a country code and one of three outcomes and nothing else, so there is nobody in it to identify.
6. Your rights
Whoever and wherever you are, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, or ask for it in a portable format. Email [email protected] from your account address; we answer within one month, or within 45 days for requests under the CCPA/CPRA. Deleting your account from the dashboard already erases your content and your records.
If the GDPR or the UK GDPR applies to you, you additionally have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection to processing based on legitimate interest (Art. 21) and withdrawal of consent (Art. 7), and you may complain to your national supervisory authority — in the UK, the Information Commissioner's Office.
If you are a California resident, you have the rights to know, delete, correct and opt out of the sale or sharing of personal information, and not to be discriminated against for exercising them. We do not sell personal information and we do not share it for cross-context behavioural advertising.
If you are in the United Arab Emirates, your rights under Federal Decree-Law No. 45 of 2021 include access, correction, erasure, restriction and objection, and you may complain to the UAE Data Office.
7. Security
Data is encrypted in transit. Your clip bucket is private and no object in it is ever made public: delivery is a signed link that expires on its own and cannot be used to list the bucket. API keys and sign-in tokens are stored only as SHA-256 hashes, so a database dump is not a set of live credentials. Access to production is limited to the people who need it. No system is perfectly secure, and we do not claim otherwise.
8. Age
The service is not directed at children and you must be at least 18 to create an account. If we learn that we hold data about a child, we delete it.
9. Changes
If we change this policy in any meaningful way we will tell you by email or in-app before the change takes effect, and the date on this page always reflects the current version.
10. Contact
Privacy questions, data requests and complaints: [email protected] — FLISTONE TECHNOLOGIES - FZCO, IFZA Business Park, Building 2, DDP 68171-001, Dubai Silicon Oasis (DSO), Dubai, United Arab Emirates.