1. Who is responsible for your data
The controller of your personal data is [LEGAL NAME NOT CONFIGURED], of [ADDRESS NOT CONFIGURED]. Contact us through the contact form or at noreply@clipspark.online about anything on this page, including a request to exercise the rights in section 7.
2. What we collect
Because you gave it to us
- Your email address and password. The password is stored only as a one-way hash; we cannot read it and neither can anyone who obtains the database.
- Video you upload, and the clips produced from it.
- Anything you write to support, including the address you give on the contact form.
Because you used the Service
- Project records: filenames, video length, the settings you chose, when a job ran, whether it succeeded, and what it cost in credits.
- Credit and payment history: what was granted, spent, refunded, and purchased.
- Security and diagnostic logs: IP address, timestamps, and the outcome of sign-in attempts. These are what let us rate-limit abuse and tell you whether someone else has been in your account.
Cookies
Two, and this is the whole list. clipspark_session keeps you
signed in and carries the CSRF token that stops other sites submitting forms
as you. Ticking "keep me signed in" adds Flask-Login's
remember_token for 14 days; it does nothing except keep you signed
in across browser restarts. Both are strictly necessary to operate the
Service, which is why there is no cookie banner to click through: there is no
advertising cookie, no third-party analytics, and no tracking pixel to ask
you about. If you would rather not have the second one, do not tick the box.
Paying is the one place you leave our site. Checkout and the billing portal are hosted by Polar on their own domain, and any cookie set there is set by them under their privacy policy, not ours.
3. Why we are allowed to hold it
- To perform our contract with you — your account, your uploads, processing, and billing. Without these the Service cannot run.
- Our legitimate interests — security logs, rate limiting, and abuse prevention, balanced against your privacy by keeping them short-lived and minimal.
- Legal obligation — payment and tax records, kept for as long as the law requires.
We do not sell your data. We do not use your video, transcripts, or clips to train models of our own.
4. Who else receives it
These are every third party that handles your data as part of running the Service. Each acts as our processor, or as an independent controller where noted.
| Who | What they receive | Why |
|---|---|---|
| Oracle Cloud Infrastructure | Everything — the servers, the database, and the stored files are hosted with them. | Hosting and storage. |
| Google (Gemini API) | The video you upload for analysis, and limited clip metadata when you request generated hooks, captions, or post copy. It does not receive a second copy of the rendered video. | Finding moments and generating optional copy. |
| Polar | Your email address, and your card details — which you enter on Polar's own page and which never reach our servers. Polar is the merchant of record for the sale, so it is an independent controller for payment data and holds the transaction as its own seller record, not merely as a processor acting for us. Polar in turn vaults card details with its own payment processor, Stripe. | Taking payment, subscriptions, tax, invoices, and the billing portal. |
| Namecheap (Private Email) | Your email address, and the contents of emails we send you. | Delivering verification, password reset, and notification email. |
Several of these are based in the United States, so your data is transferred outside the UK and EEA. Those transfers rely on the standard contractual clauses in each provider's data processing terms.
We may also disclose data where we are legally required to, or to establish or defend a legal claim.
5. AI processing, stated plainly
Finding a good clip means Gemini has to watch your video, so the uploaded video leaves our servers and is sent to Google. When you request generated hooks or platform post copy, Gemini receives only the limited clip context and campaign requirements you enter, not another copy of the rendered video. If that is not acceptable for a particular piece of footage, do not upload it or request generated copy.
We send only what the analysis needs, and we do not attach your name or email address to it. What each provider does with data sent to its API is governed by its own terms; we do not opt into any programme that uses customer API content for model training.
6. How long we keep it
- Uploaded source video: about 24 hours, so a failed job can be retried, then deleted.
- Campaign workspaces: kept with your account, including archived campaigns, until you edit them or delete the account.
- Clips: your plan's retention window — 30 days on the free plan, 90 days on paid plans — then deleted. We email you before this happens.
- Project and credit history: for the life of your account.
- Payment records: as long as tax and accounting law requires, which is longer than your account may last.
- Security logs: a short rolling window, long enough to investigate an incident.
- Support tickets: kept while they are useful for handling follow-up questions, then deleted.
Deleting your account deletes your projects, clips, and credit history. Payment records we are required to keep are retained, and anonymised where we can.
7. Your rights
Depending on where you live, you have the right to ask for a copy of your data, to correct it, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. You can change your email address and delete your account yourself from your account settings; for anything else, contact us and we will respond within one month.
You also have the right to complain to a data protection authority in your country. We would rather you told us first, but that is your choice, not a condition.
8. Security
Passwords are hashed, not stored. Sessions are held server-side and invalidated everywhere when you change your password. Payment card details never touch our servers. Access to production data is limited to the people who operate the Service.
No system is perfectly secure. If a breach affects your personal data and puts you at risk, we will tell you and the relevant authority as the law requires, rather than waiting to be asked.
9. Children
The Service is not for children. We do not knowingly collect data from anyone under 16 and will delete such an account if we learn of it.
10. Changes
If this policy changes materially — in particular if a new processor is added to section 4 — we will update the effective date at the top and notify account holders before the change takes effect.