Last updated: January 1, 2026
This Privacy Policy explains how Clipto ("Clipto", "we", "us", or "our") collects, uses, stores, shares, and protects information when you use our website, dashboard, and related services (collectively, the "Service"). It applies to all users of the Service.
By creating an account or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Service.
We collect information you give us directly, including:
When you use the Service, we automatically collect certain operational data:
We use the information we collect to:
Where the GDPR or similar laws apply, we process personal data on these bases: performance of our contract with you (to deliver the Service), our legitimate interests (securing and improving the Service), your consent (where required, e.g. optional communications), and compliance with legal obligations.
When you connect Buffer, your Buffer API key is encrypted at rest using AES-256-GCM and used solely to read your channel list and publish videos you have queued. We do not use it to read unrelated account data, and you can revoke it at any time from your Buffer settings or by disconnecting in Clipto.
We access publicly available TikTok content only. We never request or store TikTok passwords.
We do not sell your personal information. We share data only:
We rely on a small set of vetted sub-processors, including cloud hosting and database providers, our publishing partner, and our AI provider for metadata generation. Each is bound by contractual confidentiality and data-protection obligations. We maintain an internal list of sub-processors and update it as our infrastructure evolves.
We apply industry-standard safeguards: API keys and connected-service credentials are encrypted at rest with AES-256-GCM; passwords are hashed with bcrypt and never stored in plain text; database and cache layers run on private networking and are not exposed to the public internet; and traffic is served over TLS.
No method of transmission or storage is perfectly secure. We work to protect your data but cannot guarantee absolute security.
We retain account and configuration data while your account is active. When you delete your account from the Settings page, we permanently delete associated personal data within 30 days, except where we must retain limited records to comply with legal, tax, or fraud-prevention obligations. Encrypted credentials are deleted immediately on disconnection.
Depending on your location, you may have the right to:
Our infrastructure is primarily hosted in the United States. If you access the Service from outside the US, your information may be transferred to and processed in countries with different data-protection laws. Where required, we rely on appropriate safeguards for such transfers.
The Service is not directed to anyone under 16, and we do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this Policy from time to time. Material changes will be announced by email or in-app, and the "last updated" date below will change. Continued use after an update constitutes acceptance.
Questions or requests regarding this Policy or your data can be sent to privacy@clipto.io.