Privacy Policy

Last updated: January 1, 2026

1. Introduction

This Privacy Policy explains how Clipto ("Clipto", "we", "us", or "our") collects, uses, stores, shares, and protects information when you use our website, dashboard, and related services (collectively, the "Service"). It applies to all users of the Service.

By creating an account or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Service.

2. Information You Provide

We collect information you give us directly, including:

  • •Account details — your name, email address, and a hashed password.
  • •Connected-service credentials — the Buffer API key you choose to add, stored encrypted, used only to publish on your behalf.
  • •Configuration — pipelines you create, TikTok source usernames, target channels, schedules, and AI settings.
  • •Billing information — your blockchain deposit address and on-chain transaction records associated with token purchases.
  • •Support communications — messages you send us by email or contact form.

3. Information Collected Automatically

When you use the Service, we automatically collect certain operational data:

  • •Usage data — pipelines run, jobs processed, tokens consumed, and feature interactions.
  • •Log and device data — IP address, browser type, and timestamps, used for security and debugging.
  • •Session cookies — a single authentication cookie to keep you signed in. We do not use third-party advertising or cross-site tracking cookies.

4. How We Use Information

We use the information we collect to:

  • •Provide, operate, and maintain the Service and your automated pipelines.
  • •Process token purchases and apply plan upgrades.
  • •Publish your content to your connected channels at your instruction.
  • •Send transactional messages (job results, low-balance alerts, security notices).
  • •Detect, prevent, and investigate fraud, abuse, and security incidents.
  • •Comply with legal obligations and enforce our Terms of Service.

5. Legal Bases for Processing

Where the GDPR or similar laws apply, we process personal data on these bases: performance of our contract with you (to deliver the Service), our legitimate interests (securing and improving the Service), your consent (where required, e.g. optional communications), and compliance with legal obligations.

6. Connected Accounts (Buffer & YouTube)

When you connect Buffer, your Buffer API key is encrypted at rest using AES-256-GCM and used solely to read your channel list and publish videos you have queued. We do not use it to read unrelated account data, and you can revoke it at any time from your Buffer settings or by disconnecting in Clipto.

We access publicly available TikTok content only. We never request or store TikTok passwords.

7. How We Share Information

We do not sell your personal information. We share data only:

  • •With service providers (sub-processors) that host and operate the Service — for example our cloud infrastructure (AWS), our publishing partner (Buffer), and our AI metadata provider — strictly to deliver the Service.
  • •To comply with the law, a valid legal request, or to protect our rights, users, and the public.
  • •In connection with a merger, acquisition, or asset sale, with notice to you.

8. Sub-processors

We rely on a small set of vetted sub-processors, including cloud hosting and database providers, our publishing partner, and our AI provider for metadata generation. Each is bound by contractual confidentiality and data-protection obligations. We maintain an internal list of sub-processors and update it as our infrastructure evolves.

9. Data Security

We apply industry-standard safeguards: API keys and connected-service credentials are encrypted at rest with AES-256-GCM; passwords are hashed with bcrypt and never stored in plain text; database and cache layers run on private networking and are not exposed to the public internet; and traffic is served over TLS.

No method of transmission or storage is perfectly secure. We work to protect your data but cannot guarantee absolute security.

10. Data Retention

We retain account and configuration data while your account is active. When you delete your account from the Settings page, we permanently delete associated personal data within 30 days, except where we must retain limited records to comply with legal, tax, or fraud-prevention obligations. Encrypted credentials are deleted immediately on disconnection.

11. Your Rights

Depending on your location, you may have the right to:

  • •Access the personal data we hold about you.
  • •Correct inaccurate data.
  • •Delete your data ("right to be forgotten").
  • •Export your data in a portable format.
  • •Object to or restrict certain processing, and withdraw consent.

12. International Transfers

Our infrastructure is primarily hosted in the United States. If you access the Service from outside the US, your information may be transferred to and processed in countries with different data-protection laws. Where required, we rely on appropriate safeguards for such transfers.

13. Children’s Privacy

The Service is not directed to anyone under 16, and we do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes & Contact

We may update this Policy from time to time. Material changes will be announced by email or in-app, and the "last updated" date below will change. Continued use after an update constitutes acceptance.

Questions or requests regarding this Policy or your data can be sent to privacy@clipto.io.