Skip to main content
Pre-release draft. This page is available for implementation review, but it is not approved for a hosted paid launch. The operator identity, jurisdiction, billing policy, processor list, retention wording, effective date, and policy version must be configured and reviewed by the repository owner and qualified legal counsel. This text does not constitute legal advice.

Version draft · Effective Not yet effective

Privacy policy

This policy describes the data Clipilot processes when you use the hosted service, why it is used, the systems involved, and how to request access, correction, or deletion. It is not legal advice.

1. Operator and contact

Clipilot is operated by Operator identity not configured, at Operator address not configured. The launch jurisdiction is Launch jurisdiction not configured.

Privacy and data-rights requests should be sent to the legal contact address, which has not yet been configured. We may need to verify your identity, and your authority over a shared workspace, before disclosing or acting on account data.

2. Data Clipilot processes

  • Account and authentication data: email, name, display preferences, and a session cookie issued when you sign in with a password. Clipilot does not currently offer social/OAuth sign-in.
  • Workspace membership, roles (owner, editor, viewer), invitations, projects, tasks, automation configuration, and an internal audit log of workspace actions.
  • Source media you submit — uploaded files or URLs — plus resulting transcripts, candidate selections, generated clip drafts, captions, thumbnails, exports, and processing status.
  • Connected-platform identifiers and access tokens when you enable an optional integration (for example, YouTube).
  • Hosted billing identifiers and subscription status when hosted billing is enabled; Clipilot does not store your payment-card details, which stay with Stripe.
  • API-key metadata, webhook delivery records, product feedback you submit, waitlist sign-up email addresses, and operational request logs.

3. Why the data is used

Clipilot uses this information to authenticate you, operate workspaces, receive and process the media you submit, generate draft clips, provide exports, run automations you configure, connect the integrations you enable, enforce plan limits, process a hosted subscription when applicable, protect the service from abuse, diagnose failures, and respond to support or data-rights requests.

Generated clips are drafts. Clipilot does not represent that automated transcription, selection, or rendering is error-free, publication-ready, or cleared for every intended use — you review output before you publish it.

4. Hosting and subprocessors

The service is hosted by Hosting provider not configured in Hosting region not configured. The processors and integrations below are used for the stated purposes, according to the configuration published for this deployment; several are active only when the corresponding optional feature is enabled:

  • Hosting provider: Application, database, cache, and durable-media hosting; provider and region must be configured before launch.
  • Stripe (when hosted billing is enabled): Checkout, subscriptions, invoices, customer portal, payment status, cancellations, and refunds.
  • AssemblyAI: Audio transcription and word-level timing for submitted media.
  • Configured LLM provider: Transcript analysis and candidate clip generation; the active provider is one of OpenAI, Google, Anthropic, or an operator-configured Ollama endpoint.
  • Pexels (when enabled): Optional stock B-roll footage used in generated clips.
  • Apify (when enabled): Optional paid YouTube-download fallback.
  • YouTube (when connected): Source metadata lookup, automation discovery, user-authorized publishing, and analytics import.
  • Discord (when configured): Forwards in-app feedback to the operator; does not process end-user account data.
  • Resend (when hosted email is enabled): Transactional and waitlist email delivery.

A self-hosted deployment (not this hosted instance) is operated on infrastructure the self-hosting party controls, and this list may not apply to it.

5. Waitlist sign-ups

If you join the Clipilot waitlist, we store your email address, separately from product account data, to manage early-access invitations. We do not sell it or include it in analytics events. There is intentionally no public email-only deletion endpoint today: send a removal request to the contact above and the team will process it manually — this stops future waitlist contact but does not immediately erase the stored address.

6. Retention and deletion — current limitations

Clipilot does not yet offer a self-service “delete my account” or “export my data” control. Account, workspace, project, task, and generated-content records persist until an authorized operator acts on a request, following an internal procedure that verifies identity and scopes shared-workspace data so another member's information is not disclosed.

  • Deleting a user record cascades to that user's own tasks, projects, sessions, and workspaces they own; it does not, by itself, remove durable media storage or rendered exports.
  • Removing a shared workspace or its stored media currently requires direct operator action; there is no automatic scheduled purge for this today.
  • Backup expiration is not configured; deletion from the live service does not retroactively erase existing backups.

We disclose these limitations rather than promise a self-service flow that does not yet exist. If this changes, this section will be updated with the new policy version.

7. Access, correction, and deletion requests

Send a request to the contact address above. Because export and deletion are handled manually today, requests may take longer to complete than an automated system, and some categories (for example, entries in a shared audit log, or data already captured in a database backup) may not be fully removable — see Section 6.

8. Security and limitations

Clipilot uses access controls, workspace-scoped authorization, encrypted integration credentials, and rate limits. No service can guarantee absolute security. Do not submit media or credentials you are not authorized to process.

Publication of this policy is not a claim of SOC 2, ISO 27001, GDPR certification, HIPAA readiness, or completion of an independent security or legal audit.

9. Policy changes

Material revisions receive a new policy version and effective date, shown at the top of this page. Changes that materially affect users will be reviewed before publication and communicated through an appropriate product or account channel where required.

Privacy policy · Clipilot