Privacy Policy
Last updated: 29 July 2026
1. Data controller
The data controller is Laurent Richard, based in France. For any question or request relating to personal data, write to [email protected].
2. Scope
This policy covers Clipit, a video-scheduling and publishing tool open to anyone — anyone can create an account at dashboard.clipit.app, there is no invitation or approval step. Each account's data is kept isolated from every other account (see "Security" below).
3. Data we collect
The table below lists every category of personal data Clipit processes. Nothing else is collected — there is no advertising identifier, and no third-party tracking or analytics script runs on the site. Its pages load no fonts and no scripts from third-party servers either: everything they need is served by Clipit itself, so browsing the site does not reveal your address to anyone outside the list of sub-processors below.
Not every row is data you typed. One of them arrives on its own: when a platform needs to tell us something about an account you connected, it sends us a message and we keep it. Retention is covered in section 6, which also describes the single record that can outlive a deleted account.
| Data | Source | Purpose |
|---|---|---|
| Account profile: email address, name, profile picture | Auth0, when you sign in | Authenticating you and identifying your account |
| Interface language preference | Chosen in your account settings | Serving the interface in your preferred language |
| Content you create: video ideas, titles, descriptions, subtitles (in every language you publish in), and scheduling dates | Entered by you in the application | Scheduling and publishing your videos |
| Files you upload: the thumbnail and the video file of an entry, together with their original file name, their size and their type | Uploaded by you from an entry's page | Showing them back to you and publishing them with the video |
| Publication records: platform, language, status, URL, scheduled and published dates | Generated as you schedule and publish | Showing you the status of each video in the calendar |
| Audience figures for a connected account: follower, view, like, comment and share counts, each with the hour it was read | Read from the platform once an hour, because no platform reports how these figures change over time | Showing you how a channel evolves. Kept for 90 days, then deleted |
| Publishing preferences for a connected account: which languages it publishes, whether subtitles for the other languages travel with them, where inside the account each language lands, and the hours it publishes on each day of the week, in the time zone you set for it | Chosen by you when you attach an account to a workspace | Sending each language to the account you picked for it, instead of sending everything everywhere, and choosing when to publish: when you set a date without a time, each account's declared hours decide it |
| Service API keys: a name, a short prefix and a one-way hash — never the key itself | Created by you in account settings | Letting your own tools read and write your data through the API |
| Connected platform account: account identifier, display name, username, avatar and granted permissions, plus encrypted access tokens | TikTok, when you connect your account | Publishing to the account you connected |
| Notifications about a connected account: the platform's identifier for that account, what it says happened, when it says it happened, and the details it sent with it | Pushed to us by the platform, without any action on your part | Telling you that an account needs reconnecting, for example after you revoked Clipit's access from the platform itself |
| What Clipit told you: a record of each publication that went out or failed — the video title as it stood at that moment, the platform, the language and the outcome | Written by Clipit itself, each time a publication reaches its outcome | Showing you in Clipit what happened, whether or not your device was reachable at the time |
| Device notification subscriptions, if you turn them on: the delivery address your browser issues for that device, and the two keys it provides so we can encrypt each message — we never send the contents of a notification in the clear | Issued by your browser when you turn notifications on for a device | Sending the outcome of a publication to that device. Kept until you turn notifications off there, or until the delivery service tells us the subscription is gone |
4. How we use it
The data above is used for one purpose only: running the service — letting you plan, write and track the publication of your own videos.
It is never used for anything else. Specifically, we do not:
- sell, rent or trade your data;
- share it with third parties for commercial purposes;
- use it for advertising, profiling or automated decision-making;
- run any third-party analytics or tracking service on it;
- use your content to train artificial intelligence models.
5. Storage and sub-processors
The following providers process data on our behalf:
| Provider | Role |
|---|---|
| Auth0 | Authentication (sign-in) |
| OVHcloud | Application server and PostgreSQL database (France, EU) |
| Cloudflare | Media storage and network access to the public pages |
| Google Cloud Storage | Storage of the daily database backup, kept for 14 days |
| TikTok | Publishing to the account you connect |
No other sub-processor is involved.
6. Retention
- Your data is kept for as long as your account exists.
- When you delete your account, Clipit first tries to ask every platform that still holds an access you granted to revoke it. Your account is then deleted from the live database — profile data, content, publication records, service keys and connected platform accounts — and the events those platforms sent us about the accounts you connected are deleted with it. Your account is deleted even if that request fails: we never keep your data because someone else's service did not answer.
- When that revocation does not succeed and Clipit still holds the refresh token needed to ask again, one record per connection outlives your account: that encrypted token, the platform it belongs to, an expiry date, the date the record was created, and the three identifiers that token is cryptographically tied to — your Clipit account identifier, the identifier of the connection itself, and your identifier on that platform, in clear, because the token cannot be decrypted without them. It holds nothing else: no name, no email address, no content, and it cannot bring your account back. Its only use is to finish revoking that access, and it is deleted as soon as that revocation is obtained — or as soon as the platform tells us that the access no longer exists. When no such token is left, nothing outlives your account, and that access can then only be withdrawn by you, from the platform itself. Nothing retries on a schedule yet: asking again is a command we run by hand, so such a record stays in the database until we run it. Past the expiry date it carries, Clipit stops using it altogether, and the next run deletes it.
- Disconnecting a connected platform account tries once to ask the platform to revoke its authorization right away. When that request does not succeed immediately (for example a temporary network or platform issue), the account's encrypted token stays in the database rather than being deleted straight away — it is no longer used for anything else. If it is later revoked, it is deleted at that point; otherwise it eventually becomes unusable once it reaches its own expiry, but the application does not currently delete it from the database at that point.
- The notifications platforms push to us about a connected account are kept for as long as your account exists: nothing expires them automatically, and there is no default retention period. They are deleted with your account, and we can also delete the older ones by hand — that too is a command we run, not a schedule. Each one holds only what the platform sent: its own identifier for the account, what happened and when, and the details of that message.
- The database is also backed up once a day and the backup is kept for 14 days on Google Cloud Storage, whose storage is encrypted at rest by the storage provider (the backup file itself is not separately encrypted). Data you delete can therefore still exist in a daily backup for up to 14 days after deletion, after which it no longer exists in any backup.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and object to the processing of your personal data, as well as the right to data portability.
Erasure you can carry out yourself, at any time: your account settings page deletes your account and everything attached to it, immediately and permanently. Everything else — access, a copy of your data (portability), rectification, restriction, objection — is handled by email: write to [email protected] and you will receive a reply within 30 days. There is no self-service export in the application today; when there is one, this page will say so.
If you consider that your rights have not been respected, you may lodge a complaint with the French data protection authority, the CNIL.
8. How to delete your data
There are two ways to have your data removed:
- Delete your account. From account settings, typing the confirmation word permanently erases every workspace, video, publication record and service key, and tries to ask every platform that still holds an access you granted to revoke it (see "Retention" above for what a failed revocation leaves behind). This takes effect immediately and cannot be undone.
- Ask us directly. Write to [email protected] if you would rather have us action a request than do it yourself.
You can also revoke a single service API key from your account settings, without deleting anything else.
9. Security
All traffic uses HTTPS. Service API keys are stored as a one-way hash — never in full — so a database copy alone cannot be used to act as you. Every account's data is isolated at the database level (PostgreSQL row-level security): a query scoped to one account structurally cannot return another account's rows.
Connected platform account tokens are additionally encrypted by the application itself (AES-256-GCM) before being written to the database, using an encryption key that is never stored in the database. This protects a copy of the database — for example an exfiltrated backup — from yielding usable tokens; it does not protect against a compromise of the application server itself, where that key is present.
10. Children
This service is not intended for, and is not made available to, anyone under the age of 16.
11. Changes to this policy
This policy may be updated. The "last updated" date at the top of this page indicates the version in force.
12. Contact
Privacy and data protection requests: [email protected]
Anything else: [email protected]