Privacy Policy
Last updated: 29 July 2026
1. Data controller
The data controller is Laurent Richard, based in France. For any question or request relating to personal data, write to [email protected].
2. Scope
This policy covers Clipit, a video-scheduling and publishing tool open to anyone — anyone can create an account at dashboard.clipit.app, there is no invitation or approval step. Each account's data is kept isolated from every other account (see "Security" below).
3. Data we collect
The table below lists every category of personal data Clipit processes. Nothing else is collected — there is no advertising identifier, and no third-party tracking or analytics script runs on the site. Its pages load no fonts and no scripts from third-party servers either: everything they need is served by Clipit itself, so browsing the site does not reveal your address to anyone outside the list of sub-processors below.
| Data | Source | Purpose |
|---|---|---|
| Account profile: email address, name, profile picture | Auth0, when you sign in | Authenticating you and identifying your account |
| Interface language preference | Chosen in your account settings | Serving the interface in your preferred language |
| Content you create: video ideas, titles, descriptions, subtitles (in every language you publish in), and scheduling dates | Entered by you in the application | Scheduling and publishing your videos |
| Publication records: platform, language, status, URL, scheduled and published dates | Generated as you schedule and publish | Showing you the status of each video in the calendar |
| Service API keys: a name, a short prefix and a one-way hash — never the key itself | Created by you in account settings | Letting your own tools read and write your data through the API |
4. How we use it
The data above is used for one purpose only: running the service — letting you plan, write and track the publication of your own videos.
It is never used for anything else. Specifically, we do not:
- sell, rent or trade your data;
- share it with third parties for commercial purposes;
- use it for advertising, profiling or automated decision-making;
- run any third-party analytics or tracking service on it;
- use your content to train artificial intelligence models.
5. Storage and sub-processors
The following providers process data on our behalf:
| Provider | Role |
|---|---|
| Auth0 | Authentication (sign-in) |
| OVHcloud | Application server and PostgreSQL database (France, EU) |
| Cloudflare | Media storage and network access to the public pages |
| Google Cloud Storage | Storage of the daily database backup, kept for 14 days |
No other sub-processor is involved.
6. Retention
- Your data is kept for as long as your account exists.
- When you delete your account, your profile data, content and publication records are deleted from the live database straight away.
- The database is also backed up once a day and the backup is kept for 14 days on Google Cloud Storage, whose storage is encrypted at rest by the storage provider (the backup file itself is not separately encrypted). Data you delete can therefore still exist in a daily backup for up to 14 days after deletion, after which it no longer exists in any backup.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and object to the processing of your personal data, as well as the right to data portability.
Erasure you can carry out yourself, at any time: your account settings page deletes your account and everything attached to it, immediately and permanently. Everything else — access, a copy of your data (portability), rectification, restriction, objection — is handled by email: write to [email protected] and you will receive a reply within 30 days. There is no self-service export in the application today; when there is one, this page will say so.
If you consider that your rights have not been respected, you may lodge a complaint with the French data protection authority, the CNIL.
8. How to delete your data
There are two ways to have your data removed:
- Delete your account. From account settings, typing the confirmation word permanently erases every workspace, video, publication record and service key. This takes effect immediately and cannot be undone.
- Ask us directly. Write to [email protected] if you would rather have us action a request than do it yourself.
You can also revoke a single service API key from your account settings, without deleting anything else.
9. Security
All traffic uses HTTPS. Service API keys are stored as a one-way hash — never in full — so a database copy alone cannot be used to act as you. Every account's data is isolated at the database level (PostgreSQL row-level security): a query scoped to one account structurally cannot return another account's rows.
10. Children
This service is not intended for, and is not made available to, anyone under the age of 16.
11. Changes to this policy
This policy may be updated. The "last updated" date at the top of this page indicates the version in force.
12. Contact
Privacy and data protection requests: [email protected]
Anything else: [email protected]