ClipFlow

Effective 2026-09-04

Sub-processors

This page lists every third-party service that processes personal data or customer content on our behalf. It is referenced from our Privacy Policy and is the source of truth for the current list.

We will announce any change to this list by email at least 30 days before the new sub-processor starts handling data.

Current sub-processors

ProviderRoleData typesLocationDPA
SupabaseAuthentication, application databaseEmail, hashed sign-in tokens, video metadata, captions, scheduling recordsIreland / Germany (EU region)DPA
VercelApplication hosting (Next.js frontend + API)Request logs, IP addresses (short-term)Multi-region including EUDPA
CloudflareCDN, DNS, DDoS protection, R2 video/clip storageRequest logs, uploaded videos, generated clipsMulti-region including EUDPA
Modal.comServerless video processing worker (ffmpeg + transcription)Video files during processing only; deleted immediately afterUS (with EU region available)DPA
StripePayment processing, subscription managementBilling email, VAT number, payment method (Stripe holds the card, not us)US and IrelandDPA
ResendTransactional email (sign-in links, receipts, alerts)Email address, message content, delivery statusUS and EUDPA
TikTokPublishing platform — only if you connect your TikTok accountVideo clips you elected to publish; OAuth tokens (stored by us, sent to TikTok on publish)Ireland / US / SingaporeDPA
Google (YouTube)Publishing platform — only if you connect a YouTube channelVideo clips published as Shorts; OAuth tokens for the YouTube Data APIUS and Ireland (EU region available)DPA
Meta (Instagram + Facebook)Publishing platform — only if you connect an Instagram or Facebook PageVideo clips published as Reels; OAuth tokens for the Meta Graph APIUS and IrelandDPA

Platform data handling — what we do with your connected accounts

Each publishing platform (TikTok, YouTube, Instagram, Facebook) is connected through its own official OAuth flow. That platform — not us — decides whether to authorise access and asks you to confirm the exact scopes we request.

TikTok scopes we request:

  • user.info.basic — read your public handle and display name, so we can show you which account is connected and audit publish activity.
  • video.upload — upload video files to your account, which is required to publish clips.
  • video.publish — mark uploaded videos as published on your feed at the time you scheduled.

YouTube scopes we request:

  • youtube.upload — upload video files to your channel to publish them as Shorts.

Instagram + Facebook scopes we request:

  • instagram_content_publish — publish Reels to your Instagram Business account.
  • pages_manage_posts — publish Reels to your Facebook Page.
  • pages_read_engagement — read basic Page info so we can show you which Page is connected.

Every platform issues short-lived access tokens and long-lived refresh tokens on connection. Both are stored encrypted in our database and are only used from server-side jobs that publish your scheduled clips. We never share them. You can revoke a connection at any time from Settings, or from the platform's own authorised-apps screen — either revocation deletes both tokens on our side.

We do not download, cache, or otherwise process any platform content that is not the immediate response to a publish request we initiated on your behalf.

Contact

Questions about our sub-processors: privacy@clipflow.app.