ClipFlow

Effective 2026-09-04

Privacy Policy

This policy explains what personal data ClipFlow (“we”, “us”) collects about you when you use the Service, why we collect it, and what your rights are. We are the data controller for that data.

Controller: [YOUR LEGAL NAME] ([SOLE PROPRIETORSHIP / ApS / …], [YOUR CVR / VAT NUMBER]), [YOUR REGISTERED ADDRESS], Denmark. Privacy contact: privacy@clipflow.app.

1. What we collect and why

CategoryWhatWhyLegal basis (GDPR Art. 6)
AccountEmail address; hashed sign-in tokensTo create your account, sign you in, contact you about the ServicePerformance of contract
ContentVideo files you upload; clips we generate from them; captions you writeTo provide the Service — cut, store, and publish your contentPerformance of contract
Third-party tokensOAuth access + refresh tokens for connected accounts (currently TikTok)To publish clips to your account on your behalfPerformance of contract
Third-party profilePublic handle + display name of your connected TikTok accountTo show you which account is connected; audit loggingPerformance of contract
BillingHandled by Stripe — we do not store card numbersTo collect subscription feesPerformance of contract
Service usageWhich pages you visit, error logs, IP address (short-term)To keep the Service secure and fix bugsLegitimate interests (running a secure Service)
Support correspondenceEmails you send us and our repliesTo answer your questionsLegitimate interests (responding to you)

We do not use your uploaded videos to train AI models, sell them to advertisers, or make them public in any way other than publishing to the platform you have connected.

2. How long we keep it

  • Account data: for as long as your account exists, plus up to 30 days after deletion for backup rotation.
  • Uploaded videos and clips: for as long as your account exists, or until you delete them from the dashboard, whichever is sooner.
  • Third-party access tokens: until you disconnect the account or delete yours, then deleted immediately.
  • Billing records: as long as required by tax law in Denmark (currently 5 years).
  • Support correspondence: 3 years after the last message.

3. Who we share it with — sub-processors

We use a small set of trusted third-party services to run the Service. Each is bound by a Data Processing Agreement and appears on our sub-processors page, which is the source of truth for the current list. Broadly:

  • Hosting and database (Supabase, Vercel, Cloudflare)
  • Video storage and processing (Cloudflare R2, Modal.com)
  • Payment processing (Stripe)
  • Transactional email (Resend or equivalent)
  • Publishing target platform (TikTok — only if you connect it)

We will notify you at least 30 days before adding a new sub-processor that handles content or account data, giving you a chance to object by terminating your subscription.

4. International transfers

Some sub-processors are based outside the EU/EEA (notably some Cloudflare, Stripe, and TikTok facilities). Where personal data leaves the EEA, we rely on the European Commission's Standard Contractual Clauses, plus any supplementary measures required for the destination country. Details are in the sub-processors page.

5. Cookies

The Service uses a small number of first-party cookies that are strictly necessary to keep you signed in and to remember your preferences. We do not use advertising cookies or third-party analytics that track you across sites. Because these cookies are strictly necessary, no consent banner is shown.

6. Your rights under GDPR

If you are in the EU/EEA (or the UK), you have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Rectify — correct inaccurate data;
  • Erase — have your data deleted (subject to legal retention obligations);
  • Restrict — limit how we process your data;
  • Object — object to processing based on our legitimate interests;
  • Portability — receive your data in a portable format;
  • Withdraw consent — where processing is based on consent;
  • Complain — lodge a complaint with your supervisory authority. In Denmark, that is Datatilsynet.

Most rights are exercisable directly from Settings (export data, delete account). For anything else, email privacy@clipflow.app. We will respond within 30 days.

7. Security

We take reasonable technical and organisational measures to protect your data — encrypted transport (TLS), encryption at rest for access tokens and payment data, least-privilege access controls, and audit logging. No system is perfectly secure; if we ever become aware of a personal-data breach affecting you, we will notify you and the supervisory authority within 72 hours as required by GDPR Art. 33-34.

8. Children

The Service is not intended for anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.

9. Changes

We may update this policy. Material changes will be announced by email at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.

10. Contact

Privacy questions: privacy@clipflow.app. General support: hello@clipflow.app.