Privacy Policy — Clipperok

Privacy Policy

Effective Date: February 9, 2026

This Privacy Policy describes how Clipperok ("we", "us", or "our") collects, uses, and protects your personal information when you use our AI-powered video clip creation service. By using Clipperok, you consent to the data practices described in this policy.

1. Information We Collect

Automatically Collected Information

When you use the Service, we automatically collect:

  • Browser Information: IP address, browser type and version, operating system
  • Usage Data: Pages visited, features used, task history, clip creation activities
  • Device Information: Device type, screen resolution, language preferences

Information You Provide

  • Account Information: Email address, name (if provided), password (hashed)
  • Google OAuth: Email, name, and Google ID when using "Sign in with Google"
  • Video Content: Videos you upload or YouTube URLs you provide for processing
  • TikTok Integration: TikTok OAuth tokens, open_id, and account information when connected

2. How We Use Your Information

We use your information to:

  • Provide the Service: Process videos, generate transcriptions, create clips, and render subtitles
  • AI Processing: Analyze video content using Whisper AI for transcription and DeepSeek AI for clip recommendations
  • Authentication: Verify your identity and maintain secure access to your account
  • Third-Party Publishing: Publish clips to TikTok when authorized
  • Service Improvement: Analyze usage patterns to improve features and performance
  • Communication: Send service-related notifications about task status and updates

3. AI Processing and Video Handling

Transcription: We use Whisper AI (open-source model running on our servers) to convert speech to text. Transcriptions are stored in our database and used for subtitle generation.

AI Clip Analysis: We use DeepSeek AI API to analyze transcriptions and identify engaging moments. Only text transcriptions (not video files) are sent to DeepSeek for analysis.

Video Processing: All video processing (cutting, formatting, subtitle rendering) is performed on our own servers using FFmpeg. Video files are not shared with third-party AI services.

Storage Duration: Videos and clips are stored temporarily and may be automatically deleted based on age and storage capacity. We recommend downloading your clips promptly.

4. Data Storage and Security

Security Measures

  • Password Security: Passwords are hashed using bcrypt (industry-standard) before storage
  • Authentication: JWT tokens with secure signing, stored in httpOnly cookies to prevent XSS attacks
  • OAuth Token Encryption: All OAuth tokens (Google, TikTok) are encrypted using Fernet encryption with PBKDF2 key derivation and random salt before storage
  • HTTPS/TLS: All data transmission is encrypted using SSL/TLS
  • Database Security: PostgreSQL database with connection pooling and secure access controls
  • Server Security: Docker containerization with non-root user, resource limits, and regular security updates

Limitations

No data transmission over the Internet can be guaranteed 100% secure. While we implement industry-standard security measures, you acknowledge that you use the Service at your own risk. You are responsible for keeping your device and credentials secure.

Breach Notification

In the event of a security breach that may harm your data, we will make reasonable efforts to notify affected users via email within a reasonable timeframe.

5. Third-Party Services

We integrate with the following third-party services, each governed by their own privacy policies:

Google OAuth & YouTube

When you sign in with Google or download YouTube videos, we collect and store OAuth tokens to access Google and YouTube APIs on your behalf. You can revoke authorization at any time through your Google Account settings.

TikTok API

When you connect your TikTok account, we store encrypted OAuth tokens to publish videos on your behalf. You can revoke authorization at any time through your TikTok settings or by disconnecting in the app.

DeepSeek AI

We use DeepSeek AI API to analyze text transcriptions and suggest engaging clips. Only transcribed text (not video files) is sent to DeepSeek. DeepSeek's data processing is governed by their privacy policy.

6. Data Sharing

We do not sell your personal information. We may share information only in these circumstances:

  • With Your Consent: When you authorize us to publish to TikTok or access YouTube on your behalf
  • Legal Compliance: When required by law, court order, or government request
  • Service Providers: With trusted partners who assist in operating the Service (cloud hosting, AI APIs) under strict confidentiality agreements
  • Business Transfer: In the event of a merger, acquisition, or sale of assets
  • Protect Rights: To prevent fraud, enforce our Terms, or protect user safety

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

General Rights

  • Access: Request a copy of your personal information
  • Correction: Update or correct inaccurate data
  • Deletion: Request deletion of your account and associated data
  • Data Portability: Export your data in a structured format
  • Withdraw Consent: Revoke OAuth permissions for Google or TikTok
  • Object to Processing: Opt out of certain data processing activities

GDPR Rights (European Users)

If you are located in the European Economic Area, you have additional rights under GDPR, including the right to lodge complaints with data protection authorities.

CCPA Rights (California Residents)

California residents have the right to request information about data collection, deletion of personal information, and opt-out of data sales (note: we do not sell data). We will not discriminate against you for exercising these rights.

Exercising Your Rights

To exercise your rights, please contact us through the application. We may require identity verification to process your request. We will respond within a reasonable timeframe as required by applicable law.

8. Data Retention

  • Account Data: Retained while your account is active
  • Video Files: Temporarily stored and may be automatically deleted based on age and storage limits
  • Transcriptions: Stored in database linked to tasks; deleted when account is deleted
  • OAuth Tokens: Retained until you revoke authorization or delete your account
  • Logs: Server logs retained for security and debugging purposes (typically 30-90 days)

Upon account deletion, we will permanently remove your personal information and video content within a reasonable timeframe, except where retention is required by law.

9. Cookies and Tracking

Authentication Cookies

We use secure, HTTP-only cookies to store your authentication session. These cookies:

  • Cannot be accessed by JavaScript (protection against XSS attacks)
  • Are encrypted and signed using JWT
  • Expire after a set period or when you log out
  • Are essential for the Service to function

Local Storage

We use browser localStorage to store non-sensitive application preferences (UI settings, theme). No personal information is stored in localStorage.

Third-Party Tracking

We do not use third-party analytics, advertising cookies, or tracking pixels. Your activity is not shared with advertisers or data brokers.

10. Children's Privacy

The Service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it. Parents who believe their child has provided information to us may contact us to request deletion.

11. International Data Transfers

Your information may be processed and stored on servers located in various jurisdictions. By using the Service, you consent to the transfer of your information to these locations, which may have different data protection laws than your country of residence. We take appropriate measures to ensure your data is protected in accordance with this Privacy Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. The "Effective Date" at the top indicates the most recent revision. We will notify you of significant changes by posting the new policy on this page. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

For questions about this Privacy Policy, to exercise your rights, or to report privacy concerns, please contact us through the application or visit our support resources.

By using Clipperok, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.