Legal
Privacy policy
This policy explains what personal data ClippyOS handles, why, for how long, and the rights you have over it. It is deliberately short, because the architecture keeps most of your data out of our hands entirely: your footage is processed on your own machine and never reaches us.
Last updated: August 20, 2026
On this page
- The short version
- Who we are and our role
- Your footage never reaches us
- Data we do collect
- How we use it
- Reference reels
- AI calls — exactly what is sent
- Sharing and processors
- International transfers
- How long we keep data
- Your rights (UK/EU GDPR & CCPA)
- Cookies and local storage
- Security
- Children
- Changes and contact
1. The short version
- Your video footage never leaves your machine. Clips are read from your disk, analysed, and rendered inside your browser. There is no upload path in the product, and we operate no media storage.
- Finished videos are written straight to your disk. We never receive, host, or keep a copy.
- We hold the minimum a subscription product needs: your account details, your billing state, and a small number of usage counters that enforce plan limits.
- Reference reels you paste are fetched by our server, streamed to your browser for analysis, and discarded. We never store other people’s reels.
- Our AI calls send transcript and quote text — never your audio, never your footage. The only image ever sent is a single frame of the public reference reel you pasted, so its on-screen quote can be read.
- We do not sell personal data, and we run no advertising trackers.
2. Who we are and our role
ClippyOS (“ClippyOS”, “we”, “us”) is operated from the United Kingdom, and UK data protection law is our home framework. For the account, billing, and usage data described in this policy, we are the data controller.
Your footage occupies a special position: because it is processed entirely on your own device and never transmitted to us, we are neither controller nor processor of it — we simply never have it.
You can reach us about anything in this policy through the contact form or at support@clippyos.com.
ClippyOS is operated by [LEGAL ENTITY NAME], registered in England and Wales, [REGISTERED ADDRESS].
3. Your footage never reaches us
When you point ClippyOS at a folder, your browser reads the clips directly from your disk using its built-in file access. Indexing results — quality scores, scene boundaries, embeddings, thumbnails — are cached in your browser’s local storage, on your device, so returning to the app doesn’t repeat the work. Rendering also happens in the browser, and finished videos are saved directly back to your disk.
None of this content is transmitted to ClippyOS or to any third party. If you clear your browser’s site data for ClippyOS, the local caches are gone and we could not restore them — we never had them.
4. Data we do collect
Account data
- Email address, name, and a password (stored as a hash by our authentication provider, Supabase — we never see plaintext passwords).
Billing data
- Plan and subscription state. Payment is handled by Stripe. We store your Stripe customer reference and subscription status, never your card number.
Usage data
- Counters that enforce plan limits — for example, that a free account has used its generate, and how many exports a Pro account has made this week. These are counts and timestamps, not content: we record that you generated reels, never what was in it.
Reference links
- The URL of a reel you paste, so your recent references work across sessions. We keep no copy of the video (see section 6).
Support and error data
- Messages you send through the contact form, and error reports collected by Sentry when something breaks — technical context such as browser, OS, and the failing code path. Error reports never include your footage. It isn’t on our servers to include.
5. How we use it
- To operate your account: signing you in, verifying your email, resetting passwords.
- To run your subscription: charging, invoicing, and applying plan limits.
- To send transactional email — verification links, receipts, payment-failure notices. We do not send marketing email.
- To answer support messages and fix errors.
- To prevent abuse — rate-limiting and enforcing the weekly reel ceiling that stops resale.
Our legal bases under UK/EU GDPR are performance of the contract (the product itself), legitimate interests (security, abuse prevention, fixing errors), and consent where we ask for it. We do not use personal data for automated decisions with legal effect, and we do not sell it to anyone.
6. Reference reels
When you paste a public reel URL, our server fetches that reel (via our fetching provider, Apify), streams it to your browser for analysis, and discards it. The analysis — cut timing, text placement, the track’s name — happens in your browser. We never store other people’s reels, and we keep no copy of the video after the stream completes. What leaves your machine here is the URL you pasted, which goes to Apify so the reel can be fetched. The video bytes are streamed through our server and never stored.
One thing happens on your side: when a set you generate used a reference, ClippyOS saves that reel’s video file alongside the set in your own browser’s storage, on your computer — so reusing the reference doesn’t fetch it again. That copy is yours, sits on your machine, and never reaches us. Deleting the set from your library deletes it.
7. AI calls — exactly what is sent
A few features use a language model (provided by Anthropic): finding where a talking point ends in a transcript, writing quote variations in a reference’s theme, and explaining what makes a reel work. What leaves your machine for these calls is narrow, and worth stating exactly:
- The timestamped transcript text of your talking clips, produced on your machine — text only, never your audio and never your video.
- The reference reel’s quote text and any topic you type.
- A single frame (one JPEG image) of the reference reel — the public reel whose link you pasted, never your own footage — so the quote on its screen can be read.
Separately, the reel URL you paste goes to our fetching provider, Apify (see section 6). Your footage and your finished videos never leave your machine. Under Anthropic’s commercial API terms, content sent to the API is not used to train their models by default.
9. International transfers
We are UK-based. Several of our processors run infrastructure in the United States and the EU. Where personal data leaves the UK or EEA, we rely on recognised safeguards — the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses, and, where a provider is certified, the UK–US Data Bridge / EU–US Data Privacy Framework.
10. How long we keep data
Each kind of data is kept only as long as the job it exists for, then removed — by a daily job for the short-lived rows, and immediately when you delete your account.
| Data | Kept for | Then |
|---|---|---|
| Account (email, name, password hash) | While your account exists | Deleted the moment you delete your account. Removed from encrypted database backups within 30 days. |
| Plan and subscription state | While your account exists | Deleted with the account. Stripe keeps the invoices and payment records tax law requires (six years in the UK) under its own policy. |
| Free-generate flag | While your account exists | Deleted with the account. |
| Weekly reel counts | 90 days from the end of each seven-day period | Pruned by the daily job. The current period is all the limit needs. |
| Rate-limit counters (per account, per IP) | 2 days from the start of the window | Pruned by the daily job. Counters keyed to your account or email are erased when you delete the account, without waiting. |
| Abuse blocks (repeat breaches) | 7 days after the block expires | Pruned by the daily job. |
| Server request logs (Vercel) | A short window set by Vercel — hours to a few days | Rotated by Vercel. |
| Error reports (Sentry) | 90 days | Expired by Sentry. |
| Page-view analytics | Held by Vercel as aggregate counts | No per-person record is kept by us. |
| Support messages | Up to two years in our support mailbox | Deleted. They are never stored in our database. |
| Your footage, clip indexes and finished videos | Never held by us | Nothing to retain or delete on our side. Clear them from your own browser any time. |
11. Your rights (UK/EU GDPR & CCPA)
If you are in the UK or EU you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. If you are a California resident, the CCPA gives you closely matching rights, plus the right to know that we do not sell or share personal information as those terms are defined there.
Send any request through the contact form or to support@clippyos.com. We respond within a month. You can also complain to your supervisory authority — in the UK, the Information Commissioner’s Office (ICO).
13. Security
Everything between your browser and our servers travels over TLS. Passwords are hashed by Supabase. Card data never touches our systems. Access to production data is limited and logged. The strongest safeguard is architectural: the most sensitive thing you have — your footage — is never in our hands at all, so no breach of our systems could expose it.
14. Children
ClippyOS is not directed at children and requires you to be at least 16 (or the age of digital consent where you live). If you believe a child has created an account, contact us and we will delete it.
15. Changes and contact
If we change this policy in a way that matters, we will email account holders before the change takes effect and update the date at the top. Questions, requests, or complaints: the contact form or support@clippyos.com — both reach a human.