Klipara

Published documents

Privacy Policy

Last checked against the software on 2026-08-10

We process the video you give us in order to find clips in it. We do not train models on it, we do not sell it, and we delete it when you tell us to.

Who we are

Klipara is operated by [legal entity], registered in [jurisdiction] at [registered address]. For anything on this page, write to [email protected].

For GDPR purposes we are the controller of your account data and the processor of the video, audio and transcripts you upload. If you are an agency using Klipara for your own clients, you are the controller of their material and we are your processor — a Data Processing Agreement is available on request.

What we collect

Because you gave it to us

Your email address and name, the workspaces, clients and brands you create, and the video, audio and links you submit for analysis.

Because the product produces it

Transcripts, clip candidates, per-signal scores, rendered clips, and the decisions you make about them — which clips you kept, which you discarded, and the reason you gave when you told us a clip was not a keeper.

Because you connected an account

When you connect a social account or a watched source, we hold an access credential for it and the metadata needed to poll it. No table has a token column; see Credentials.

Because platforms report it

Once you publish, we periodically retrieve public performance metrics for your own posts — views, watch time, engagement — on a decaying schedule. We never retrieve anyone else’s.

What we do not collect

No advertising cookies. No cross-site tracking. No third-party analytics script of any kind — errors and analytics both run on our own infrastructure. No location data. No biometric identifiers derived from faces in your video: the visual pass measures where a speaker is in the frame so the clip can be cropped, and that measurement is discarded with the render.

Why we are allowed to process it

Running your account, processing your video
Performance of a contract — Art. 6(1)(b)
Billing, fraud prevention, keeping records of what we charged
Legal obligation and legitimate interests — Art. 6(1)(c), (f)
Security logging and abuse prevention
Legitimate interests — Art. 6(1)(f)
Improving your own workspace’s clip selection
Performance of a contract — see the commitment below
Anything a marketing email would need
Consent — Art. 6(1)(a), withdrawable at any time

We do not rely on legitimate interests to train models.

The training commitment

We do not train models on your video, audio or transcripts. Not for our own models, not across tenants, not in anonymised aggregate, not ever.

This is deliberately unqualified. Our customers are brands and agencies handling material that is confidential until it is published — an unreleased announcement, an interview under embargo, a recording a client has not approved. A policy with an “except in aggregate” clause is not a commitment; it is a plan.

What we do learn from is your own workspace’s decisions about its own clips — which ones you kept, which you discarded, and how they performed. That improves the selection for that workspace only, and never crosses a tenant boundary. If we ever want to change this, the change will be announced in advance, will be opt-in, and this paragraph is what we will be held to.

Who we send it to

We self-host wherever self-hosting is not a false economy. Transcription, embeddings, object storage, the database, the queue, error tracking, analytics and the status page all run on our own infrastructure — they are not sub-processors because nobody else is involved. The ones that are:

Anthropic
Transcript text for the semantic pass. Never the video, never the audio.
Google (Gemini)
Sampled frames for the visual pass, when enabled.
Resend
Your email address and the message we send you.
Stripe
Billing details. We never see or store a card number.
Deepgram
Audio, only if you enable the hosted transcription fallback. Off by default.
Upload-Post
The clip and caption you chose to publish, at the moment you publish it.

We will publish changes to this list before they take effect. We do not sell personal data. There is no arrangement under which we could.

Credentials

Access tokens for connected accounts are held in a secret store, referenced from the database by pointer only. Webhook signing secrets are derived rather than stored: the database holds a non-secret identifier and the actual secret is computed from it under a server-side key, so a database dump contains no signing material at all. Invite and API-key tokens are stored as digests, never in the clear.

A data export deliberately excludes all of it. The right to your data is not a right to a file that lets whoever obtains it post as you.

How long we keep it

Source video and audio
30 days after upload by default, then deleted
Transcripts and clip metadata
For the life of the workspace
Rendered clips
For the life of the workspace, or until you delete them
Billing and ledger records
7 years, or as tax law requires
Request and security logs
90 days

Your rights

You have the rights the GDPR and UK GDPR give you: access, rectification, erasure, restriction, portability, and objection. Two of them are buttons rather than an email address.

Export. One JSON document containing everything we hold about your workspace, with media listed as signed download links rather than inlined. It states what was deliberately left out and why, rather than omitting it silently.

Deletion. Scheduled seven days out, not immediate, and the delay is intentional: an account destroyed the instant a button is pressed gives a compromised session an irreversible weapon and gives an honest mistake no way back. You get an email with the date and a link that cancels it. On the day, the storage objects go first and then every row.

One exception, disclosed rather than buried: records of what our payment provider told us survive deletion, with no tenant attached. Financial records carry their own retention period and a chargeback six months later has to remain answerable. That is the Art. 17(3)(b) carve-out and it is the only one.

For any other right, write to [email protected]. We answer within 30 days. If we get it wrong you can complain to your supervisory authority — in the UK, the ICO.

Where your data is

Primary processing is in [region]. Some sub-processors above process outside the UK and EU; those transfers rely on the UK IDTA or the EU Standard Contractual Clauses as applicable, per [per-processor mechanism].

Children

Klipara is not for anyone under 18 and we do not knowingly hold their data. If you believe a child has an account, tell us and we will delete it.

Changes

We will post material changes here and email workspace owners before they take effect. The training commitment will not be weakened without notice and an opt-in.