Back to Home

Privacy Policy

Last updated: March 2026

This Privacy Policy explains how Clip Dash collects, uses, stores, and shares your information when you use our video scheduling service. Please read it carefully.

1. Who We Are

Clip Dash ("Clip Dash", "we", "our", "us") operates the video scheduling and publishing service available at clipdash.org. We act as the data controller for personal data collected through this Service. For questions about this policy, contact us at privacy@clipdash.org.

2. Information We Collect

We collect the following categories of information:

  • Account Information: Your email address and hashed password when you register. Managed through Supabase authentication.
  • Platform Authorization Tokens: When you connect social media accounts (YouTube, TikTok, Instagram, Facebook, LinkedIn, Bluesky), we store OAuth access tokens, refresh tokens, and platform-specific identifiers (user IDs, page IDs, DID handles) to act on your behalf. We do not store your social media passwords.
  • Uploaded Content: Video files and thumbnail images you upload for scheduling. Stored in Supabase Storage and used solely to publish to your connected platforms.
  • Post Metadata: Titles, descriptions, hashtags, captions, scheduling times, privacy settings, and platform-specific settings you configure.
  • Profile Information: Platform usernames, channel/page names, profile pictures, and account identifiers received via platform APIs when you connect an account.
  • Team and Billing Information: Team name, member email addresses, subscription plan, and Stripe customer ID. Payment card details are processed and stored by Stripe — we do not store card numbers.
  • Usage and Log Data: IP addresses, browser type, device information, pages visited, feature usage, and error logs. Collected automatically by our infrastructure (Vercel, Supabase).
  • Communications: Messages you send us via email or support channels.

3. How We Use Your Information

We use your information for the following purposes:

  • Providing the Service: storing, processing, and publishing your video content to connected platforms on your behalf
  • Authenticating your identity and managing your account and team
  • Processing payments and managing subscriptions via Stripe
  • Maintaining and automatically refreshing platform OAuth connections
  • Sending transactional notifications (post success, failure, reconnect alerts)
  • Generating AI-powered hashtag suggestions using Anthropic Claude (your caption/title text may be sent to Anthropic's API)
  • Detecting and preventing fraud, abuse, and security incidents
  • Complying with legal obligations
  • Improving the Service based on aggregate, anonymized usage patterns

We do not sell, rent, or share your personal information with third parties for advertising or marketing purposes. We do not use your content or platform data to train AI models.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process your personal data on the following legal bases:

  • Performance of a contract: Processing necessary to provide the Service you signed up for (account management, video publishing, scheduling).
  • Legitimate interests: Security monitoring, fraud prevention, service improvement, and sending service-critical communications.
  • Legal obligation: Where we are required to process data to comply with applicable law.
  • Consent: For optional communications such as product updates and marketing emails, where you have opted in. You may withdraw consent at any time.

5. Google API Services and YouTube Data

Clip Dash uses Google APIs (including the YouTube Data API v3) to publish content to YouTube on your behalf. Our use of information received from Google APIs, including YouTube, adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically regarding Google/YouTube data:

  • We only request YouTube API scopes necessary to upload and manage your videos
  • We do not use Google user data for advertising, profiling, or any purpose other than providing the scheduling Service
  • We do not sell, transfer, or share Google user data with third parties except as necessary to operate the Service
  • We do not use Google user data to train AI or machine learning models
  • Human access to Google user data is strictly limited to troubleshooting issues at your direct request
  • YouTube OAuth tokens are stored server-side, never exposed to the browser or third parties
  • You can revoke Clip Dash's YouTube access at any time via Settings or through your Google Account permissions

6. Third-Party Services and Subprocessors

Clip Dash integrates with and relies on the following third-party services. Each processes your data only to the extent necessary for their stated function:

  • YouTube (Google LLC): Video publishing via YouTube Data API v3. Governed by Google Privacy Policy.
  • TikTok (TikTok Inc.): Video publishing via TikTok Content Posting API. Governed by TikTok Privacy Policy.
  • Facebook (Meta Platforms, Inc.): Video publishing to Facebook Pages via Meta Graph API. Governed by Meta Privacy Policy.
  • Instagram (Meta Platforms, Inc.): Reel/Story publishing via Instagram Graph API (Business and Creator accounts only). Governed by Meta Privacy Policy.
  • LinkedIn (LinkedIn Corporation): Video publishing to LinkedIn profiles via LinkedIn API. Governed by LinkedIn Privacy Policy.
  • Bluesky (Bluesky PBLLC): Video publishing via AT Protocol to bsky.social. Governed by Bluesky Privacy Policy. App passwords are stored server-side and never exposed to the browser.
  • Supabase (Supabase Inc.): Database, authentication, and file storage infrastructure. Data stored in Supabase-managed PostgreSQL and object storage.
  • Vercel Inc.: Cloud hosting and serverless function execution. May process request logs and IP addresses.
  • Stripe Inc.: Payment processing and subscription management. Stripe processes payment card data directly and is PCI-DSS compliant. We store only your Stripe customer ID.
  • Anthropic PBC: AI-powered hashtag suggestions. When you use this feature, your post title and description are sent to Anthropic's Claude API. Anthropic does not use this data to train models by default.
  • Resend Inc.: Transactional email delivery (post status notifications, team invitations).

We only transmit your content and data to these platforms as necessary to perform the actions you request. Video files are sent directly to the platform API at the scheduled time and are not forwarded to any other party.

7. Data Storage, Security, and International Transfers

Your data is stored on servers operated by Supabase and Vercel, which may be located in the United States or other countries. By using the Service, you consent to the transfer and processing of your data in these locations.

We take reasonable technical and organizational measures to protect your data, including:

  • HTTPS encryption for all data in transit
  • OAuth tokens and app passwords stored server-side only, never exposed to the browser
  • Database access restricted via service role credentials not accessible to client code
  • Row-Level Security policies on database tables
  • Access controls limiting employee and contractor access to user data

For transfers of EEA personal data to the United States, we rely on Standard Contractual Clauses or equivalent mechanisms where required by applicable law.

In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify you and relevant authorities as required by applicable law.

8. Data Retention

We retain your data as follows:

  • Account data: Retained while your account is active. Deleted within 30 days of account deletion.
  • Uploaded video files: Retained until you delete them or your account is closed.
  • Scheduled and posted content metadata: Retained while your account is active.
  • OAuth tokens: Retained while the platform connection is active. Deleted immediately upon disconnection.
  • Bluesky app passwords: Retained while the connection is active. Deleted immediately upon disconnection.
  • Billing records: Retained for up to 7 years as required by financial regulations.
  • Server logs: Retained for up to 90 days for security and debugging purposes.

9. Data Deletion and Facebook/Instagram Callback

You can request deletion of your data at any time:

  • Disconnect a platform: Go to Settings → Connections and click "Disconnect." This immediately deletes all stored tokens and platform-specific identifiers for that connection.
  • Delete your account: Use the "Delete Account" option in Settings → Account. This permanently removes your account, uploaded files, scheduled posts, and all platform tokens. Account deletion is processed within 30 days.
  • Facebook/Instagram data deletion: If you connected Facebook or Instagram, you may request data deletion directly through Facebook at Facebook Settings → Apps and Websites. We also provide an automated data deletion callback endpoint at /api/account/delete as required by Meta Platform Terms.
  • Contact us: Email privacy@clipdash.org to request deletion of any specific data.

10. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Authentication: Supabase session cookies to keep you logged in across page visits
  • Security: CSRF protection and OAuth state validation tokens
  • Preferences: Local storage for UI settings (e.g., platform defaults)

We do not use third-party advertising cookies or behavioral tracking. You can clear cookies via your browser settings, which will log you out of the Service.

11. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
  • Portability: Receive your data in a structured, machine-readable format.
  • Restriction: Request that we restrict processing of your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
  • Revoke platform access: Disconnect any linked platform account at any time via Settings, or directly through each platform's security settings.

To exercise any of these rights, email privacy@clipdash.org. We will respond within 30 days (or within the timeframe required by applicable law). If you are an EEA resident, you also have the right to lodge a complaint with your local data protection authority.

12. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, our business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: Request deletion of personal information we have collected, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To submit a request, email privacy@clipdash.org. We will respond within 45 days.

13. Children's Privacy

The Service is intended for users aged 13 and older. If you are in the EEA, you must be at least 16 (or the minimum age required by your country) to use the Service without parental consent. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly. If you believe a minor has provided us with personal data, contact us at privacy@clipdash.org.

14. Automated Decision-Making

We do not make any decisions about you based solely on automated processing that produce legal or similarly significant effects. The AI hashtag suggestion feature generates suggestions that you review and apply manually — it does not make automated decisions about your account.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by displaying a prominent notice in the Service at least 30 days before the changes take effect. The "Last updated" date at the top of this policy reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

16. Contact

For questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at: privacy@clipdash.org