ZClips app icon

ZClips · Last updated: 2026-06-18

Privacy Policy

1. Who we are

ZClips (zclips.me) is a commercial AI-powered short-form video platform. This Privacy Policy describes what personal data ZClips collects, why, for how long, and what rights you have as a data subject. Data controller contact: legal@zclips.me.

ZClips operates as a public commercial service. By creating an account or using the Service you agree to the practices described in this Policy.

2. Data we collect

We process the data necessary to operate the Service. Concretely:

  • Account data: email address, hashed password (if you sign in with email/password), OAuth provider identifier (if you use social sign-in), display name, avatar URL, account creation/update timestamps, email-verified flag. Stored in our Postgres database.
  • Session data: session tokens and timestamps used to keep you signed in.
  • Source video data: the video URLs you submit, files you upload, derived audio, transcripts, AI-selected segment timestamps and metadata.
  • Generated clip data: rendered MP4 clips, caption text, virality and engagement scores assigned by the AI, processing mode, caption template, language and other generation options.
  • Task data: task identifiers, status, progress events, error traces and timestamps.
  • Team data: if you create or join a team — team name, members, roles, monitored YouTube channels, auto-clip configuration.
  • Third-party connection tokens: when you link TikTok, YouTube/Google, Facebook/Meta, Twitch or Kick, we store the OAuth access token, refresh token and the scopes you granted. Tokens are encrypted at rest using AES-GCM.
  • Third-party profile snapshots: minimal profile data returned by an integration so we can show which account is connected — provider id, username/handle, display name and avatar URL.
  • Publish history: identifiers and status of clips you chose to publish to a destination platform, plus error reasons returned by that platform's API.
  • Performance analytics data: metrics imported from destination platforms (views, likes, comments, shares, estimated reach) for clips you have published. Stored in a time-series table (clip_metrics) and displayed in the in-app analytics dashboard.
  • Share link data: when you create a public share link for a clip, we generate a short token and record the clip it points to, its creation time, expiry time and access count. Share links do not require a visitor account.
  • Subscription and billing data: Stripe customer identifier, subscription identifier, plan, status, current period dates, token balance and token transaction history. We do not store full payment card numbers.
  • Operational logs: task status, queue progress, error traces, IP address and User-Agent of requests at the reverse-proxy layer. These may include user identifiers but not source video content.
  • Support data: messages and attachments you send via our in-app support system, including your email address and any information you voluntarily provide.

3. How we use your data

We use the data above to:

  • authenticate you and keep you signed in;
  • process source video into clips (download, transcription, segment selection, rendering, captioning, optional B-roll insertion);
  • store resulting clips so you can review, edit and re-export them;
  • when you explicitly request it for a specific clip, upload and publish the clip to your linked destination account (TikTok, YouTube, Facebook/Meta, Twitch, Kick);
  • if you enable it, periodically check connected YouTube channels for new uploads and auto-generate / optionally auto-publish clips;
  • generate temporary public share links and serve the linked clip to visitors within its validity period;
  • import and display performance metrics from destination platforms for clips you have published;
  • show which third-party accounts are linked and allow you to disconnect them;
  • operate team workspaces — show team-scoped content to authorized members only;
  • process payments, manage subscriptions and track token balances;
  • send transactional emails (sign-in confirmations, password resets, task completion, subscription updates, support replies);
  • respond to support requests;
  • diagnose errors, prevent abuse and operate the Service reliably.

What we do not do: we do not sell your personal data; we do not use it for behavioural advertising or profiling unrelated to the Service; we do not share it with data brokers; we do not use data obtained from third-party integrations (TikTok, YouTube/Google, Facebook/Meta, Twitch, Kick) to train machine learning models; and we do not use that data for any purpose beyond providing the specific feature you requested.

4. Legal basis (GDPR)

Where GDPR applies, our legal bases are:

  • Performance of a contract (Art. 6(1)(b)) — to operate your account, produce the clips you request, and process payments;
  • Consent (Art. 6(1)(a)) — for connecting external accounts (TikTok, YouTube/Google, Facebook/Meta, Twitch, Kick), enabling auto-clip / auto-publish, and optional analytics integrations. You can withdraw consent at any time;
  • Legitimate interest (Art. 6(1)(f)) — to keep the Service secure, prevent abuse and maintain operational logs;
  • Legal obligation (Art. 6(1)(c)) — to retain billing records as required by tax or accounting law.

5. Cookies and similar technologies

ZClips uses a small number of cookies and local storage items:

  • Session cookie: strictly necessary to keep you signed in. httpOnly, SameSite=Lax.
  • Language cookie (zclips.lang): stores your chosen interface language (en or es). Strictly necessary for locale routing.
  • Theme preference: light/dark/system, stored in local storage.
  • Analytics (only if enabled): see §6 below.

We do not use third-party advertising cookies or cross-site tracking cookies. No cookie consent banner is required for the strictly necessary cookies listed above.

6. Analytics

A deployment may optionally enable DataFast analytics (cookieless, privacy-friendly traffic analytics) by setting the relevant environment variables. When enabled, DataFast collects aggregated, anonymized page-view information; we do not transmit personal data beyond the pseudo-identifier sent by the identity script for authenticated users. If those variables are not configured, no analytics script is loaded.

7. Third-party processors and recipients

To deliver the Service we transmit certain data to third parties acting as processors. Each operates under its own privacy policy:

  • TikTok (Login Kit, Content Posting API, Share Kit, Webhooks) — receives your generated clip file and publish parameters when you ask us to publish.
  • YouTube / Google (source ingestion, OAuth, YouTube Data API) — when you import a video by YouTube URL or connect your Google/YouTube account, we fetch the video and/or channel data from Google's services. Use of data received via Google APIs complies with Google API Services User Data Policy, including the Limited Use requirements.
  • Facebook / Meta (source ingestion, OAuth, Meta Graph API) — when you import a video from Facebook or connect your Meta account, we authenticate via Meta OAuth and may receive profile metadata and video content for processing and publishing. We request only the permissions necessary for the specific feature you enable and do not use Facebook/Meta data for any other purpose.
  • Twitch / Kick — when you import a video by URL or connect these accounts, we authenticate via their OAuth and may receive channel/profile metadata.
  • AssemblyAI — receives source video audio for transcription.
  • LLM provider — receives the transcript to identify candidate clip segments. Depending on configuration: Google Gemini, OpenAI, Anthropic, or a self-hosted model (Ollama). When using a self-hosted model, the transcript does not leave the deployment.
  • Pexels — queried for stock B-roll keywords if you enable the B-roll option.
  • yt-dlp — used for source downloads through the configured proxy pool.
  • Stripe — payment processing and subscription management. Stripe processes payment card data under its own privacy policy; ZClips stores only the Stripe customer and subscription identifiers.
  • Resend / SMTP provider — transactional email delivery when an email provider is configured.
  • DataFast — analytics, only if configured (see §6).
  • Hosting provider — the server infrastructure hosting our Postgres database, Redis instance and worker processes.

We do not provide your data to these providers for any purpose other than the specific service described above.

8. TikTok data specifically

When you authorize ZClips through TikTok Login Kit, we receive only the data permitted by the scopes you grant. We store the OAuth refresh token (encrypted) and a minimal profile snapshot (open id, username, display name, avatar URL) so we can show which account is connected and attribute publishes. We do not request, store or use any other TikTok data. We do not use TikTok data for advertising, profiling, resale or training ML models — only for the publishing flow you initiate. When you disconnect TikTok from Settings, or when we receive a TikTok authorization.removed webhook, we immediately revoke and delete the stored tokens and profile snapshot.

9. Google / YouTube data specifically

Our use of data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use data obtained via Google APIs only to provide or improve user-facing features in ZClips; we do not transfer this data to third parties except as necessary to provide the Service; we do not use this data for serving advertising; and we do not allow humans to read this data unless required for security or legal compliance, or with your explicit consent. We store only the OAuth tokens and minimal profile/channel data necessary to identify the connected account and to operate the auto-clip and publishing features you enable.

10. Facebook / Meta data specifically

When you connect your Facebook/Meta account, we request only the permissions required for the specific features you choose to enable (source ingestion or publishing). We store the OAuth access/refresh tokens (encrypted) and a minimal profile snapshot. We do not use this data for advertising, profiling, or training ML models, and we do not share it with third parties beyond what is necessary to operate the Service. You can disconnect your Facebook/Meta account at any time from Settings, which immediately revokes and deletes the stored tokens and profile snapshot.

11. Source platforms (Twitch, Kick)

If you import a video by URL we fetch the public video for processing; we do not keep authentication state for that platform unless you explicitly connect it. If you connect a platform, we store the OAuth tokens encrypted and use them only for the resources you authorized. You can disconnect at any time from Settings.

12. Teams, shared data and personal workspace

If you create or join a team, the team's tasks, generated clips, monitored channels, auto-clip configuration and member list are visible to all members of that team according to their role. Removing a member revokes their access to that team's content. Deleting a team deletes the team record and team-scoped content.

Each user also has a personal workspace (a private team-of-one). Data in the personal workspace is visible only to that user.

13. Auto-clip and channel monitoring

If you enable auto-clip on a YouTube channel, the worker polls that channel's public uploads feed on a schedule using the YouTube Data API or yt-dlp. We store: the channel id, the last poll timestamp, the most recent video ids seen, and any clips generated from those videos. You can disable auto-clip at any time, which stops the polling.

14. Billing data

We store the following billing-related data: Stripe customer id, subscription id, current plan and status, current billing period and renewal date, token balance and token transaction log. We do not store full payment card numbers. Refer to Stripe's Privacy Policy for how Stripe handles payment instrument data.

15. Retention

  • Account data: kept while your account exists. Deleted on account-deletion request, except where retention is required by law.
  • Source video, transcript, generated clips: kept until you delete the task, or until the configured retention window of the deployment expires (whichever is sooner). Worker scratch files are removed shortly after a task completes.
  • Third-party tokens and profile snapshots: kept until you disconnect the integration; deleted immediately upon disconnect or upon receipt of a revocation/deauthorization webhook.
  • Billing records: retained as required by applicable tax/accounting law (typically up to 6 years in Spain under Spanish tax law), even after account deletion.
  • Operational logs: kept up to 30 days for debugging and security purposes, then rotated out.
  • Support data: kept for as long as necessary to resolve your request and for the applicable legal limitation period thereafter.

16. Security

Third-party secrets and tokens are encrypted at rest with AES-GCM. Account passwords are hashed using industry-standard algorithms. Internal calls between the frontend and backend are signed with HMAC. We make reasonable technical and organizational efforts to protect your data, but no system is perfectly secure. In the event of a personal data breach likely to result in high risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by GDPR.

17. Your rights

Subject to applicable law (including GDPR where it applies), you have the right to: access, correct, export, restrict, object to the processing of, or delete your personal data; withdraw any consent you have given; and lodge a complaint with a supervisory authority. To exercise any right, write to legal@zclips.me. We will respond within 30 days. You may also lodge a complaint with the Spanish data protection authority: Agencia Española de Protección de Datos (aepd.es).

You can disconnect any third-party integration at any time from the Settings page; doing so revokes the stored tokens. You can request full account deletion by email at the address above.

18. Children

ZClips is not directed at children under 16 and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

19. International data transfers

Some third-party processors may be located outside the European Economic Area (for example, AssemblyAI, Google, Meta, Stripe, OpenAI and others may process data in the United States or other countries). Where required, we rely on lawful transfer mechanisms such as the European Commission's Standard Contractual Clauses or an adequacy decision to ensure your data receives an equivalent level of protection.

20. Changes to this policy

We may update this policy from time to time. The "Last updated" date above reflects the most recent revision. Material changes will be communicated by email or in-app notice at least 30 days before they take effect for users with active paid subscriptions.

21. Contact

Privacy questions, deletion requests and any other data-protection enquiries: legal@zclips.me.

See also: Terms of Service · Legal Notice.

Last updated: 2026-06-18.