Privacy policy
What we collect, why, which kinds of providers process it, how long it is kept, and the choices you have.
Draft v0.2, last updated September 4, 2026, pending legal review
1. Overview
This policy explains which personal data TapToClip collects, why, who processes it, how long it is kept, and what choices you have. It describes what we actually do rather than claiming compliance with any particular framework; where a law gives you specific rights, we honour the rights that apply to you.
The identity and registered address of the data controller will be completed before this draft becomes final. You can contact TapToClip at contact@taptoclip.io.
2. Data we collect
- Account data. Email address, display name, optional avatar, locale, timezone, the identifier of a linked Google account, and the session information needed to keep you signed in.
- Billing data. Your plan, subscription status, billing period, and the invoice and customer identifiers held at our payment provider. Card details are entered on the hosted pages of the payment provider; we never see or store full card numbers.
- Media data. The videos you upload or that we fetch from the links you submit, and everything derived from them: extracted audio, previews and thumbnails, face-tracking data used for reframing, candidate clips, your edits, rendered clips, and ZIP exports.
- Transcript data. The transcript of each source with word timings, speaker labels, and audio-event tags, together with the automated scores and rationales for candidate clips.
- Analytics and operational data. Product events such as a project being started or an export completing, browser and device information, IP addresses and request identifiers in server logs, error reports, processing metrics, and an audit log of account and billing actions. Analytics events never contain your media, transcripts, file names, or email address.
- Communications. Messages you send to support and your email notification preferences.
3. How we use data
We use this data to:
- provide the Service: import, store, transcribe, analyse, reframe, edit, and render your media, and let you download the results;
- run your account, keep you signed in, and protect it against unauthorized access;
- bill subscriptions, apply quota, and keep the records that tax and accounting rules require;
- send transactional messages such as project completion, failed processing, render or export completion, and payment problems;
- understand how the product is used in aggregate, fix errors, and improve reliability;
- prevent abuse, enforce our terms and the Media policy, and comply with legal obligations.
We do not use your media or transcripts to train models of our own, and we do not sell personal data.
4. Providers
We rely on providers that process data on our behalf:
- hosting and delivery of the application, and the database and authentication service that stores account and project data;
- private object storage and media processing servers for uploads, previews, and renders;
- transcription and AI analysis providers, which receive the audio, transcript excerpts, and short video windows needed to transcribe speech and propose clips;
- a payment provider for subscriptions and invoices;
- an email provider for transactional messages;
- a product analytics provider that receives content-free events and pseudonymous identifiers.
Providers act under contracts that limit them to the task we request. Some are located outside your country, in which case data is transferred under the safeguards those contracts provide. Provider settings for retention and for the use of data to improve their models are reviewed before launch, and the final arrangements will be described here.
5. Retention
- Project media, including sources, extracted audio, previews, face-tracking data, and rendered clips, is deleted 30 days after processing completes. Media is never deleted while processing or rendering is still running.
- ZIP exports expire 7 days after they are created.
- Project details, transcripts, candidate clips, scores, and edits stay until you delete the project or your account.
- Account data stays until you delete your account, after which it is removed except where we must keep it.
- Billing records are kept for as long as tax and accounting rules require.
- Server logs and error reports are kept for the limited period needed for security and debugging, then deleted.
Deleting a project or an account marks the data for deletion immediately, blocks any new access to it, and removes the underlying files asynchronously.
6. Your rights and choices
You can view and change your display name, avatar, locale, timezone, and email notification preferences in Settings, and you can delete projects or your whole account there. Deleting your account cancels any subscription.
Depending on where you live, you may also have the right to access, correct, export, restrict, or delete your personal data, to object to certain processing, and to complain to a supervisory authority. Email contact@taptoclip.io to exercise a right you cannot exercise in Settings; we may ask you to verify your identity first.
We use only the cookies needed to keep you signed in and to protect the Service. Product analytics runs in cookieless mode and sends content-free events directly to our analytics provider. Security and legally required messages cannot be turned off, but marketing communication is sent only with your separate consent.
7. Security controls
Media is stored in private storage and served only through short-lived signed links issued after an authorization check. Access rules in the database restrict every project, transcript, clip, and file to its owner, and every request is authorized again on the server. Credentials for providers and storage stay on the server and never reach the browser, and our own servers authenticate each other with signed requests. Connections are encrypted, credentials follow least privilege, and account and billing actions are recorded in an audit log.
No system is perfectly secure. If you believe you have found a vulnerability, email contact@taptoclip.io and we will respond promptly.
8. Contact and changes
Questions and requests about this policy go to contact@taptoclip.io.
We may update this policy. The current version is always published here with its date, and we notify account holders of material changes before they take effect.