Clipkiln — Privacy Policy
Version: 1.4 · Last updated: 2026-09-10
Who is responsible
Charles Benjamin Towe, trading as Clipkiln. Address: Crowle Court Farmhouse, Bredicot Lane, Crowle, Worcestershire, WR7 4AY, United Kingdom · Contact: support@clipkiln.com ICO registration: ZC240709
The short version
Your videos never leave our server. Transcription (Whisper) and rendering (ffmpeg) both run on our own machine. Your footage is not uploaded to any AI cloud.
The transcript does leave. The text of what is said in your video is sent to our AI provider so it can find the best moments, write hook lines, and translate subtitles. If your video contains things you would not paste into a chatbot, do not upload it.
What we collect
Your account: email address, a hashed password (bcrypt — we never see the original), display name, plan, minutes used this period, and your Stripe customer ID.
Your content, stored on our server: the videos you upload, transcripts of them, clips we render, and any logo, music, or transition sound you upload.
Support: if you use the Contact form, we receive what you write and any files you attach.
How you found us: if the link you arrived through carried a campaign tag, or your browser told us which site sent you, we store that on your account — the tag and the site's hostname. It is what lets us tell which of the things we post actually brings people who stay. It is deleted with your account.
A record of what your account did, and when: when you signed up, when you confirmed your address, when a video finished processing, when you reached your monthly limit, and when a payment succeeded, failed or was refunded. It is counts and times — never the words in your video, the names of your files, or anything you typed. We use it to see whether the product is working and where people get stuck. It is deleted with your account.
Accounts you connect: if you connect TikTok, YouTube or Google Drive so you can post from inside Clipkiln, we store the access token that platform gives us, the account's display name or handle, and a record of what was posted. We store no password for them. The tokens are encrypted at rest, so they are not readable in the database or in a backup of it. Disconnecting in the app deletes the token.
Google user data. Clipkiln's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice that means we ask for the narrowest access that does the job — for Google Drive we request drive.file, which can only see the files Clipkiln itself puts there and gives us no access to the rest of your Drive, and for YouTube we request youtube.upload, which can upload to your channel and nothing else. That data is used only to deliver the feature you asked for; it is never sold, never used for advertising, and never used to train any model.
Your IP address is used, in memory only, to rate-limit sign-ups and uploads so the service cannot be flooded. We do not keep it in our database and we do not use it to profile you. Our web server keeps ordinary access logs, as any web server does.
We do not use cookies for advertising or tracking. We do not sell your data.
Who else sees it
| Who | What they receive | Why |
|---|---|---|
| Stripe (Managed Payments) | Your email and payment details | They are the merchant of record and take the payment. We never see your card number. |
| OpenRouter | The transcript of your video (the words spoken), and your script if you use the story tab | To score the best moments, write hooks, and translate subtitles. We send every request with a "do not collect" data policy, so it is routed only to AI providers that do not store or train on your transcript. |
| Pexels | Search terms derived from your video's content (e.g. "barbell squat") | To fetch matching stock footage, only if you switch b-roll on |
| Resend (email delivery) | Your email address, and anything you write in the Contact form | It delivers our account emails and carries your support messages to us, so we can reply |
| Telegram | Your email address, in a short operational message when you sign up, confirm your address, finish processing a video, subscribe, change plan, cancel, or a payment fails — plus a nightly total of those counts | It is how the operator is alerted to things that need a human. No video, no transcript and no content ever goes to it |
| TikTok, YouTube, Google Drive | The finished clip, its caption, and whatever the platform needs to post it — but only for accounts you connected, and only when you press publish | To post the clip to your own account, on your instruction |
| Modal (GPU compute) | The text of your narration script, if you use the story tab | It runs the synthetic voice on a GPU. It receives text and returns audio; it is not shown your videos, and nothing is kept there |
| Anthropic / OpenAI | Only if you enter your own API key for the automation feature: the story theme you typed | To write scripts on your own account, billed to you, not us. If you do not enter a key, nothing is sent to them |
We never send your video file to Stripe, OpenRouter, Pexels, Resend or Telegram. The only place a video goes is a platform you have connected yourself and asked us to post to.
Where they are. Stripe, OpenRouter, Resend, Modal, Google, TikTok, Anthropic and OpenAI are all outside the UK, Pexels is in the EU, and Telegram operates internationally. Where personal data reaches them it is transferred under the UK's approved safeguards for international transfers (the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision where one applies). You can ask us for detail on any of them.
Cookies and what we store in your browser
We use no cookies and no third-party trackers. There is no Google Analytics, no advertising pixel, and nothing that follows you to other websites.
We do count visits to our own pages, on our own server. For each page view we record the page, the date and time, any campaign tag in the link you clicked (the utm_... part of the address), and the hostname of the site that sent you — "tiktok.com", never the full address of the page you came from. It tells us whether what we post is bringing anyone here. Nothing is stored in your browser, nothing is shared with anyone, and no profile of you is built.
We do not keep your IP address. To tell 300 page views apart from 40 people, the counter stores a scrambled one-way code made from your address, your browser's user-agent, our secret key and today's date. The address cannot be recovered from it. Because the date is part of it, the code is different tomorrow — so it cannot be used to recognise you on another day, and it is deleted with the visit.
We store two things in your browser's local storage, all of them strictly necessary for the service you asked for:
| What | Why |
|---|---|
| Your login token | So you stay signed in and we are not asking for your password on every page |
| The ID of your last upload | So closing the tab, or your laptop sleeping, does not lose the video you are part-way through |
Because these are strictly necessary to provide a service you actively requested, they are exempt from the consent requirement under PECR reg 6(4) — which is why you are not being shown a cookie banner.
Counting visits does not change that, and it was designed so that it would not. PECR reg 6 is about storing things on your device or reading things back from it. The visit counter stores nothing on your device at all — no cookie, no local storage, nothing — so there is nothing to ask consent for. Our lawful basis for the counting itself is our legitimate interest in knowing whether the service reaches anyone; it is not used to make any decision about you, and you can object using the rights below.
You can clear all of it at any time through your browser settings. Doing so signs you out and forgets which upload you were working on; it deletes nothing from your account.
Is my video "biometric data"?
We do not identify anyone, and we keep nothing that could. But we would rather describe what actually happens than give you a one-word answer.
- Speech becomes text. Whisper transcribes what is said. That is the transcript, and it is the thing that gets sent to our AI provider.
- We do no face recognition. Faces are detected — a box on the screen, so the crop can follow whoever is speaking — but never matched against any database or against each other across videos.
- Auto-reframe tells speakers apart within one video. If you switch it on, we compute a mathematical summary of each voice so we can group the moments where the same person is talking, and point the crop at the right face. It exists to answer "is this the same speaker as ten seconds ago?", never "who is this?". Those summaries are held in memory for the length of that one render and then discarded — they are never written to disk, never attached to your account, and never compared between videos or between users.
The ICO is explicit that a photo or "a recording of someone talking" is a biometric sample, not biometric data: it becomes special-category data only when it is processed for the purpose of uniquely identifying someone. Distinguishing two speakers inside one video, and then forgetting how, is not that.
Our legal basis
- Running your account and providing the service: performance of a contract.
- Posting to a TikTok, YouTube or Google Drive account you connected: performance of a contract. Connecting the account is the request; you can disconnect at any time.
- Keeping the service secure and preventing abuse: legitimate interests.
- Support messages: legitimate interests.
- Alerting the operator that an account signed up, subscribed, changed plan or failed a payment: legitimate interests — a one-person business has to know when something needs a human. Only an email address and the event go into that alert.
- Keeping a hashed record of a closed account's free trial: legitimate interests, in not having a one-per-customer offer taken repeatedly. See the retention section.
How long we keep things
| Data | Kept for |
|---|---|
| An upload, and everything belonging to it | 5 days after you last touched it — the source video, its clips, and the record of the upload itself are all deleted together |
| Rendered clips you did not save | Deleted with their upload at 5 days (sooner if you delete the upload) |
| Stock footage we fetched for a job | 1 day |
| A video you send to the transcriber or the subtitler (the Other tab) | 4 hours after you send it. The subtitled video we make is not stored either and cannot be saved to your account — download it, or send it to your Google Drive, before the 4 hours are up |
| Story videos you did not save | 10 days after they were made — the script and every setting are kept, so you can re-render the video at any time |
| Clips you saved to your account | Until you delete them or close your account |
| Account data (email, plan, usage) | While your account is open. Closing your account deletes it immediately — there is no grace period and no soft-delete |
| Tokens for accounts you connected | Until you disconnect them or close your account |
| Files you attach to a support message | Deleted as soon as the message is sent — they are never stored and never forwarded; only the number of files goes in the email to us |
| Support messages | Clipkiln itself stores none — your message is delivered to our email inbox and lives there, where we keep it for up to 12 months so we can follow up |
| Page-view counts (page, campaign tag, referring site's hostname, the day-code above) | 90 days, then deleted automatically |
| The record of what your account did and when | 400 days, and in any case only while your account is open — closing your account deletes it |
| A record of money taken, refunded or failed — the amount, the date and the Stripe reference | Kept after you close your account for 6 years, as tax law requires. The link to you is removed when the account closes — see below |
| A one-way hash of your email address, plus whether that account used its free trial and whether it ever paid | Kept after you close your account, indefinitely — see below |
What outlives your account, and why. Two things, and nothing else.
The trial mark. The free trial is one per person, so if closing an account wiped every trace of it, closing and re-registering would be a way to take another one. When an account closes we keep a one-way cryptographic hash of your email address — not the address, and it cannot be turned back into one — whether that account had used its trial, and whether it had ever paid. It is read for one purpose only: recognising, at sign-up, that this mailbox has had its trial. Our lawful basis is our legitimate interest in preventing repeated use of a one-per-customer offer, and you can object to it using the rights below.
The payment record. We keep the amount, the date and the Stripe reference for money taken, refunded or failed, because tax law requires a business to be able to show what it was paid. The link to your account is removed when the account closes, so what remains is a line in a ledger rather than a record about you. Stripe, as the merchant of record, keeps its own copy under its own obligations either way. Our lawful basis is our legal obligation to keep accounting records.
Your rights
You can ask us to: see the data we hold on you, correct it, delete it, export it, or object to how we use it. Email support@clipkiln.com.
We will respond within one month. Where we need to confirm who you are first, that month runs from when we have verified your identity.
If you are unhappy, complain to us first at support@clipkiln.com. We will acknowledge your complaint within 30 days. You can also complain to the Information Commissioner's Office (ico.org.uk) at any time — you do not have to come to us first.
Security
Passwords are hashed with bcrypt, so we cannot read them. The tokens for any social account you connect, and any AI provider key you enter, are encrypted at rest. The service is served over HTTPS, and access to your files requires your login. No system is perfectly secure — do not upload anything whose exposure you could not tolerate.
Children
Clipkiln is not for under-18s and we do not knowingly hold their data.
Changes
We will post updates here and email you about material ones.