Legal · Privacy
Privacy Policy
Clipsie processes the accounts and content you connect to find clip-worthy moments and publish them according to your settings. Google OAuth tokens are encrypted, the production YouTube connection is upload-only, we do not sell Google user data, and disconnecting YouTube revokes and deletes Clipsie's stored grant.
Clipsie ("Clipsie", "we", "us") is a video-clipping automation service operated by Yari Eugster (Switzerland), the controller for the processing described here. Our full identity and postal address are in the Impressum. This policy explains what data we collect, why, and what control you have over it. It applies to the Clipsie website and service at clipsie.app.
Where we process personal data on behalf of a customer — the chat, voices and faces their stream captures — we act as their processor, not as controller. Those terms are in our Data Processing Agreement.
Data we collect
Account data. When you sign up we collect your email address, authentication details, and billing information (processed by our payment provider; we do not store full card numbers).
Connected accounts (via OAuth). You authorize Clipsie to act on platforms you choose. We access only what's needed to operate the service:
- Twitch: the channels you connect, public stream and broadcaster metadata, live chat messages, and clip URLs, used to detect clip-worthy moments and retrieve source footage.
- YouTube: an encrypted OAuth access and refresh token for the Google account you authorize. The production Clipsie connection requests only the
youtube.uploadpermission and uses it to upload videos and their thumbnails to your YouTube channel. It does not read your channel, videos, comments, subscribers, or analytics, and it does not post comments. You choose whether uploads are private, unlisted, or public and whether Clipsie may post automatically. By connecting YouTube you agree to the YouTube Terms of Service. Google's own processing is governed by the Google Privacy Policy. You can also revoke access from Google's security permissions. - TikTok: OAuth tokens for the accounts you authorize, used solely to publish videos via the TikTok Content Posting API. We do not access your followers, messages, or analytics.
Content we process. To create and review a clip we handle its video and audio and generate a transcript, title, thumbnail, captions, scores, and technical rendering metadata. We also store publishing status and destination video identifiers so the dashboard can show what happened.
Usage & technical data. Standard logs (IP address, timestamps, error and upload events) used to operate, secure, and debug the service.
How we use your data
- To detect moments, create clips, and publish them to the accounts you connect.
- To show a review queue, respect your YouTube visibility and auto-post choices, and report upload status.
- To run your account, process payments, and provide support.
- To keep the service secure, prevent abuse, and fix problems.
We do not sell your personal data, and we do not use it for advertising.
Limited Use (Google API Services). Clipsie's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the YouTube upload feature you request. It is not sold, used for advertising, used to build advertising profiles, exposed to humans except for security/support with your permission, or transferred except as necessary to provide the feature, comply with law, or complete a merger or acquisition.
Legal bases for processing
Where the GDPR applies, we rely on these grounds under Art. 6(1):
- Performance of a contract (Art. 6(1)(b)). Creating and running your account, detecting moments, rendering clips, publishing them to the destinations you authorise, showing your review queue, and answering support requests. This is the basis for most of what Clipsie does — it is the service you asked us for.
- Legal obligation (Art. 6(1)(c)). Keeping invoicing and accounting records for the periods Swiss law requires, and responding to lawful requests and valid copyright notices.
- Legitimate interests (Art. 6(1)(f)). Keeping the service secure, preventing abuse, diagnosing failures, and understanding aggregate reliability and cost so the pipeline keeps working. Our interest is running a functioning, non-abused service; we balance it by keeping this data operational rather than personal wherever possible, not building profiles, and not using it for advertising. You can object to processing on this basis at any time — see section 07.
- Consent (Art. 6(1)(a)). Only where we ask for it explicitly, such as optional product emails that are not service notices. You can withdraw consent at any time, and withdrawing it does not affect processing that already happened.
Under the Swiss FADP the structure differs — a private controller may process personal data unless doing so breaches the data subject's personality rights — but in practice we hold ourselves to the same limits described here.
People who appear in streams
Clipsie processes personal data belonging to people who never signed up with us: chat participants, guests, and anyone visible or audible in a stream that a customer connects. We want to be straight about how that works.
We are not the controller for that data — the streamer is. They decide what to stream, which channel to connect, and what gets published. We act only on their instructions, as their processor, under our Data Processing Agreement. That means the decisions about your data, and the duty to inform you about them, sit with the channel whose stream you took part in.
What we handle on their behalf: chat messages and the display names attached to them, the audio and video of the stream, transcripts generated from that audio, and clips derived from it. We do not use any of it to build a profile of you, to advertise, or to train our own models, and we do not sell it.
If you want a clip removed or your data deleted, the fastest route is the channel that published it — they can delete it in Clipsie and on the platform it was posted to. You can also write to privacy@clipsie.app. We will not act on the request ourselves, because it is not our decision to make, but we will pass it to the responsible customer without undue delay and tell you that we have.
Third-party processors
We share data with a small set of providers strictly to deliver the service:
- Anthropic: Twitch-derived transcripts and short text are sent to Claude to score moments and generate titles. Google user data and Google OAuth tokens are not sent to Anthropic.
- Groq: Twitch-derived clip audio is sent for speech-to-text transcription. Google user data and Google OAuth tokens are not sent to Groq.
- Our hosting and payment providers: for infrastructure and billing.
- The platforms you connect (Twitch, YouTube, TikTok): to read source content and publish on your behalf.
The complete, current list — naming each provider, what it receives, and where it processes — is at clipsie.app/subprocessors. We give 30 days' notice there before adding a new one.
Storage & retention
OAuth access and refresh tokens are encrypted at rest. A YouTube disconnect request is sent to Google's revocation endpoint and Clipsie's encrypted token is deleted promptly. One-time authorization codes and PKCE verifiers are redacted when the connection completes, and completed handoff records are removed after 24 hours.
Review media may be retained for up to 30 days so you can preview and approve it; rejected or failed review media is normally removed within 7 days. Operational clip records such as titles, status, source URL, destination video ID, and rendering metadata are retained while your Clipsie account is active so the dashboard and support history work. Operational logs rotate and are used only for security and debugging; transcript text is not written to application logs.
When you request account deletion, we revoke your connected-platform access and delete the encrypted tokens immediately, and we delete your remaining Clipsie account data within 30 days, except information we must retain for legal, fraud-prevention, or security obligations. Videos already uploaded to YouTube remain under your control on YouTube and are not deleted merely because you disconnect Clipsie.
Your rights & choices
You can disconnect any platform from the dashboard. For YouTube, this triggers Google revocation and local token deletion.
Deleting your account and data does not require contacting us: open Account → Delete account and data in the dashboard and confirm. Every platform connection is revoked and all clipping stops right away; your account, clips, render history and settings are permanently deleted 30 days later. Until that date you can stop the deletion by emailing privacy@clipsie.app; after it, nothing remains to restore. You can also request access to, export of, or correction of your Clipsie data at the same address. Where applicable, we honor rights under the EU GDPR and the Swiss FADP. You can also revoke Clipsie's access directly in your Twitch, YouTube/Google, or TikTok account settings.
Your full set of rights. Where the GDPR applies you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object to processing based on our legitimate interests (Art. 21). Where processing rests on consent, you can withdraw it at any time. We answer within one month and will not charge you for it.
Complaining about us. If you think we have handled your data unlawfully, please tell us first — but you do not have to. You have the right to lodge a complaint with a supervisory authority, in particular in the EU or EEA country where you live, where you work, or where the alleged infringement happened. In Switzerland the competent authority is the Federal Data Protection and Information Commissioner (FDPIC). A list of EU authorities is published by the European Data Protection Board.
Cookies & local storage
Clipsie runs no advertising and no cross-site trackers, and we do not build profiles of visitors. We count visits with Cloudflare Web Analytics: it sets no cookies, stores nothing in your browser, and cannot follow you to other sites. It tells us how many people opened a page, which site linked them here, and the rough country and device type — never who you are. Cloudflare already hosts this site, so the measurement falls under the same agreement; see the sub-processor list.
We store a small amount of data in your browser:
- Session and authentication — keeps you signed in to the dashboard, and carries the short-lived state that makes a platform authorisation round-trip work. Strictly necessary; without it the app cannot work.
- Display preferences — your light or dark theme and your interface language.
- Interface state — which tab you last had open and which channels you had selected, so the dashboard looks the same when you come back.
- Onboarding progress — lets the first-run setup resume after you return from a platform's authorisation screen.
- Cached homepage figures — the public clip and view counts shown on our homepage, kept so a reload doesn't reset the counter animation. It describes Clipsie, not you, and contains no information about your visit.
- First-touch source (
clipsie_attr) — stored only if you arrive through a campaign link or from another website, and then it holds just that one value: the campaign tag or the referring site's name. It lets us see which channel brought someone who later joins the waitlist. If you arrive directly or from a search engine, nothing is stored. It is never shared, never linked to an advertising identifier, and never leaves our own systems.
All of it is first-party and stays in your browser until you clear it. You can remove it at any time through your browser's site-data settings, and the site will keep working.
Security
We protect data with HTTPS in transit, encryption of OAuth tokens at rest, row-level access controls, service-role separation, and least-privilege OAuth scopes. OAuth client secrets and token-encryption keys are not sent to the browser. No system is perfectly secure, but we work to keep your tokens and content safe and respond quickly to incidents.
International transfers
Your account records, clip metadata and encrypted tokens are stored in the European Union (Frankfurt, Germany). Clip processing runs in Switzerland, which holds an EU adequacy decision, so no additional safeguard is required for that leg.
Some providers process data in the United States — see the sub-processor list for exactly which, and what each receives. For those transfers we rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with the Swiss addendum recognised by the FDPIC, supplemented by the technical measures in section 09. Where a provider is certified under the EU–U.S. or Swiss–U.S. Data Privacy Framework, we may rely on that instead. You can request a copy of the safeguards we rely on by writing to privacy@clipsie.app.
EU representative
Clipsie is established in Switzerland. Where Art. 27 GDPR requires a controller outside the EU to designate a representative within it, we have not appointed one, and we would rather say so than leave the question unanswered. We will appoint one before we begin serving customers in the EU, and this section will name them when we do. Nothing about your rights changes in the meantime: you can exercise all of them directly with us at privacy@clipsie.app, and you can complain to your own supervisory authority as described in section 07.
Children’s privacy
Clipsie is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Changes
We may update this policy as the service evolves. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to you directly.
Contact
Questions or requests: privacy@clipsie.app, or use the contact form.
Copyright and takedown notices: dmca@clipsie.app (see our Terms of Service).
Provider identity and postal address: Impressum.