Privacy Policy
Last updated 11 September 2026
Who is responsible for your information
Edit Clips operates Clyptaro and is responsible for the connected-account information described in this policy. Our contact address is 82, Unit A James Carter Road, Bury St. Edmunds, United Kingdom, IP28 7DE. For privacy questions or requests, email hello@clyptaro.com.
This policy explains how Clyptaro handles information when you connect a social account and publish through it, including information processed through YouTube API Services and TikTok Login Kit and Content Posting API, Meta's Instagram and Facebook APIs, the X API, and Snapchat's Public Profile API where that connection is enabled. Google's handling of information is described in the Google Privacy Policy.
Information we handle
When you connect an account we handle your platform account identifier, display name, granted scopes, short-lived authorization codes, and OAuth access and refresh tokens, plus the media and metadata you choose to publish. For YouTube this includes the finished video, title, description, tags, privacy setting, and the returned video identifier. For TikTok, this includes the immutable account identifier, nickname, creator posting capabilities, caption, privacy and disclosure choices, rights-confirmation time and version, Direct Post identifier, processing status, and any public post identifier TikTok later provides. For Instagram and Facebook, this includes the professional-account or Page identifier, display information, Reel caption or description, upload/container identifiers, processing status, and permalink. For X, this includes the account identifier, username, video media identifier, post text, processing status, and returned post identifier. For Snapchat, this includes authorized Public Profile identifiers, usernames, display names and profile images, the video, Spotlight description, language and profile-placement choice, upload and Spotlight identifiers, and submission and moderation status.
How we use it
Information is used only to authenticate the account, upload the content you request to the connected channel, check publishing status, and show which account is connected. TikTok access is limited to basic profile information and Direct Post; Clyptaro does not request draft-upload permission. Clyptaro does not use connected-platform data for advertising, profiling, or sale.
Data protection and security
We protect personal information, including Google and YouTube user data, with safeguards designed to prevent unauthorized access, disclosure, alteration and loss.
Encryption in transit. Requests between Clyptaro and Google's OAuth and YouTube APIs use HTTPS/TLS encryption. You can access Clyptaro over an encrypted connection at https://clyptaro.com.
Encrypted credentials. Google and other connected-platform access and refresh tokens are encrypted at rest using AES-256-GCM and a separate encryption key for each connected account. The key that protects those account keys is kept in server-side secret configuration, separately from the database. Tokens are used on our servers to act on your behalf and are not exposed in the account-management interface.
Access controls. Authenticated sessions, workspace membership checks and database row-level access policies restrict access to connected-account information. Operator access is limited to service operation, support, security and handling lawful requests.
Private media. Private video files are kept in access-controlled storage. Access to private clip media uses signed, expiring links restricted to the requested files.
Storage and retention
You can disconnect an account at any time, which deletes its stored tokens from Clyptaro. Provider-specific authorization and revocation options are described below. Publishing records are retained so we can show status and performance until you delete them or close your account.
TikTok posting capability snapshots and rights confirmations are retained with each delivery for security, billing, and audit purposes.
Sharing
Information is sent to Google or another connected platform only as needed to perform an action you authorize. Clyptaro does not sell personal information or YouTube API data, use it for advertising, or use connected-platform data to build advertising profiles.
We use service providers to operate Clyptaro: Cloudflare for web delivery, network services and private media storage; Supabase for the database and authentication; and Hetzner for trusted processing and publishing infrastructure. These providers process information on our behalf as needed to provide their services. Access by our operators is limited to service operation, support, security and handling lawful requests.
International processing
Our production database is hosted in Germany. Network processing and provider support can involve other countries, including the United States and Singapore; choosing a database region does not restrict every provider access location. Where an international transfer requires safeguards, the applicable provider data-processing terms and transfer safeguards govern that processing. You can contact us for information about the providers and safeguards relevant to your data.
Requests from public authorities
We verify the requester and review the legal basis and scope before disclosing information to a public authority. We seek clarification or challenge requests we consider unlawful or excessive, and obtain qualified advice where needed. Any disclosure is limited to the information necessary for the reviewed request. We keep a restricted record of the request, legal reasoning, people involved, decision and response, and notify affected users where legally permitted. These procedures took effect on 10 September 2026.
Revocation and deletion
Disconnecting Snapchat removes the selected Public Profile's encrypted tokens from Clyptaro. To revoke the Snapchat authorization itself, remove Clyptaro in Snapchat Manage Apps. Removing the app there can affect all Public Profiles connected through that authorization. Disconnecting does not delete Spotlights already submitted to Snapchat; manage those in Snapchat. Snap handles information under its Privacy Policy.
You may revoke Clyptaro's Google access from your Google Account connections. You may also request deletion of stored credentials or records by emailing the address below.
TikTok access can be removed from TikTok's connected-app settings or by disconnecting the exact TikTok account in Clyptaro. Clyptaro then asks TikTok to revoke that grant and removes its encrypted tokens. TikTok separately handles information under the TikTok Privacy Policy.
Instagram and Facebook access can be removed from Meta's Apps and Websites settings or by disconnecting the account or Page in Clyptaro. X access can be removed from X's connected apps settings or by disconnecting the X account in Clyptaro. Clyptaro removes the encrypted credentials it no longer needs and requests provider revocation when the provider supports revoking that grant at the selected account boundary. Meta and X separately handle information under their own privacy policies.
Contact
Privacy requests may be sent to hello@clyptaro.com.