Privacy Policy

Last updated: March 2026

1. Introduction

Clipper Lab ("we", "us", "our") respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy explains what data we collect, why we collect it, and how we handle it when you use our AI-powered video clipping service.

2. Data We Collect

Account information: When you create an account, we collect your email address and a hashed password. If you enable two-factor authentication, we store the encrypted TOTP secret.

Usage data: We track which features you use, the number of projects and clips you create, and general usage patterns to improve the service.

Payment information: Payments are processed by LemonSqueezy. We store your subscription status and invoice history but never store credit card numbers or full payment details.

Video URLs: We store the YouTube URLs you submit for processing and cache video metadata to avoid re-downloading the same content.

3. Data We Don't Collect

We do not collect or store your browsing history outside our platform, information from your social media accounts beyond what is needed for upload features, or any data from videos you do not explicitly submit for processing.

4. Video Processing

Videos you submit are downloaded temporarily for processing. Transcription is performed locally using OpenAI Whisper — your audio data is not sent to any external transcription service. Generated clips are stored on our servers and made available for download. Video cache and clip files may be periodically cleaned up based on your plan's storage limits.

5. Third-Party Services

We use the following third-party services:

  • Supabase — Database hosting, authentication, and file storage
  • Google Gemini API — AI analysis of video transcripts to identify clip-worthy segments (only text transcripts are sent, not audio or video)
  • OpenAI Whisper — Runs locally on our servers for speech-to-text transcription; no data leaves our infrastructure
  • LemonSqueezy — Payment processing and subscription management

6. Google User Data

Clipper Lab's use of Google API Services (YouTube Data API v3) is limited to enabling you to upload your generated clips directly to your own YouTube channel. We request the following Google OAuth scopes:

  • youtube.upload — to upload video files to your YouTube channel on your behalf
  • youtube.readonly — to read your channel details (channel name, ID) so we can confirm the upload destination

How we use this data: Your Google OAuth access token and refresh token are stored securely in encrypted cookies on your device and used solely to make YouTube API requests on your behalf when you explicitly trigger an upload from within Clipper Lab.

Sharing, transfer, and disclosure: We do not share, sell, transfer, or disclose your Google user data (including OAuth tokens, channel information, or any data obtained via Google APIs) to any third party. Your data is used exclusively to provide the YouTube upload feature within Clipper Lab and for no other purpose.

Revocation: You can disconnect your YouTube account at any time from the Settings page. This will delete your stored OAuth tokens from our system. You can also revoke access directly from your Google Account permissions.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Data Security & Protection Mechanisms

We take the security of your data seriously and apply the following technical and organisational safeguards:

  • Encryption in transit: All data exchanged between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). OAuth tokens received from Google are transmitted exclusively over encrypted connections.
  • Encryption at rest: Sensitive data stored in our database — including Google OAuth access tokens and refresh tokens — is stored in Supabase, which encrypts database volumes at rest using AES-256. Tokens stored in browser cookies are protected with HttpOnly and Secure flags to prevent client-side access.
  • Access controls: Database access is restricted via Row Level Security (RLS) policies so that each user can only access their own data. Server-side API routes require an authenticated session before any Google API call is made. OAuth tokens are never exposed to the client-side JavaScript bundle.
  • Minimal retention: Google OAuth tokens are only retained for as long as you keep your YouTube account connected. Disconnecting your account from the Settings page immediately deletes stored tokens from our system.
  • No unnecessary data storage: We do not log, cache, or persist any YouTube video data, channel metadata, or subscriber information beyond what is transiently required to complete an upload request.

These protections apply specifically to sensitive data including Google user data obtained via OAuth. If you believe your data has been compromised, please contact us immediately at hi@baguspramajaya.com.

8. Storage & Retention

Account data is retained for as long as your account is active. Processed video files and clips are stored according to your plan's storage limits. If you delete your account, all associated data — including clips, job history, and personal information — will be permanently deleted within 30 days.

9. Cookies

We use essential cookies to maintain your authenticated session. We use a localStorage entry to remember your theme preference (light or dark mode). We do not use tracking cookies or third-party analytics cookies.

10. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and all associated data
  • Export your data in a portable format
  • Withdraw consent at any time by deleting your account

To exercise any of these rights, contact us at the email address below.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notice. The "Last updated" date at the top of this page indicates when the policy was last revised.

12. Contact

If you have questions or concerns about this Privacy Policy, contact us at hi@baguspramajaya.com

Clipper Lab
© 2026 Clipper Lab. All rights reserved.