Privacy Policy
Version: September 2026
This document is published in English for all languages. The English text is the authoritative version. Your statutory rights under the mandatory law of your country of residence are unaffected.
This Privacy Policy explains how Clip processes personal data when you visit our website, create an account and use the Clip platform (the “Service”). It is written to meet the transparency requirements of the General Data Protection Regulation (GDPR).
Where you use the Service to process personal data contained in your own content, you act as controller and Clip acts as processor on your behalf. That relationship is governed by our Data Processing Agreement, which forms part of the agreement between us.
1. Who is responsible
The controller for the processing described in this policy is:
- Clip
- Vossiusstraat 20-2
- 1071 AD Amsterdam
- The Netherlands
- Chamber of Commerce (KvK): 81707169
- VAT: NL003597297B90
We have not appointed a Data Protection Officer; we are not required to do so. You can reach us about any privacy question through the contact options published on our website, and we will route your request internally.
2. What personal data we process
We process the following categories of data:
- Account data — email address, authentication identifiers, password hashes held by our authentication provider, the display name you choose, your workspace and project ownership, and your language preference.
- Customer Content — prompts, briefs, uploaded images, audio, video and reference material, generated images, video scenes, voice-over, captions, transcripts and finished exports, together with the project, series and scene structure around them. This content may contain personal data if you put it there.
- Usage and product data — the screens and actions you use, generation jobs and their parameters, model and provider routing decisions, credit reservations and charges, job states, retries and failures.
- Technical and security data — IP address, browser and device information, timestamps, request and error logs, rate-limiting counters and abuse signals.
- Support, feedback and requests — messages you send us, problem reports, feature feedback, and data export or deletion requests you raise in the product.
- Billing data — plan, credit balance and transaction records. Card details are handled by the payment provider and are not stored by Clip.
- Legal records — which version of the Terms & Conditions and Privacy Policy your account accepted, when, and from which browser user agent.
3. Why we process it, and on what legal basis
- To provide the Service — creating and running your account, generating, storing and delivering Output. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To meter and bill usage — credit reservation, charging, refunds and plan enforcement. Legal basis: performance of a contract, and legal obligation for invoicing and tax records (Art. 6(1)(b) and (c)).
- To keep the Service secure and prevent abuse — rate limiting, fraud and abuse detection, spend caps, logging and incident investigation. Legal basis: legitimate interests in protecting the Service, our users and ourselves (Art. 6(1)(f)).
- To improve and debug the Service — diagnosing errors, monitoring reliability, understanding which features are used. Legal basis: legitimate interests (Art. 6(1)(f)).
- To communicate with you — service notices, responses to support and feedback, and messages required for your account. Legal basis: performance of a contract and legitimate interests.
- To comply with legal obligations — accounting, responding to lawful requests, handling data subject rights. Legal basis: legal obligation (Art. 6(1)(c)).
4. AI providers and transmission of content
Generating Output requires sending your prompts, reference material and, depending on the step, your uploaded or previously generated media to third-party AI and media providers. This transmission is necessary to deliver the Service you request; without it no Output can be produced.
We select providers on the basis of capability, cost and their published data handling terms, and we pass only what the requested step needs. Providers process the data as our processors or sub-processors for the purpose of returning the requested Output, subject to their own terms. Some providers may retain content briefly for abuse monitoring under their own policies.
Do not submit content you are not permitted to send to a third-party processor, and do not submit special categories of personal data, government identifiers, or the personal data of children, unless you have a lawful basis and appropriate safeguards.
5. We do not sell your data, and we do not train on your content
We do not sell personal data and we do not share it for cross-context behavioural advertising.
We do not train our own generative models on Customer Content, and we do not supply Customer Content to third parties for the purpose of training their models, without your separate explicit permission. Content is sent to AI providers only to execute the generation you requested.
6. Storage of your media
Uploaded and generated media are stored in private storage. Access is scoped to the owning account and workspace, enforced on the server, and delivered through short-lived signed links. Media is not published to a permanent public address by the platform. If you choose to distribute Output to a connected third-party platform, that platform's own terms and visibility settings then apply.
7. Who receives personal data
We share personal data with categories of recipients that are necessary to run the Service:
- Cloud hosting, database, authentication and storage infrastructure.
- AI model and media processing providers for generation, transcription, voice and rendering.
- Rendering and export infrastructure.
- Payment and billing providers.
- Publishing platforms you explicitly connect, for content you choose to publish.
- Email and operational communication providers.
- Professional advisers and authorities where required by law.
We can provide the current list of the specific processors we use on request through the contact options on our website.
8. International transfers
Some providers process data outside the European Economic Area, including in the United States. Where that happens, we rely on the European Commission's Standard Contractual Clauses, an adequacy decision, or another transfer mechanism permitted by Chapter V GDPR, as offered by the relevant provider. You can ask us which mechanism applies to a particular provider.
9. How long we keep data
- Account data — for as long as your account exists, and for a short wind-down period afterwards.
- Customer Content and Output — until you delete it, or until your account is deleted, subject to short backup retention.
- Usage, job and credit records — retained while needed for billing accuracy, dispute handling and capacity planning.
- Security and abuse logs — kept for a limited period proportionate to the security purpose, and longer where an incident, fraud investigation or legal claim requires it.
- Invoices and accounting records — kept for the statutory retention period under Dutch law, currently seven years.
- Legal acceptance records — kept for as long as needed to evidence the agreement, and afterwards for the limitation period of potential claims.
10. Security
We apply measures appropriate to the risk, including encryption in transit, private-by-default media storage with server-enforced ownership checks and expiring signed access, row-level access control in the database, scoped server-side credentials that are never exposed to the browser, rate limiting, spend caps and audit logging of privileged actions.
No service can be guaranteed secure. We hold no security certification and claim none; we do not currently publish an external audit report. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected users.
12. Automated decision-making
The Service makes automated technical decisions such as which model to route a generation to, and automated abuse and rate-limit checks that can temporarily block a request. These do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. Decisions to suspend or terminate an account for substantiated abuse involve human review.
13. Your rights
Subject to the conditions in the GDPR, you have the right to:
- Access the personal data we hold about you and receive a copy.
- Have inaccurate data corrected.
- Have data erased, where one of the grounds in Article 17 applies.
- Have processing restricted, or object to processing based on our legitimate interests.
- Receive data you provided in a portable format.
- Withdraw consent, where processing is based on consent, without affecting past processing.
You can raise a data export or deletion request directly in the product, from your account settings. We respond within one month, extendable by two further months for complex requests, and we will tell you if we extend. We may need to verify your identity, and we may retain data where a legal obligation or the establishment or defence of legal claims requires it.
14. Complaints
If you believe we process your data unlawfully, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens — or with the authority in the EU country where you live or work, or where the alleged infringement took place.
15. Children
The Service is not directed to children and accounts are for users aged 18 or over. We do not knowingly process the personal data of children through account creation. If you believe a child has provided personal data to us, contact us and we will delete it.
16. Changes to this policy
This policy is version September 2026. We may update it as the Service changes. Material changes will be announced in the product or by email before they take effect, and the version stamp above will change. Continuing to use the Service after a change takes effect means the updated policy applies to you, without prejudice to any consent that must be collected separately.