Privacy Policy
Last updated: 5 May 2026
Clip & Post ("we", "us", or "our") is operated by CG Industries Ltd, a company registered in England and Wales. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use the Clip & Post platform and services ("Service").
We are committed to protecting your privacy and handling your data transparently. This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (as provided during registration)
- Password (stored in hashed form — we never store plain-text passwords)
Connected Social Media Account Data
When you connect social media accounts via OAuth, we receive and store:
- TikTok: User ID, display name, profile picture URL, access and refresh tokens. When publishing, we access the Content Posting API to upload videos on your behalf. We also access basic video analytics (view counts, likes, comments, shares) via the Display API to provide performance insights.
- Instagram: User ID, username, access token. We use the Instagram Graph API to publish Reels and access post-level engagement metrics.
- YouTube: Channel ID, channel name, access and refresh tokens. We use the YouTube Data API to upload Shorts and retrieve video analytics.
- Facebook: Page ID, page name, access token. We use the Facebook Graph API to publish videos and access page-level insights.
Access tokens are encrypted at rest using industry-standard encryption (Fernet/AES-256). We do not store your social media passwords. You may revoke access at any time by disconnecting your account in your settings or through the respective platform's app permissions.
Content Data
When you upload or link video content, we temporarily process and store:
- Video files (for AI analysis and clip extraction)
- Generated clips (retained until published or deleted by you)
- Metadata (titles, descriptions, scheduling preferences)
Usage Data
We automatically collect:
- Log data (IP address, browser type, access times)
- Feature usage patterns (to improve the Service)
- Error reports and performance data
2. How We Use Your Information
| Purpose | Legal Basis (UK GDPR) |
|---|---|
| Providing and operating the Service (clipping, scheduling, publishing) | Contract performance |
| Publishing content to your connected social media accounts | Contract performance / Consent |
| Displaying analytics from your connected accounts | Contract performance |
| Sending transactional emails (account confirmation, publish notifications) | Contract performance |
| Improving the Service and AI clip detection | Legitimate interest |
| Ensuring security and preventing abuse | Legitimate interest |
3. Data Sharing
We do not sell your personal data. We share data only in the following circumstances:
- Social media platforms: When you instruct us to publish content, we transmit your video content and associated metadata to the relevant platform (TikTok, Instagram, YouTube, Facebook) via their official APIs.
- Service providers: We use trusted third-party services for hosting, analytics, and email delivery. These providers process data on our behalf under data processing agreements.
- Legal requirements: We may disclose data if required by law, regulation, or valid legal process.
4. Data Retention
- Account data: Retained for as long as your account is active. Deleted within 30 days of account deletion.
- Video content: Source videos and generated clips are deleted within 90 days of processing, or upon your request, whichever is sooner.
- Access tokens: Retained while your social media account is connected. Immediately deleted upon disconnection.
- Analytics data: Aggregated performance data may be retained for up to 12 months for your dashboard. Personal identifiers are removed from archived data.
- Usage logs: Retained for up to 12 months for security and debugging purposes.
5. Data Security
We implement appropriate technical and organisational measures to protect your data:
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Social media access tokens are encrypted using Fernet symmetric encryption with keys stored in secure key management
- We conduct regular security reviews of our codebase and infrastructure
- Access to production data is restricted and audited
6. Your Rights
Under the UK GDPR, you have the right to:
- Access your personal data and receive a copy
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict processing of your data
- Port your data to another service
- Object to processing based on legitimate interest
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. TikTok-Specific Disclosures
When you connect your TikTok account to Clip & Post:
- We access your TikTok data solely to provide the Service (publishing clips and retrieving analytics)
- We do not use TikTok user data for advertising, profiling, or any purpose beyond operating the Service on your behalf
- TikTok data is not shared with any third parties beyond what is necessary to operate the Service
- You can revoke Clip & Post's access to your TikTok account at any time through your TikTok app settings (Settings → Security → Manage app permissions) or by disconnecting within Clip & Post
- Upon disconnection or account deletion, all TikTok-related data (tokens, cached analytics) is permanently deleted within 24 hours
8. Cookies
We use strictly necessary cookies for authentication and session management. We do not use advertising or tracking cookies. No third-party tracking scripts are loaded on our site.
9. International Transfers
Your data is primarily processed and stored in the United Kingdom. Where data is transferred outside the UK (e.g., to social media platform APIs), we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
10. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we will also notify you via email.
12. Contact Us
If you have questions about this Privacy Policy or our data practices:
- Email: [email protected]
- Data Controller: CG Industries Ltd
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.