Skip to document

Legal document

Privacy policy

What data we collect, why, who it is shared with, how long it is kept and how to exercise your rights. Includes the platform-specific sections YouTube, TikTok and Meta require.

Last updated:

1. Who we are

ZClips (zclips.me) is a commercial AI-powered short-form video platform. This Privacy Policy describes what personal data ZClips collects, why, for how long, and what rights you have as a data subject.

Data controller: ZELIKA DESARROLLOS AUDIOVISUALES, S.L., NIF B16684763, registered at Calle Molino de Viento, 61, 35004 Las Palmas de Gran Canaria, España, trading as ZClips. Contact for data protection matters: legal@zclips.me.

ZClips operates as a public commercial service. By creating an account or using the Service you agree to the practices described in this Policy.

ZClips uses YouTube API Services. Several features — importing a YouTube video, connecting a YouTube channel, auto-clip, publishing to YouTube and the YouTube figures in the analytics dashboard — are built on them. Because of that, data Google receives is also governed by the Google Privacy Policy at https://www.google.com/policies/privacy. Section 9 sets out exactly which YouTube data we store, how to delete it, and how to revoke our access to it through your Google account.

2. Data we collect

We process the data necessary to operate the Service. Concretely:

  • Account data: email address, hashed password (if you sign in with email/password), OAuth provider identifier (if you use social sign-in), display name, avatar URL, account creation/update timestamps, email-verified flag. Stored in our Postgres database.
  • Session data: session tokens and timestamps used to keep you signed in.
  • Source video data: the video URLs you submit, files you upload, derived audio, transcripts, AI-selected segment timestamps and metadata.
  • Generated clip data: rendered MP4 clips, caption text, virality and engagement scores assigned by the AI, processing mode, caption template, language and other generation options.
  • Task data: task identifiers, status, progress events, error traces and timestamps.
  • Workspace data: if you create or join a workspace — workspace name, members, roles, monitored YouTube channels, auto-clip configuration, invite links (and the invitee email address if you send an email invite), audit-log entries, and any moderation records (warnings, sanctions, suspensions) applied to the workspace and your acknowledgement of them.
  • Account security data: if you enable two-factor authentication, the TOTP secret and backup/recovery codes (stored encrypted/hashed) and whether 2FA is enabled; if you use email one-time codes, the code is hashed, not stored in plain text. We also store a list of your active sign-in sessions (approximate device/browser, IP address and last-seen time) so you can review and revoke them from Settings.
  • Channel reference images: if you opt in, photos you upload (for example a face or logo) to guide AI-generated thumbnails for a specific channel you monitor. These are used only as visual references for that channel's thumbnail generation and are kept until you delete them — unlike the 7-day generated-thumbnail library, a reference photo does not expire automatically.
  • Music library data: audio files you upload for use in your clips, a content fingerprint used to detect duplicates, derived audio features (tempo, energy, loudness), and your region and rights-acknowledgement preferences.
  • Recordings data: video files you upload through the OBS/recording connector or as linked VODs, an identifier for the device/machine bound to your recording link, and any public share tokens you create for a recording. Storage duration and quota depend on your plan (see §17).
  • Third-party connection tokens: when you link TikTok, YouTube/Google, Facebook/Meta, Twitch, Kick or Discord, we store the OAuth access token, refresh token and the scopes you granted. Tokens are encrypted at rest using AES-GCM.
  • Third-party profile snapshots: minimal profile data returned by an integration so we can show which account is connected — provider id, username/handle, display name and avatar URL.
  • Publish history: identifiers and status of clips you chose to publish to a destination platform, plus error reasons returned by that platform's API.
  • Performance analytics data: metrics imported from destination platforms (views, likes, comments, shares, estimated reach) for clips you have published, and, if you separately authorize the YouTube monetary analytics scope, estimated revenue and CPM for your own YouTube videos. Stored in a time-series table (clip_metrics) and displayed in the in-app analytics dashboard.
  • Share link data: when you create a public share link for a clip, we generate a short token and record the clip it points to, its creation time, expiry time and access count. Share links do not require a visitor account.
  • Subscription and billing data: Stripe customer identifier, subscription identifier, plan, status, current period dates, token balance and token transaction history. We do not store full payment card numbers.
  • Operational logs: task status, queue progress, error traces, IP address and User-Agent of requests at the reverse-proxy layer. These may include user identifiers but not source video content.
  • Support data: messages and attachments you send via our in-app support system, including your email address and any information you voluntarily provide.
  • Community and feedback data: if you post in the in-app feedback forum (on the web or via our Discord bot), your display name, avatar and admin status (if applicable) are shown to other signed-in users. Votes are stored per user but shown to others only as an aggregate score.
  • Discord data: if you sign in with Discord or your workspace connects our Discord bot, we store your Discord user ID; for workspace-linked Discord channels, the bot may grant access based on the Discord IDs of workspace members and post task/upload notifications that mention your Discord ID.

3. How we use your data

We use the data above to:

  • authenticate you and keep you signed in, including via two-factor authentication if you enable it;
  • process source video into clips (download, transcription, segment selection, rendering, captioning, optional B-roll insertion);
  • store resulting clips so you can review, edit and re-export them;
  • when you explicitly request it for a specific clip, upload and publish the clip to your linked destination account (TikTok, YouTube, Facebook/Meta, Twitch, Kick);
  • if you enable it, periodically check connected YouTube channels for new uploads and auto-generate / optionally auto-publish clips;
  • if you opt in, use your uploaded reference photos, or a monitored channel's own past thumbnails/titles, as style references so AI-generated thumbnails and titles for that channel are more consistent;
  • store and let you manage music you upload to your library, and accept recordings sent through the OBS/recording connector or as linked VODs;
  • generate temporary public share links and serve the linked clip or recording to visitors within its validity period;
  • import and display performance metrics from destination platforms for clips you have published, including estimated revenue/CPM if you authorize that YouTube scope;
  • show which third-party accounts are linked and allow you to disconnect them;
  • operate workspaces — show workspace-scoped content to authorized members only;
  • operate the in-app feedback/community forum, including feedback submitted through our Discord bot, and moderate workspaces (warnings, suspensions) to enforce our Terms;
  • process payments, manage subscriptions and track token balances;
  • send transactional emails (sign-in confirmations, password resets, task completion, subscription updates, support replies);
  • respond to support requests;
  • diagnose errors, prevent abuse and operate the Service reliably.

What we do not do: we do not sell your personal data; we do not use it for behavioural advertising or profiling unrelated to the Service; we do not share it with data brokers; we do not use data obtained from third-party integrations (TikTok, YouTube/Google, Facebook/Meta, Twitch, Kick) to train machine learning models; and we do not use that data for any purpose beyond providing the specific feature you requested.

4. Legal basis (GDPR)

Where GDPR applies, our legal bases are:

  • Performance of a contract (Art. 6(1)(b)) — to operate your account, produce the clips you request, and process payments;
  • Consent (Art. 6(1)(a)) — for connecting external accounts (TikTok, YouTube/Google, Facebook/Meta, Twitch, Kick), enabling auto-clip / auto-publish, and optional analytics integrations. You can withdraw consent at any time;
  • Legitimate interest (Art. 6(1)(f)) — to keep the Service secure, prevent abuse and maintain operational logs;
  • Legal obligation (Art. 6(1)(c)) — to retain billing records as required by tax or accounting law.

5. Cookies and similar technologies

ZClips uses a small number of cookies and local storage items:

  • Session cookie: strictly necessary to keep you signed in. httpOnly, SameSite=Lax.
  • Language cookie (zclips.lang): stores your chosen interface language (en or es). Strictly necessary for locale routing.
  • Theme preference: light/dark/system, stored in local storage.
  • Analytics (only if enabled): see §6 below.

We do not use third-party advertising cookies or cross-site tracking cookies. No cookie consent banner is required for the strictly necessary cookies listed above.

6. Analytics

A deployment may optionally enable cookieless, privacy-friendly traffic analytics by setting the relevant environment variables. When enabled, the analytics provider collects aggregated, anonymized page-view information; we do not transmit personal data beyond the pseudo-identifier sent by the identity script for authenticated users. If those variables are not configured, no analytics script is loaded.

7. Third-party processors and recipients

To deliver the Service we transmit certain data to third parties acting as processors. Each operates under its own privacy policy:

  • TikTok (Login Kit, Content Posting API, Share Kit, Webhooks) — receives your generated clip file and publish parameters when you ask us to publish.
  • YouTube / Google (source ingestion, OAuth, YouTube Data API) — when you import a video by YouTube URL or connect your Google/YouTube account, we fetch the video and/or channel data from Google's services. Use of data received via Google APIs complies with Google API Services User Data Policy, including the Limited Use requirements.
  • Facebook / Meta (source ingestion, OAuth, Meta Graph API) — when you import a video from Facebook or connect your Meta account, we authenticate via Meta OAuth and may receive profile metadata and video content for processing and publishing. We request only the permissions necessary for the specific feature you enable and do not use Facebook/Meta data for any other purpose.
  • Twitch / Kick — when you import a video by URL, sign in, or connect these accounts, we authenticate via their OAuth and may receive channel/profile metadata.
  • Discord — used for "Sign in with Discord" (if enabled) and to power our optional community bot: workspace notification channels, task/upload alerts that mention your Discord ID, and a feedback command that writes into the same feedback forum described in §14.
  • Speech-to-text provider — receives the audio of your source video in order to transcribe it.
  • Language-model (LLM) provider — receives the transcript in order to identify candidate clip segments. It receives the transcript text, not the video.
  • Stock footage provider — receives the B-roll keywords derived from your transcript, and only if you enable the B-roll option. It receives no video, no audio and nothing that identifies you.
  • Stripe — payment processing and subscription management. Stripe processes payment card data under its own privacy policy; ZClips stores only the Stripe customer and subscription identifiers.
  • Transactional email provider — receives your e-mail address and the content of service messages we send you (verification, password reset, notifications).
  • Analytics provider — receives the usage events described in §6, and only if analytics is configured.
  • Hosting provider — operates the server infrastructure on which the Service runs, and therefore holds the data described in §2 at rest.

We do not provide your data to these providers for any purpose other than the specific service described above.

The entries above that are given as a category rather than a name are vendors whose identity is not itself information about you. If you want to know exactly which company sits behind any of them, write to legal@zclips.me and we will tell you — that is your right of access and we answer it.

8. TikTok data specifically

When you authorize ZClips through TikTok Login Kit, we receive only the data permitted by the scopes you grant. We store the OAuth refresh token (encrypted) and a minimal profile snapshot (open id, username, display name, avatar URL) so we can show which account is connected and attribute publishes. We do not request, store or use any other TikTok data. We do not use TikTok data for advertising, profiling, resale or training ML models — only for the publishing flow you initiate. When you disconnect TikTok from Settings we immediately revoke the grant with TikTok and delete the stored tokens and profile snapshot. When we receive a TikTok authorization.removed webhook — that is, when you revoked us from TikTok yourself — we delete them immediately; the grant is already gone at that point, so there is nothing left for us to revoke.

9. YouTube API Services and Google data specifically

ZClips uses YouTube API Services. The features that rely on them are: importing a video from a YouTube URL, connecting a YouTube channel or signing in with Google, auto-clip (polling a channel for new uploads), publishing a clip or long video to YouTube, setting a generated thumbnail on a video you published, and importing YouTube performance figures into the analytics dashboard.

Our use of data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements, and with the Google Privacy Policy. Specifically: we use data obtained via Google APIs only to provide or improve user-facing features in ZClips; we do not transfer this data to third parties except as necessary to provide the Service; we do not use this data for serving advertising; and we do not allow humans to read this data unless required for security or legal compliance, or with your explicit consent. We store only the OAuth tokens and minimal profile/channel data necessary to identify the connected account and to operate the auto-clip and publishing features you enable.

Scopes we request, and what each one is used for. ZClips asks for YouTube access at two distinct moments, and only for the scopes the features you enable actually need:

  • https://www.googleapis.com/auth/youtube.readonly — requested when you sign in with Google, and again when you connect a channel. We call channels.list?mine=true to identify which YouTube channel the connection belongs to, so we can display it in the interface and automatically link it to your account. We also use it to read the public metadata of your own uploads (title, publication date, thumbnail URL) for the channels you choose to monitor for auto-clip.
  • https://www.googleapis.com/auth/youtube.upload — requested only when you explicitly connect a YouTube channel as a publishing destination. Used for videos.insert, to upload to your own channel the clips and videos you choose to publish. We never publish to a channel you have not connected for that purpose.
  • https://www.googleapis.com/auth/youtube.force-ssl — requested with that same publishing connection. Used for thumbnails.set, to attach a cover image to a video ZClips has just uploaded, and for videos.update, to correct the title, description or tags of a video ZClips published. The upload scope on its own does not authorize editing an existing video, which is why this scope is necessary. We use it only on videos published through ZClips.
  • https://www.googleapis.com/auth/yt-analytics.readonly — requested with the publishing connection. Used to read the performance of your own videos (views, watch time, average view duration, audience retention) and show it in the ZClips analytics dashboard, so you can compare how the clips we generated performed.
  • https://www.googleapis.com/auth/yt-analytics-monetary.readonly — requested with the publishing connection. Used only to display estimated revenue and CPM for your own videos in that same dashboard. It never gates any other feature, the figures are shown back to you alone, and if you do not grant it the rest of the dashboard keeps working.

Signing in with Google requests read-only access only; the publishing and analytics scopes are requested separately, at the moment you connect a channel for auto-clip or auto-upload. You can disconnect from ZClips Settings at any time, which immediately revokes and deletes the stored tokens, and you can also revoke access directly from your Google account permissions page.

Deleting stored YouTube data, and revoking our access. You have three independent routes and can use any of them at any time:

  • Disconnect inside ZClips. Settings → Connections for a personal connection, or your workspace settings for a workspace publishing connection. On disconnect we immediately revoke and delete the stored OAuth access and refresh tokens and the profile/channel snapshot for that connection.
  • Revoke from your Google account. Open the Google security settings page at https://myaccount.google.com/connections?filters=3,4&hl=en, select ZClips and remove its access. This works even if you can no longer sign in to ZClips. It stops any further access on Google's side; use one of the other two routes to also erase what we had already stored.
  • Delete everything. Request full account deletion as described on our Data deletion page. This removes your account together with all YouTube-derived data we hold: tokens, profile and channel snapshots, monitored-channel records, imported source video, transcripts, generated clips and publish history. We verify the request and confirm by email within 30 days.

Deleting a task, a clip or a monitored channel from within the app deletes the corresponding YouTube-derived records at that moment, without waiting for account deletion. Beyond these routes we retain only what §17 lists, plus billing records we are legally required to keep — which contain no YouTube data.

10. Discord data specifically

If you use "Sign in with Discord", we receive your Discord user ID and the minimal profile fields Discord returns (username, avatar) to create or match your account. If your workspace enables our Discord bot, we create a private Discord channel for that workspace, grant access to it based on the Discord IDs of workspace members, and post task/upload notifications that mention your Discord ID. If you use the bot's feedback command, the title and message you submit are written directly into the same feedback forum described in §14, together with your Discord ID and display name. We do not use Discord data for advertising or profiling, and we only request the scopes needed for sign-in and for the bot features your workspace enables.

11. Facebook / Meta data specifically

When you connect your Facebook/Meta account, we request only the permissions required for the specific features you choose to enable (source ingestion or publishing). We store the OAuth access/refresh tokens (encrypted) and a minimal profile snapshot. We do not use this data for advertising, profiling, or training ML models, and we do not share it with third parties beyond what is necessary to operate the Service. You can disconnect your Facebook/Meta account at any time from Settings, which immediately revokes and deletes the stored tokens and profile snapshot.

12. Source platforms and additional sign-in providers (Twitch, Kick)

If you import a video by URL we fetch the public video for processing; we do not keep authentication state for that platform unless you explicitly connect it or use it to sign in. If you connect a platform or sign in with it, we store the OAuth tokens encrypted and use them only for the resources you authorized. You can disconnect at any time from Settings.

13. Workspaces, shared data and personal workspace

If you create or join a workspace, the workspace's tasks, generated clips, monitored channels, auto-clip configuration and member list are visible to all members of that workspace according to their role. Removing a member revokes their access to that workspace's content. Deleting a workspace deletes the workspace record and workspace-scoped content.

Workspace owners can invite members by email or by generating a shareable invite link; we store the invitee email address (for email invites) or the link's token, role, expiry and usage count (for link invites) until the invite is used, revoked or expires. Actions taken within a workspace (role changes, invites, moderation) are recorded in an audit log tied to the workspace.

Platform administrators may apply moderation actions to a workspace (warning, sanction, suspension or block) for violations of our Terms. Moderation records include the acting admin, the action and an internal note, and are shown to workspace members as a one-time acknowledgement; administrators can remove moderation records.

Each user also has a personal workspace (a private workspace-of-one). Data in the personal workspace is visible only to that user.

14. Feedback forum and community visibility

ZClips includes an in-app feedback forum, reachable from the web app and, if your workspace enables it, from our Discord bot. Threads and replies you post show your display name, avatar and whether you are a ZClips administrator to every other signed-in user — this content is not private between you and support staff. Your vote on a thread is stored against your account but shown to other users only as part of an aggregate score. Posts submitted through Discord are stored in the same forum and carry your Discord ID and display name.

15. Auto-clip, channel monitoring and AI reference images

If you enable auto-clip on a YouTube channel, the worker polls that channel's public uploads feed on a schedule using the YouTube Data API. We store: the channel id, the last poll timestamp, the most recent video ids seen, and any clips generated from those videos. You can disable auto-clip at any time, which stops the polling.

If you opt in per channel, we may reuse that same channel's own public video thumbnails and titles (already collected for detection) as style references for AI-generated thumbnails and titles on that channel — never another channel's or another workspace's content. Reusing past thumbnails as a style reference is off by default; reusing past titles is on by default. You can change either at any time in your channel settings.

If you additionally upload reference photos (for example a face or logo) for a channel, those images are sent to the AI image model only to guide thumbnails for that channel and are kept until you remove them — unlike our 7-day generated-thumbnail library, a reference photo does not expire automatically because its purpose (recognizable identity) does not go stale.

16. Billing data

We store the following billing-related data: Stripe customer id, subscription id, current plan and status, current billing period and renewal date, token balance and token transaction log. We do not store full payment card numbers. Refer to Stripe's Privacy Policy for how Stripe handles payment instrument data.

17. Retention

  • Account data: kept while your account exists. Deleted on account-deletion request, except where retention is required by law.
  • Source video, transcript, generated clips: kept until you delete the task, or until the configured retention window of the deployment expires (whichever is sooner). Worker scratch files are removed shortly after a task completes.
  • Recordings (OBS/VOD uploads): retention and storage quota depend on your plan (Free 48h/10GB, Pro 72h/200GB, Ultimate 168h/500GB at the time of writing); a scheduled job deletes expired recordings and their thumbnails automatically.
  • Music library uploads: kept until you delete them from your library.
  • Channel reference images: kept until you delete them; they do not expire automatically.
  • Two-factor authentication data: kept until you disable 2FA on your account, or your account is deleted.
  • Third-party tokens and profile snapshots: kept until you disconnect the integration; deleted immediately upon disconnect or upon receipt of a revocation/deauthorization webhook.
  • Workspace moderation and audit records: kept for the life of the workspace as part of its administrative history; administrators can remove individual moderation records.
  • Billing records: retained as required by applicable tax/accounting law (typically up to 6 years in Spain under Spanish tax law), even after account deletion.
  • Operational logs: kept up to 30 days for debugging and security purposes, then rotated out.
  • Support data: kept for as long as necessary to resolve your request and for the applicable legal limitation period thereafter.

18. Security

Third-party secrets and tokens are encrypted at rest with AES-GCM. Account passwords are hashed using industry-standard algorithms. Two-factor backup codes and email one-time codes are likewise stored hashed, never in plain text. Internal calls between the frontend and backend are signed with HMAC. You can review and revoke your active sign-in sessions from Settings. We make reasonable technical and organizational efforts to protect your data, but no system is perfectly secure. In the event of a personal data breach likely to result in high risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by GDPR.

19. Your rights

Subject to applicable law (including GDPR where it applies), you have the right to: access, correct, export, restrict, object to the processing of, or delete your personal data; withdraw any consent you have given; and lodge a complaint with a supervisory authority. To exercise any right, write to legal@zclips.me. We will respond within 30 days. You may also lodge a complaint with the Spanish data protection authority: Agencia Española de Protección de Datos (aepd.es).

You can disconnect any third-party integration at any time from the Settings page; doing so revokes the stored tokens. You can request full account deletion by email at the address above.

20. Children

ZClips is not directed at children under 16 and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

21. International data transfers

Some third-party processors may be located outside the European Economic Area (for example, Google, Meta, Discord, Stripe and the service providers listed by category in §7 may process data in the United States or other countries). Where required, we rely on lawful transfer mechanisms such as the European Commission's Standard Contractual Clauses or an adequacy decision to ensure your data receives an equivalent level of protection.

22. Changes to this policy

We may update this policy from time to time. The "Last updated" date above reflects the most recent revision. Material changes will be communicated by email or in-app notice at least 30 days before they take effect for users with active paid subscriptions.

23. Contact

Privacy questions, deletion requests and any other data-protection enquiries: legal@zclips.me.

See also: Terms of Service · Legal Notice.

Last updated: 2026-08-17.

Privacy policy · ZClips