Privacy policy
Your content and account data, explained.
This policy describes the information ClipHabit needs to schedule and publish your TikTok posts, how long it is kept, and the choices you have.
Effective date: September 25, 2026. Controller: [[LEGAL_ENTITY]], [[ADDRESS]]. Contact: hello@cliphabit.com.
What we collect
- Account data: your email address, login records, workspace membership, plan, and account settings.
- TikTok connection: account identifier, nickname, avatar, OAuth access and refresh tokens, and permissions you grant through TikTok Login Kit. We do not collect your TikTok password.
- Content and schedule: uploaded videos and photos, captions, hashtags, templates, schedule, publishing choices, AI-generated content flag, client approval decisions, and post status. If you use the video builder, this includes scene text and the URLs of images, clips, or audio you supply.
- Performance data: TikTok video metrics, including views and publication time, used for queue history, best-time suggestions, and evergreen sorting on eligible plans.
- Billing and support: subscription status, Stripe customer and payment identifiers, invoices, and messages you send to support. Stripe handles payment card details; ClipHabit does not store full card numbers.
- Technical data: IP address, browser and device information, security and error logs needed to operate and protect the service.
Why we use it
We use account, TikTok, media, and scheduling data to provide the service you request, including OAuth connection, queue management, direct publishing or sending to TikTok drafts, video rendering, account alerts, billing, and support. We use necessary technical data for security, reliability, and fraud prevention. We use payment records for accounting and legal obligations. Where required, we request consent for optional analytics.
TikTok and AI assistant connections
When you connect TikTok, TikTok provides the data permitted by the scopes you approve. ClipHabit sends your selected media and settings to TikTok through its official Content Posting API. TikTok handles data under its own privacy terms. If you connect an AI assistant through MCP, that client can receive data and perform the tools you authorize. Review the assistant provider's privacy terms before connecting. Posts created through MCP wait for your approval in ClipHabit before scheduling.
Video builder processing
If you use the video builder through an AI assistant or API, ClipHabit downloads the images, clips, and optional audio from the URLs you provide. We process those files and your scene text on our servers to validate the media, create previews, and render a vertical video with ffmpeg. The resulting video is stored as ClipHabit media and marked AI-generated by default. Your assistant provider may also process the instructions and content you share with it under its own privacy terms.
Storage and retention
The ClipHabit app and database run on our Hetzner Cloud server in Nuremberg, Germany. Media storage uses S3-compatible storage on Hetzner or, if enabled, Cloudflare R2. Uploaded media stays available while needed for your queue. ClipHabit deletes media files from its storage 30 days after publication. Unpublished media remains until you remove it or delete your account. Account and workspace data remain while your account is active. When you delete your account in the app, we delete associated service data, subject to records we must retain for tax, payment disputes, security, or other legal obligations. Such records are kept only for the applicable required period. Backup copies may take additional time to expire. TikTok may retain content published on its platform under its own rules.
Service providers and transfers
Hetzner Online GmbH hosts the app and database in Germany and may host media storage. Cloudflare Pages hosts the static website; Cloudflare R2 may host media storage if enabled. Stripe processes subscription payments and billing. Resend delivers sign-in, queue, and failure emails. TikTok provides account authorization, publishing, and metrics. Plausible may provide optional cookieless website analytics if enabled. Media validation, previews, and video builder rendering run on our server, using ffmpeg for rendering. These providers process data only for the relevant service, subject to their own terms and locations. Data may be processed outside the EEA or UK. Where required, we use applicable adequacy decisions or safeguards such as Standard Contractual Clauses. Contact us for details of the safeguards in use.
Cookies and analytics
The public website does not use advertising cookies. If enabled, Plausible provides cookieless aggregate analytics without cross-site tracking. The ClipHabit app and Stripe Checkout may use essential storage or cookies needed for login, security, and billing. See their privacy notices for their own processing.
Your rights and choices
You can disconnect TikTok, cancel billing through Stripe Customer Portal, and delete your ClipHabit account and data from your account settings. You can also email hello@cliphabit.com to request access, correction, deletion, export, or restriction of personal data, or to object to certain processing. EEA and UK users may lodge a complaint with their data protection authority. California residents may request to know, access, correct, or delete personal information, and may exercise any applicable opt-out rights. We do not sell personal information or share it for cross-context behavioral advertising. We will not discriminate against you for exercising privacy rights. We may need to verify your request and may retain information where law permits.
Children and changes
ClipHabit is intended for adults and businesses, not children under 18. If you believe a child provided personal data, contact us. We may update this policy and will post the revised version with a new effective date; material changes will be communicated through the service or email when appropriate.
Contact
[[LEGAL_ENTITY]], [[ADDRESS]]. Email hello@cliphabit.com.