Zum Inhalt springen

ClipDraft ClipDraft

Privacy Policy

Overview of data processing, retention periods, legal bases, and your rights.

Last updated: 2026-04-09 Contact: ttposter@gmx.de

1. Controller

Controller under GDPR: Julius Knippel
Address: Zum Kreuzbaum 29, 54413 Gusenburg, Germany
E-Mail: ttposter@gmx.de

2. Purpose of Website and Tool

  • Provide public information pages including Terms/Privacy.
  • Provide the tool for prompt generation and own video uploads.
  • Optional: connect a TikTok account and export videos as TikTok drafts (Inbox Draft).
  • Optional: browser push notifications when a video has finished generating (only with explicit consent).
  • Provide free Creator Tools (Hashtag Generator, Caption Writer, Script Writer, Bio Generator, Video Ideas Generator) — publicly accessible, no login required.
  • Security, error analysis, and abuse prevention.

3. Data We Process

3.1 Technical Data

  • IP address, timestamp, requested pages/endpoints, user agent.
  • Error/security logs (e.g., failed requests, status codes).

3.2 Inputs and Generated Content

  • Prompt/input text used for video generation (please avoid sensitive data).
  • Topic inputs in the free Creator Tools (e.g., Hashtag Generator, Caption Writer) — forwarded to OpenAI for AI processing (see Section 5). Please do not enter sensitive data.
  • Uploaded videos, generated video files, and metadata (job ID, timestamps, status, file size).

3.3 TikTok OAuth & Draft Export (Optional)

  • OAuth tokens (access token, refresh token) and metadata (expiry times).
  • open_id (TikTok identifier) and, where available, basic profile data (e.g., username) for account mapping in the UI.
  • Upload status/IDs (e.g., publish_id) for technical traceability.

3.5 Push Notifications (Optional, Consent-Based)

  • If you enable push notifications, a browser-generated push subscription endpoint (push token) is stored on our server. This endpoint is linked to your open_id (TikTok identifier) and is used solely to deliver job-status notifications (e.g., "video ready").
  • No marketing messages are sent. Push tokens are never shared with third parties.
  • Push tokens are deleted when you disable push notifications in your browser, delete your account, or when the subscription expires at the browser vendor level.
  • Legal basis: Art. 6(1)(a) GDPR (consent). You may withdraw consent at any time via browser Settings → Notifications → ClipDraft → Block, or by deleting your account.

3.4 Feedback & Ratings (Optional)

  • If you submit a voluntary rating or review: star rating (1–5), optional free-text, page identifier.
  • Hashed IP address (SHA-256, non-reversible) for abuse prevention (duplicate ratings).
  • If logged in: open_id (TikTok identifier) for attribution. Usable anonymously.

4. Legal Bases (GDPR)

  • Art. 6(1)(b) GDPR (contract/performance): provision of tool functions (generation, export).
  • Art. 6(1)(a) GDPR (consent): push notifications (only where you have actively opted in).
  • Art. 6(1)(f) GDPR (legitimate interest): IT security, stability, abuse prevention, error analysis.

5. Recipients / Third Parties

  • Hosting: Hetzner Online GmbH, Gunzenhausen, Germany (server operation, EU).
  • Video generation: Atlas Cloud / Seedance — for AI-based creation of video files from your prompts. Data transfer may occur outside the EU on the basis of standard contractual clauses (Art. 46 GDPR).
  • AI text processing: OpenAI, L.L.C. (USA) — for prompt enhancement, automated content briefs, news research, and processing inputs from the free Creator Tools (Hashtag Generator, Caption Writer, Script Writer, Bio Generator, Video Ideas Generator). Data transfer to the USA on the basis of standard contractual clauses (Art. 46 GDPR). Privacy policy: openai.com/privacy.
  • Caption generation: Salad Cloud Inc. (USA) — for AI-based subtitle/caption creation. Data transfer to the USA on the basis of standard contractual clauses (Art. 46 GDPR).
  • Payment processing: Lemon Squeezy, LLC (USA) — for credit purchases. Payment data (e.g., card details) are processed solely by Lemon Squeezy; ClipDraft does not store payment data. Data transfer to the USA on the basis of standard contractual clauses (Art. 46 GDPR). Privacy policy: lemonsqueezy.com/privacy.
  • TikTok: for draft export, required video data/metadata are transmitted to TikTok.

This list is updated when processors change. Last updated: 2026-04-02.

6. Retention Periods

  • Videos: typically up to 14 days (download/export/troubleshooting), then deleted.
  • Logs: typically up to 14 days, then deleted.
  • Tokens: until revocation or automatic deletion after 90 days of inactivity.
  • Invoices and accounting records: statutory retention obligations under German law (§§ 147 AO, 257 HGB — generally 6–10 years) take precedence over the periods above. Relevant data are retained accordingly and deleted thereafter.

7. Security

  • Transport encryption (HTTPS).
  • Server-side file/secret access controls (least privilege).

8. Cookies / Tracking

Public pages do not use ad tracking. The tool may use local browser storage (localStorage) for convenience (e.g., last job handle, inputs, mode and toggle state). No non-essential tracking cookies are set.

Technically necessary cookies: cd_lang — stores the chosen language preference (de/en), HttpOnly, 90 days, no tracking.

9. Your Rights

  • Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20).
  • Right to withdraw consent (Art. 7(3) GDPR): Any consent you have given (e.g., for push notifications) may be withdrawn at any time with effect for the future, without giving reasons. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
  • Right to object (Art. 21 GDPR): You may object at any time to processing based on Art. 6(1)(f) GDPR with effect for the future. We will then cease that processing unless we can demonstrate compelling legitimate grounds that override your interests.
  • Complaint to the competent data protection supervisory authority (for us: Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, P.O. Box 30 40, 55020 Mainz, Germany, e-mail: poststelle@datenschutz.rlp.de).

10. Contact

Privacy requests: ttposter@gmx.de

Download

30 Tage verfügbar