Open Clipper Privacy Policy

Last updated: August 3, 2026

This Privacy Policy applies to the Open Clipper desktop application and its optional GrepCut cloud features.

1. Scope and Data Controller

This Privacy Policy applies to Open Clipper, a free, open-source (MIT), local-first desktop application for Windows developed by GrepCut and operated by Adam Ziółko, Warsaw, Poland. We act as the data controller for personal data processed through Open Clipper's optional cloud features.

Open Clipper is designed to work primarily on your device. Most editing, transcription, reframing, and export activity stays local and does not require an account.

Contact: [email protected] | Supervisory authority: UODO, Warsaw, Poland.

2. Information We Collect

2.1 Local data (stored on your device)

By default, Open Clipper stores the following data locally in SQLite and related app data folders (typically under %APPDATA%\com.openclipper.app):

  • Project data: Project names, clip selections, transcripts, captions, export settings, and pipeline state.
  • Media metadata: File paths, format, resolution, duration, and related editing metadata.
  • App preferences: Transcription provider settings, caption presets, update preferences, and other configuration.
  • Bring-your-own-key (BYOK) credentials: If you enable cloud transcription, your Groq or OpenRouter API keys are stored locally in SQLite on your device.
  • Downloaded models: Speech and vision models cached locally for offline processing.
  • Session token: If you sign in, a desktop refresh token may be stored in local storage to keep your session active.

Source videos, rendered exports, and local transcripts are not uploaded to GrepCut unless you explicitly use a cloud-connected feature described below.

2.2 Cloud data (only when you sign in or use connected features)

  • Account data: Name, email, and profile picture from Google OAuth when you choose to sign in.
  • Social connection data: Platform identifiers, display names, and encrypted OAuth tokens for connected accounts (YouTube, Facebook, Instagram, X, and TikTok when available).
  • Publishing data: When you publish a clip, we receive the rendered video, title, description, privacy settings, and related metadata needed to complete the upload to the selected platform. Some platforms require temporary staging on Cloudflare R2.
  • Subscription linkage: If your GrepCut account has a Paddle subscription, we may store subscription identifiers to manage billing when you delete your account. Open Clipper itself does not offer in-app checkout.
  • Update checks: App version, product identifier, target platform, architecture, and update channel when the app checks for updates.
  • Technical logs: IP addresses, authentication events, publish job status, and support or abuse-prevention logs on our servers.

2.3 Data sent directly to third parties you configure

  • Cloud transcription (BYOK): If you provide your own Groq or OpenRouter API key, audio is sent directly from your device to that provider. GrepCut does not receive or store the audio for those requests.
  • Social platforms: When you publish, content and metadata are transmitted to the platform you selected under that platform's terms.

3. Why We Process Your Data

  • To provide optional cloud features (contract): account sign-in, social publishing, and app updates.
  • For service stability and security (legitimate interest): authentication, publish job processing, abuse prevention, and infrastructure protection.
  • With your consent: connecting third-party social accounts and initiating publishes to those platforms.
  • Legal obligations: Retaining payment-related records where applicable.

Local processing on your device for editing, transcription, reframing, and export does not require cloud account data and is performed to deliver the app functionality you request.

4. Who We Share Your Data With (Processors)

When you use cloud-connected features, we share the minimum data necessary with these providers. We have entered into Data Processing Agreements (DPAs) or equivalent terms with subprocessors as required by GDPR Art. 28:

  • Google — optional app sign-in and YouTube publishing
  • Meta — Facebook Page and Instagram publishing
  • TikTok — publishing when the integration is available
  • X (Twitter) — publishing
  • Cloudflare R2 — model distribution, update delivery, and temporary social publishing staging
  • Paddle — subscription cancellation when you delete a linked GrepCut account. Paddle's privacy policy: paddle.com/legal/privacy
  • Gmail SMTP — transactional emails

If you use BYOK cloud transcription, your audio is sent directly to Groq or OpenRouter under their respective privacy policies. GrepCut is not the processor for that transmission.

We do not sell your data. Open Clipper does not use your content to train AI models.

5. Local-First Processing and MCP

Open Clipper's MCP (Model Context Protocol) server runs locally on your device (127.0.0.1) and reads your local project database to help with clip selection. MCP traffic does not leave your machine and does not require sign-in.

Local speech-to-text (Whisper, Parakeet) and reframing models run on your hardware. We do not receive the underlying media for those operations.

6. Automated Decision-Making and Profiling

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects for you (under GDPR Art. 22).

7. How to Request Deletion of Your Data

You can request deletion of personal data we hold about you through Open Clipper or by contacting us directly.

7.1 Delete your GrepCut / Open Clipper account (cloud data)

  1. Open Open Clipper on your Windows device.
  2. Go to Settings.
  3. Open the Delete account section.
  4. Confirm deletion by typing DELETE and submitting the request.

This deletes your cloud account data, including social connections, publish job records, and sessions. If your account is linked to a Paddle subscription, we will attempt to cancel it as part of deletion.

Alternatively, email [email protected] from the address associated with your account.

7.2 Meta (Facebook / Instagram) platform data

If you connected Open Clipper to Facebook or Instagram and want us to delete the Platform Data we received from Meta:

  1. Follow the account deletion steps above, or email [email protected] with your request.
  2. You may also remove Open Clipper from your Facebook account at Facebook Apps and Websites and request deletion there.

We delete associated social tokens and publish metadata within 30 days of a valid request, except where retention is required by law.

7.3 Local data on your device

Deleting your cloud account does not automatically erase local SQLite databases, cached models, or exported files on your computer. To remove local data, uninstall Open Clipper and delete the app data folder at %APPDATA%\com.openclipper.app, or delete individual projects from within the app.

8. Data Security

We protect cloud-held data with encryption in transit (TLS 1.2+), encryption at rest for stored tokens and server data, secure authentication, access controls, and input validation. Social OAuth tokens are stored encrypted on our servers and are not written into the desktop app.

You are responsible for securing your device, local database, and any BYOK API keys you store in Open Clipper.

9. Data Retention

  • Local project data: Retained on your device until you delete it or uninstall the app.
  • Account and social connection data: Kept while your account is active; deleted within 30 days of account deletion.
  • Publish job records: Retained as needed to process and audit publishing; deleted with your account unless legally required otherwise.
  • Temporary publish staging files: Removed according to platform publishing policies, typically shortly after upload completes.
  • Payment records: Up to 7 years where legally required.
  • Server logs: Typically up to 90 days, unless a longer period is needed for security or abuse investigations.

10. International Data Transfers

Some providers operate in the United States and other countries outside the EEA. Where required, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses (SCCs), or equivalent transfer mechanisms offered by the provider. Contact us if you need more detail about a specific transfer.

11. Your Rights

Under GDPR you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data (“right to be forgotten”)
  • Restrict processing
  • Port your data to another service
  • Object to processing based on legitimate interest
  • Withdraw consent at any time for consent-based processing, such as connected social accounts

Contact [email protected] to exercise these rights. We respond within 30 days. You may also lodge a complaint with your local data protection authority or UODO.

12. Children's Privacy

Open Clipper is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

13. Data Breach Notification

In the event of a data breach posing risk to your rights, we will notify the supervisory authority within 72 hours and inform affected users without undue delay.

14. Changes to This Policy

We may update this Policy from time to time. For material changes, we will provide reasonable notice before they take effect. Continued use after the effective date means the updated Policy applies.

15. Contact Us

Email: [email protected] | Contact page

See also our Open Clipper Terms of Service.