Privacy Policy
Effective date: May 29, 2026 · Last updated: September 14, 2026
1. Who We Are
Clepora ("we", "us", "our") is a software-as-a-service platform that helps creators and businesses publish content across multiple social media platforms from a single dashboard. Our registered contact address is legal@clepora.com.
This Privacy Policy applies to all users of Clepora's web application, mobile application, and API services (collectively, the "Service").
2. Age Restriction
Clepora is strictly for users aged 18 and over.
We do not knowingly collect personal data from anyone under the age of 18. If we discover that a user is under 18, we will immediately terminate the account and delete all associated data. If you believe a minor has registered, please contact us at legal@clepora.com.
3. Data We Collect
3.1 Account Data
- Name and email address provided at registration
- Encrypted password (we never store plain-text passwords)
- Account creation date and last login timestamp
3.2 Content Data
- Videos and media files you upload for processing
- Captions, titles, descriptions, and hashtags you create
- Publishing schedules and platform connection tokens
3.3 Platform Connection Data
- OAuth access tokens for connected platforms (YouTube, TikTok, Meta, LinkedIn, Pinterest), and bot/webhook credentials for Telegram and Discord
- Platform-specific account identifiers and page IDs
- These tokens are stored encrypted at rest
You can disconnect any connected social account at any time from the Connections section of your dashboard (each connected platform has a “Disconnect / release” option). When you disconnect, Clepora revokes the access token with that platform where the platform supports revocation and deletes the stored token and connection from our systems. After disconnecting, Clepora can no longer access or publish to that account. For YouTube, disconnecting also deletes every piece of YouTube data Clepora holds for that channel at the same moment — see section 5.1.
3.4 Usage Data
- Analytics data retrieved from connected platforms (views, engagement and, where the platform reports it, revenue). Data from YouTube is described in section 5.1.
- Feature usage patterns for service improvement
- Error logs and performance data
3.5 Traffic Measurement
We count visits to our own pages so we know which ones are useful. For each page view we record the path, the referring URL, your browser's user-agent string, and a visitor identifier that we derive on our server from a salted hash of your IP address and user-agent.
Two things about that identifier are deliberate. It is never stored on your device — no cookie, no local storage entry, nothing to consent to. And it changes every day at midnight UTC, so it can count how many people visited on a given day but cannot be used to recognise you from one day to the next. Your IP address itself is not stored.
We use no third-party analytics service. There is no Google Analytics, no tag manager, and no tracking pixel anywhere on this site.
3.6 Data We Do NOT Collect
- We do not collect payment card numbers (handled directly by our payment processor)
- We do not collect biometric data
- We do not track your activity outside of Clepora
4. How We Use Your Data
- To provide the Service — process your videos, publish to platforms, and display analytics
- To send transactional emails — publish confirmations, view milestone alerts, account notifications
- To improve the Service — aggregate, anonymised usage analysis
- To comply with law — responding to valid legal requests and protecting our rights
- To prevent abuse — detecting and stopping fraud, spam, and policy violations
Clepora’s Free plan displays Clepora’s own promotional slots. Which advert you see is decided by your plan alone. No personal data, browsing history, or content of yours is used to select it, and no advertising network is involved. Paid plans display no adverts at all.
We do not use your data for:
- Selling to third parties
- Advertising or retargeting
- Training AI models on your private content without explicit consent
5. Third-Party Services
To operate Clepora, we share data with the following processors under strict data processing agreements:
| Service | Purpose | Data shared |
|---|---|---|
| AWS (Amazon) | Object storage, AI inference, content moderation | Media files, video frames |
| Resend | Transactional email delivery | Email address, name, and the name of an account you connect (for YouTube, the channel title) in the connection confirmation email |
| YouTube / Google | Video publishing, live streaming and analytics (when connected) | Videos, the title, description and settings you choose, OAuth token |
| Meta (Facebook/Instagram) | Publishing and analytics (when connected) | Videos, captions, OAuth token |
| TikTok | Video publishing (when connected) | Videos, captions, OAuth token |
| Publishing and analytics (when connected) | Posts, OAuth token | |
| Publishing (when connected) | Pins, videos, OAuth token | |
| Telegram | Publishing (when connected) | Messages, videos, bot token |
| Discord | Publishing (when connected) | Messages, videos, webhook URL |
| ACRCloud | Audio copyright fingerprinting | Audio sample (10 seconds) |
| Stripe | Subscription payments and billing | Email address, name, billing details |
| Twilio | SMS delivery for login and verification codes | Phone number |
| Jamendo | Royalty-free music search (fallback only) | Search query only — no personal data |
5.1 YouTube API Services
Clepora uses YouTube API Services to upload videos to, stream live to, and read analytics from a YouTube channel you have connected. By using Clepora, you agree to be bound by the YouTube Terms of Service.
Data obtained through YouTube API Services is also handled under Google's privacy practices, as described in the Google Privacy Policy, in addition to this Policy.
What Clepora accesses
When you connect a channel you grant Clepora permission, on Google's own consent screen, to upload videos to that channel, to create and manage live broadcasts on it, and to read its YouTube Analytics reports, including revenue reports where the channel is monetised. Clepora uses that permission only to do what you ask it to do. It does not read comments on your videos, and it does not search, edit or delete anything on YouTube.
What Clepora stores
- OAuth tokens for your channel, encrypted at rest (see section 9).
- Your channel title and avatar, so Connections can show which channel you linked. They are refreshed from the API at every sync, roughly every three hours.
- Performance statistics — views, likes, comments and, where the channel is monetised, revenue reported by the YouTube Analytics API — for the last 30 days. They are refreshed at every sync and deleted if not refreshed within 30 days.
- The IDs and links of videos and live broadcasts you published through Clepora, so each post can link to what it published. They are kept for at most 30 days.
Stored YouTube data is refreshed from the API on a three-hourly schedule. In line with the YouTube API Services Developer Policies, Clepora does not store or display YouTube statistics for more than 30 days: a daily sweep deletes any figure that has not been refreshed within that period, and the analytics views for YouTube cover the last 30 days only.
How Clepora uses it
- To publish what you direct. YouTube uploads send the title, description, privacy setting, made-for-kids setting, category and synthetic-content disclosure exactly as you chose them. Clepora adds nothing to a YouTube title or description — no hashtags and no #Shorts tag.
- To show you your channel and its figures. Every YouTube figure shown in Clepora is a value returned by the YouTube API. The single exception is engagement rate, which Clepora calculates from the likes and views the API returns, and which is labelled as Clepora-calculated everywhere it appears.
YouTube data is never merged with data from other platforms, never used to model revenue or estimate audiences, and never sent to our AI provider.
Who it is shared with
YouTube API data is not sold, and is shared with no one except as needed to run the Service: it is held on our AWS infrastructure, and your channel title appears in the confirmation email we send you through Resend when you connect the channel. Google receives the videos and settings you publish to YouTube.
Revoking access and deleting your YouTube data
- In Clepora, via Connections → Manage → Disconnect, or by deleting your Clepora account. Clepora revokes its access with Google and immediately deletes your OAuth tokens, channel title and avatar, all stored YouTube statistics, and the stored YouTube video and broadcast IDs — never later than 7 days after you disconnect.
- Directly with Google, via the Google security settings page. Clepora detects the revoked grant at its next sync, normally within hours, and runs the same deletion automatically — in every case within 30 days of the revocation.
- By asking us. Email legal@clepora.com to have the YouTube data Clepora stores about you deleted, and we will act on the request within 7 days.
Deleting the data Clepora stores does not, in any way, affect data stored by YouTube: videos you published remain on your channel until you remove them on YouTube.
5.2 Meta Platforms — Facebook, Instagram and Threads
Where you connect a Facebook Page, an Instagram professional account or a Threads profile, Clepora receives an access token and the identifiers for the Page or account you selected, and uses them solely to publish the posts you direct it to publish and to read that account's own performance metrics.
Clepora does not read your feed, your friends or followers, your messages, or any account you did not explicitly connect.
You can require deletion of the data Clepora holds from a Meta platform in three ways: disconnect the account in Clepora, remove Clepora from your Facebook settings (which calls Clepora's deauthorisation endpoint and deletes the stored credential), or follow the instructions at clepora.com/data-deletion, which returns a confirmation code you can use to track the request.
5.3 TikTok
Where you connect a TikTok account, Clepora receives an access token and your account identifier, and uses the TikTok Content Posting API to publish the videos you direct it to publish. Clepora asks you to choose the audience and the comment, duet and stitch settings for each post rather than assuming them, and passes exactly those choices to TikTok.
Clepora does not hold TikTok's Display API permissions, so it cannot and does not read your TikTok videos, profile content, or follower data. Disconnecting the account deletes the stored token.
5.4 LinkedIn, Pinterest, Telegram and Discord
For LinkedIn and Pinterest, Clepora receives an OAuth token and the identifier of the profile, page or board you selected, and uses them only to publish what you direct it to publish and — where the platform provides it — to read that content's own metrics.
Telegram and Discord have no OAuth flow. You supply a bot token and channel, or a webhook URL, that you created and control. Clepora stores these encrypted, uses them only to deliver your posts, and deletes them when you disconnect. Revoking the bot token or deleting the webhook on the platform's own side stops Clepora's access immediately and independently of Clepora.
5.5 What is true of every connected platform
- Clepora only ever receives a token. It never receives, sees or stores your password for any platform.
- Clepora requests the narrowest set of permissions that lets it publish and report on what you publish, and nothing that would let it read content you did not create through Clepora.
- Disconnecting a platform revokes the token where the platform supports revocation, deletes the stored credential, and ends all publishing and metric syncing for that account.
- Anything Clepora already published to that platform remains on your account there. Removing it is done on the platform, by you.
6. Your Rights
Depending on your location, you have some or all of the following rights:
Right to access
Request a copy of all personal data we hold about you
Right to deletion
Request deletion of your account and all associated data — available directly in Settings → Delete Account
Right to portability
Request your data in a machine-readable format
Right to rectification
Correct inaccurate personal data
Right to restrict processing
Ask us to stop processing your data in certain ways
Right to object
Object to processing based on legitimate interests
Right to withdraw consent
Withdraw consent at any time without affecting prior lawful processing
To exercise any right, email legal@clepora.com. We will respond within 30 days, and requests to delete data obtained through YouTube API Services are acted on within 7 days (see 5.1). EU/UK users may also lodge a complaint with their local supervisory authority.
7. Data Deletion
You may delete your account at any time from Settings → Delete Account. Upon deletion:
- All personal data is deleted from our databases within 30 days
- All uploaded media files are deleted from object storage within 30 days
- Platform connection tokens are revoked and deleted immediately
- Data obtained through YouTube API Services — OAuth tokens, channel title and avatar, statistics, and video and broadcast IDs — is deleted immediately, and never later than 7 days
- Anonymised, aggregated analytics data may be retained. This never includes data obtained through YouTube API Services, which is deleted in full
- Data required by law may be retained for the legally required period
You can also request deletion without signing in, using the instructions at clepora.com/data-deletion. This is the route to use if you removed Clepora from a connected platform's settings and want the data deleted at the same time; it returns a confirmation code you can use to check the status of the request.
When you delete your Clepora account, all of your information and every connection to your social media accounts are removed. Clepora revokes and deletes the access tokens and webhook/bot credentials for all connected platforms (YouTube, TikTok, Instagram, Facebook, Threads, LinkedIn, Pinterest, Telegram, Discord), which means Clepora will no longer have any access to those social media accounts.
8. Data Retention
- Account data: retained while your account is active, deleted within 30 days of account deletion
- Published media: deleted 7 days after the post is first published. The clock starts at the first successful publish, not at upload. The post record, its published URLs (for YouTube, for at most 30 days) and its analytics all survive the deletion — only the rendered video files are removed, and a post whose media has been removed cannot be published again.
- Media Library files: deleted 7 days after upload. The Library is a staging area for files you are about to use, not an archive.
- Media for posts you never publish: retained while the post exists, and deleted when you delete the post.
- Analytics statistics: deleted if not refreshed within 30 days. Figures from every connected platform are refreshed at each sync, and a daily sweep deletes any that have not been refreshed within 30 days. YouTube video and broadcast IDs are kept for at most 30 days.
- Page-view records: deleted after 90 days. The derived visitor identifier in them is already useless for recognising anyone after 24 hours; the rows themselves are removed by a daily job.
- Legal hold data: retained as required by applicable law
Deleting a post removes its stored files first and then its record. Content you have already published stays on the destination platform — it belongs to your account there, not to Clepora, and only you or that platform can remove it.
9. Security
- Passwords are hashed using bcrypt — we cannot recover your password
- OAuth tokens and bot/webhook credentials are encrypted at rest using authenticated symmetric encryption (AES-128-CBC with HMAC-SHA256)
- All data in transit is encrypted using TLS 1.2 or higher
- Object storage is access-controlled — media is not publicly accessible without a time-limited signed URL
- In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours
10. Regulatory Compliance
Clepora is designed to comply with the following regulations:
- GDPR (EU General Data Protection Regulation 2016/679) — lawful basis for processing, data subject rights, breach notification
- UK GDPR — equivalent protections post-Brexit
- CCPA / CPRA (California Consumer Privacy Act) — right to know, delete, and opt out of sale (we do not sell data)
- COPPA (Children's Online Privacy Protection Act) — COPPA governs children under 13; Clepora goes further and permits no users under 18 at all
- PIPEDA (Canada) — consent-based processing, access rights
- LGPD (Brazil Lei Geral de Proteção de Dados) — lawful basis, data subject rights
- Australian Privacy Act 1988 — Australian Privacy Principles compliance
- DMCA (Digital Millennium Copyright Act) — designated agent for takedown notices, and a repeat-infringer policy
- Platform developer policies — YouTube Terms of Service, Meta Platform Policy, TikTok Developer Agreement, LinkedIn API ToS, Pinterest Developer Policy
11. Cookies and Local Storage
Clepora sets no cookies at all. What the Service does use is your browser's local storage, and only for things the Service cannot work without:
- Your sign-in token, so you stay signed in between page loads
- Small interface preferences, such as which platforms you last had open
Both are strictly necessary to provide a service you asked for, both stay on your device, and both are cleared when you sign out or clear your browser data. We store nothing on your device for analytics, advertising, or tracking — our visitor counting is done server-side (see 3.5) precisely so that it needs nothing stored on your device.
Because everything we store is strictly necessary, no consent banner is required.
12. International Data Transfers
Your data may be processed in the United States (AWS infrastructure). For EU/UK users, such transfers are made under Standard Contractual Clauses (SCCs) as approved by the European Commission. We do not transfer data to countries without adequate protection without appropriate safeguards.
13. Changes to This Policy
We will notify you of material changes to this policy by email and by posting a notice in the Clepora dashboard at least 30 days before changes take effect. Continued use of the Service after that date constitutes acceptance of the updated policy.
14. Contact
Data Controller: Clepora
Privacy enquiries: legal@clepora.com
DMCA notices: legal@clepora.com
General support: support@clepora.com