Clipscene Privacy Policy
Effective date: July 17, 2026 Last updated: July 17, 2026
Status: Draft for legal review. Replace bracketed placeholders before publication. This document is not legal advice.
Operator: [LEGAL ENTITY NAME] (“Clipscene,” “we,” “us,” or “our”), operating the Clipscene service at [WEBSITE URL] and related applications, APIs, and websites (the “Service”).
Privacy contact: [PRIVACY@CLIPSCENE.APP] General support: [SUPPORT@CLIPSCENE.APP]
This Privacy Policy explains how we collect, use, share, and protect personal information when you use Clipscene. It works together with our Terms of Service.
1. Scope
This Policy applies to personal information we process when you:
- Visit or browse Clipscene (including without an account)
- Create or use an account
- Publish or watch videos, join Watch Parties, follow creators, or subscribe to collections
- Buy or spend Coins, tip or support creators, or receive creator payouts
- Contact us or interact with emails and notifications we send
It does not cover third-party websites, apps, or services that we do not control (including payment providers’ own pages), which have their own privacy practices.
2. Information we collect
2.1 Information you provide
| Category | Examples |
|---|---|
| Account details | Email address, password (stored hashed), display name, avatar/profile photo, bio |
| Creator / Studio content | Videos, thumbnails, titles, descriptions, cast/credits, tags, collection metadata, publish schedules |
| Social & community | Comments, ratings, likes, follows, collection subscriptions, Watch Party chat and reactions, party invites you send (e.g. email or username) |
| Support & reports | Messages to support, video reports and reason codes, information you include in disputes |
| Payout / tax (creators) | Information required by our payout partner (e.g. Stripe Connect), which may include legal name, address, government ID, bank/payout details, and tax forms (W-9 / W-8BEN). Much of this is collected directly by the payment provider |
| Preferences | Notification toggles (e.g. new videos, collection releases, premieres), settings you save in the product |
2.2 Information collected automatically
| Category | Examples |
|---|---|
| Device & log data | IP address, browser/user agent, approximate request timestamps, pages or API routes requested, referrer, error logs |
| Approximate location | At registration we may derive a coarse location (e.g. city/region/country) from your IP via a geolocation lookup (best-effort). Creators may also set a self-reported location on their profile. Collection “setting location” may default from your detected location |
| Usage & engagement | Watch sessions and heartbeats, watch progress/resume position, watchlist and watched history, unlocks, tips, gifts, feed interactions, search/browse activity used for rankings and anti-fraud |
| Fraud / integrity signals | Signals used to detect bots and invalid views (e.g. IP + user agent patterns, rate limits, engagement anomalies) |
| Cookies & similar tech | Session cookies for authentication (e.g. Auth.js / NextAuth session), preference or local storage keys (e.g. activity-feed seen state), and any analytics cookies we enable later |
2.3 Information from third parties
- Payment processors (e.g. Stripe): payment status, Coin purchase confirmations, chargeback/dispute signals, and Connect onboarding/payout status. We do not store full card numbers on Clipscene servers when Checkout is used as designed.
- Email provider (e.g. Mailgun): delivery events for transactional email (welcome, password reset, party invites).
- Hosting / storage / CDN (e.g. AWS, Cloudflare R2): operational logs and media delivery metadata needed to run the Service.
- Invitees / other users: if someone invites you to a Watch Party or interacts with your public profile/content, we process the data involved in that interaction.
We do not require you to connect social login providers in the current product; if we add them later, we will update this Policy.
3. How we use information
We use personal information to:
- Provide the Service — create accounts, authenticate sessions (frontend session + backend API tokens), stream and transcode media, sync Watch Parties, show profiles and feeds
- Enable monetization — process Coin purchases and spends, credit creator earnings, apply holds, run payouts, handle chargebacks
- Personalize and operate discovery — activity feed, following/subscriptions, recommendations or rankings as features ship
- Communicate — transactional email, in-app notifications, security alerts, and (with appropriate consent or as allowed by law) product updates
- Safety and integrity — prevent fraud, enforce Terms, process reports, apply trust/admin review, protect users and the platform
- Improve and debug — analytics, performance monitoring, load/error investigation, product development
- Comply with law — tax reporting, responding to lawful requests, establishing or defending legal claims
- Business operations — accounting, vendor management, corporate transactions (see §5)
Legal bases (EEA/UK and similar regions): where required, we rely on one or more of: contract performance (providing the account and paid features you request), legitimate interests (security, fraud prevention, product improvement, limited marketing where allowed), consent (where we ask for it, e.g. certain cookies or optional notifications), and legal obligation (tax, accounting, lawful requests).
4. How we share information
We share personal information only as described below:
4.1 Public by design
Depending on your settings and what you publish, others may see your display name, avatar, bio, public profile, public collections/videos, comments, and similar public activity. Private/unlisted content is shared according to those visibility controls, but is never perfectly secret from admins or technical staff who need access to operate the Service.
4.2 Service providers
We use vendors who process data on our behalf, including:
- Cloud hosting and databases (e.g. AWS)
- Media storage and delivery (e.g. Cloudflare R2 / CDN)
- Authentication/session infrastructure (Auth.js / NextAuth patterns on our stack)
- Email delivery (e.g. Mailgun)
- Payments and payouts (e.g. Stripe Checkout and Stripe Connect)
- Optional IP geolocation lookups (e.g. ip-api or similar)
- Monitoring and security tooling we enable for production
These providers may process data in the countries where they operate, subject to their agreements with us.
4.3 Other users and creators
If you tip, unlock, gift, follow, subscribe, comment, or join a party, relevant information is shared with the involved creators/users as needed to provide that feature (e.g. tip attribution, chat messages to party participants).
4.4 Legal, safety, and business transfers
We may disclose information if we believe it is reasonably necessary to comply with law, enforce our Terms, protect rights/safety, or in connection with a merger, acquisition, financing, or sale of assets (with appropriate confidentiality protections).
4.5 We do not sell personal information
We do not sell your personal information for money. We also do not share personal information for cross-context behavioral advertising as those terms are commonly defined under US state privacy laws, unless we update this Policy and provide required notices/opt-outs before doing so.
5. Cookies and similar technologies
We use:
- Essential cookies / storage — to keep you signed in, protect sessions, and remember security-related state
- Functional local storage — e.g. client-side activity-feed “seen” markers until fully replaced by server-side read state
- Analytics / advertising cookies — only if we enable them; if we do for visitors in regions that require consent, we will present a consent mechanism before non-essential cookies run
You can control cookies through your browser settings. Blocking essential cookies may prevent login or core features from working.
6. Retention
We keep personal information only as long as needed for the purposes above, including:
- Account data — for the life of the account, then for a reasonable period afterward for backups, disputes, and legal retention
- Content you publish — until you delete it (where the product allows) or your account is removed, subject to caches, backups, and legal holds
- Watch / engagement logs — for fraud prevention, analytics, and creator earnings calculations for periods consistent with payout holds and audit needs
- Payment and tax records — as required by law and payment-partner rules (often multiple years)
- Reports and moderation records — as needed for safety and repeat-offender tracking
When data is no longer needed, we delete or de-identify it.
7. Security
We use administrative, technical, and organizational measures appropriate to the risk, including hashed passwords, authenticated API access, HTTPS in production, and access controls for admin tools. No method of transmission or storage is 100% secure. Please use a strong unique password and notify us of suspected unauthorized access.
8. Your choices and rights
8.1 In-product controls
- Update profile and many account settings in Settings / Studio
- Control certain notification preferences
- Manage follows, subscriptions, watchlist, and content you own (subject to product limits)
- Log out; request account help via support
8.2 Marketing
Transactional and security emails are not marketing. Where we send optional product marketing email, you can unsubscribe via the link in the message or by contacting us.
8.3 Region-specific rights
Depending on where you live (for example EEA/UK GDPR, California CCPA/CPRA, and other US state laws), you may have rights to:
- Access / know what personal information we hold
- Correct inaccurate information
- Delete information (subject to legal exceptions)
- Export / portability
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Opt out of “sale” or “sharing” for targeted advertising if we ever engage in those activities
- Appeal a denied privacy request where required by law
To exercise rights, email [PRIVACY@CLIPSCENE.APP]. We may need to verify your identity. You may authorize an agent where the law allows. You will not be discriminated against for exercising privacy rights.
EEA/UK: You may lodge a complaint with your local supervisory authority.
California: We will disclose categories of personal information collected, sources, purposes, and disclosures as required in our notices. Submit requests to the privacy contact above. [If we appoint a toll-free number or webform, add it here.]
9. Children
Clipscene is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact [PRIVACY@CLIPSCENE.APP] and we will delete the information as required.
Coin purchases and creator payouts are limited to users who meet the age requirements in our Terms (generally 18+ or age of majority).
10. International transfers
We may process and store information in the United States and other countries where we or our providers operate. If we transfer personal information from the EEA/UK/Switzerland to countries without an adequacy decision, we will use appropriate safeguards (such as Standard Contractual Clauses) where required.
11. Creators and public profiles
If you use Creator Studio, information about your public channel, published content, and engagement metrics needed to operate the Service may be processed more intensively (analytics, leveling, trust review, payouts). Earnings, Trust Score, and wallet details are treated as private account data and are not shown on public profiles by default.
12. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date. If changes are material, we will provide additional notice as required by law (for example in-product or by email).
13. Contact
Privacy questions or requests: [PRIVACY@CLIPSCENE.APP] Support: [SUPPORT@CLIPSCENE.APP] Postal address: [LEGAL ENTITY MAILING ADDRESS]
EEA/UK representative (if applicable): [NAME / CONTACT] Data Protection Officer (if applicable): [NAME / CONTACT]
Appendix A — Data map (current systems, informational)
| System / vendor | Role | Typical data |
|---|---|---|
| Clipscene app + API | Controller / primary processor | Accounts, content, engagement, coins ledger, reports |
| Auth.js / session cookies | Auth session on web | Session identifiers tied to logged-in user |
| FastAPI JWT | API authorization | Token claims (user id, admin flag, etc.) |
| PostgreSQL (e.g. AWS RDS) | Primary database | Persistent account and product data |
| Redis | Parties / jobs | Ephemeral sync and queue data |
| Cloudflare R2 / CDN | Media storage | Uploaded videos/thumbnails and delivery logs |
| Stripe | Payments & Connect payouts | Purchase and payout compliance data |
| Mailgun | Transactional email | Email address + message metadata |
| IP geolocation provider | Coarse location at signup | IP → approximate location string |
| Local / browser storage | Client UX | Feed seen IDs, UI preferences |
Appendix B — Pre-publication checklist
- [ ] Insert legal entity, postal address, and privacy email
- [ ] Confirm geolocation provider and document it accurately
- [ ] Finalize cookie consent for EU/UK before enabling analytics
- [ ] Confirm Stripe / Mailgun / hosting regions and SCCs if needed
- [ ] Add California “Notice at Collection” details if required at signup/checkout
- [ ] Define account-deletion SLA and how media/earnings records are handled
- [ ] Cross-check age statements with Terms of Service
Privacy requests: [PRIVACY@CLIPSCENE.APP] after placeholders are filled in for launch.