1. Scope
This policy explains how Cendro Labs Pty Ltd (ABN 84 697 743 598), trading as ClipFlight (“ClipFlight”, “we”, “us” or “our”), handles personal information when you visit clipflight.com, use the ClipFlight publishing application at app.clipflight.com, contact us or purchase a paid plan. We are established in Australia.
By using a connected platform through ClipFlight, you also remain subject to that platform’s own privacy policy and terms.
2. Data we handle
Account, session and security data
When you sign in with Google, we receive your Google account identifier, name, email address, profile image and email-verification status. We store the account record, encrypted OAuth credential data needed for sign-in, and the session cookie used to protect the application. Our hosting provider also makes limited request and security metadata available to us, such as timestamps, IP address, user agent and error diagnostics.
Google sign-in establishes your ClipFlight identity only. Connecting a YouTube channel for publishing is a separate authorization with separate permissions, and is not required merely to sign in.
Connected-account data
When you connect a social account, we store the platform account or channel identifier, display name, username, avatar URL, granted scopes, token expiry information and encrypted OAuth access credentials. We do not ask for or store your Google, YouTube, Instagram or TikTok password.
Media and publishing data
We temporarily store videos you upload in Cloudflare object storage so we can validate and publish them. We also store basic media metadata needed for preflight checks, captions and platform settings you submit, publishing status, platform post identifiers, permalinks and diagnostic errors. Uploaded source videos are not kept permanently.
Support data
If you email us, we receive your email address and the information you include in the message.
Billing and transaction data
If you purchase a paid plan, the merchant of record or payment provider presented at checkout collects your payment method and billing details. ClipFlight does not receive or store complete card numbers. We may receive and store your billing email, billing country, plan, subscription status, renewal and cancellation dates, transaction and customer references, invoice details, tax status, limited payment-method information and refund or dispute status.
3. How we use data
We use this information only to authenticate access, display the accounts you connected, validate media, perform publishing actions you explicitly request, show progress and results, administer plans and subscriptions, provide billing support, prevent fraud, secure and maintain the service, troubleshoot failures, respond to requests and comply with legal or platform-policy obligations.
Within Cendro Labs, access is limited to authorized personnel and contractors who need the information for those purposes. They may process it only on our instructions and must keep it confidential.
We do not sell personal information, run behavioural advertising, or use your uploaded media or connected-platform data to train AI models.
4. YouTube API Services
ClipFlight uses YouTube API Services. When you connect YouTube, ClipFlight requests permission to read basic information about the YouTube channel you control and to upload videos only when you initiate a publish action.
ClipFlight may access and store your channel ID, channel title, channel avatar, granted scopes, encrypted access and refresh tokens, token expiry, uploaded video ID, visibility choice and resulting YouTube permalink. ClipFlight uses this data only to identify the selected channel, maintain the authorized connection, upload the video and display the result.
ClipFlight does not retrieve, display or store YouTube statistics such as view counts, subscriber counts, likes or comments. An hourly authorization check begins refreshing stored channel profile data once it reaches 29 days old. If that data has not been refreshed by the retention safety cutoff, ClipFlight automatically removes the YouTube credential and channel data before they reach 30 days old. Revoked or invalid authorization is removed sooner. A separate hourly retention job removes completed publishing History within 30 days, and independently removes YouTube video IDs and permalinks before that deadline even if deletion of other ClipFlight data needs to be retried. Eligible History can be deleted sooner.
Your use of YouTube features is subject to the YouTube Terms of Service. Google’s handling of data is described in the Google Privacy Policy.
You can revoke ClipFlight’s access from the Channels screen or through Google’s security permissions page. Revoking access stops future API access. You may also request deletion of the YouTube data stored by ClipFlight by emailing support@clipflight.com.
6. Retention, revocation and deletion
ClipFlight account and sign-in data are kept while your account is active and are deleted after a valid account-deletion request, subject to limited records we must retain for security or legal reasons. Connected-platform OAuth credentials are kept only while the platform account remains connected and are deleted after disconnection or a valid deletion request. YouTube API data that is not otherwise permitted to be retained is deleted or refreshed within the periods required by YouTube’s developer policies.
Source media for successfully published or canceled posts is retained for 14 days after the post reaches that status. Source media for failed or partially published posts is retained for up to 30 days so you can retry, and uploaded media that is never used in a post is removed after 30 days. Scheduled, queued or actively publishing media is not automatically deleted before the publishing process finishes. An hourly cleanup removes media after the applicable period. If the same source file is still needed by another post, it is retained until that post is no longer active and its applicable retention period has ended.
Completed publishing History is retained for up to 30 days. You can use Manage or the Delete action in History to remove eligible History records and source media sooner. Manual and automatic cleanup removes data from ClipFlight’s database and object storage only; it does not request deletion of content already published on YouTube, Instagram or TikTok.
Subscription, transaction, invoice, refund and dispute records may be retained for the periods required for accounting, tax, fraud prevention and legal compliance. The merchant of record or payment provider keeps the information it controls under its own privacy notice and retention rules.
We process valid deletion and revocation requests as soon as practical and, for YouTube Authorized Data, within seven calendar days. Deleting data from ClipFlight does not delete a video or other data held by a connected platform. To delete content from YouTube, Instagram or TikTok, use that platform’s application or an authorized client that supports deletion.
7. Security and international processing
ClipFlight uses encrypted OAuth-token storage, workspace-scoped data access, HTTPS, secure cookies and access controls intended to protect stored data. No system can guarantee absolute security. Cloudflare may process data in countries other than your own as part of its global infrastructure.
8. Your choices and privacy rights
Depending on where you live, you may have rights to ask for access to or correction of your personal information, request deletion or restriction, object to certain processing, receive a portable copy, or complain to a privacy regulator. We may need to verify your identity before acting on a request, and legal exceptions may apply.
You can disconnect a social account from the Channels screen, delete completed publishing items from History, cancel a paid subscription through the billing controls made available in ClipFlight or by the provider identified at checkout, and ask us to close your ClipFlight account by email.
9. Contact and changes
For privacy questions, access requests, deletion requests or complaints, email support@clipflight.com. Please do not send passwords, OAuth tokens or platform secrets.
We may update this policy when the service or applicable requirements change. The effective date at the top of this page will be revised when we do.