Last updated 14 September 2026
AGclips turns long videos into short vertical clips. This page explains what we hold, why we hold it, and what you can make us do about it. It is written to be read rather than to be survived.
AGclips is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For data protection purposes we are the data controller for the information described below.
| What | Why | Where |
|---|---|---|
| Your email address | To identify your account and send account-related email | Supabase |
| Video you upload, and the clips made from it | It is the thing the product makes. Kept so you can come back to it | Our server, plus Cloudflare R2 for durability |
| Transcripts, face-tracking data, thumbnails | Working files produced while making your clips | Our server. Rebuildable, and not backed up |
| Your settings, brand kits, presets | So the studio looks the same next time | Our server, plus Cloudflare R2 |
| Access tokens for social accounts you link | Only to post the clips you tell us to post | Our server, in a database separate from your work |
Sign-in goes from your browser straight to Supabase, our authentication provider, over an encrypted connection. Our servers never receive it, and there is nothing for us to leak. We receive only a signed token proving who you are, and we store only the account identifier inside it.
Your video is processed on our own machines and is not sent to any third-party AI service. Transcription, face detection, framing and rendering all run on servers we control, using software installed on them.
The one exception is optional and never automatic: if you choose to use the Pro editor's audio-cleanup feature and it is configured to use a hosted speech service, the audio for that clip is sent to that provider to be processed. Nothing is sent anywhere until you press the button.
We do not use your video to train models — not ours, not anybody else's. We do not sell it, license it, or show it to anyone. Staff do not watch it except where you have asked for support and given permission, or where we are legally required to.
Two, both strictly necessary, and no others:
Both are HttpOnly, which means scripts running in the page cannot read them, and both are marked Secure over HTTPS. There are no advertising cookies, no analytics cookies and no third-party trackers on this site. That is also why you are not asked to dismiss a cookie banner: there is nothing to consent to.
If you connect TikTok, YouTube, Instagram, Facebook or Snapchat, we store the access tokens those services give us. We use them for exactly two things: posting the clips you ask us to post, and — where the platform offers it — reading back how a clip you published performed, so the studio can show you.
We never post anything you have not asked us to post. You can unlink an account at any time in Settings, which deletes the stored tokens.
If you use the Analytics dashboard to track a public account, we read that account's public profile and recent posts — the same information the platform shows anybody — about once a day, and cache it. We do not access anything private, and we do not track individuals.
Each is used for that purpose alone. We do not share your data with anyone else, and we do not sell it to anyone under any circumstances.
Our servers are in [DATACENTRE LOCATION]. Object storage is provided by Cloudflare R2. If you are outside that region, your data will be transferred there in order to provide the service.
Your work stays until you delete it or close your account. Deleting a video in the Library removes it from our servers and from object storage. Closing your account removes everything belonging to it.
Working files — transcripts, thumbnails, tracking caches — may persist a little longer while caches are cleared, and are deleted with the source they were made from.
You can ask us to:
Email us and we will do it. We will not make you justify the request. If you are in the UK or EU and think we have handled your data badly, you have the right to complain to your data protection regulator — in the UK that is the Information Commissioner's Office at ico.org.uk.
Connections are encrypted. Sign-in tokens are held in cookies that scripts cannot read. Each account's files are kept in a separate area and requests are checked against the account making them.
No service can promise it will never be breached. If yours is affected by one, we will tell you, and we will tell you what actually happened.
If this policy changes in a way that matters, we will say so on this page and, for anything significant, by email. The date at the top is always the date of the current version.
Questions, requests, or complaints: [email protected]. We answer these ourselves.