Last updated 7 September 2026
Clipsourced helps a business plan and publish its own social content. This policy explains exactly what we collect, why, who else sees it, and how to get it deleted. It is written to be read, not to be survived.
Clipsourced is operated by Ravinaro (registered entity details available on request from privacy@ravinaro.com). For personal data described in this policy we act as the controller, except where stated otherwise in section 3.
Privacy contact: privacy@ravinaro.com.
| Category | What it is | Where it comes from |
|---|---|---|
| Account | Email address, hashed password, role, the workspaces you belong to, last sign-in time | You, at sign-up |
| Workspace | Business name, brand profile and palette, logo, competitor handles, settings | You, or derived from a website address you give us |
| Session | A signed session token in a cookie, its creation time, and the IP address used for rate limiting | Automatically, when you sign in |
| Connected accounts | Access tokens, the platform user id and the handle for each social account you connect | The platform, after you authorise it |
| Content | Uploaded clips and images, generated assets, ideas, captions, publishing schedule and history | You, and our generation pipeline |
| Billing | Plan, renewal date, credit ledger entries, Stripe customer and subscription identifiers | You and Stripe. We never see or store your card details. |
| Audit | A record that a security-relevant action happened — who, what action, when | Automatically. Secret values are never written to it. |
We do not collect special category data, we do not buy personal data from data brokers, and we do not run advertising or cross-site tracking on this service.
When you connect Instagram, LinkedIn or TikTok, that platform gives us an access token scoped
to what you approved on its own consent screen. We ask for the minimum needed to publish on your
behalf and to show you which account is connected — for Instagram that is
instagram_business_basic and instagram_business_content_publish, and
nothing else.
With that token we: read the account's id and username so the app can show you what is connected, and create posts that you have approved. We do not read your direct messages, we do not post without an action from you, and we do not use platform data to build profiles of anyone or to train models.
The product only proposes an idea when it can cite a real post that already performed. To do that we retrieve publicly visible posts and their public engagement counts from accounts you choose to watch — typically your own accounts and competitors in your market. We store the post's public metrics, a link to it, and enough of its content to justify the citation.
We do not collect private posts, follower lists, contact details, or anything behind a login. If you are the author of a public post in our corpus and want it removed, email privacy@ravinaro.com with the link and we will delete it, normally within 30 days.
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the service — accounts, workspaces, generation, publishing | Performance of a contract |
| Billing, plan limits and credit accounting | Performance of a contract; legal obligation for tax records |
| Security: rate limiting, session integrity, the audit trail | Legitimate interests — keeping accounts and workspaces from being taken over |
| Analysing public posts to source and evidence ideas | Legitimate interests — market and competitor research, using only content the author published publicly |
| Service email: password resets, invitations, expiry warnings | Performance of a contract |
| Keeping records to defend or bring legal claims | Legitimate interests |
Where UAE Federal Decree-Law No. 45 of 2021 applies, we rely on the equivalent grounds: performance of a contract with you, our legitimate interests, and compliance with law.
We use third-party models to classify public posts, draft copy, and generate images. Three commitments govern that, and they are enforced in the code, not just stated here:
AI output can be wrong, generic, or unsuitable. Review it before it goes out — see the Terms.
We do not sell personal data. We share it only with the providers that make the service work:
| Provider | What it handles |
|---|---|
| Cloudflare | Hosting, the databases and the media store. All application data lives here. |
| Anthropic | Classification of public posts and drafting of copy. |
| OpenAI, Freepik | Image generation, when you use it. |
| ScrapeCreators | Retrieval of public posts and public metrics. |
| Meta, LinkedIn, TikTok | The publishing destinations you connect, when you publish. |
| Stripe | Payments and subscriptions. Stripe is the controller of your card data. |
| Resend | Transactional email — resets, invitations, warnings. |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If the business is ever sold or reorganised, data may transfer with it; this policy continues to apply until you are told otherwise.
Ravinaro operates from the United Arab Emirates and the United States, with customers and providers in the European Union. Personal data therefore moves between the UAE, the US and the EU. Where data leaves the UK or EEA we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one exists. Where UAE PDPL applies to a transfer, we rely on adequacy or on contractual safeguards binding the recipient to PDPL-equivalent protection.
| Data | Kept for |
|---|---|
| Account and workspace | While the account exists, then deleted on closure |
| Sessions | 14 days, or until you sign out |
| Password reset and invitation links | 1 hour and 14 days respectively; single use |
| Connected-account tokens | Until you disconnect, the platform revokes them, or the account closes |
| Rate-limit counters | Rolling window, hours |
| Content, ideas, assets and publishing history | While the workspace exists |
| Public-post corpus | Rolling 365-day window |
| Billing and credit records | Up to 7 years, where tax and accounting law requires it |
| Audit trail | Up to 24 months |
Deletion is free. We will never charge for it or make you talk to a salesperson first.
Before you delete, Settings → Export gives you a machine-readable copy of the workspace. We may keep the minimum needed for legal, tax or fraud-prevention reasons, and backups age out on their own cycle.
Subject to the law that applies to you, you can ask for: access to your data, correction, deletion, restriction of processing, portability, and objection to processing we base on legitimate interests. You can also withdraw consent where we relied on it, without affecting what came before.
Email privacy@ravinaro.com. We reply within 30 days. There is no fee. If you are unhappy with the outcome you can complain to your local data protection authority, or in the UAE to the UAE Data Office.
No system is perfect. If you find a vulnerability, please tell us at support@ravinaro.com before disclosing it publicly; we will not pursue good-faith researchers.
We use two, both strictly necessary, neither used for tracking or advertising: a session cookie that keeps you signed in, and a small preference that remembers light or dark mode. There are no analytics, advertising or third-party tracking cookies on this service, which is why you are not being shown a consent banner.
Clipsourced is a business tool and is not directed at children. Do not use it if you are under 18. If we learn we hold a child's personal data we delete it. Contact privacy@ravinaro.com.
If we make a material change we will update the date at the top and, for significant changes, tell account holders by email before it takes effect. Continuing to use the service after that means you accept the updated policy.
Privacy: privacy@ravinaro.com · Everything else: support@ravinaro.com