Clipsourced

Privacy Policy

Last updated 7 September 2026

Clipsourced helps a business plan and publish its own social content. This policy explains exactly what we collect, why, who else sees it, and how to get it deleted. It is written to be read, not to be survived.

Contents
  1. Who we are
  2. What we collect
  3. Data from connected social accounts
  4. Public content we analyse
  5. Why we process it, and our legal basis
  6. How AI models are used
  7. Who we share data with
  8. International transfers
  9. How long we keep things
  10. Deleting your data
  11. Your rights
  12. Security
  13. Cookies
  14. Children
  15. Changes and contact

1. Who we are

Clipsourced is operated by Ravinaro (registered entity details available on request from privacy@ravinaro.com). For personal data described in this policy we act as the controller, except where stated otherwise in section 3.

Privacy contact: privacy@ravinaro.com.

2. What we collect

CategoryWhat it isWhere it comes from
AccountEmail address, hashed password, role, the workspaces you belong to, last sign-in timeYou, at sign-up
WorkspaceBusiness name, brand profile and palette, logo, competitor handles, settingsYou, or derived from a website address you give us
SessionA signed session token in a cookie, its creation time, and the IP address used for rate limitingAutomatically, when you sign in
Connected accountsAccess tokens, the platform user id and the handle for each social account you connectThe platform, after you authorise it
ContentUploaded clips and images, generated assets, ideas, captions, publishing schedule and historyYou, and our generation pipeline
BillingPlan, renewal date, credit ledger entries, Stripe customer and subscription identifiersYou and Stripe. We never see or store your card details.
AuditA record that a security-relevant action happened — who, what action, whenAutomatically. Secret values are never written to it.

We do not collect special category data, we do not buy personal data from data brokers, and we do not run advertising or cross-site tracking on this service.

3. Data from connected social accounts

When you connect Instagram, LinkedIn or TikTok, that platform gives us an access token scoped to what you approved on its own consent screen. We ask for the minimum needed to publish on your behalf and to show you which account is connected — for Instagram that is instagram_business_basic and instagram_business_content_publish, and nothing else.

With that token we: read the account's id and username so the app can show you what is connected, and create posts that you have approved. We do not read your direct messages, we do not post without an action from you, and we do not use platform data to build profiles of anyone or to train models.

Disconnecting. Removing the connection in Settings → Publishing connections, or removing the app from the platform's own settings, deletes our copy of that token. For Meta we also honour the deauthorize and data-deletion callbacks automatically — see section 10.

4. Public content we analyse

The product only proposes an idea when it can cite a real post that already performed. To do that we retrieve publicly visible posts and their public engagement counts from accounts you choose to watch — typically your own accounts and competitors in your market. We store the post's public metrics, a link to it, and enough of its content to justify the citation.

We do not collect private posts, follower lists, contact details, or anything behind a login. If you are the author of a public post in our corpus and want it removed, email privacy@ravinaro.com with the link and we will delete it, normally within 30 days.

5. Why we process it, and our legal basis

PurposeLegal basis (UK/EU GDPR)
Providing the service — accounts, workspaces, generation, publishingPerformance of a contract
Billing, plan limits and credit accountingPerformance of a contract; legal obligation for tax records
Security: rate limiting, session integrity, the audit trailLegitimate interests — keeping accounts and workspaces from being taken over
Analysing public posts to source and evidence ideasLegitimate interests — market and competitor research, using only content the author published publicly
Service email: password resets, invitations, expiry warningsPerformance of a contract
Keeping records to defend or bring legal claimsLegitimate interests

Where UAE Federal Decree-Law No. 45 of 2021 applies, we rely on the equivalent grounds: performance of a contract with you, our legitimate interests, and compliance with law.

6. How AI models are used

We use third-party models to classify public posts, draft copy, and generate images. Three commitments govern that, and they are enforced in the code, not just stated here:

AI output can be wrong, generic, or unsuitable. Review it before it goes out — see the Terms.

7. Who we share data with

We do not sell personal data. We share it only with the providers that make the service work:

ProviderWhat it handles
CloudflareHosting, the databases and the media store. All application data lives here.
AnthropicClassification of public posts and drafting of copy.
OpenAI, FreepikImage generation, when you use it.
ScrapeCreatorsRetrieval of public posts and public metrics.
Meta, LinkedIn, TikTokThe publishing destinations you connect, when you publish.
StripePayments and subscriptions. Stripe is the controller of your card data.
ResendTransactional email — resets, invitations, warnings.

We may also disclose data where we are legally required to, or to establish or defend legal claims. If the business is ever sold or reorganised, data may transfer with it; this policy continues to apply until you are told otherwise.

8. International transfers

Ravinaro operates from the United Arab Emirates and the United States, with customers and providers in the European Union. Personal data therefore moves between the UAE, the US and the EU. Where data leaves the UK or EEA we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one exists. Where UAE PDPL applies to a transfer, we rely on adequacy or on contractual safeguards binding the recipient to PDPL-equivalent protection.

9. How long we keep things

DataKept for
Account and workspaceWhile the account exists, then deleted on closure
Sessions14 days, or until you sign out
Password reset and invitation links1 hour and 14 days respectively; single use
Connected-account tokensUntil you disconnect, the platform revokes them, or the account closes
Rate-limit countersRolling window, hours
Content, ideas, assets and publishing historyWhile the workspace exists
Public-post corpusRolling 365-day window
Billing and credit recordsUp to 7 years, where tax and accounting law requires it
Audit trailUp to 24 months

10. Deleting your data

Deletion is free. We will never charge for it or make you talk to a salesperson first.

Before you delete, Settings → Export gives you a machine-readable copy of the workspace. We may keep the minimum needed for legal, tax or fraud-prevention reasons, and backups age out on their own cycle.

11. Your rights

Subject to the law that applies to you, you can ask for: access to your data, correction, deletion, restriction of processing, portability, and objection to processing we base on legitimate interests. You can also withdraw consent where we relied on it, without affecting what came before.

Email privacy@ravinaro.com. We reply within 30 days. There is no fee. If you are unhappy with the outcome you can complain to your local data protection authority, or in the UAE to the UAE Data Office.

If you contacted one of our customers rather than us — for example your public post is cited inside their workspace — that customer decides what happens in their workspace. Write to us anyway and we will route it and help them act.

12. Security

No system is perfect. If you find a vulnerability, please tell us at support@ravinaro.com before disclosing it publicly; we will not pursue good-faith researchers.

13. Cookies

We use two, both strictly necessary, neither used for tracking or advertising: a session cookie that keeps you signed in, and a small preference that remembers light or dark mode. There are no analytics, advertising or third-party tracking cookies on this service, which is why you are not being shown a consent banner.

14. Children

Clipsourced is a business tool and is not directed at children. Do not use it if you are under 18. If we learn we hold a child's personal data we delete it. Contact privacy@ravinaro.com.

15. Changes and contact

If we make a material change we will update the date at the top and, for significant changes, tell account holders by email before it takes effect. Continuing to use the service after that means you accept the updated policy.

Privacy: privacy@ravinaro.com · Everything else: support@ravinaro.com