Clippr AI Clippr.ai
Data Privacy & Security Standard

Global Privacy Policy

Effective Date: September 30, 2026 • Compliant with GDPR, CCPA/CPRA, and CalOPPA

1. Commitment to Data Sovereignty

At Clippr AI (operated by CyberMonarch Autonomous Technologies), we engineer privacy by design. We strictly do not sell, rent, or trade your personal information to third parties, data brokers, or advertising exchanges. This policy outlines what minimal data is collected, how it is processed to deliver our video synthesis tools, and your absolute statutory rights.

2. Information We Collect & Process

  • Account & License Telemetry: Email address, Whop User ID, active subscription tier, and API license keys necessary to authenticate and permit video export.
  • Operational Logs & Session State: IP addresses, browser user-agent, request timestamps, and rate-limiting metrics to protect GPU infrastructure from automated denial-of-service attacks.
  • Local Storage Preferences: Audio haptic preferences (muted/unmuted) and studio UI composition states stored solely in your client browser's local memory.

3. Zero-Sale Policy (CCPA / CPRA Invariant)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents are guaranteed the right to opt out of the sale or sharing of their personal information.

🛡️ SOVEREIGN INVARIANT: Clippr AI has never sold, does not currently sell, and will never sell personal information to any third party for financial or other valuable consideration.

4. Third-Party Processors & Merchant of Record

We partner only with security-certified, industry-leading processors:

  • Whop Inc.: Merchant of Record for subscription billing and tax compliance. Clippr never sees or stores full payment card numbers (PCI-DSS Level 1 certified).
  • Cloudflare Inc.: DDoS protection, edge caching, and Zero Trust ingress routing.
  • Direct GPU Cloud & Local Nodes: Neural transcription and FFmpeg 60FPS video assembly executed in isolated runtime sandboxes.

5. European Union & UK Data Subject Rights (GDPR)

If you reside within the European Economic Area (EEA) or UK, you possess statutory rights under Articles 15-22 of the GDPR:

  • Right of access and data portability.
  • Right to rectification of inaccurate personal data.
  • Right to erasure ("Right to be Forgotten") from our customer databases.
  • Right to restrict or object to automated data processing.

To exercise any GDPR right, contact our Data Protection Officer at [email protected]. Requests are completed within 30 days without cost.

6. Data Retention & Cryptographic Security

All API communications and browser sessions utilize TLS 1.3 encryption. Video renders in the ephemeral studio buffer are purged automatically on rolling 72-hour lifecycles unless explicitly downloaded by the subscriber. Local SQLite databases employ strict write-ahead logging (WAL) and access privilege sandboxing.