Last updated: July 12, 2026
Privacy Policy
Data we process
We process identity/authentication records, selected role and 18+ attestation, campaigns and submissions, moderation/audit events, the internal journal, Ethereum addresses, transaction/log identifiers, and withdrawal records.
YouTube and TikTok
YouTube linking uses youtube.readonly separately from Google sign-in. TikTok uses user.info.basic, user.info.profile, user.info.stats, and video.list. We read provider identity, public video metadata, followers, and available engagement counts for ownership, eligibility, ranking, and settlement; we do not publish content on a user's behalf.
Reference assets
For Banner and Music, we store the uploaded file in private object storage with an opaque object key, SHA-256, MIME type, size, duration, owner, and attachment status. Object keys and owners are never exposed by public APIs. Unattached uploads become unavailable after 24 hours and closed-campaign files after 180 days. The hash and minimal audit metadata may be retained longer for disputes and immutability evidence.
Publication descriptions and comments
When a campaign requires a caption or pinned comment, raw provider text is used only while the check runs and is not retained. We retain the result, a minimal evidence hash, and the operational metadata needed for audit and the final recheck. Public projections expose only an aggregate status and general reason; the internal checklist is admin-only.
Use and sharing
Verified metrics, review status, forecast, and settlement lines are shared with the relevant campaign parties. Our infrastructure, email, private storage, RPC, and monitoring providers process data only as needed to operate the service. We do not sell provider data.
Tokens and security
OAuth state is single-use and stored as a hash. Provider tokens are encrypted with expiry, scopes, and key version. The session cookie is Secure, HttpOnly, and SameSite. Treasury private keys and the deposit xprv are absent from the public API/app host; an approved immutable batch hash is signed locally.
Retention
Without a separate YouTube derived-metrics/storage permission, provider metadata and statistics are refreshed or deleted under a 30-day policy. The financial journal, on-chain events, withdrawals, refunds, and security/admin audit may be retained longer for legal, security, accounting, or dispute requirements.
Deletion, disconnect, and revoke
A user can disconnect a provider account in the UI or revoke access at the provider. ClipIndex invokes provider revoke, removes active tokens/provider data, and stops metrics. Account deletion pseudonymizes the owner but does not cascade-delete retained financial/audit records.
Rights and contact
For access, correction, deletion, provider revoke, or data questions, contact support@clipindex.app. A request may require identity verification, especially when financial records or a refund are involved.