Legal

Privacy Policy

Last updated: 3 August 2026

About this document. This policy was written by reading the shipping code and the database schema, not by filling in a template. Every claim in it describes something the software actually does today, and where a practice is still being tightened, it says so instead of rounding up. That makes it accurate. It does not make it legal advice, and it has not been reviewed by a lawyer. Have qualified counsel review it before you rely on it.

1. Who we are and how to contact us

ClipLogger is three things: a native macOS application, a web account at cliplogger.com, and an optional cloud batch analysis service called Rush.

The data controller for everything described in this policy is Sous Creative LLC, a Florida limited liability company, of 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States. ClipLogger is a product of Sous Creative LLC

For any privacy question or request, email hello@cliplogger.com. Put "Privacy" in the subject line so it gets routed correctly.

We have not appointed a Data Protection Officer. At our size we are not required to have one, and the address above reaches someone who can answer.

If you are in the EEA or the UK, you can reach us at the address above or by email, and you can complain to your own national data protection authority. We answer rights requests within one month wherever you live

2. The short version

This is a summary. The rest of the document governs.

  1. The app runs without us. ClipLogger works with no account, no sign-in, and no network connection. Offload, browsing, projects, subjects, logging, on-device AI, renaming, and every export work offline.
  2. We never hold your footage. Not on the free tier, not on a paid plan, not during a Rush job. There is no field in our database that could store a video file.
  3. An account holds business records, not creative work. Your email, your display name, a Stripe customer reference, your subscription and credit history, your team membership, and records of the Rush jobs you ran.
  4. Nothing follows you around. The website counts page views with a cookie-free analytics tool and measures page speed; both are described precisely in section 2 and in the Cookie Policy, and neither stores anything on your device or builds a profile of you. There are no advertising pixels, no session recording, no heatmaps, no cross-site trackers. The desktop app sends no telemetry at all. Fonts are served from our own domain, so no font provider ever sees your IP address.
  5. One default is ON, and you should know about it. If your media lives on a JuiceMount server, ClipLogger publishes the metadata it derives back to that server so your team can see it. Section 3 explains exactly what travels and how to turn it off.

3. The product model: local-first by default

ClipLogger requires macOS 15 or later on Apple silicon.

Local-first is not a slogan here, it is the default execution path. Concretely:

  • You can download the app, point it at a card or a drive, and do a full day of work without ever creating an account.
  • Analysis runs on-device by default. Frames are extracted, examined, and discarded on your Mac.
  • The metadata ClipLogger produces is written to sidecar files named .logger.json, stored beside your own footage on your own disks. The format is open and documented, so the data stays readable with or without us.
  • None of that reaches our servers. We could not produce a copy if asked.

The honest exception: publishing to a JuiceMount server

There is one case where ClipLogger sends derived metadata somewhere without you pressing a button each time. If your media is stored on a JuiceMount server, ClipLogger publishes the metadata it derives back to that server, so the rest of your team sees your work. Two settings control this, in Settings, Sharing & Privacy, and both are ON by default.

  • What travels: derived metadata only. Transcript text, text read from the image (OCR), embeddings, the identifiers and image regions ClipLogger uses to group the same face across clips, tags, and notes.
  • What does not travel: your footage. The media files are not uploaded by this feature.
  • Where it goes: to the JuiceMount server that holds your media, which is normally a server you or your organisation runs. This feature does not send anything to us.
  • How long it is kept there: that is decided by whoever operates that server, not by us.
  • How to stop it: turn both settings off in Settings, Sharing & Privacy, ideally before you connect a JuiceMount volume.

4. What we collect, by situation

Each table lists the data, why we hold it, the GDPR Article 6 basis, and how long it stays.

(a) Visiting the website

DataPurposeLegal basisRetention
Browsing a public page: nothing is stored in your browser — no cookie, no localStorage, no sessionStorage. Fonts come from our own domain.Showing you the pages you asked forNo storage on your device, so no consent is requiredNot applicable
Page-view measurement via Simple Analytics (Netherlands): page path, user agent, browser/OS, screen size, language, time zone, and an in-memory visit id that is never written to your device. Your IP reaches them, is used to derive a country, and is not stored. Honours Do Not Track.Knowing which pages are actually readLegitimate interests, Art. 6(1)(f)Aggregated statistics; no per-visitor record to retain
Page-speed measurement via Netlify Real User Metrics: load timings for the page you requested, reported to the host that already served itKnowing whether pages load quickly enough to useLegitimate interests, Art. 6(1)(f)Provider defaults
Server request logs at our hosting and database providers: IP address, timestamp, path requested, user agent, response statusDelivering the site, diagnosing failures, blocking abuseLegitimate interests, Art. 6(1)(f)Provider defaults. 7 days

(b) Creating an account

DataPurposeLegal basisRetention
Email addressIdentifying your account, signing you in, sending account and receipt emailContract, Art. 6(1)(b)Life of the account
Password, stored only as a salted hash by our authentication provider. We never see or store the plaintext.Signing you inContract, Art. 6(1)(b)Life of the account
Display nameShowing who you are to yourself and to teammatesContract, Art. 6(1)(b)Life of the account
Account timestamps and sign-in metadata (created at, last sign-in, email confirmation state)Running the account, detecting abuse of the free trial creditsContract, Art. 6(1)(b) and legitimate interests, Art. 6(1)(f)Life of the account

Providing this data is a contractual requirement for having an account. Without it we cannot create one. You are free to use the app with no account at all.

(c) Buying a plan, seats, or a credit pack

Payments are handled by Stripe. Card numbers, expiry dates, and security codes never reach our servers or our database. Stripe Managed Payments is enabled, so Stripe is the merchant of record and handles sales tax and VAT.

DataPurposeLegal basisRetention
Stripe customer identifier stored on your profileLinking your account to your billing records so credits land in the right placeContract, Art. 6(1)(b)Life of the account, then as long as tax law requires
Subscription record: plan, status, seat count, current period start and endGranting the right entitlements and creditsContract, Art. 6(1)(b)Life of the account
Credit ledger entries: amount, reason, kind, the Stripe event that caused it, and which team member spent the creditComputing your balance, showing your history, preventing double-spendContract, Art. 6(1)(b)Retained after account deletion where it forms part of a financial record. See section 9.
Invoices and receipts, held by StripeMeeting invoicing and tax obligationsLegal obligation, Art. 6(1)(c)As required by tax law

Auto top-up exists, it is opt-in, and it is off by default. If you turn it on, it charges the card Stripe already holds for you when your balance runs low. You can turn it off at any time.

(d) Submitting a Rush job

Rush only runs when you explicitly submit a batch. The default engine is on-device.

DataPurposeLegal basisRetention
Extracted frames (still images pulled from your clips) uploaded to our storage. The video files themselves are not uploaded.Sending to a model provider for analysis, and re-running the job if it failsContract, Art. 6(1)(b)See section 9. This is the one window we cannot state as a fixed number today.
Job and per-clip records: clip identifiers, status, timings, token counts, measured cost, error reasonsRunning the job, settling credits correctly, showing you what happened, diagnosing failuresContract, Art. 6(1)(b)Life of the account
The analysis results returned by the providerHanding the result back to your Mac, where it is written into your own sidecar filesContract, Art. 6(1)(b)Life of the account, unless you delete the job

Credits are reserved when you submit and settled when the job finishes. Clips that process burn a credit, clips that fail burn nothing, and the difference is refunded to your balance automatically.

On training. We build no models and we train nothing on your data, ever. Frames go to the model provider handling that job and are governed by that provider's terms. Anthropic states that inputs submitted through its API are not used to train its models by default. We grant no provider permission to train on your content.

(e) Turning on project sync

Project sync is off until you turn it on. When you do, your project documents and their revision history are stored on our infrastructure so your devices, and your teammates, can see the same project.

DataPurposeLegal basisRetention
Your project documents and their revisions. These contain metadata you authored, which can include the names of people you logged, for example an athlete roster or a cast list.Syncing a project between your devices and your teamContract, Art. 6(1)(b)Until you delete the project or the account

This is the only place we hold personal data about other people on your behalf. When that happens you are the controller of those names and we act as your processor, handling them only on your instructions.

If you use project sync and need a signed data processing agreement, our Data Processing Addendum covers it.

If your name appears in someone else's project and you did not put it there, we received it from that customer, not from you. Contact them first, since they decide what the project contains. If you cannot reach them, email hello@cliplogger.com and we will help you identify the controller and pass the request on.

(f) Joining or running a team

DataPurposeLegal basisRetention
Team membership record: member user id, role, revoked stateRunning seats and pooled credits, controlling who can do whatContract, Art. 6(1)(b)Life of the team, or until the member is removed
Invite token and the invited email addressDelivering the invitation and letting the right person accept itContract, Art. 6(1)(b)Until the invite is accepted, revoked, or expires
Which member spent each credit, recorded on the ledger entryLetting the account owner see where pooled credits went, resolving disputesContract, Art. 6(1)(b), and legitimate interests, Art. 6(1)(f), of the account ownerWith the ledger. See section 9.

If you are on a team, your account owner can see your team membership, your role, and the credits spent under your seat. They cannot see the contents of your projects unless you sync those projects to the shared team account.

(g) Writing to us

The contact form at cliplogger.com/contact is hosted by Netlify, the same host as the rest of the site, so nothing new leaves for a new company. It has no CAPTCHA and loads no third-party script: a hidden field catches bots instead.

DataPurposeLegal basisRetention
Your name and email addressReplying to youLegitimate interests, Art. 6(1)(f): you asked us a question and expect an answerKept with the correspondence, then deleted when it is no longer needed
The topic and your messageAnswering, and fixing what you reportedLegitimate interests, Art. 6(1)(f)As above
Your confirmation that you understood thisShowing we told you before you sent itLegitimate interests, Art. 6(1)(f)As above

If your message is a data request (access, correction, export or deletion) we use it only to answer that request, and we answer within one month.

Every purpose above maps to one of these:

  • Performance of a contract, Art. 6(1)(b). Creating and running your account, subscriptions and seats, granting and settling credits, running the Rush jobs you submit, syncing the projects you chose to sync, and answering your support requests.
  • Legal obligation, Art. 6(1)(c). Keeping invoice, payment, and tax records for the period the law requires.
  • Legitimate interests, Art. 6(1)(f). Keeping the service secure and available, preventing fraud and abuse of the free trial credits, understanding failures from server logs, measuring which pages are read and how fast they load, and establishing or defending legal claims. In each case our interest is running a service that stays up and does not get defrauded, the data involved is minimal and operational, and we consider the effect on you to be low. You can object at any time. See section 10.
  • Consent, Art. 6(1)(a). We do not currently rely on consent for anything. The analytics we run store nothing on your device, so they do not trigger the consent rule in the ePrivacy Directive or PECR, and we send no marketing email. If we ever add something that does store or read information on your device, or anything that tracks you across sites, we will ask you first, the choice will be genuinely optional, and you will be able to withdraw it as easily as you gave it.

6. Sub-processors

These are the companies that process personal data on our behalf. Each is bound by a contract that limits what they can do with it.

Sub-processorRoleLocation
SupabaseAuthentication, Postgres database, file storageAWS us-east-1, United States
NetlifyWebsite hosting, serverless functions, request logsUnited States
StripePayment processing, merchant of record, billing portalUnited States and global
AnthropicRush model provider: frames are sent for analysis. Anthropic does not train on API inputs, and retains them for up to 30 days for trust and safety.United States
OpenRouterRush model provider: routes frames to a model vendor. Every request we send demands no-retention routing, so a vendor that stores prompts is never used.United States
Simple AnalyticsCookie-free page-view counting on the website. Receives the values listed in section 2. Does not run on the desktop app.Netherlands, European Union

Account email (sign-in links, confirmations, receipts) is sent through our authentication provider's built-in mailer, so no separate email vendor is involved. Account email (sign-in links, password resets) is sent by Supabase, which is already listed above. We use no separate email provider. If that changes, this table changes first

Changes. We update this table before a new sub-processor starts handling personal data, and note the change in the "last updated" date. Account holders get an email about any addition that materially changes where data is processed.

7. International transfers

All processing happens in the United States. If you are in the EEA, the UK, or Switzerland, that means your personal data is transferred out of your region under Chapter V of the GDPR.

Every sub-processor listed above publishes a data processing agreement incorporating the EU Standard Contractual Clauses, and, for UK data, the UK International Data Transfer Addendum. Those clauses are the transfer mechanism we rely on. They bind the recipient to European-standard protections and give you enforceable rights against them.

In practice this means your data sits on United States infrastructure, and United States authorities can in principle make legal demands of a United States provider. The clauses require those providers to challenge overbroad demands and, where lawful, tell us about them.

Each of these publishes a data processing agreement incorporating the Standard Contractual Clauses, and each takes effect on our acceptance of that vendor's terms

8. Security

  • Row Level Security is enabled on the database tables that hold user data. Your session can read only the rows belonging to you or your team, enforced by the database itself rather than by application code.
  • Writes to the sensitive tables (the credit ledger, subscriptions, job records) come only from our server-side functions, using a privileged key that never leaves the server. No browser can mint credits or rewrite history.
  • No card data is held by us. Card details go from your browser to Stripe. We store only a Stripe customer reference.
  • Passwords are stored only as salted hashes by our authentication provider.
  • On your Mac, the desktop app stores its sign-in token in the macOS Keychain, protected by the operating system, not in a plain file.
  • In transit, everything moves over HTTPS.

No system is perfect. If we discover a breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.

9. How long we keep things

CategoryRetention
Account records (profile, display name, authentication record)For as long as your account exists. Deleted or anonymised after you close it.
Subscription and team membership recordsLife of the account or the team.
Credit ledger, invoices, and payment recordsKept after account deletion for as long as tax and accounting law requires, typically six to seven years. This is a legal obligation carve-out: we cannot delete a financial record on request, and we will tell you so if you ask.
Rush job and per-clip recordsLife of the account, unless you delete the job.
Rush framesFrames are working data for the job. Our sweep process deletes them once a retention window is configured, and today that window is not set, which means frames from completed jobs stay in storage until we remove them by hand. We would rather tell you that than quote a number we do not enforce. We keep the frames from a Rush job for as long as we need them, and no longer. In practice that means for as long as the job record exists, because that is what lets a result be traced back to what produced it and lets us investigate if you tell us a result was wrong. There is no fixed calendar window, so the criteria are the honest answer: the frames go when the job goes. Delete the job, ask us to delete it, or close your account, and they are removed
Synced project documents and revisionsUntil you delete the project, or delete your account.
Server logs (hosting and database)Provider defaults. Both are retained for 7 days
Metadata published to your JuiceMount serverControlled by whoever operates that server. Not by us.

10. Your rights

If the GDPR or UK GDPR applies to you, you have all of the following. To exercise any of them, email hello@cliplogger.com from the address on your account, or tell us which account you are asking about so we can verify you.

  • Access. Ask for a copy of the personal data we hold about you, and the information in this policy applied to your specific record.
  • Rectification. Ask us to correct anything wrong. You can change your display name and email in the account area yourself.
  • Erasure. Ask us to delete your account and the personal data attached to it. There is no self-serve delete button today, so email us and we will do it. Financial records covered by section 9 survive deletion, and we will tell you exactly what was kept and why. Anything on your own Mac is untouched, because it was never ours. A self-serve delete control is on the roadmap. Until it ships, email us and we will do it
  • Restriction. Ask us to stop processing your data while a dispute about its accuracy or our legal basis is resolved.
  • Portability. Ask for the data you gave us, and the data generated by your use of the service, in a structured, machine-readable format. Your .logger.json sidecars are already yours in an open format, on your own disks, with no request needed.
  • Objection. Object to any processing we base on legitimate interests (section 5). We will stop unless we can show compelling grounds that override your interests.
  • Withdrawing consent. We do not currently rely on consent for anything. If we ever do, withdrawing it will be one click, and it will not affect processing that already happened.
  • Complaining to a supervisory authority. You can complain to the data protection authority in the country where you live or work, or where you believe the problem happened. In the UK that is the Information Commissioner's Office. We would rather you came to us first, but you do not have to.

Our response time. We answer within one month of receiving your request. If a request is unusually complex, we can extend by up to two further months, and we will tell you about the extension, with the reason, inside the first month. We do not charge for this.

11. California residents (CCPA/CPRA)

If you live in California, you have the right to know what personal information we collect and why, the right to delete it, the right to correct it, and the right to opt out of sale or sharing.

We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. We never have. There is no opt-out to click because there is nothing to opt out of.

We do not process sensitive personal information for the purpose of inferring characteristics about you.

The categories we collect map to the tables in section 4: identifiers (email, display name, account and customer identifiers), commercial information (your subscription, credit, and purchase history), internet or network activity (server request logs only, no browsing profile), and the content you choose to submit to Rush or to project sync. We collect these for the business purposes stated in section 4 and disclose them only to the sub-processors in section 6, who are contractually barred from using them for their own purposes.

To make a request, email hello@cliplogger.com. We verify you by matching the request against the email on the account. Authorised agents are welcome, with proof of authority. We will not discriminate against you for exercising any of these rights. Your price, your credits, and your access do not change.

12. Automated decision-making

ClipLogger's AI produces suggestions, and suggestions are proposals. Tags, groupings, names, and log entries proposed by the model are shown to you for review, and they take effect when a human confirms them. You can reject any of them, and rejecting one teaches the app for next time.

We make no decision about you that produces a legal effect or a similarly significant effect by automated means. There is no automated profiling, no scoring of you as a person, and no automated decision about your access, pricing, or eligibility.

13. Children

ClipLogger is a professional tool. It is not directed at children and is not designed or marketed for anyone under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, email hello@cliplogger.com and we will delete it.

14. Changes to this policy

When this policy changes, we update the "last updated" date at the top. For changes that materially affect how we handle your personal data, such as adding a sub-processor or relying on a new legal basis, we email account holders before the change takes effect. The previous version stays available on request, so you can see what changed.

Questions about any of this: hello@cliplogger.com.