Last updated: 3 August 2026
About this document. This policy was written by reading the shipping code and the database schema, not by filling in a template. Every claim in it describes something the software actually does today, and where a practice is still being tightened, it says so instead of rounding up. That makes it accurate. It does not make it legal advice, and it has not been reviewed by a lawyer. Have qualified counsel review it before you rely on it.
1. Who we are and how to contact us
ClipLogger is three things: a native macOS application, a web account at cliplogger.com, and an optional cloud batch analysis service called Rush.
The data controller for everything described in this policy is Sous Creative LLC, a Florida limited liability company, of 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States. ClipLogger is a product of Sous Creative LLC
For any privacy question or request, email hello@cliplogger.com. Put "Privacy" in the subject line so it gets routed correctly.
We have not appointed a Data Protection Officer. At our size we are not required to have one, and the address above reaches someone who can answer.
If you are in the EEA or the UK, you can reach us at the address above or by email, and you can complain to your own national data protection authority. We answer rights requests within one month wherever you live
2. The short version
This is a summary. The rest of the document governs.
- The app runs without us. ClipLogger works with no account, no sign-in, and no network connection. Offload, browsing, projects, subjects, logging, on-device AI, renaming, and every export work offline.
- We never hold your footage. Not on the free tier, not on a paid plan, not during a Rush job. There is no field in our database that could store a video file.
- An account holds business records, not creative work. Your email, your display name, a Stripe customer reference, your subscription and credit history, your team membership, and records of the Rush jobs you ran.
- Nothing follows you around. The website counts page views with a cookie-free analytics tool and measures page speed; both are described precisely in section 2 and in the Cookie Policy, and neither stores anything on your device or builds a profile of you. There are no advertising pixels, no session recording, no heatmaps, no cross-site trackers. The desktop app sends no telemetry at all. Fonts are served from our own domain, so no font provider ever sees your IP address.
- One default is ON, and you should know about it. If your media lives on a JuiceMount server, ClipLogger publishes the metadata it derives back to that server so your team can see it. Section 3 explains exactly what travels and how to turn it off.
3. The product model: local-first by default
ClipLogger requires macOS 15 or later on Apple silicon.
Local-first is not a slogan here, it is the default execution path. Concretely:
- You can download the app, point it at a card or a drive, and do a full day of work without ever creating an account.
- Analysis runs on-device by default. Frames are extracted, examined, and discarded on your Mac.
- The metadata ClipLogger produces is written to sidecar files named
.logger.json, stored beside your own footage on your own disks. The format is open and documented, so the data stays readable with or without us. - None of that reaches our servers. We could not produce a copy if asked.
The honest exception: publishing to a JuiceMount server
There is one case where ClipLogger sends derived metadata somewhere without you pressing a button each time. If your media is stored on a JuiceMount server, ClipLogger publishes the metadata it derives back to that server, so the rest of your team sees your work. Two settings control this, in Settings, Sharing & Privacy, and both are ON by default.
- What travels: derived metadata only. Transcript text, text read from the image (OCR), embeddings, the identifiers and image regions ClipLogger uses to group the same face across clips, tags, and notes.
- What does not travel: your footage. The media files are not uploaded by this feature.
- Where it goes: to the JuiceMount server that holds your media, which is normally a server you or your organisation runs. This feature does not send anything to us.
- How long it is kept there: that is decided by whoever operates that server, not by us.
- How to stop it: turn both settings off in Settings, Sharing & Privacy, ideally before you connect a JuiceMount volume.
4. What we collect, by situation
Each table lists the data, why we hold it, the GDPR Article 6 basis, and how long it stays.
(a) Visiting the website
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Browsing a public page: nothing is stored in your browser — no cookie, no localStorage, no sessionStorage. Fonts come from our own domain. | Showing you the pages you asked for | No storage on your device, so no consent is required | Not applicable |
| Page-view measurement via Simple Analytics (Netherlands): page path, user agent, browser/OS, screen size, language, time zone, and an in-memory visit id that is never written to your device. Your IP reaches them, is used to derive a country, and is not stored. Honours Do Not Track. | Knowing which pages are actually read | Legitimate interests, Art. 6(1)(f) | Aggregated statistics; no per-visitor record to retain |
| Page-speed measurement via Netlify Real User Metrics: load timings for the page you requested, reported to the host that already served it | Knowing whether pages load quickly enough to use | Legitimate interests, Art. 6(1)(f) | Provider defaults |
| Server request logs at our hosting and database providers: IP address, timestamp, path requested, user agent, response status | Delivering the site, diagnosing failures, blocking abuse | Legitimate interests, Art. 6(1)(f) | Provider defaults. 7 days |
(b) Creating an account
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Identifying your account, signing you in, sending account and receipt email | Contract, Art. 6(1)(b) | Life of the account |
| Password, stored only as a salted hash by our authentication provider. We never see or store the plaintext. | Signing you in | Contract, Art. 6(1)(b) | Life of the account |
| Display name | Showing who you are to yourself and to teammates | Contract, Art. 6(1)(b) | Life of the account |
| Account timestamps and sign-in metadata (created at, last sign-in, email confirmation state) | Running the account, detecting abuse of the free trial credits | Contract, Art. 6(1)(b) and legitimate interests, Art. 6(1)(f) | Life of the account |
Providing this data is a contractual requirement for having an account. Without it we cannot create one. You are free to use the app with no account at all.
(c) Buying a plan, seats, or a credit pack
Payments are handled by Stripe. Card numbers, expiry dates, and security codes never reach our servers or our database. Stripe Managed Payments is enabled, so Stripe is the merchant of record and handles sales tax and VAT.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Stripe customer identifier stored on your profile | Linking your account to your billing records so credits land in the right place | Contract, Art. 6(1)(b) | Life of the account, then as long as tax law requires |
| Subscription record: plan, status, seat count, current period start and end | Granting the right entitlements and credits | Contract, Art. 6(1)(b) | Life of the account |
| Credit ledger entries: amount, reason, kind, the Stripe event that caused it, and which team member spent the credit | Computing your balance, showing your history, preventing double-spend | Contract, Art. 6(1)(b) | Retained after account deletion where it forms part of a financial record. See section 9. |
| Invoices and receipts, held by Stripe | Meeting invoicing and tax obligations | Legal obligation, Art. 6(1)(c) | As required by tax law |
Auto top-up exists, it is opt-in, and it is off by default. If you turn it on, it charges the card Stripe already holds for you when your balance runs low. You can turn it off at any time.
(d) Submitting a Rush job
Rush only runs when you explicitly submit a batch. The default engine is on-device.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Extracted frames (still images pulled from your clips) uploaded to our storage. The video files themselves are not uploaded. | Sending to a model provider for analysis, and re-running the job if it fails | Contract, Art. 6(1)(b) | See section 9. This is the one window we cannot state as a fixed number today. |
| Job and per-clip records: clip identifiers, status, timings, token counts, measured cost, error reasons | Running the job, settling credits correctly, showing you what happened, diagnosing failures | Contract, Art. 6(1)(b) | Life of the account |
| The analysis results returned by the provider | Handing the result back to your Mac, where it is written into your own sidecar files | Contract, Art. 6(1)(b) | Life of the account, unless you delete the job |
Credits are reserved when you submit and settled when the job finishes. Clips that process burn a credit, clips that fail burn nothing, and the difference is refunded to your balance automatically.
On training. We build no models and we train nothing on your data, ever. Frames go to the model provider handling that job and are governed by that provider's terms. Anthropic states that inputs submitted through its API are not used to train its models by default. We grant no provider permission to train on your content.
(e) Turning on project sync
Project sync is off until you turn it on. When you do, your project documents and their revision history are stored on our infrastructure so your devices, and your teammates, can see the same project.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Your project documents and their revisions. These contain metadata you authored, which can include the names of people you logged, for example an athlete roster or a cast list. | Syncing a project between your devices and your team | Contract, Art. 6(1)(b) | Until you delete the project or the account |
This is the only place we hold personal data about other people on your behalf. When that happens you are the controller of those names and we act as your processor, handling them only on your instructions.
If you use project sync and need a signed data processing agreement, our Data Processing Addendum covers it.
If your name appears in someone else's project and you did not put it there, we received it from that customer, not from you. Contact them first, since they decide what the project contains. If you cannot reach them, email hello@cliplogger.com and we will help you identify the controller and pass the request on.
(f) Joining or running a team
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Team membership record: member user id, role, revoked state | Running seats and pooled credits, controlling who can do what | Contract, Art. 6(1)(b) | Life of the team, or until the member is removed |
| Invite token and the invited email address | Delivering the invitation and letting the right person accept it | Contract, Art. 6(1)(b) | Until the invite is accepted, revoked, or expires |
| Which member spent each credit, recorded on the ledger entry | Letting the account owner see where pooled credits went, resolving disputes | Contract, Art. 6(1)(b), and legitimate interests, Art. 6(1)(f), of the account owner | With the ledger. See section 9. |
If you are on a team, your account owner can see your team membership, your role, and the credits spent under your seat. They cannot see the contents of your projects unless you sync those projects to the shared team account.
(g) Writing to us
The contact form at cliplogger.com/contact is hosted by Netlify, the same host as the rest of the site, so nothing new leaves for a new company. It has no CAPTCHA and loads no third-party script: a hidden field catches bots instead.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Your name and email address | Replying to you | Legitimate interests, Art. 6(1)(f): you asked us a question and expect an answer | Kept with the correspondence, then deleted when it is no longer needed |
| The topic and your message | Answering, and fixing what you reported | Legitimate interests, Art. 6(1)(f) | As above |
| Your confirmation that you understood this | Showing we told you before you sent it | Legitimate interests, Art. 6(1)(f) | As above |
If your message is a data request (access, correction, export or deletion) we use it only to answer that request, and we answer within one month.
5. Legal bases, in full
Every purpose above maps to one of these:
- Performance of a contract, Art. 6(1)(b). Creating and running your account, subscriptions and seats, granting and settling credits, running the Rush jobs you submit, syncing the projects you chose to sync, and answering your support requests.
- Legal obligation, Art. 6(1)(c). Keeping invoice, payment, and tax records for the period the law requires.
- Legitimate interests, Art. 6(1)(f). Keeping the service secure and available, preventing fraud and abuse of the free trial credits, understanding failures from server logs, measuring which pages are read and how fast they load, and establishing or defending legal claims. In each case our interest is running a service that stays up and does not get defrauded, the data involved is minimal and operational, and we consider the effect on you to be low. You can object at any time. See section 10.
- Consent, Art. 6(1)(a). We do not currently rely on consent for anything. The analytics we run store nothing on your device, so they do not trigger the consent rule in the ePrivacy Directive or PECR, and we send no marketing email. If we ever add something that does store or read information on your device, or anything that tracks you across sites, we will ask you first, the choice will be genuinely optional, and you will be able to withdraw it as easily as you gave it.
6. Sub-processors
These are the companies that process personal data on our behalf. Each is bound by a contract that limits what they can do with it.
| Sub-processor | Role | Location |
|---|---|---|
| Supabase | Authentication, Postgres database, file storage | AWS us-east-1, United States |
| Netlify | Website hosting, serverless functions, request logs | United States |
| Stripe | Payment processing, merchant of record, billing portal | United States and global |
| Anthropic | Rush model provider: frames are sent for analysis. Anthropic does not train on API inputs, and retains them for up to 30 days for trust and safety. | United States |
| OpenRouter | Rush model provider: routes frames to a model vendor. Every request we send demands no-retention routing, so a vendor that stores prompts is never used. | United States |
| Simple Analytics | Cookie-free page-view counting on the website. Receives the values listed in section 2. Does not run on the desktop app. | Netherlands, European Union |
Account email (sign-in links, confirmations, receipts) is sent through our authentication provider's built-in mailer, so no separate email vendor is involved. Account email (sign-in links, password resets) is sent by Supabase, which is already listed above. We use no separate email provider. If that changes, this table changes first
Changes. We update this table before a new sub-processor starts handling personal data, and note the change in the "last updated" date. Account holders get an email about any addition that materially changes where data is processed.
7. International transfers
All processing happens in the United States. If you are in the EEA, the UK, or Switzerland, that means your personal data is transferred out of your region under Chapter V of the GDPR.
Every sub-processor listed above publishes a data processing agreement incorporating the EU Standard Contractual Clauses, and, for UK data, the UK International Data Transfer Addendum. Those clauses are the transfer mechanism we rely on. They bind the recipient to European-standard protections and give you enforceable rights against them.
In practice this means your data sits on United States infrastructure, and United States authorities can in principle make legal demands of a United States provider. The clauses require those providers to challenge overbroad demands and, where lawful, tell us about them.
Each of these publishes a data processing agreement incorporating the Standard Contractual Clauses, and each takes effect on our acceptance of that vendor's terms
8. Security
- Row Level Security is enabled on the database tables that hold user data. Your session can read only the rows belonging to you or your team, enforced by the database itself rather than by application code.
- Writes to the sensitive tables (the credit ledger, subscriptions, job records) come only from our server-side functions, using a privileged key that never leaves the server. No browser can mint credits or rewrite history.
- No card data is held by us. Card details go from your browser to Stripe. We store only a Stripe customer reference.
- Passwords are stored only as salted hashes by our authentication provider.
- On your Mac, the desktop app stores its sign-in token in the macOS Keychain, protected by the operating system, not in a plain file.
- In transit, everything moves over HTTPS.
No system is perfect. If we discover a breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.
9. How long we keep things
| Category | Retention |
|---|---|
| Account records (profile, display name, authentication record) | For as long as your account exists. Deleted or anonymised after you close it. |
| Subscription and team membership records | Life of the account or the team. |
| Credit ledger, invoices, and payment records | Kept after account deletion for as long as tax and accounting law requires, typically six to seven years. This is a legal obligation carve-out: we cannot delete a financial record on request, and we will tell you so if you ask. |
| Rush job and per-clip records | Life of the account, unless you delete the job. |
| Rush frames | Frames are working data for the job. Our sweep process deletes them once a retention window is configured, and today that window is not set, which means frames from completed jobs stay in storage until we remove them by hand. We would rather tell you that than quote a number we do not enforce. We keep the frames from a Rush job for as long as we need them, and no longer. In practice that means for as long as the job record exists, because that is what lets a result be traced back to what produced it and lets us investigate if you tell us a result was wrong. There is no fixed calendar window, so the criteria are the honest answer: the frames go when the job goes. Delete the job, ask us to delete it, or close your account, and they are removed |
| Synced project documents and revisions | Until you delete the project, or delete your account. |
| Server logs (hosting and database) | Provider defaults. Both are retained for 7 days |
| Metadata published to your JuiceMount server | Controlled by whoever operates that server. Not by us. |
10. Your rights
If the GDPR or UK GDPR applies to you, you have all of the following. To exercise any of them, email hello@cliplogger.com from the address on your account, or tell us which account you are asking about so we can verify you.
- Access. Ask for a copy of the personal data we hold about you, and the information in this policy applied to your specific record.
- Rectification. Ask us to correct anything wrong. You can change your display name and email in the account area yourself.
- Erasure. Ask us to delete your account and the personal data attached to it. There is no self-serve delete button today, so email us and we will do it. Financial records covered by section 9 survive deletion, and we will tell you exactly what was kept and why. Anything on your own Mac is untouched, because it was never ours.
A self-serve delete control is on the roadmap. Until it ships, email us and we will do it - Restriction. Ask us to stop processing your data while a dispute about its accuracy or our legal basis is resolved.
- Portability. Ask for the data you gave us, and the data generated by your use of the service, in a structured, machine-readable format. Your
.logger.jsonsidecars are already yours in an open format, on your own disks, with no request needed. - Objection. Object to any processing we base on legitimate interests (section 5). We will stop unless we can show compelling grounds that override your interests.
- Withdrawing consent. We do not currently rely on consent for anything. If we ever do, withdrawing it will be one click, and it will not affect processing that already happened.
- Complaining to a supervisory authority. You can complain to the data protection authority in the country where you live or work, or where you believe the problem happened. In the UK that is the Information Commissioner's Office. We would rather you came to us first, but you do not have to.
Our response time. We answer within one month of receiving your request. If a request is unusually complex, we can extend by up to two further months, and we will tell you about the extension, with the reason, inside the first month. We do not charge for this.
11. California residents (CCPA/CPRA)
If you live in California, you have the right to know what personal information we collect and why, the right to delete it, the right to correct it, and the right to opt out of sale or sharing.
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. We never have. There is no opt-out to click because there is nothing to opt out of.
We do not process sensitive personal information for the purpose of inferring characteristics about you.
The categories we collect map to the tables in section 4: identifiers (email, display name, account and customer identifiers), commercial information (your subscription, credit, and purchase history), internet or network activity (server request logs only, no browsing profile), and the content you choose to submit to Rush or to project sync. We collect these for the business purposes stated in section 4 and disclose them only to the sub-processors in section 6, who are contractually barred from using them for their own purposes.
To make a request, email hello@cliplogger.com. We verify you by matching the request against the email on the account. Authorised agents are welcome, with proof of authority. We will not discriminate against you for exercising any of these rights. Your price, your credits, and your access do not change.
12. Automated decision-making
ClipLogger's AI produces suggestions, and suggestions are proposals. Tags, groupings, names, and log entries proposed by the model are shown to you for review, and they take effect when a human confirms them. You can reject any of them, and rejecting one teaches the app for next time.
We make no decision about you that produces a legal effect or a similarly significant effect by automated means. There is no automated profiling, no scoring of you as a person, and no automated decision about your access, pricing, or eligibility.
13. Children
ClipLogger is a professional tool. It is not directed at children and is not designed or marketed for anyone under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, email hello@cliplogger.com and we will delete it.
14. Changes to this policy
When this policy changes, we update the "last updated" date at the top. For changes that materially affect how we handle your personal data, such as adding a sub-processor or relying on a new legal basis, we email account holders before the change takes effect. The previous version stays available on request, so you can see what changed.
Questions about any of this: hello@cliplogger.com.