Privacy Policy
Effective date: May 29, 2026 · Last updated: September 15, 2026
1. Who We Are
Clepora ("we", "us", "our") is a software-as-a-service platform that helps creators and businesses publish content across multiple social media platforms from a single dashboard. You can reach us about privacy at legal@clepora.com.
This Privacy Policy applies to Clepora's website and web application at clepora.com, its API, and the podcast feeds it hosts (collectively, the "Service").
2. Age Restriction
Clepora is strictly for users aged 18 and over.
We ask for your date of birth when you register so that we can confirm you are at least 18. We do not knowingly collect personal data from anyone under the age of 18. If we discover that a user is under 18, we will terminate the account and delete the associated data. If you believe a minor has registered, please contact us at legal@clepora.com.
3. Data We Collect
3.1 Account Data
- Name and email address provided at registration
- Your password, stored only as a bcrypt hash
- Date of birth, your confirmation that you are 18 or older, and the version and time of the terms you accepted
- Phone number, if you turn on SMS sign-in codes
- Two-factor authentication data: the method you chose, the authenticator-app secret, short-lived one-time codes (stored only as keyed fingerprints, never as the code itself), and single-use recovery codes (stored only as hashes, so we cannot show them to you again)
- Security questions you set, with your answers stored only as hashes
- A recovery email address, if you add one
- Sign-in protection data: a count of failed sign-ins on your account, and short-lived counters that slow repeated wrong passwords down
- Subscription and billing identifiers: your plan, monthly usage counts, and the Stripe customer and subscription IDs linked to your account (card details are held by Stripe, not by us)
- Your marketing email preference
- Account creation date
3.2 Content Data
- Videos, audio and images you upload or record for processing
- Captions, titles, descriptions, hashtags, transcripts and podcast show and episode details
- Publishing schedules, publishing history, posting slots and brand-kit settings
3.3 Platform Connection Data
- OAuth access tokens for connected platforms (YouTube, TikTok, Meta, LinkedIn, Pinterest), and bot/webhook credentials for Telegram and Discord
- Platform-specific account identifiers and page IDs
- These tokens are stored encrypted at rest
You can disconnect any connected social account at any time from the Connections section of your dashboard (each connected platform has a “Disconnect / release” option). When you disconnect, Clepora revokes the access token with that platform where the platform supports revocation and deletes the stored token and connection from our systems. After disconnecting, Clepora can no longer access or publish to that account. For YouTube, disconnecting also deletes every piece of YouTube data Clepora holds for that channel at the same moment — see section 5.1.
3.4 Usage Data
- Analytics data retrieved from connected platforms (views, engagement and, where the platform reports it, revenue). Data from YouTube is described in section 5.1.
- Feature usage patterns for service improvement
- Server error logs and performance data
3.5 Security and Activity Logs
To protect accounts and investigate abuse, we keep a log of sign-ins, security changes and account actions. Each entry records the type of event, the time, your account and email address, your IP address and your browser's user-agent. We also keep a list of recognised devices (user-agent, IP address, first and last seen) so that a sign-in from a new device can be verified.
3.6 Traffic and Site Health Measurement
We count visits to our own pages so we know which ones are useful. For each page view we record the path, the referring URL, your browser's user-agent string, and a visitor identifier that we derive on our server from a salted hash of your IP address and user-agent.
Two things about that identifier are deliberate. It is never stored on your device — no cookie, no local storage entry, nothing to consent to. And it changes every day at midnight UTC, so it can count how many people visited on a given day but cannot be used to recognise you from one day to the next. Your IP address itself is not stored in these traffic records.
To keep the site fast and working, pages also send us web vitals (loading and responsiveness timings) and browser error reports (the error message, the script location and the stack trace), each with the page path and the same daily visitor identifier.
We use no third-party analytics service. There is no Google Analytics, no tag manager, and no tracking pixel anywhere on this site.
3.7 Podcast Listeners
If you host a podcast with Clepora, the people who download your episodes are usually not Clepora users. For each download we record the episode, the day, the number of bytes sent, the listener's app user-agent, and a salted listener identifier that changes every day — never the listener's IP address — so that downloads can be counted to the IAB podcast measurement standard.
3.8 Other People's Data You Give Us
- Team invitees: when you invite someone to a team workspace, we store their email address, the role you offered and the invitation status, and we email them the invitation.
- Support requests: when anyone contacts support through the Service, we store the name, contact details and message they send.
3.9 Data We Do NOT Collect
- We do not collect payment card numbers (handled directly by our payment processor)
- We do not collect biometric data
- We do not track your activity outside of Clepora
4. How We Use Your Data
- To provide the Service — process your videos, publish to platforms, host your podcast feed, and display analytics
- To generate captions, titles and suggestions — when you use these features, transcripts, titles, briefs and sampled video frames are sent to our AI inference provider (AWS)
- To check uploads — sampled video frames are checked by an automated content-moderation service (AWS), and a short audio sample is checked for copyrighted music (ACRCloud)
- To send service emails — publish confirmations, view milestone alerts, security alerts and account notifications
- To send occasional announcements — for example seasonal or product messages to account holders. Every announcement has a one-click unsubscribe link (see section 6); unsubscribing does not stop service and security emails.
- To keep accounts secure — verifying sign-ins, detecting and stopping fraud, spam, abuse and policy violations
- To improve the Service — aggregate usage analysis
- To comply with law — responding to valid legal requests and protecting our rights
Clepora’s Free plan displays Clepora’s own promotional slots. Which advert you see is decided by your plan alone. No personal data, browsing history, or content of yours is used to select it, and no advertising network is involved. Paid plans display no adverts at all.
We do not use your data for:
- Selling to third parties
- Advertising or retargeting
- Training AI models on your private content without explicit consent
5. Third-Party Services
To operate Clepora, we share data with the following service providers, and only the data each one needs to do its job:
| Service | Purpose | Data shared |
|---|---|---|
| AWS (Amazon) | Hosting (servers, database, object storage, backups), AI inference, content moderation | All account and content data we store; transcripts, titles, briefs and sampled video frames for AI features and moderation |
| Resend | Email delivery (service emails and announcements) | Email address, name, message content, and the name of an account you connect (for YouTube, the channel title) in the connection confirmation email |
| Google Workspace | Our own mailboxes (support@, legal@) | Messages you send to our email addresses |
| Cloudflare | DNS for clepora.com | Domain lookups — no account data |
| YouTube / Google | Video publishing, live streaming and analytics (when connected) | Videos, the title, description and settings you choose, OAuth token |
| Meta (Facebook/Instagram) | Publishing and analytics (when connected) | Videos, captions, OAuth token |
| TikTok | Video publishing (when connected) | Videos, captions, OAuth token |
| Publishing and analytics (when connected) | Posts, OAuth token | |
| Publishing (when connected) | Pins, videos, OAuth token | |
| Telegram | Publishing (when connected) | Messages, videos, bot token |
| Discord | Publishing (when connected) | Messages, videos, webhook URL |
| ACRCloud | Audio copyright fingerprinting | Audio sample (10 seconds) |
| Stripe | Subscription payments and billing | Email address, account ID, and the billing details you enter at checkout |
| Twilio | SMS delivery for login and verification codes | Phone number, verification code |
| Jamendo | Royalty-free music search (fallback only) | Search query only — no personal data |
| Podcast apps and directories | Distributing a podcast you publish (when you submit your feed) | Your public feed: show and episode details, author name, owner email, artwork and episode audio |
An experimental text-to-video feature that uses external video-generation providers is restricted to Clepora staff and is not available to customers.
5.1 YouTube API Services
Clepora uses YouTube API Services to upload videos to, stream live to, and read analytics from a YouTube channel you have connected. By using Clepora, you agree to be bound by the YouTube Terms of Service.
Data obtained through YouTube API Services is also handled under Google's privacy practices, as described in the Google Privacy Policy, in addition to this Policy.
What Clepora accesses
When you connect a channel you grant Clepora permission, on Google's own consent screen, to upload videos to that channel, to create and manage live broadcasts on it, and to read its YouTube Analytics reports, including revenue reports where the channel is monetised. Clepora uses that permission only to do what you ask it to do. It does not read comments on your videos, and it does not search, edit or delete anything on YouTube.
What Clepora stores
- OAuth tokens for your channel, encrypted at rest (see section 9).
- Your channel title and avatar, so Connections can show which channel you linked. They are refreshed from the API at every sync, roughly every three hours.
- Performance statistics — views, likes, comments and, where the channel is monetised, revenue reported by the YouTube Analytics API — for the last 30 days. They are refreshed at every sync and deleted if not refreshed within 30 days.
- The IDs and links of videos and live broadcasts you published through Clepora, so each post can link to what it published. They are kept for at most 30 days.
Stored YouTube data is refreshed from the API on a three-hourly schedule. In line with the YouTube API Services Developer Policies, Clepora does not store or display YouTube statistics for more than 30 days: a daily sweep deletes any figure that has not been refreshed within that period, and the analytics views for YouTube cover the last 30 days only.
How Clepora uses it
- To publish what you direct. YouTube uploads send the title, description, privacy setting, made-for-kids setting, category and synthetic-content disclosure exactly as you chose them. Clepora adds nothing to a YouTube title or description — no hashtags and no #Shorts tag.
- To show you your channel and its figures. Every YouTube figure shown in Clepora is a value returned by the YouTube API. The single exception is engagement rate, which Clepora calculates from the likes and views the API returns, and which is labelled as Clepora-calculated everywhere it appears.
YouTube data is never merged with data from other platforms, never used to model revenue or estimate audiences, and never sent to our AI provider.
Who it is shared with
YouTube API data is not sold, and is shared with no one except as needed to run the Service: it is held on our AWS infrastructure, and your channel title appears in the confirmation email we send you through Resend when you connect the channel. Google receives the videos and settings you publish to YouTube.
Revoking access and deleting your YouTube data
- In Clepora, via Connections → Manage → Disconnect, or by deleting your Clepora account. Clepora revokes its access with Google and immediately deletes your OAuth tokens, channel title and avatar, all stored YouTube statistics, and the stored YouTube video and broadcast IDs — never later than 7 days after you disconnect.
- Directly with Google, via the Google security settings page. Clepora detects the revoked grant at its next sync, normally within hours, and runs the same deletion automatically — in every case within 30 days of the revocation.
- By asking us. Email legal@clepora.com to have the YouTube data Clepora stores about you deleted, and we will act on the request within 7 days.
Deleting the data Clepora stores does not, in any way, affect data stored by YouTube: videos you published remain on your channel until you remove them on YouTube.
5.2 Meta Platforms — Facebook, Instagram and Threads
Where you connect a Facebook Page, an Instagram professional account or a Threads profile, Clepora receives an access token and the identifiers for the Page or account you selected, and uses them solely to publish the posts you direct it to publish and to read that account's own performance metrics.
Clepora does not read your feed, your friends or followers, your messages, or any account you did not explicitly connect.
You can require deletion of the data Clepora holds from a Meta platform in three ways: disconnect the account in Clepora, remove Clepora from your Facebook settings (which calls Clepora's deauthorisation endpoint and deletes the stored credential), or follow the instructions at clepora.com/data-deletion, which returns a confirmation code you can use to track the request.
5.3 TikTok
Where you connect a TikTok account, Clepora receives an access token and your account identifier, and uses the TikTok Content Posting API to publish the videos you direct it to publish. Clepora asks you to choose the audience and the comment, duet and stitch settings for each post rather than assuming them, and passes exactly those choices to TikTok.
Clepora does not hold TikTok's Display API permissions, so it cannot and does not read your TikTok videos, profile content, or follower data. Disconnecting the account deletes the stored token.
5.4 LinkedIn, Pinterest, Telegram and Discord
For LinkedIn, Clepora receives an OAuth token and the identifier of the profile or page you selected, and uses them to publish what you direct it to publish and to read that content's own metrics.
For Pinterest, Clepora stores only an OAuth token. It reads your list of boards when you are choosing one, and reads your Pinterest username and profile image each time the Connections page shows you which account is linked — Pinterest’s developer guidelines let us keep nothing its API returns, so neither is written to our database. They are fetched for that page and discarded. Clepora uses them only to create the Pins you direct it to create, on the board you choose for each Pin. Clepora does not read Pinterest analytics. Disconnecting deletes the token.
Telegram and Discord have no OAuth flow. You supply a bot token and channel, or a webhook URL, that you created and control. Clepora stores these encrypted, uses them only to deliver your posts, and deletes them when you disconnect. Revoking the bot token or deleting the webhook on the platform's own side stops Clepora's access immediately and independently of Clepora.
5.5 What is true of every connected platform
- Clepora only ever receives a token. It never receives, sees or stores your password for any platform.
- Clepora requests the narrowest set of permissions that lets it publish, choose where to publish, and report on what you publish. Where a platform bundles read access into that grant, Clepora uses it only for those purposes — on Pinterest it reads the list of your boards so that you can choose which board a Pin goes to. Pinterest’s consent screen also lists reading your Pins; Clepora holds that permission but does not use it, and does not read, copy or store posts you created outside Clepora on any platform.
- Disconnecting a platform revokes the token where the platform supports revocation, deletes the stored credential, and ends all publishing and metric syncing for that account.
- Anything Clepora already published to that platform remains on your account there. Removing it is done on the platform, by you.
6. Your Rights and Choices
Depending on where you live, you may have some or all of the following rights. We offer the self-service tools below to every user.
Right to access
Download a copy of the personal data we hold about your account at any time from Settings → Account → Download my data
Right to portability
The same download is a machine-readable JSON file
Right to deletion
Delete your account and its associated data directly in Settings → Account → Delete account (see section 7)
Right to rectification
Correct your details in Settings, or ask us to correct anything you cannot change yourself
Right to restrict processing
Ask us to stop processing your data in certain ways
Right to object
Object to processing based on legitimate interests
Right to withdraw consent
Withdraw consent at any time without affecting prior lawful processing
The data download covers your profile, workspace settings, posts and captions, schedules, publishing history, connected-account identities, analytics, podcast show and episode details, team memberships and invitations, and your security and activity log. It never contains passwords, security-answer hashes, two-factor secrets or platform tokens, and it does not include media files. You can download it up to 3 times a day.
Marketing email: every announcement we send includes a one-click unsubscribe link. Once you unsubscribe we stop sending you announcements; emails about your account itself — security alerts, sign-in codes, publishing results — continue, because the Service cannot work safely without them.
To exercise any other right, email legal@clepora.com. We will respond within 30 days, and requests to delete data obtained through YouTube API Services are acted on within 7 days (see 5.1). EU/UK users may also lodge a complaint with their local supervisory authority.
7. Data Deletion
You may delete your account at any time from Settings → Account → Delete account. Upon deletion:
- Your account record, posts, schedules, connections, analytics and recognised devices are deleted from our database immediately
- Your uploaded and rendered media files are deleted from object storage immediately. Our object storage keeps earlier versions of files so that accidental deletions can be recovered, so a deleted file can remain in that version history after it is gone from the Service
- Platform connection tokens are revoked and deleted immediately
- Data obtained through YouTube API Services — OAuth tokens, channel title and avatar, statistics, and video and broadcast IDs — is deleted immediately, and never later than 7 days
- Security and activity log entries are unlinked from your account immediately; your email address, IP address and device details are removed from them within 30 days, and the entries themselves are deleted once they are 365 days old
- Database backups roll over every 7 days, so deleted records can remain in a backup for up to 7 days
- If you ever had a paid subscription, your customer record at Stripe is not deleted automatically — email legal@clepora.com and we will have it removed, subject to the records Stripe must keep by law
- Anonymised, aggregated analytics data may be retained. This never includes data obtained through YouTube API Services, which is deleted in full
- Data required by law may be retained for the legally required period
You can also request deletion without signing in, using the instructions at clepora.com/data-deletion. This is the route to use if you removed Clepora from a connected platform's settings and want the data deleted at the same time; it returns a confirmation code you can use to check the status of the request.
When you delete your Clepora account, all of your information and every connection to your social media accounts are removed. Clepora revokes and deletes the access tokens and webhook/bot credentials for all connected platforms (YouTube, TikTok, Instagram, Facebook, Threads, LinkedIn, Pinterest, Telegram, Discord), which means Clepora will no longer have any access to those social media accounts.
8. Data Retention
- Account data: retained while your account is active, and deleted when you delete your account (see section 7)
- Published media: deleted 7 days after the post is first published. The clock starts at the first successful publish, not at upload. The post record, its published URLs (for YouTube, for at most 30 days) and its analytics all survive the deletion — only the rendered video files are removed, and a post whose media has been removed cannot be published again.
- Media Library files: deleted 7 days after upload. The Library is a staging area for files you are about to use, not an archive.
- Media for posts you never publish: retained while the post exists, and deleted when you delete the post.
- Analytics statistics: deleted if not refreshed within 30 days. Figures from every connected platform are refreshed at each sync, and a daily sweep deletes any that have not been refreshed within 30 days. YouTube video and broadcast IDs are kept for at most 30 days.
- Page-view records: deleted after 90 days. The derived visitor identifier in them is already useless for recognising anyone after 24 hours; the rows themselves are removed by a daily job.
- Web vitals and browser error reports: deleted after 90 days. Aggregated request timings, which contain no personal data, are deleted after 30 days.
- Security and activity logs: deleted after 365 days. Entries no longer linked to an existing account — including every entry of a deleted account — have the email address, IP address and device details removed once they are 30 days old.
- Support requests: deleted after 365 days.
- Podcast listener download records: deleted after 400 days. After that only a daily download count per episode is kept, with no listener information.
- Expired links and codes: cleared 7 days after they expire. This covers password-reset links, one-time sign-in codes, staff invitations and team invitations, including the invitee's email address.
- Temporary sign-in state for connecting a platform: deleted after 24 hours.
- Database backups: kept for 7 days.
- Legal hold data: retained as required by applicable law
Deleting a post removes its stored files first and then its record. Content you have already published stays on the destination platform — it belongs to your account there, not to Clepora, and only you or that platform can remove it.
9. Security
- Passwords are hashed using bcrypt — we cannot recover your password
- OAuth tokens and bot/webhook credentials are encrypted at rest using authenticated symmetric encryption (AES-128-CBC with HMAC-SHA256)
- All data in transit is encrypted using TLS 1.2 or higher
- Object storage is access-controlled — your uploads and rendered media are reachable only through a time-limited signed URL
- Podcasts are public by design: the RSS feed, show artwork and episode audio you publish can be fetched by anyone with the feed address, and the feed includes the author name and owner email you enter for the show
- If a data breach affects your personal data, we will notify you, and the relevant authorities where the law requires it, within the time limits that apply
10. Laws and Platform Policies
Clepora is operated from the United States and is used by people in many countries. We have written this policy with the EU and UK General Data Protection Regulation, the California Consumer Privacy Act (as amended by the CPRA) and similar privacy laws in mind, and we offer the rights in section 6 to every user wherever they live. We do not sell personal data and do not share it for cross-context behavioural advertising.
The Service is not directed to children: the US Children's Online Privacy Protection Act (COPPA) governs children under 13, and Clepora permits no users under 18 at all.
When you connect a platform, Clepora also follows that platform's developer rules, including the YouTube Terms of Service, the Meta Platform Terms, the TikTok Developer Terms, the LinkedIn API Terms and the Pinterest Developer Guidelines.
Copyright complaints can be sent to legal@clepora.com; see our Terms of Service.
11. Cookies and Local Storage
Clepora sets no cookies at all. What the Service does use is your browser's local storage, and only for things the Service cannot work without:
- Your sign-in token, so you stay signed in between page loads
- Small interface preferences, such as which platforms you last had open
Both are strictly necessary to provide a service you asked for, both stay on your device, and both are cleared when you sign out or clear your browser data. We store nothing on your device for analytics, advertising, or tracking — our visitor counting is done server-side (see 3.6) precisely so that it needs nothing stored on your device.
Because everything we store is strictly necessary, no consent banner is required.
12. International Data Transfers
Clepora's servers and storage are in the United States (AWS, US East). If you use the Service from outside the United States, your data is transferred to and processed in the United States, and some of the providers in section 5 may process it in other countries under their own terms.
13. Changes to This Policy
We will notify you of material changes to this policy by email and by posting a notice in the Clepora dashboard at least 30 days before changes take effect. Continued use of the Service after that date constitutes acceptance of the updated policy.
14. Contact
Service: Clepora
Privacy enquiries: legal@clepora.com
Copyright notices: legal@clepora.com
General support: support@clepora.com