Legal

Privacy Policy

Last updated: 6 August 2026

This Privacy Policy explains what personal data Pickin, the video clipping service available at pickin.io and presented in-product as "clip." (the "Service"), operated by Pickin ("we", "us"), collects, why we collect it, who we share it with, and the rights you have over it. We are the data controller for the processing described here.

1. Data we collect

Account data. When you create an account we collect your email address and the account identifier issued by our authentication provider. We do not collect or store your password: authentication is handled by our provider.

Content you submit. This includes the video URLs you submit, the video files you upload, and any brand logo or audio track you add. It also includes everything the Service derives from that material: transcripts, generated clips, thumbnails, captions and clip metadata such as titles, hooks and suggested hashtags.

Usage data. Processing job records (status, progress, timestamps, source duration, error messages) and your credit ledger, so we can run the Service, meter usage and diagnose failures.

Connected platform data. If you choose to connect a third-party account such as TikTok, we receive and store the information described in section 4.

Technical data. Server logs containing IP address, request time, and user agent, retained for security and troubleshooting.

2. Why we use it, and our legal basis

  • To provide the Service — downloading or receiving your source video, transcribing it, selecting highlights, rendering clips, and publishing to a platform at your request. Legal basis: performance of a contract.
  • To manage your account and credits — authentication, usage metering, and support. Legal basis: performance of a contract.
  • To keep the Service secure and reliable — abuse prevention, rate limiting, error diagnosis, and protecting our infrastructure. Legal basis: our legitimate interests.
  • To comply with legal obligations — responding to lawful requests and keeping records we are required to keep. Legal basis: legal obligation.

We do not sell your personal data, we do not use it for advertising, and we do not use your content to train our own artificial-intelligence models.

3. How automated processing works

Transcription happens on our own servers. Speech recognition runs locally on the infrastructure we operate. Your video and audio files are not sent to a third-party transcription service.

Highlight selection uses a third-party language model. To choose which moments become clips, the text of the transcript, and not the video or audio itself, is sent to our language-model provider (Anthropic, and where configured DeepSeek). Under the API terms of these providers, content submitted through the API is processed only to return the requested result and is not used to train their models.

Framing and captioning happen on our servers. Face detection, reframing and caption rendering run locally on our infrastructure.

4. TikTok integration

Connecting a TikTok account is entirely optional and always initiated by you through an explicit authorisation flow on TikTok. If you never connect an account, none of the processing in this section takes place.

What we receive from TikTok. When you authorise the connection, TikTok provides us with an access token and a refresh token, your TikTok user identifiers (open ID and, where provided, union ID), the permissions you granted, and basic profile information used only to show you which account is connected: display name, username and avatar image URL.

What we send to TikTok. Only when you explicitly choose to publish a specific clip do we send that video file to TikTok, together with the post settings you selected in the application, such as the title and the privacy level. Before each direct post we also query TikTok for your current creator settings, such as the privacy options available to your account, so the application can present valid choices.

How your tokens are protected. TikTok access and refresh tokens are encrypted at rest using authenticated symmetric encryption with a key that is held separately from the database. They are decrypted only in memory, at the moment an authorised request is made on your behalf. They are never written to logs, never exposed through our interface or API, and never shared with any third party.

How to disconnect. You can disconnect your TikTok account at any time from the Connected accounts panel in the application. When you do, we ask TikTok to revoke the token and we delete the stored credentials and profile information from our systems. You can also revoke access directly from the security settings of your TikTok account.

Our use of information received from TikTok complies with the TikTok Developer Terms of Service and applicable TikTok developer policies. We use this information solely to provide the publishing features you request, and for no other purpose.

5. Who we share data with

We share personal data only with the service providers needed to operate the Service, and only to the extent necessary:

  • Clerk — user authentication and session management (email address, account identifiers).
  • Anthropic, and DeepSeek where configured — highlight selection from transcript text.
  • TikTok — only if you connect an account, and only as described in section 4.
  • OVH — hosting of the servers and storage on which the Service runs.

We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety and property of our users or of ourselves. If our business is transferred, data may be transferred as part of that transaction, subject to this Policy.

6. Where data is stored and transferred

Your videos, clips, transcripts and account records are stored on servers located in France, within the European Union. Some of the providers listed in section 5 are established outside the European Economic Area. Where personal data is transferred outside the EEA, that transfer is governed by an appropriate safeguard, such as the European Commission Standard Contractual Clauses or an adequacy decision.

7. How long we keep data

  • Account data is kept for as long as your account exists.
  • Uploaded source videos are retained while your account is active, because they are the only copy available for re-rendering an existing clip with different settings.
  • Generated clips, transcripts and job records are kept for as long as your account exists, so they remain available in your workspace.
  • Connected platform credentials are kept until you disconnect the account or delete your account.
  • Server logs are kept for a limited period for security and troubleshooting.

When you delete your account, or when you ask us to delete specific content, we remove the corresponding data from our active systems. Residual copies may persist in encrypted backups for a limited period before being overwritten.

8. Security

  • All traffic between your browser and the Service is encrypted in transit using TLS.
  • Third-party OAuth credentials are encrypted at rest, as described in section 4.
  • Access to media files is granted through short-lived signed links rather than public URLs.
  • Access to production systems is restricted to the people who need it to operate the Service.

No system can be guaranteed completely secure. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority, and you where required, within the timeframes set by applicable law.

9. Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • access the personal data we hold about you and obtain a copy of it;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to certain processing, including processing based on our legitimate interests;
  • receive the data you provided in a portable, machine-readable format;
  • withdraw any consent you have given, without affecting processing carried out before the withdrawal.

To exercise any of these rights, contact privacy@pickin.io. We respond within one month, as required by the General Data Protection Regulation. You also have the right to lodge a complaint with your local supervisory authority, which in France is the Commission Nationale de l'Informatique et des Libertes (CNIL).

10. Cookies

We use strictly necessary cookies only. These are session cookies set by our authentication provider to keep you signed in and to protect against request forgery. We do not use advertising cookies, and we do not use third-party tracking or analytics cookies for profiling.

11. Children

The Service is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this Policy

We may update this Policy as the Service evolves. We will revise the "Last updated" date above and, where the change is material, provide a more prominent notice before it takes effect.

13. Contact us

For any question about this Policy or about how your data is handled, contact us at privacy@pickin.io. For general enquiries, use contact@pickin.io.