Privacy policy
Last updated 9 September 2026
Clippings takes short videos you choose to save, turns them into text, and delivers that text to a destination of your own — a NotebookLM inbox Doc, a Notion workspace, or an Obsidian vault. This page explains what that means for your data, in plain terms.
Who is responsible for your data
The controller of your personal data — the one who decides what is collected and why, and who you can hold to this policy — is Folding Distance Inc., a corporation carrying on business as Clippings, at 570 Hood Rd, Unit 14 # 4013, Markham, ON L3R 4G7, Canada. Reach us at contact@clippingsapp.xyz.
Clippings is operated from Canada and is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA). As PIPEDA requires, one person is accountable for the personal information we hold and for our compliance with this policy. At Folding Distance Inc. that person is Rory Duffy, reachable at the address above.
Clippings is sold from Canada, in Canadian and US dollars, in English. We do not direct it at the United Kingdom or the European Union, and we have not appointed a representative in either, because we are not offering the service into those markets. If that changes — if we price in euros or pounds, or market there — this page changes first.
None of which is a reason to hold your data to a lower standard. Much of what follows is written to the GDPR's shape because it is a clearer way to show our reasoning than prose would be, and because it is a good standard whoever you are.
What we store
- Your account: your email address and your name, as given to us by WorkOS AuthKit when you sign in. If you sign in with a password, WorkOS holds it — Clippings never sees or stores it. If you sign in with Google, we receive only your email address and name.
- What you save: the links you submit, the notes you write, the notebooks you create, and the transcripts and takeaways we generate. We also keep a thumbnail URL and duration where the platform gives us one.
- Your connections: a Google refresh token if you connect Google Drive, and a Notion access token if you connect Notion. These let us write to your documents; both can be disconnected at any time.
- Billing: your plan, subscription status and Stripe customer reference. Card details go directly to Stripe and never reach our servers.
- Connected apps: when you connect the Obsidian plugin, the iPhone app or an AI assistant, we store the access token it was issued — hashed, never in the clear — a name for the vault or device so you can tell them apart in Settings, and a record of which clips that app has already collected, so reconnecting resumes where it left off instead of duplicating everything.
- Push notifications: if you use the iPhone app and allow notifications, we store the push token for that device with its platform and the device name it reports, so we can tell you when a clip is ready.
- Newsletter: if you give us your email address on the marketing site, we store that address by itself, separately from any account. Canadian anti-spam law means we only send to it if you actively asked us to — never a pre-ticked box — and every message we send carries our mailing address and a one-click unsubscribe.
- Technical: ordinary server logs, and the IP address a request came from when an AI assistant first registers a connection — used only to rate-limit that endpoint against abuse.
Why we hold it
Everything above, with the reason we have it. Under Canadian law the test is whether you meaningfully consented and whether the purpose is one a reasonable person would consider appropriate. We have also mapped each row onto the GDPR's six lawful bases — those are the article references — because naming the basis is a more honest way to show our thinking than a paragraph of reassurance. Where the basis is consent, withdrawing it is a switch you control: disconnect the service, turn the notification off, or unsubscribe, and the data goes.
| What | Why we have it | Legal basis |
|---|---|---|
| Email address and name | Creating your account, signing you in, and reaching you about it | Contract — Art. 6(1)(b) |
| Links, notes, notebooks, transcripts, takeaways | The service itself: this is the thing you came for | Contract — Art. 6(1)(b) |
| Google refresh token, Notion access token | Writing to the destination you connected | Consent — Art. 6(1)(a) |
| Connected app records (vault, device, assistant) | Running the connection you authorised, and letting you review and revoke it | Consent — Art. 6(1)(a) |
| Push token, platform, device name | Telling you on your phone when a clip is ready | Consent — Art. 6(1)(a) |
| Plan, subscription status, Stripe reference | Taking payment and running your subscription | Contract — Art. 6(1)(b), and legal obligation for the records we must keep — Art. 6(1)(c) |
| Newsletter email address | Sending you news about Clippings | Consent — Art. 6(1)(a) |
| PostHog analytics and session replay | Understanding how the site is used and finding what is broken | Consent — Art. 6(1)(a) |
| Server logs, and the IP behind an assistant registering | Keeping the service up and stopping abuse | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, the interest is keeping Clippings running and free of abuse, and we have weighed it against the fact that logs are short-lived and are not used to build any picture of you. You can object to that processing at any time — see “Your rights” below.
Who else processes it
We use a small number of providers, each for one job. Where a provider is outside the UK and EU, that is noted here and the transfer is covered by the safeguards described further down.
- WorkOS — sign-in, passwords, email verification and two-factor authentication. United States.
- Groq — transcribes audio when a video has no usable captions, and cleans up transcripts. Audio is sent for processing and not retained by us; we never store video or audio files. United States.
- Anthropic — reads the text off the slides when you save a photo carousel or slideshow, which has no audio to transcribe. The slide images are sent for processing and not retained by us. United States.
- ScrapeCreators — fetches transcripts from the platforms. It receives the link you saved. United States.
- Google — creates and appends to the inbox Docs in your own Drive, if you connect it. United States.
- Notion — creates pages in your workspace, if you connect it. United States.
- Stripe — payments and subscription management. Stripe also sends the receipts and renewal notices for your subscription. United States and Ireland.
- Expo — delivers push notifications to the iPhone app, if you use it and allow them. United States.
- PostHog — product analytics, described in the next section. United States.
- Railway — hosting and the database. United States.
We do not sell your data, we do not use your content to train models, and we do not run advertising trackers or sell space to advertisers.
Where your data goes
Clippings is run from Canada, so that is where your account lives.
From there, most of the providers listed above are in the United States. PIPEDA allows this — a Canadian organisation may use foreign processors — but it requires two things of us, and we will be straight about both. We stay accountable for your data in their hands and use contracts to hold them to a comparable standard. And you should know that while information is in another country it is subject to that country's laws, which means it can in principle be reached by that country's courts and law-enforcement agencies, regardless of what we would prefer. That is true of any service that uses American infrastructure, and it is true of this one.
Ask us what covers a particular provider and we will tell you.
Analytics
We use PostHog to understand how Clippings is used and to find things that are broken. It runs on the marketing site and inside the app, and it records page views, clicks on buttons and links, and errors the app throws in your browser. When you are signed in we tell PostHog which account you are, along with your email address and which plan you are on, so that we can see how one person's session actually went rather than a pile of anonymous events. Signing out clears that association in your browser.
On the public pages — the home page and the ones around it, like pricing and this one — PostHog also records the visit itself: a replay of the page as you scrolled and clicked through it, so we can see where the site confuses people. That recording stops at the sign-in line. It does not run on your dashboard, your clips, your notebooks, your settings or the onboarding, and anything you type into a form is masked before the recording leaves your browser.
What PostHog does not get is the substance of what you save. Your transcripts, notes, takeaways and notebook contents are never sent to it. We also capture a small number of events on our own servers — an account being created, a plan changing, a clip finishing or failing — which record that the thing happened and to which account, not what the clip said.
PostHog runs in two modes, and the banner on your first visit is what chooses between them. Until you accept — or if you refuse, or if your browser sends a Global Privacy Control signal, which we honour without asking — it runs without storing anything in your browser: no cookie, no local storage, no identifier. Page views and clicks are still counted, but each visitor is a hash that PostHog computes on its own servers from the day, the site and a few properties of the connection, and throws away the next day, so one day's visit cannot be tied to the next and nothing about you is written to your device. In that mode we never tell PostHog which account you are, even when you are signed in, and there is no session replay. Accept the banner and PostHog switches to its normal mode: it sets its cookies, recognises you across visits, is told which account you are when you are signed in, and records the replays described above on the public pages. The cookie button in the corner of any page changes your mind later. Every cookie the normal mode sets is named in the cookie policy.
The events we record on our own servers are a separate matter, and we would rather say so plainly than let the banner imply otherwise. An account being created, a plan changing, a clip finishing or failing — those go to PostHog from our servers, keyed to your account, and they never pass through your browser, so declining cookies does not stop them. They record that the thing happened and to which account, never what the clip said; they are how we know whether the product works at all. If you want out of those too, write to us at the address at the bottom of this page and we will take you out by hand.
Google access
Clippings uses the drive.file scope, which means it can only see and edit Google Docs that Clippings itself created. It cannot read anything else in your Drive. Since sign-in moved to WorkOS, connecting Google is a separate, optional step used purely for delivery — it no longer tells us anything about who you are. Clippings' use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Disconnecting revokes the token.
Obsidian
The Clippings plugin for Obsidian pulls your finished clips down into a vault on your own machine and writes them as notes there. The plugin signs in to your Clippings account and asks our server for the clips you have not already collected; nothing is pushed to you, and we never see inside your vault — we store only its name, so you can recognise it in Settings, and the list of clips it has taken. Disconnect it from Settings or from the plugin and the pulling stops. Notes already written into the vault are files on your own disk and stay there.
AI assistants
If you connect an assistant such as Claude (Settings → “Ask your AI about your clippings”), it can read the clippings you approved it for — transcripts, your notes, takeaways and notebook names — and that content is sent to whoever runs the assistant when you ask it a question. Clippings does not send anything on its own: nothing leaves until the assistant asks for it on your behalf. You choose read-only or read-and-save when you connect, and you can disconnect at any time in Settings, which cuts access immediately.
An assistant only ever sees what its permission covers: your notebooks, your clips and their transcripts, notes and takeaways, and — if you granted saving — the ability to add a new one. It never sees your password or session, your email address or plan, your card or billing details, or the credentials of anything else you have connected, including your Google and Notion tokens. It cannot disconnect a destination or close your account.
One distinction worth being plain about: whoever runs the assistant — Anthropic, OpenAI, or whoever else you pick — is a service you chose and connected, not a processor working for us. Once the assistant has read something from your account, that content is in their hands and their privacy policy governs it, not this one. That is why they are not on the list above. What we keep is the record of the connection itself, so you can see it and revoke it.
A caution about transcripts
A clipping is speech from somebody else's video, transcribed as it was said. We label it as quoted material when an assistant reads it, and assistants are generally good at treating it that way — but text you did not write is being placed in front of a system that can act. Treat what an assistant tells you about a clipping as a summary of what a stranger said, not as fact, and be deliberate about which other tools you give that assistant at the same time. The same applies to the transcripts we deliver to NotebookLM and Notion.
The iPhone app
The Clippings app for iPhone talks to the same account and the same data as the website, and everything above applies to it. It holds your sign-in token in the iOS keychain, and it asks for permission to send notifications and to accept links shared to it from other apps — both of which you can refuse or withdraw in iOS Settings without losing the rest of the app. The app itself carries no analytics SDK: the PostHog described above runs on the web, not inside it.
Cookies
Clippings sets no advertising cookies and takes part in no ad network. Most of what it does set is necessary for the site to work at all:
- Your sign-in session — an encrypted cookie that keeps you signed in.
- A security token — protects forms against being submitted from another site on your behalf.
- Your appearance choice — remembers light or dark mode.
- Short-lived cookies during sign-in and when connecting Google or Notion — they exist for a few minutes and are deleted as soon as the step finishes.
- Your cookie choices — what you told the banner, and the country it resolved you to so the right rules apply. These are set whatever you decide, including when you decline everything else.
On top of those, PostHog sets its own cookies to recognise a returning browser and to group a visit into a session. Those are analytics cookies rather than necessary ones, and they are not set unless you allow them — see the analytics section above for what they are used for.
The cookie policy lists every one of these by name, with what it does and how long it lasts. It is generated from the same settings that drive the banner, so it cannot drift from what the site actually sets.
How long we keep it
- Clips, notes and notebooks — until you delete them or close your account. Deleting a notebook archives it so the clips filed there keep working; closing your account removes the lot.
- Connection tokens — deleted the moment you disconnect. Disconnecting a vault, device or assistant takes its record and its sync history with it.
- Processing records — the queue rows behind a clip being made are deleted 7 days after the job finishes.
- Newsletter address — until you unsubscribe.
- Billing records — kept for 6 years from the end of the tax year they relate to, which is what the Canada Revenue Agency requires of our books. This is the one category we cannot delete on request while that period is running.
- Closing your account — email us and we will do it within 30 days, usually the same week. Everything except the billing records above goes.
Documents already written into your Google Drive or Notion, and notes already written into an Obsidian vault, belong to you and are untouched by any deletion here — remove those yourself if you want them gone.
Your rights
You can ask us for a copy of the data we hold about you (Art. 15), to correct it if it is wrong (Art. 16), to delete it (Art. 17), to restrict what we do with it (Art. 18), to hand it over in a portable form (Art. 20), or to object to processing we base on legitimate interests (Art. 21). Where we rely on your consent you can withdraw it at any time, which does not undo processing that was lawful before you did (Art. 7(3)).
Email contact@clippingsapp.xyz. We will respond within 30 days, as Art. 12(3) requires; if a request is complicated enough to need longer, we will tell you inside those first 30 days rather than going quiet. There is no charge.
Under PIPEDA you have the right to know what personal information we hold, to see it, to have it corrected if it is wrong, and to challenge how we are handling it. Those rights sit alongside the ones above rather than competing with them, and the same email address reaches us for either.
If you think we have got something wrong, complain to us first and we will take it seriously. If that does not resolve it, you can go to the Office of the Privacy Commissioner of Canada — 30 Victoria Street, Gatineau, Quebec K1A 1H3, or priv.gc.ca — which oversees us. If you are outside Canada, you can also raise it with the data-protection authority where you live.
Security
- All traffic runs over HTTPS, so it is encrypted in transit.
- Passwords are handled entirely by WorkOS and never reach us — we have nothing to leak.
- The credentials for the services you connect — your Google refresh token and your Notion access token — are encrypted before they are written to the database, under a key held in the environment rather than alongside the data. A stolen copy of the database does not open them.
- Tokens issued to AI assistants, the Obsidian plugin and the iPhone app are stored as hashes rather than in the clear, expire on their own, and can be revoked one at a time from Settings.
- Video and audio are written to a temporary directory for the seconds it takes to transcribe them, and are deleted when that finishes. We never keep the media itself.
No system is perfect. If personal information is lost or exposed in a way that creates a real risk of significant harm to you, PIPEDA requires us to report it to the Office of the Privacy Commissioner of Canada and to tell you, both as soon as feasible, and we will. We also keep a record of every breach for at least 24 months, including the ones that do not meet that threshold, which is what the law asks of us and is also how you learn anything from them.
“As soon as feasible” is the legal standard and it is a soft one, so here is a harder commitment: we will tell you within 72 hours of knowing, which is the deadline the GDPR sets and a reasonable bar to hold ourselves to whether or not it binds us.
Children
Clippings is not intended for children. You need to be at least 16, and old enough to enter into a contract where you live, to hold an account. We do not knowingly collect anything from anyone younger; if you think a child has an account, tell us at the address below and we will remove it.
Changes
If we change this policy in a way that matters, we will say so by email or in the app before it takes effect. The date at the top always reflects the current version.
Contact
Questions about any of this: contact@clippingsapp.xyz.