Privacy Policy
Last Updated: August 7, 2026
Cyberseeds ("Company," "we," "us," or "our") operates NexClip AI (the "App"), a macOS video editing application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Password (encrypted, never stored in plaintext)
1.2 Video and Audio Data
When you use the App's transcription features, we process:
- Audio data: Extracted from your video files and temporarily uploaded to our servers for transcription processing
- Video metadata: File name, duration, resolution, frame rate
- Transcription data: Text output from speech-to-text processing, including word-level timestamps, sentence boundaries, and speaker identification
- Checksums: SHA-256 hash of audio files for duplicate detection
1.3 User-Generated Content
- Topic data: AI-extracted topics from your transcriptions
- Clip selections: Your chosen topics and target durations for video clips
- Custom prompts: Text prompts you provide for custom clip generation
- Subtitles: AI-generated subtitle text for your clips
1.4 Usage Data
- API request logs (for debugging and service improvement)
- Error reports and crash data
1.5 Device Information
- macOS version
- App version
- Device identifiers necessary for license validation
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the App
- Process your video transcriptions and generate clips
- Authenticate your account and manage your subscription
- Detect and prevent duplicate file processing
- Respond to your requests and provide customer support
- Monitor and analyze usage patterns to improve our services
- Comply with legal obligations
When you join our launch waitlist, we send a confirmation email to the address you provide so you can opt in (double opt-in). We only add confirmed addresses to our launch-notification list, and you can unsubscribe at any time.
3. How We Share Your Information
We share your information with the following third-party service providers, solely for the purpose of operating the App:
3.1 ElevenLabs (Speech-to-Text Processing)
- Data shared: Audio data extracted from your videos
- Purpose: Speech-to-text transcription
- Retention: ElevenLabs retains data for up to 3 years after your last interaction; audio can be deleted via their API at any time
3.2 Google (AI Processing)
- Data shared: Transcription text, sent to the Google Gemini API (no audio or video data)
- Purpose: Topic extraction, relevance scoring, and subtitle generation
3.3 Supabase (Authentication and Database)
- Data shared: Account information, transcription data, topic data, and usage metadata
- Purpose: User authentication, data storage, and retrieval
3.4 Amazon Web Services (Cloud Storage)
- Data shared: Audio files
- Purpose: Temporary storage for transcription processing
3.5 Google LLC / YouTube (Video Publishing)
The App uses YouTube API Services. When you choose to publish a sequence to YouTube, we use Google's OAuth 2.0 to obtain your authorization and then upload the rendered video file to your own YouTube channel through the YouTube Data API. By connecting a channel, you agree to be bound by the YouTube Terms of Service.
The YouTube data ("API Data") that the App accesses, collects, and stores is limited to the following:
- Channel information we access: When you authorize the connection, the App makes a single request to the YouTube Data API (channels.list) for the channel you authorized, and receives its channel ID, channel title, and channel thumbnail URL. These values are used only to show you which channel you are publishing to. The App repeats this request solely to refresh that information as described below.
- Video and metadata we submit: When you publish, the App sends the rendered video file to the YouTube Data API (videos.insert) together with the metadata you enter in the App: title, description, tags, category, visibility setting, and, if you schedule the video, the scheduled publication time. YouTube returns the ID of the created video.
- Authorization credentials: The App requests the youtube.upload and youtube.readonly OAuth scopes. The youtube.readonly scope is used solely to read the name of the channel you authorized so that the App can display it to you. The access token is held in memory for the duration of the session and is never written to disk. The refresh token is stored in the macOS Keychain on your device and is never transmitted to us.
The App does not request, access, or collect any other YouTube data. It does not read video statistics or analytics, other users' channels, playlists, comments, subscriptions, or search results, and it does not download or copy content from YouTube.
Where API Data is stored, and for how long:
- On your device: The refresh token is stored in the macOS Keychain. The channel ID, channel title, and channel thumbnail URL of the connected channel are cached by the App. For each video you publish, the App records the returned video ID and the time of upload in its project database on your Mac so that it can link you to your video.
- On our servers: None. No API Data is stored on our servers: no channel identifiers, no channel names, no video IDs, and no YouTube statistics are written to any database, cache, log, or analytics event that we operate.
- Refresh and deletion: We do not store YouTube statistics or analytics data of any kind — we never request it. All other API Data stored on your device, namely the cached channel information and the video IDs listed above, is refreshed from the YouTube Data API or deleted within 30 days of being stored, in accordance with the YouTube API Services Developer Policies; your OAuth refresh token is kept for as long as the connection is active, as authorization credentials are excluded from that requirement. Disconnecting a channel deletes the stored credential and all cached channel information immediately.
This application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke the App's access to your YouTube data at any time. In the App, open Settings → YouTube → Disconnect; the App then calls Google's token revocation endpoint and deletes the stored credential and cached channel information from your device. You can also revoke access from the Google security settings page, or from your Google Account third-party access page.
Cookies, local storage, and similar technologies on your device:
- In the macOS App: The App does not use cookies. The YouTube refresh token is stored in the macOS Keychain, and the cached channel information and video IDs described above are stored in the App's database on your Mac. Neither is transmitted to our servers.
- On our website: Our website uses cookies and browser local storage for PostHog, which measures aggregate website usage. These are set only when you visit our website, are not used by the App, and never contain YouTube API Data.
Your use of YouTube through the App is governed by the YouTube Terms of Service. Google's handling of your information is described in the Google Privacy Policy.
3.6 Product Analytics (PostHog)
We use PostHog to understand aggregate product usage and where our visitors come from. We send only anonymous, minimal data.
- What we send: An anonymous identifier (your account's random user ID), event names (such as page view, sign-up, and first export), and coarse usage counts such as processing minutes and plan type.
- What we never send: Your videos, audio, transcript content, file names, email address, and name are never transmitted to PostHog.
- Your choice: On our website you can turn analytics off at any time under Account → Settings. Separately, the macOS app reports a small number of milestone events from our servers (first upload, first export, and purchase); the website setting does not currently stop those. If you would like your analytics data removed, contact us and we will delete it.
3.7 Sentry (Crash and Error Reporting)
We use Sentry to detect crashes and errors in the App so that we can fix them.
- What we send: Crash and error reports, performance samples, the App version, your macOS version and device model, and — when a network request fails — the address of the request that failed. The Sentry SDK also generates a random identifier for your installation; we do not link it to your account.
- What we never send: Your videos, audio, transcript content, file names, email address, and name are never transmitted to Sentry.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. Data Retention
- Account data: Retained as long as your account is active. Deleted upon account deletion request.
- Audio files: Temporarily stored on AWS S3 for processing; retained for duplicate detection purposes.
- Transcription data: Retained as long as your account is active and the associated project exists.
- Topic and clip data: Retained as long as the associated transcription exists.
- Usage logs: Retained for up to 12 months for debugging and service improvement.
5. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption in transit: All data transmitted between the App and our servers uses TLS/HTTPS encryption
- Encryption at rest: Sensitive data is encrypted at rest in our databases
- Authentication tokens: Stored securely in macOS Keychain
- Presigned URLs: Audio uploads use time-limited presigned URLs that expire after use
- Access controls: Role-based access controls and row-level security (RLS) ensure users can only access their own data
6. Your Rights
6.1 All Users
- Access: Request a copy of your personal data
- Deletion: Request deletion of your account and all associated data
- Correction: Update your account information through the App
- Portability: Request your data in a portable format
6.2 European Economic Area (EEA) Residents
Under the General Data Protection Regulation (GDPR), you additionally have the right to:
- Object to processing of your personal data
- Restrict processing of your personal data
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
6.3 California Residents
Under the California Consumer Privacy Act (CCPA), you have the right to:
- Know what personal information is collected about you
- Know whether your personal information is sold or disclosed and to whom
- Say no to the sale of personal information (we do not sell your data)
- Request deletion of your personal information
- Not be discriminated against for exercising your privacy rights
7. Children's Privacy
The App is not intended for use by children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy within the App and updating the "Last Updated" date.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
- Email: privacy@cyberseeds.com
- Company: Cyberseeds
- Website: https://www.nexclipai.com