Who controls the data
The deployment operator must publish its legal identity before accepting production payments. Open-source contributors do not receive deployment data only because they contributed code.
Privacy notice · 2026-08-30
This notice describes the data used by the hosted ClipThrone deployment. A self-hosted operator is responsible for its own deployment and notices.
The deployment operator must publish its legal identity before accepting production payments. Open-source contributors do not receive deployment data only because they contributed code.
We process paid amount, board, Stripe confirmation identifiers, Product and Placement details, prompts, optional source images, generated media URLs, generation state, and timestamps. Stripe processes card and billing details. The application does not store full card numbers.
A random HttpOnly visitor cookie supports click deduplication and viewer estimates. Click records use a secret-keyed hash for one Placement and UTC day. The application does not store raw IP addresses in click records. Hosting and security providers can still process normal request data such as IP address, user agent, and referrer.
We use data to take payment, rank bids, create and show videos, redirect visitors, count activity, prevent abuse, moderate content, debug errors, keep financial records, resolve disputes, and meet legal duties.
Stripe handles checkout. fal and its model providers handle generation and V1 media storage. The deployment can also use PostgreSQL, hosting, network, email, monitoring, and analytics providers. These providers process data under their own terms and operator agreements.
Brand name, destination domain, paid amount, rank, video, reign time, click count, and activity history can be public. Do not submit information that you do not want displayed. Private payment credentials and prompts are not part of the public board DTO.
Payment and Placement records can be kept for tax, accounting, fraud, audit, and dispute needs. Public history can remain after a reign ends. Visitor and operational records should be kept only as long as needed. No system is completely secure. Production operators must set retention periods, access controls, backups, and incident procedures.
Depending on your location, you can have rights to access, correct, delete, restrict, object to, or export personal data. You can clear the visitor cookie in your browser. Some financial, security, and legal records cannot be deleted immediately.
A production operator must configure and publish a privacy contact.
The date at the top is the current notice version. A material change will be published here. Production operators must review this template with qualified counsel and change it to match their actual infrastructure and jurisdiction.