Skip to content
WordToClip

Privacy policy

Privacy policy

Last updated: 30 September 2026

This policy explains what personal data WordToClip collects, why, who else handles it, how long we keep it, and how you can see, correct or delete it. It covers the website, the MCP server and the community area.

Contents
  1. 1. Who is responsible
  2. 2. The short version
  3. 3. What we collect, feature by feature
  4. 4. Why we use it, and on what legal basis
  5. 5. Automated decisions
  6. 6. Who else processes your data
  7. 7. International transfers
  8. 8. How long we keep it
  9. 9. Cookies and local storage
  10. 10. Your rights
  11. 11. Children
  12. 12. Security
  13. 13. Changes to this policy
  14. 14. Contact

1. Who is responsible

The controller of your personal data is Daniel Metodiev, a sole proprietor in Bulgaria, who runs WordToClip. For anything about your data, write to support@wordtoclip.com. We have not appointed a data protection officer, because the law does not require one for a service of this kind; the address above reaches the people who handle your data.

  • Operator: Daniel Metodiev, a sole proprietor in Bulgaria, trading as WordToClip
  • Address: Pernik, Bulgaria
  • Website: www.wordtoclip.com
  • Contact: support@wordtoclip.com
  • Payments: Paddle.com Market Limited is the merchant of record for every purchase (see the Refund policy).

2. The short version

  • We collect what the service needs to work, and little more.
  • No advertising, no ad tracking, no analytics scripts, no selling or sharing of personal data for anyone else's purposes.
  • The only cookies are strictly necessary ones: they keep you signed in, protect forms, and count free Play time for visitors without an account. There is nothing to consent to, so there is no cookie banner.
  • You can delete your account yourself, and it takes your data with it.

3. What we collect, feature by feature

When you visit without an account

  • Network data: your IP address, browser user agent, the page or API address requested and the time, in our server logs, and the IP address in short-lived counters that enforce rate limits and the 30-second preview window.
  • Searches: the words you search, the search mode and filters, how many results came back and how long it took. Website searches are stored without any link to you or your IP address; we use them for the trending lists and to improve search.
  • Your browser: a few preferences kept in your browser's local storage (see Cookies). They stay in your browser; the exceptions are listed there.

Your account

  • Sign-in: your email address and a salted hash of your password (never the password itself). If you use “Continue with Google”, we receive your Google account ID, email address, name and picture from Google (the openid email profile scopes) and store only the ID and the email; the name and picture are discarded.
  • Account emails: when you confirmed your email address, a new address waiting to be confirmed, and when you accepted the Terms (with their version). We email you only about your account: the link that confirms your address or a new one (valid for 3 days), password-reset links (valid once, for 60 minutes), notices when your password is reset or changed, when a change of sign-in address is asked for and when it happens, and when someone tries to sign up with your address. No marketing.
  • Profile: your handle (a random one until you choose), and optionally a display name, a bio and a profile photo. These are public on your creator page.
  • Devices: for each signed-in session: the browser user agent, when it started and when it was last active, so you can see and end sessions. We do not record your location.
  • Plan and credits: your plan, its status and billing period, and a ledger of every credit movement (grants, purchases, spending, refunds), plus your low-credit alert threshold.

Payments

Paddle, our merchant of record, collects your payment details, billing address and tax information on its own checkout; we never see your card number. Paddle sends us your Paddle customer and subscription IDs, what you bought, the amounts and the transaction status, which we store as the record of your plan and purchases.

Your work

  • Exports and projects: the videos and time ranges you clip, presets and export options, project contents, saved moments, and the rendered files (video, subtitles and poster image).
  • Uploads: music, sound effects and images you upload, with the time you confirmed you hold the rights. They are private to your account.
  • AI mode: your prompt, the options you chose, the plan the model returned, and technical data about the generation (model, tokens used, cost and outcome).
  • AI assistants (MCP) and alerts: the keys you create to connect an AI assistant (a name, the first characters, a one-way hash, the scope, when it was last used and how many requests it made per day, kept 90 days; the full key is shown once and never stored readable), searches your assistant made with a key (linked to that key and your account), keyword alerts and their matches, webhook addresses (retired API plans only), signing secrets and delivery logs (kept 90 days), and request replay records (kept 24 hours). The MCP server keeps state per account: a project's export options (for up to 30 days), price quotes (15 minutes), and how many credits it spent today.

Video excerpts

  • Excerpts played: which 60-second excerpts you played today (the video and the start time), linked to your account, kept up to two days to count the daily limit, then deleted on their own.

Play time

  • Signed in: the topics you type, the moments you were played and your place in the queue, how many seconds of audio and video you used each day, your player settings (length, audio track, music, volume), and your “More like this” / “Not this” feedback (kept 90 days). A topic played, or searched through an AI assistant, by at least 5 different accounts in 30 days can be shown to everyone as a suggestion, without saying who typed it.
  • Without an account: the topic you type and the moments played for it, kept 90 days and linked to nobody; a signed cookie (cs_pt_anon) and a counter keyed by your IP address count the free moments you played today, and both expire within two days.

Community

  • Public by design: the shorts you publish (the clip, title and caption) and your comments, shown with your handle, and like and view counts.
  • Likes and reports: which shorts and profiles you liked; reports you file, with the reason and your note. Reports from visitors who are not signed in are stored with a one-way salted hash of the IP address, never the address itself. That hash is pseudonymous data: it lets us count one visitor's reports once, but cannot be turned back into the address.

Takedown notices and messages

  • Takedown notices: the name, email address, claim text and links you send through the takedown form, the time you accepted the sworn statement, your IP address (cleared after 90 days), and every decision we make on the notice.
  • Messages: what you write to us by email, and our replies.

Error reports

When our server hits an error, a report goes to our error monitoring service. It holds the page or API path that failed (without its query string), your browser's user agent, the error details (the code path, the message and the software version) and the warnings logged just before it. It is configured not to send cookies, your IP address, request bodies, query strings or the values inside the code. A report can include our internal number for your account when it appears in a log line, but never your email address or name.

4. Why we use it, and on what legal basis

  • Running the service you asked for: accounts, sign-in, search, previews, exports, projects, uploads, AI mode, Play time, the MCP server, alerts and the community. Basis: performing our contract with you (GDPR Art. 6(1)(b)).
  • Payments, credits, tax and accounting: Basis: our contract with you, and our legal obligations (Art. 6(1)(c)).
  • Security and abuse prevention: rate limits, the anonymous preview window, fraud and scraping detection, server logs and error reports. Basis: our legitimate interest in keeping the service safe and available (Art. 6(1)(f)).
  • Improving search and the trending lists: from search logs. Basis: legitimate interest; website searches are not linked to anyone.
  • Moderation and takedowns: handling reports and copyright notices, and keeping a record of our decisions. Basis: legal obligations and our legitimate interest in respecting rights holders and protecting the community.
  • Talking to you: answering messages and telling you about changes to the service or these policies. Basis: contract and legitimate interest. We do not send marketing email.

5. Automated decisions

We make no decisions about you that have legal or similarly significant effects based only on automated processing. Two things happen automatically and are always reviewed by a person: an item reported by 3 people is hidden until a moderator decides, and a takedown notice is matched to our videos but never applied until a person approves it.

6. Who else processes your data

We use these providers. Processors act only on our instructions under a data processing agreement; the others are independent controllers with their own privacy policies.

  • Hetzner Online GmbH (Germany): processor. Hosts our server, database and media files in Germany, and our off-site database backups (which are encrypted) and original video files on a Storage Box in Finland (both EU).
  • Anthropic, PBC (USA): processor. Runs the language model behind AI mode. It receives your prompt and excerpts from the archive, but not your name, email or account ID. Under its commercial terms it may not use this data to train its models.
  • Groq, Inc. (USA): processor. Transcribes archive audio, scores highlights, checks who is speaking in a video, and turns a Play time topic into search phrases. It receives archive content and, for Play time, the topic a signed-in reader types, but not your name, email or account ID.
  • DeepInfra, Inc. (USA): processor. Transcribes the archive's audio. It receives archive content only, no data about you.
  • Functional Software, Inc. (Sentry, USA): processor. Error monitoring for our server, set up without user identifiers.
  • Email: Resend: processor. Delivers our account emails (address confirmation, password reset) and hosts the mailboxes we use to answer support messages and takedown notices.
  • Paddle.com Market Limited (UK): independent controller. Merchant of record for every purchase; see Paddle's privacy notice.
  • Google (Google Ireland Ltd / Google LLC): independent controller, only if you use “Continue with Google”.

We also share data in these cases:

  • Things you publish (shorts, comments, your profile) are visible to everyone.
  • Services you connect: an AI assistant you connect to the MCP server, or a webhook address you register, receives the data you ask it to receive. They are not our processors; their own terms apply.
  • Takedowns: if a notice concerns your short or your upload, our staff may forward it to you by email so you can respond, and forward a counter-notice you send us to the person who filed the notice, as copyright law requires. This is done by hand; nothing is sent automatically.
  • Legal requirements: to authorities or courts when the law requires it, or to protect rights and safety.
  • A change of ownership: to a successor that takes over the service, which must keep this policy's promises.

The videos in the archive come from public platforms (such as Rumble and YouTube). We send those platforms no data about you. If you follow a link from a video page to the original video, you leave WordToClip, and that platform's own privacy policy applies.

7. International transfers

Our servers and storage are in the EU (Germany and Finland). Anthropic, Groq, DeepInfra, Sentry and Google are US companies, so some data may be processed in, or accessible from, the United States. We rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses with additional safeguards. Paddle is in the UK, which the EU recognises as providing adequate protection. Ask us for a copy of the safeguards.

8. How long we keep it

  • Your account and your work: while your account exists. Deleting the account removes it (next line).
  • When you delete your account: the account and everything attached to it are erased at once: profile and photo, sign-in links, sessions, projects, exports, uploads, images, AI plans, published shorts, comments, likes, alerts, assistant keys and webhooks; their files follow within a day. Your credit movements (amounts, dates and payment references) are kept without any link to you, as financial records, and your searches remain only as anonymous statistics. Copies in our database backups are deleted as the backups age out (see Backups). Reports you filed stay as moderation records, without any link to you or your address.
  • Rendered exports: 7 days after rendering, then the files are deleted (the entry stays in your history). Download links expire after 6 hours.
  • Published shorts: until you unpublish or delete them, or delete your account. A short hidden after a report or a takedown is not deleted: its video is kept out of public reach while a report or any takedown or counter-notice case about it is open, and for 60 days after the last case closes, so it can come back if the case is decided for you. Share preview images are recreated as needed and removed after 30 days.
  • Play time: your topics, listening history and daily usage while your account exists; feedback 90 days. Topics typed without an account: 90 days.
  • Sign-in session: 14 days, or until you sign out or end the session.
  • Backups: a nightly database backup is kept 14 days on our server, and an off-site copy, which is encrypted, is deleted from the Storage Box once it is older than 14 days. The Storage Box's own snapshots, if enabled, may keep a copy for up to 14 days longer.
  • Rate-limit, preview-window and excerpt counters: from a minute up to two days, then they expire on their own; the record of which excerpts you played counts toward the daily limit and is gone within two days.
  • Server logs: rotated automatically by size and overwritten, usually within days; we do not archive them.
  • Error reports: as long as our error-monitoring plan keeps them, at most 90 days.
  • Search logs: every search is deleted after 365 days. Website searches carry no personal data. Searches an AI assistant makes with your key are linked to your account until then, or until you delete the account, after which they remain only as anonymous statistics.
  • Payment records: the purchase notifications Paddle sends us and your credit movements are kept for at least 10 years, as accounting law requires, even after your account is deleted. Paddle keeps its own records under its policy.
  • Takedown notices and decisions: as long as they may be needed to establish or defend legal claims, which is at most the applicable limitation period. The IP address a notice was sent from is cleared after 90 days.
  • Offline copies on your device: the app keeps up to 24 recently opened pages and 24 answers from our server, which is about 12 recently opened transcripts with their video details, in your browser, so they open offline. They are cleared when another account signs in on the same browser, and you can clear them with your browser's site data.
  • Removed profile photos: a moderator's removal keeps only a fingerprint of the image, so the same photo cannot be uploaded again; the image itself is deleted.

9. Cookies and local storage

We set only cookies that are strictly necessary for a service you asked for, so no consent is needed:

  • sessionid: keeps you signed in; also holds the security state for a moment while you sign in with Google. httpOnly, secure, first-party; lasts 14 days or until you sign out.
  • csrftoken: protects forms against cross-site request forgery. Secure, first-party; lasts up to one year.
  • cs_pt_anon: only for Play time without an account: counts today's free moments so the free limit holds. Signed, httpOnly, first-party; expires at midnight UTC.

Your browser's local storage holds a few values the app uses in your browser; none of them is sent to us on its own:

  • cs-reader: the internal number and plan of the account last signed in here (so the right screen shows first and another account's offline copies are cleared); emptied when you sign out.
  • cs.low-credits.dismissed.<number>: that you dismissed the low-credits notice, per account.
  • cs.install.dismissed, cs.visits: that you dismissed the install banner, and a visit count for it.
  • cs.shorts.swiped: that you have swiped the shorts feed once, so the hint is not shown again.
  • clipsearch:soundtrack:<project>: a project's soundtrack timeline while you edit it.

Session storage, which your browser empties when the tab closes, holds cs.visit-counted (this visit was counted) and clipsearch:image-rights:<number> (that account confirmed the rights to the images it uploads, so it is asked once), and mail-link:<path> (the one-time code from an email link you opened, while you finish confirming or resetting; it is sent back to us once, when you submit that step). The service worker's offline cache is described under How long we keep it.

Fonts are served from our own domain, and our pages load no third-party analytics or advertising scripts. Paddle's checkout runs on Paddle's pages under its own cookie policy.

10. Your rights

Under the GDPR (and the UK GDPR) you have the right to access your data, to correct it, to have it erased, to restrict or object to its processing, and to receive it in a portable format. Where we rely on legitimate interests, you can object, and we will stop unless we have compelling grounds.

Do it yourself

  • Change your email address or password, see your devices and sign out of them in Settings & security.
  • Edit or clear your profile, unpublish shorts, delete uploads and images, revoke assistant keys and remove alerts in your account.
  • Delete your account at the bottom of Settings & security. If you have a paid plan, cancel it in the billing portal first.

Ask us

For a copy of your data, or anything you cannot do yourself, write to support@wordtoclip.com from the address on your account. We answer within one month; if a request is complex, we may take up to two more months and will tell you why. We may ask you to confirm your identity first.

You can also complain to a data protection authority, where you live or where we are established: the Commission for Personal Data Protection (КЗЛД), Sofia, Bulgaria (cpdp.bg). We would appreciate the chance to fix the problem first.

11. Children

WordToClip is for adults. Nobody under 18 may create an account, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to support@wordtoclip.com and we will delete it.

12. Security

Passwords are stored only as salted hashes and assistant keys only as one-way hashes. All traffic is encrypted (HTTPS with HSTS); session cookies are httpOnly, secure and same-site. Downloads and working copies are served through signed links that expire. Only authorised staff can reach the administration tools, and every takedown decision is logged. Off-site backup copies are encrypted.

No system is perfectly secure. If a breach puts your data at risk, we will tell the authority and, where the law requires it, you, without undue delay.

13. Changes to this policy

When we change this policy we update the date at the top. If a change is material, for example a new purpose or a new kind of provider, we announce it on the site and, where we can, by email, before it takes effect.

14. Contact

Privacy questions and requests: support@wordtoclip.com. Everything else: support@wordtoclip.com. Requests about videos in the archive, including a person who wants a clip of them to stop being shown, go through the takedown page or to support@wordtoclip.com.