Privacy Policy
Last updated: April 26, 2026
1. Data Controller
SmartClipper ("we", "us", "our") is the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) and other applicable data protection laws.
For any data-related inquiries or to exercise your rights, contact us at: privacy@smartclipper.app
We will respond to your requests without undue delay and in any event within one month, as required by GDPR Article 12(3).
2. Data We Collect
We collect the following categories of personal data:
a) Account Information
- Name and email address (during registration)
- Google ID (if you sign in with Google)
- Hashed password (email/password registration only)
b) Learning Preferences (optional)
- Age range, knowledge level, interests, bio, content language
- Used to personalize content difficulty, tone, and recommendations
c) Content Data
- Clips you create: URLs, text prompts, AI-generated summaries, flashcards, quiz questions, lessons
- Learning paths, module progress, quiz scores
- Favorites and study preferences
d) Usage and Activity Data
- Clip creation frequency and AI token consumption (for enforcing fair-use limits)
- Study activity: streaks, XP earned, modules completed
- Flashcard review history (spaced repetition scheduling)
e) Technical Data
- Authentication tokens (stored locally on your device in encrypted storage)
- Push notification device tokens (APNs)
- Subscription status (via RevenueCat)
We do not use cookies, tracking pixels, or third-party analytics services (e.g., Google Analytics, Mixpanel). We do not track your browsing behavior outside the app.
3. Purpose and Legal Basis
We process your data on the following legal bases:
Performance of a contract (GDPR Article 6(1)(b))
- Providing the SmartClipper service: creating clips, generating study materials, managing learning paths
- Account management: authentication, email verification, subscription handling
- Communication: sending verification emails and service-essential notifications
Legitimate interest (GDPR Article 6(1)(f))
- Service protection: monitoring aggregate usage patterns to prevent abuse, enforce fair-use limits, and ensure reliable service for all users
- Service improvement: analyzing aggregate, non-identifying usage patterns
Consent (GDPR Article 6(1)(a))
- Sending optional push notification reminders (you can opt out at any time in Settings)
- Processing optional learning preferences (age range, interests, bio) to personalize content
4. Data Sharing and Third-Party Processors
We do not sell your personal data. We share data with the following third-party processors, strictly for providing the service:
- Anthropic (Claude API) — Content you submit (URLs, text prompts) is sent to Anthropic's Claude API to generate summaries, flashcards, quizzes, and lessons. Anthropic processes this data per their data processing terms and does not use it for model training.
- OpenAI (Whisper API) — Podcast audio may be sent to OpenAI's Whisper API for transcription. Only the audio content is transmitted, not your personal information.
- Resend — Your email address is shared with Resend for sending verification codes and service emails.
- RevenueCat — Your user ID and subscription events are shared for managing in-app purchases. RevenueCat does not receive your name or email.
- Apple Push Notification service (APNs) — Device tokens are shared with Apple to deliver push notifications. No personal data beyond the device token is transmitted.
- Google (OAuth) — If you use Google Sign-In, Google provides us with your name and email. We do not share your SmartClipper data with Google.
5. International Data Transfers
Some of our third-party processors are based in the United States (Anthropic, OpenAI, Resend, RevenueCat). When your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards:
- Transfers are based on Standard Contractual Clauses (SCCs) approved by the European Commission, or the processor's compliance with an adequate level of data protection.
- We take reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy.
6. Data Retention
We retain your personal data for as long as your account is active and necessary to provide the service.
- Active accounts: data retained indefinitely while the account is in use.
- Account deletion: all associated data (profile, clips, flashcards, quiz history, learning paths, activity logs, device tokens, AI usage logs) is permanently deleted from our servers.
- Guest accounts: automatically deleted within 24 hours or during daily cleanup routines.
- AI processing logs: token usage records are deleted when the associated account is deleted.
We do not retain any data after account deletion. There is no backup retention period.
7. Your Rights
Under the GDPR and applicable data protection laws, you have the following rights:
- Right of access (Art. 15) — request a copy of your personal data.
- Right to data portability (Art. 20) — export all your data in a structured, machine-readable format (JSON) via Settings > Profile > Export My Data.
- Right to erasure (Art. 17) — delete your account and all data via Settings > Profile > Delete Account.
- Right to rectification (Art. 16) — update your personal information through your profile settings.
- Right to restriction of processing (Art. 18) — request that we limit how your data is processed.
- Right to object (Art. 21) — object to processing based on legitimate interest (e.g., abuse prevention analytics). We will stop processing unless we have compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)) — for consent-based processing (push notifications, learning preferences), you can withdraw at any time in Settings without affecting the service.
- Right to lodge a complaint (Art. 77) — file a complaint with your local data protection authority.
To exercise your rights, contact us at privacy@smartclipper.app. We will respond within one month of receiving your request.
8. Automated Decision-Making
SmartClipper uses AI to generate educational content (summaries, flashcards, quizzes). This processing assists you in studying and does not produce legal effects or similarly significantly affect you.
No automated decisions are made about your access to the service, your subscription, or any other matter that produces legal or similarly significant effects. Usage limit enforcement is based on straightforward counting, not profiling.
9. Children's Data
SmartClipper is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children under 16.
If you are a parent or guardian and believe your child under 16 has provided us with personal data, please contact us at privacy@smartclipper.app and we will promptly delete the data.
10. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Password hashing using bcrypt.
- JWT-based authentication with short-lived access tokens (30 minutes) and refresh tokens.
- Encrypted data transmission (HTTPS/TLS).
- Encrypted token storage on device (iOS Keychain / Android EncryptedSharedPreferences).
- AI input/output validation and content filtering to prevent prompt injection attacks.
- Rate limiting on all API endpoints.
- Database access controls and parameterized queries.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
Continued use of SmartClipper after the effective date of changes constitutes acceptance. If you do not agree, you may delete your account before the changes take effect.
12. Contact
For questions about this privacy policy or to exercise your data protection rights, contact us at:
privacy@smartclipper.app