Skip to content

Privacy Policy

What we collect, why, who helps us run the service, and how long we keep it.

Last updated 6 October 2026

Who is responsible

CleanScript is responsible for the personal data described here. For any privacy question or request, write to mohamed@messaad.dev.

What we collect

  • Account data. Your email address and, if you sign in with Google, the basic profile Google shares with us. We never see your Google password.
  • API keys. We store only a hash of each key and a short prefix so you can recognise it. We cannot show you a key again after it is created.
  • Usage records. For each request: which key made it, the video or post ID, the endpoint, the status, how long it took, the credits used and when. These power your usage page and billing.
  • Payment records. Credit purchases and balances. Card details go straight to Stripe; we never receive or store them.
  • Stored results. The transcripts and fields we return for public posts, stored briefly to answer repeat requests.
  • Connections. Apps you connect through the MCP server (such as Claude or ChatGPT): the app's name and address, and hashed tokens, until you disconnect them in the dashboard.
  • Free-credit check. A one-way hash of your normalised email address, so free credits are given once per person. We keep it after you delete your account.
  • Technical logs. Errors and request metadata needed to run, secure and debug the service. Our hosting providers (Cloudflare, Google Cloud) log request metadata such as IP addresses. Rate limits are counted per account.

We do not sell personal data and we do not run advertising trackers.

Why we use it

To provide the service you asked for, take payment, keep it secure and prevent abuse, answer your questions, and meet our legal duties. Where the law asks for a legal basis, these are performing our contract with you, our legitimate interest in running a secure service, and legal obligation.

Public content we process

When you send a URL, we fetch that public post, its captions and its metadata, and may send its text, audio or video frames to AI models to correct captions, transcribe speech, read on-screen text or extract the fields you asked for. The content belongs to its creators; the Terms explain your duties when you use it.

How long we keep it

  • Stored results and post data: results up to 6 hours, post data less than an hour, then deleted automatically.
  • Safe-retry records (so a repeated request is not charged twice): up to 6 hours.
  • Rate-limit counters: minutes to hours, then deleted.
  • Account data, API key hashes, usage and payment records: while your account is open. Usage records are deleted with your account; payment records are kept as long as tax and accounting law requires.

You can ask us to delete your account and its data at any time; see your rights below.

Who processes data for us

  • Google Cloud (europe-west9, Paris) runs the API.
  • Cloudflare serves the website, the API proxy and DNS.
  • Supabase (eu-west-3, Paris) hosts the database and sign-in.
  • Stripe processes payments.
  • OpenRouter passes post text, audio and frames to AI model providers: OpenAI, and for speech to text Microsoft Azure, with DeepInfra or Groq as a backup. We ask for providers that neither store nor train on what we send.
  • SOAX and SmartProxy carry our requests for public posts to YouTube, TikTok and Instagram. They see the addresses of the posts, never your account.
  • Brevo sends sign-in and account emails.
  • Google, only if you sign in with Google.
  • Microsoft Clarity shows us how the website is used (see Cookies).

Some of these providers may process data outside the EU. Where they do, we rely on the safeguards the law requires, such as standard contractual clauses. We share data with them only to run the service, and with authorities only when the law requires it.

Cookies

We use cookies to keep you signed in, and Microsoft Clarity sets cookies to show us how visitors use the website: pages visited, clicks and scrolling. In the dashboard it records no text, so your keys, email and balance never reach it. We do not use advertising cookies. Stripe and Google set their own cookies on their pages when you pay or sign in with Google.

Your rights

You can ask us to access, correct, export or delete your personal data, or to object to or restrict how we use it. Write to mohamed@messaad.dev; we will reply within one month. If you are in the EU or UK, you can also complain to your local data protection authority.

Security

Keys are stored hashed, traffic is encrypted in transit, and access to production data is limited to the people who need it. No system is perfectly secure, so we cannot promise absolute protection. If a breach affects you, we will tell you as the law requires.

Children

CleanScript is not meant for children under 16, and we do not knowingly collect their data.

Changes

If we change this policy we will update the date above and, for material changes, tell you by email or in the dashboard.