Privacy notice
CLAV is operated by Clavicular. This notice describes the current early-access service.
Information we use
We store public video information such as titles, creator names, source links, thumbnails and publication dates to support search. When you sign in or contribute, we store your account email, submitted files, source links, permission statements and review records. Connecting TikTok lets us obtain the account identifier, authorization tokens and public video information covered by the permissions you approve.
Why we use it
We use this information to operate accounts, import sources, review contributions, provide search and playback, and deliver approved downloads. We do not infer download or reuse permission from a public link or a TikTok connection.
Storage and providers
Supabase provides account, database and private-file storage. Hosting providers process service requests. Embedded videos load from their original platforms when you activate the player, and those platforms may collect information under their own policies. If enabled, transcription and visual-analysis providers process contributor footage that has been approved for that purpose. AI processing runs within an operator-controlled pilot budget.
On-demand downloads
When you request a video, CLAV contacts its source platform and temporarily stores the retrieved file on the hosting server. A private, expiring link lets your browser preview and save it. Files on CLAV’s server are deleted after 15 minutes; restarting the server can expire them sooner. We retain request timestamps and random identifiers to enforce the pilot allowance. Hosting and source providers may retain request logs under their own policies. Retouched files are temporary too. To retrieve a download, CLAV may send the public video URL to Apify and its downloader provider. We request deletion of provider files after transfer where supported. Current YouTube downloads use temporary storage in our Apify account, which we request deletion of after retrieval. Earlier test providers used provider-owned storage advertised to expire after approximately three days. Other provider records and logs follow their retention policies. TikTok source links and basic download metadata may be cached privately for ten minutes to avoid repeated provider requests. We retain provider run identifiers and cost records to enforce spending limits.
Cookies and connected accounts
We use local account-session storage and a short-lived cookie to protect TikTok authorization. TikTok access and refresh tokens are encrypted before database storage and are never displayed in search results. Team administrators can disconnect TikTok through the connections page or revoke CLAV from TikTok’s app permissions.
Retention and requests
We keep account and contribution records while needed to operate the service and maintain permission and review evidence. Disconnecting TikTok removes the locally stored connection tokens after successful revocation; it does not automatically delete independently collected public source records. Contact us to request access, correction, account deletion, content removal or review of a permission claim.
Contact: clavicular@clavicular.org
Platform policies: Google Privacy Policy · TikTok Privacy Policy