1. Introduction
Clipia.ai is a service operated by Clipia LLC, a Wyoming (USA) limited liability company ("we," "our," "the Company"), which acts as the controller of your personal data. Clipia LLC respects your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use our Service, and describes your rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable U.S. privacy laws.
For users located in the Russian Federation, and for processing carried out under Russian law, the personal data operator is Individual Entrepreneur Maksim S. Zakharov (full details in Section 12). For that processing, this document also serves as the Personal Data Processing Policy required by Article 18.1(2) of Russian Federal Law No. 152-FZ of 27 July 2006 "On Personal Data", and is published without restriction at clipia.ai/privacy.
2. Data We Collect
2.1. Data you provide:
- Email and name during registration
- Payment information (processed through secure payment systems)
- Text prompts for generation
- Uploaded images and videos
- Support requests and related correspondence
2.2. Data collected automatically:
- IP address. In account sign-in records, in the administrator action log and in the billing audit log we store an irreversible hash of the address, computed with a secret salt, rather than the address itself. The hash shows that two events came from the same address, which is what protects the Service from abuse, but the original address cannot be recovered from it.
- Device and browser information
- Service usage statistics
- Cookies and similar technologies
Where the IP address stays in the clear. Hashing applies to the records listed above. Every request still reaches us from a real address, so it is present in the clear in operational technical records: web server logs, API request logs, application error records, records of authorisations granted to third-party applications, and the temporary abuse-protection and rate-limiting counters. Without it, traffic cannot be routed, failures cannot be diagnosed and network attacks cannot be blocked. Those records are accessible only to authorised personnel of the Operator and are not used to build a profile of you.
How long those records are kept. Web server logs — no more than 15 days: they are rotated every day and the 14 previous copies are retained. Application logs are rotated every day, and on heavy write volume once they reach 50 MB, with the 7 previous copies retained — for the main logs that means no more than 7 days. Copies of logs in the central log store — 30 days. Application error records are deleted 30 days after the error is resolved and in any case no later than 90 days after it first appeared. The temporary abuse-protection and rate-limiting counters live no longer than their window and never more than 24 hours. Records of authorisations granted to third-party applications are kept for as long as the authorisation is in force and are deleted together with the account. The API request log is stored in the Operator's database and is available to you in the Developer Console with a look-back window of up to 90 days; records that reach that age are deleted automatically — the cleanup runs every day. The administrator action log is kept for no more than 1 year, and administrator session records for the lifetime of the session plus 7 days after it expires; both are likewise removed by the same daily automatic cleanup.
On facial images. Images and videos you upload may contain depictions of faces. Such images are processed solely to provide the content generation and editing service. We do not use them to create a biometric identifier, faceprint, or template, and we do not use them to identify or verify any individual. Accordingly, we do not treat these images as biometric information for the purposes of the CCPA/CPRA or other applicable U.S. privacy laws.
CCPA categories. Under the CCPA/CPRA, the personal information above falls within the following statutory categories: identifiers (e.g., name, email, IP address); commercial information (e.g., transaction and payment records); internet or other electronic network activity (e.g., usage and device information); visual information (e.g., images and videos you upload); and other user-generated content (e.g., text prompts). We collect this information directly from you and automatically through your use of the Service.
3. How We Use Your Data
- Providing and improving the Service
- Processing payments
- Content moderation and security
- Personalizing user experience
- Communicating with users
- Complying with legal requirements
4. Processing Operations and Methods
We carry out the following operations with personal data: collection, recording, systematisation, accumulation, storage, clarification (updating, modification), extraction, use, transfer (provision, granting of access, including cross-border transfer), depersonalisation, blocking, deletion, and destruction.
The processing method is mixed: data is processed both with and without the use of automation tools, with and without transmission over information and telecommunication networks.
We do not sell personal data and do not disseminate it to an indefinite group of persons — except for what you publish yourself: when you post a work to a public area of the Service, your username is shown alongside it. Publishing a work is your choice and can always be undone.
On automated decisions. Decisions that produce legal consequences for a user, or that otherwise affect a user's rights and legitimate interests, are not taken solely on the basis of automated processing of personal data (Article 16 of Federal Law No. 152-FZ). The outcome of automated content checks can be reviewed by a member of our team at your request, sent to privacy@clipia.ai.
5. Moderation and Safety
To ensure platform safety, we:
- Store prompt hashes — to detect repeat violations, we store SHA-256 hashes of prompts, but not the prompts themselves
- Log moderation events — violation category, timestamp, action taken
- Do not store prohibited content — images and videos that violate our policies are immediately deleted
- Maintain a trust rating — an internal integrity score for each account
6. Data Retention and Destruction
6.1. Retention periods
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Generations | Until deleted by user or upon account deletion |
| Moderation logs | 90 days (critical — 7 years) |
| Technical logs | Web server logs — 15 days; application logs — the 7 previous copies under daily rotation, no more than 7 days for the main logs; copies in the central log store — 30 days |
| Application error records | 30 days after the error is resolved, and no more than 90 days after it first appeared |
| Sign-in and session records | For the lifetime of the session and 7 days after it expires |
| API request log | 90 days; older records are removed by an automatic daily cleanup |
| Administrator action log | No more than 1 year; older records are removed by an automatic daily cleanup |
| Payment information | As required by applicable law |
International data processing. Clipia LLC is the data controller. Personal data is processed and stored using infrastructure operated by our service provider located in the Russian Federation, under a data processing agreement that requires appropriate safeguards. By using the Service you consent to this processing location.
6.2. Destruction periods and procedure
Where processing is governed by Russian law, the following statutory deadlines apply:
- Withdrawal of consent or achievement of the processing purpose — we stop processing and destroy the personal data within no more than 30 days from the date the withdrawal is received or the purpose is achieved, unless a contract with you or a statutory retention duty requires otherwise (Article 21(4) and 21(5) of Federal Law No. 152-FZ)
- Unlawful processing identified — we stop the unlawful processing and block the data concerned within no more than 3 working days of identifying it; if lawful processing cannot be ensured, the data is destroyed within no more than 10 working days of identification (Article 21(3))
- Inaccurate data identified — the data is blocked for the period of verification and corrected within 7 working days of the inaccuracy being confirmed, after which the block is lifted (Article 21(2))
- Backups — destroyed data disappears from backup copies as they are rotated, and in any event no later than 90 days
Upon request, we send the data subject a confirmation that their personal data has been destroyed.
7. Your Rights
7.1. Rights of the data subject under Federal Law No. 152-FZ (Article 14)
If your data is processed under Russian law, you have the right to:
- Obtain information about the processing — confirmation that processing takes place, its legal grounds and purposes, the methods applied, the name and address of the operator, the categories of personal data processed and their source, the processing and retention periods, information about any actual or intended cross-border transfer, and the name of any party processing data on the operator's behalf
- Request clarification, blocking or destruction of your data where it is incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated processing purpose
- Withdraw your consent to the processing of personal data
- Object to processing carried out for the promotion of goods, works and services
- Appeal the operator's acts or omissions to Roskomnadzor or before a court
7.2. How to exercise your rights and our response time
Send your request to privacy@clipia.ai or dpo@clipia.ai. We may ask you to verify your identity before we act on the request.
Our response time is 10 working days from the date the request is received. That period may be extended by no more than 5 additional working days, and we will send you a reasoned notice explaining the reason for the extension (Article 20(1) of Federal Law No. 152-FZ).
7.3. Additional rights in specific jurisdictions
Under the CCPA/CPRA, California residents (and, where applicable, other U.S. consumers) have the following rights with respect to their personal information:
- Right to know / access — request the categories and specific pieces of personal information we have collected, the sources, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it
- Right to delete — request deletion of the personal information we collected from you, subject to legal exceptions
- Right to correct — request correction of inaccurate personal information
- Right to opt out of sale or sharing — direct us not to sell or share your personal information. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA
- Right to limit use of sensitive personal information — direct us to limit the use of any sensitive personal information to what is necessary to provide the Service
- Right to non-discrimination — we will not discriminate against you for exercising any of your privacy rights
- Right to data portability — receive a copy of your personal information in a portable, machine-readable format
Users in the European Economic Area and the United Kingdom additionally have the rights granted by the General Data Protection Regulation: access, rectification, erasure, restriction of processing, portability, objection to processing, and withdrawal of consent.
To exercise any of these rights, contact us at legal@clipia.ai or privacy@clipia.ai. We will verify your request using the information associated with your account and respond within the timeframes required by applicable law — up to 45 days under the CCPA/CPRA and up to 30 calendar days under the GDPR. You may use an authorized agent to submit a request on your behalf.
8. Cookies and Web Analytics
8.1. Cookies
We use cookies for the following purposes:
- Essential — authentication and security
- Functional — remembering your preferences
- Analytics — improving the Service
You can manage cookies through your browser settings. See our Cookie Policy for details.
8.2. Web analytics
- Russian Federation — Yandex Metrica (data stored in Russia). Session recording (Webvisor) is enabled: cursor movement, clicks, page scrolling and interaction with interface elements are recorded. These recordings are used only to diagnose the interface and improve the usability of the Service
- Users outside Russia — Google Analytics and Google Ads (USA): visit statistics and advertising performance measurement
- Foreign analytics counters are not loaded for users in the Russian Federation
- If your browser sends a Do Not Track or Global Privacy Control signal, no analytics is loaded at all
- For users in the European Economic Area, the United Kingdom and Switzerland, analytics cookies are set only after explicit consent
9. Disclosure of Personal Information to Third Parties
We disclose personal information to the following categories of third parties for business purposes only:
- AI model providers, to fulfill generation requests
- Payment processors, to handle transactions
- Stripe, which acts as the merchant of record for purchases charged in US dollars — to sell the order to you, take the payment, determine and remit applicable taxes, issue your receipt, and handle refunds and chargebacks
- Cloud and hosting providers, to store and process data
- Law enforcement or government authorities, upon a lawful request
Except as noted below, these third parties act as our service providers or contractors and are contractually restricted to using personal information only to perform services on our behalf. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
Stripe is an exception to that framing. As merchant of record it is the seller of your order, not our processor, and it determines the purposes and means of the payment data it collects — so for that processing it acts as an independent controller under its own privacy policy. Your payment details are entered directly on Stripe's hosted checkout page and are never transmitted to us; we receive only an anonymised customer identifier and the transaction result. Stripe does not receive your prompts, uploads or generated content, and plays no part in moderating them.
Because our processing infrastructure is located in the Russian Federation (see Section 6, International data processing), some disclosures involve the international transfer of personal information. Additional detail about foreign recipients and destination countries is available on request at legal@clipia.ai, and in our Cross-Border Data Transfer Policy.
10. Security and Incident Notification
10.1. Security measures
We implement industry-standard security measures:
- Encryption of data in transit (TLS/SSL)
- Encryption of data at rest
- Regular security audits
- Restricted access to personal data
10.2. Incident notification
If an incident occurs that infringes the rights of data subjects — unlawful or accidental transfer, provision, dissemination of, or access to personal data — we act in accordance with Article 21(3.1) of Federal Law No. 152-FZ:
- Within 24 hours of identifying the incident we notify Roskomnadzor of the incident itself: its presumed causes, the presumed harm to the rights of data subjects, the measures taken, and the person authorised to liaise with the regulator
- Within 72 hours of identifying the incident we notify Roskomnadzor of the results of our internal investigation and of the persons whose actions caused the incident, if any
- We inform affected users without undue delay where the incident is likely to create a risk to their rights and legitimate interests
11. Minors
- The Service is intended exclusively for persons aged 18 and over
- We do not provide the Service to persons under 18 and do not knowingly collect their personal data
- If we learn that an account was registered by a person under 18, that account is blocked and the personal data associated with it is deleted
- Parents and legal guardians can report such an account to privacy@clipia.ai
12. Controller, operator and contacts
12.1. Data controller details
| Name | Clipia LLC |
| Entity type | Limited liability company (State of Wyoming, USA) |
| D-U-N-S Number | 145057656 |
| Registered address | 30 North Gould Street, PMB R, Sheridan, WY 82801, USA |
12.2. Personal data operator for the Russian Federation
| Name | Individual Entrepreneur Maksim S. Zakharov |
| OGRNIP | 324366800070377 |
| INN | 361608356714 |
| Date of registration | 19 July 2024 |
| Address | 1 Aprelya St. 6, Otradnoye, Novousmansky District, Voronezh Region, 396336, Russia |
| Phone | +7 995 157-89-00 (weekdays, 8:00–18:00 Moscow time) |
| Registration number in the register of personal data operators | 36-26-045343 |
| Cross-border data transfer notification | No. 100330055 of 24 June 2026 |
12.3. Contacts
- Privacy requests and legal notices: legal@clipia.ai
- General personal data queries: privacy@clipia.ai
- Person responsible for organising the processing of personal data: dpo@clipia.ai
12.4. How to lodge a complaint
If you believe your privacy rights have been violated, you may lodge a complaint with the applicable regulator. In California, this is the California Privacy Protection Agency (cppa.ca.gov) or the California Office of the Attorney General (oag.ca.gov/privacy). In the Russian Federation, this is the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor), 7 bldg. 2 Kitaygorodsky Proezd, Moscow 109992 (rkn.gov.ru). We encourage you to contact us first at legal@clipia.ai so that we can address your concern.
12.5. Business purposes for processing
Consistent with the CCPA/CPRA, we collect and process personal information for the following business purposes:
- to provide, maintain, and improve the Service, and to perform our contract with you;
- to process payments and prevent fraud;
- to secure the platform, moderate content, and enforce our terms;
- to comply with legal obligations and respond to lawful requests.
Where we rely on your consent (for example, for the processing location described in Section 6), you may withdraw it at any time by contacting legal@clipia.ai, without affecting processing carried out before withdrawal.