Skip to content
snipio.io
FeaturesHow it worksUse casesPricing
Log inStart free ↗
FeaturesHow it worksUse casesPricingLog inStart free ↗

SNIPIO.IO / LEGAL

Privacy Policy

Last updated: 6 October 2026

This policy explains what information Snipio.io processes, how it is used and the choices available to you.

Terms of ServicePrivacy Policy

1. Who handles your information

This policy explains personal-data processing in Snipio.io, including the public website, studio, video-processing workflow and connected-platform publishing. Snipio.io handles account, billing and service-administration data to operate the service.

When an organisation uploads personal data on behalf of others, its own responsibilities may also apply. A separate data-processing agreement is needed where Snipio acts as its processor; these pages do not replace that agreement.

2. Information we process

  • Account: email address, account identifier, password hash if you use a password, and session records. Google sign-in also supplies a Google account identifier and verified email.
  • Creative workspace: recordings, source URLs, audio, transcripts, prompts, clip selections, captions, exports and uploaded brand assets. Recordings may contain voices, images and information about other people.
  • Connected accounts: platform identifiers, display name, profile image, authorisation tokens, granted permissions, post captions, selected settings, schedules and publication status.
  • Transactions: purchased credits, payment references, amounts, currency and payment status. Card details are entered into Stripe’s checkout, not our video editor.
  • Technical and support information: IP address, request and error logs, browser information and information you send when contacting us.

3. Why we use it

Account access, requested video processing, payments and authorised publishing support performance of our contract with you (GDPR Article 6(1)(b)). Security, abuse prevention and troubleshooting rely on legitimate interests in operating a reliable service (Article 6(1)(f)), balanced against your rights. Records required by law rely on legal obligations (Article 6(1)(c)).

Where processing requires consent, we request it separately and you may withdraw it. Platform authorisation controls API access; it is not blanket consent to unrelated data use. Required account and content data are necessary to provide the corresponding features.

4. Video processing & AI

Snipio processes your recording to create transcripts and clips. For moment selection, transcript segments, timestamps, relevant project options and your instructions are sent through OpenRouter to the configured AI model provider. This can include personal information spoken in your video or included in your prompt.

Only upload material you are entitled to process. Do not include unnecessary sensitive information. External AI providers process the information they receive under their applicable terms and privacy policies. Their handling of data, including retention, depends on the provider and service used.

AI suggests creative edits. The implemented workflow does not make legal or similarly significant automated decisions about you.

5. Your TikTok connection

When you choose to connect TikTok, Snipio requests user.info.basic and video.publish. It receives your basic profile and authorisation tokens, retrieves creator settings and sends the video, caption and publishing options you approve to TikTok. Tokens are stored encrypted in the application database.

Disconnect through Scheduler to remove the stored connection and cancel queued posts. You may also revoke access through TikTok. Existing publication history can retain the account display name; an already submitted video may still finish processing. Removing the connection does not erase previously published videos from TikTok.

TikTok handles data received on its platform under its own privacy policy. We do not request access to your TikTok password or private messages.

6. Service providers & recipients

Data is disclosed as needed to providers supporting the selected features: OpenRouter and the configured model provider for AI analysis; Stripe for payments; Google if you choose Google sign-in; TikTok if you connect and publish; and infrastructure providers for hosting, delivery, storage and security. Authorised administrators may access information for operations and support.

Data may also be disclosed where required by law or necessary to establish or defend legal claims. Provider roles and processing terms depend on the relevant service and agreement.

7. International processing

External providers may process information outside your country, including outside the EEA. Where GDPR applies, such transfers require a valid transfer mechanism and any necessary additional safeguards.

8. Storage & deletion

Workspace content remains available until you delete it or request account closure, subject to operational and legal retention needs. Deleting a project removes its project records and files; a shared source can remain while another project still uses it. Disconnecting a social account removes its connection credentials, while publication history may remain.

Security, payment, support and backup records may need separate retention periods. Data required for legal obligations or claims can be restricted and retained for that purpose.

9. Cookies & browser storage

The application uses essential authentication cookies: access_token (15 minutes) and refresh_token (30 days, renewed during session refresh). Google and social-account connection flows use temporary state cookies for up to 10 minutes. The browser may also store interface preferences locally.

These support sign-in, session security and requested connections. Blocking them can prevent those features from working. These document pages do not require cookies or JavaScript to read. Third-party checkout and sign-in pages apply their own cookie notices. Non-essential tracking requires a separate assessment and consent where applicable.

10. Your choices & rights

Where applicable, you may request access, correction, deletion, restriction and portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. Contact [email protected]; we may need proportionate identity verification. GDPR requests are normally answered within one month, with a notified extension where legally permitted.

You may complain to your local data-protection authority, including the authority where you live, work or believe an infringement occurred. For Poland, this is the President of the Personal Data Protection Office (UODO). You do not have to contact us first.

11. Security & younger users

The implementation uses password hashing, protected session cookies, access controls and encryption of stored social-platform tokens. No system is risk-free. Use a unique password and report suspected compromise without including secrets in your message.

Snipio accounts are intended for adults aged 18 or over. If you believe a child created an account or their information was uploaded unlawfully, contact the operator so it can be investigated. Users must have appropriate authority to upload recordings involving other people.

12. Policy updates & contact

We will update this document when processing practices change and give additional notice of material changes where required. The date at the top identifies this version. For questions, deletion requests or details about providers and transfers, contact [email protected].

Read the Terms of Service for account, payment and publishing conditions.

SNIPIO.IOBack to top ↑
snipio.io

Good stories deserve
more than one moment.

EXPLOREFeaturesHow it worksUse casesPricing
LET’S CREATEGet started free ↗Log inOpen studio ↗
Terms of ServicePrivacy Policy
© 2026 Snipio.ioMade for your next great moment.Back to top ↑