Skip to content

Privacy Policy

Effective and last updated: August 13, 2026

Summary

Clip QA helps you record, analyze, and share bug reports. Editing and project storage are primarily local, but account, sharing, AI analysis, billing, security, and optional analytics features use cloud services. We do not sell personal data or use your content for advertising. You control when a recording is uploaded or made available through a public link.

1. Who Is Responsible for Your Data

Controller: [LEGAL NAME], [POSTAL ADDRESS].

The controller is responsible for personal data processed through the Clip QA mobile apps, website, dashboard, and related services (together, the “Service”). Privacy questions and requests can be sent to privacy@clip.qa. General support is available at hello@clip.qa.

2. Data We Process

Account, profile, and workspace data

  • Email address, display name, profile image, internal user ID, authentication provider, and sign-in or security records.
  • Workspace membership, roles, invitations, settings, subscription entitlements, usage and quota counters, and project metadata.
  • Support messages and other information you choose to send us.

Content you choose to create, import, upload, or share

  • Screen recordings, optional microphone narration, and videos or photos you select from your device.
  • Bug reports and AI-analysis inputs and outputs, which may include transcripts, screenshots, console output, network request details and headers, request URLs, device or app context, steps, and interaction breadcrumbs.
  • Comments, annotations, report links, export data, and other content you or your collaborators add.

This content can contain personal or confidential information visible in a recording or supplied diagnostic context. Review and redact it before uploading, sharing, or exporting it.

Device, network, diagnostic, and interaction data

  • Device and operating-system type and version, app and browser version, language, timezone, consent preferences, and feature interactions.
  • IP address and request metadata processed by infrastructure providers, timestamps, security events, server logs, error details, and technical diagnostic traces.
  • Website page views, referrals, clicks, scrolling, and session-replay or heatmap data when the applicable website analytics setting permits it.

Billing data

Stripe processes payment details for Clip QA subscriptions. Clip QA receives and stores the identifiers and status needed to provide and administer a subscription, such as Stripe customer, checkout, subscription, product, transaction, and billing-state information. We do not receive full payment-card numbers.

3. Device Access and Local Files

Clip QA accesses only the device resources needed for features you choose to use:

  • Photo library or file picker: to import media you select.
  • Screen recording: to capture a recording when you start that feature.
  • Microphone: optional narration, controlled through device permissions and recording controls.
  • App storage: local projects, edits, thumbnails, recordings, and credentials in the app's sandbox or secure storage.

The current Clip QA app does not request, collect, or retain GPS or precise-location data. Local data remains under your device controls unless you choose a cloud feature such as AI analysis, cloud upload, or sharing.

4. Optional Analytics and Diagnostics

Mobile Firebase Analytics

Mobile Firebase Analytics is off unless you explicitly consent. If enabled, Firebase may process basic app, device, and session metadata supplied by its SDK, such as app version, device model, operating-system version, language, approximate region, and app-instance identifiers. The current app emits these named feature events:

  • app_open
  • video_recorded with recording duration
  • ai_report_generated with generation method
  • report_exported with export format
  • report_shared with destination type
  • paywall_shown with trigger

Recording, transcript, screenshot, bug-report, and file-path content is not intentionally placed in those analytics events. Clip QA does not currently emit Firebase screen-view or Firebase Performance events. You can withdraw mobile analytics consent in Settings; the app then disables collection and resets the SDK's on-device analytics data and app-instance identifier.

Website analytics and replay

The website may use Google Analytics 4 and Microsoft Clarity for traffic and interaction analytics according to the consent state and regional behavior implemented by the website. Clarity can provide heatmaps and session replay. The website also uses Sentry for technical error monitoring; Sentry web replay is enabled only when analytics consent is recorded. Some sensitive routes and fields receive additional masking or replay restrictions, but you should not submit information you do not want processed by the page you are using.

Mobile crash-report uploads and mobile session replay are disabled in version 1. Attached-device logs can still be used locally for diagnosis.

5. Why We Process Data and Our Legal Bases

  • Provide the Service and perform our contract: authenticate you, store projects and reports, process chosen recordings, generate AI reports, create shares and exports, support collaboration, and administer subscriptions.
  • Your consent: access optional device resources and run optional analytics or session replay where consent is required. You can withdraw consent without affecting processing that was lawful before withdrawal.
  • Legitimate interests: secure the Service, prevent abuse and repeated free-trial or quota evasion, diagnose faults, measure reliability, improve features, and enforce our terms, balanced against your rights.
  • Legal obligations: retain or disclose limited billing, tax, fraud, or compliance records where law requires it.

6. Service Providers and Other Recipients

We disclose data only as needed to operate the Service, follow your instructions, protect the Service, or comply with law. Current provider categories include:

  • Google Firebase: authentication, database, server functions, and consent-gated mobile analytics.
  • Google Gemini: processes the recording, screenshots, transcript, and diagnostic or report context you submit for AI-assisted report generation. Clip QA does not use your content to train its own models.
  • Cloudflare and Cloudflare R2: edge security, delivery, rate limiting, and storage or delivery of cloud recordings, screenshots, and share assets.
  • Sentry: website and server error monitoring, and consent-gated website replay, including technical request, device, release, stack-trace, and breadcrumb data needed to investigate faults.
  • Stripe: checkout, subscription administration, fraud prevention, and payment-related records.
  • Google Analytics 4 and Microsoft Clarity: website traffic and interaction analytics according to website consent controls.

If you export content to an integration or another service, that recipient processes it under its own terms and privacy policy. We may also disclose information to professional advisers, authorities, or a successor in a corporate transaction where permitted by law.

7. Public Links and Sharing Controls

Recording-request links are disabled in version 1 and cannot be created or used. Any pre-release recording-request-link records are inaccessible and are removed through account deletion.

Shared report and video links cannot be independently revoked in version 1. Anyone with a valid link can access the published content until its share token expires, the underlying content is deleted, or the owning account is deleted.

Public report views are designed to redact sensitive diagnostic details, but you should review the report before publishing it. Files exported to Photos, Files, another app, an integration, or another person's device are outside Clip QA's control. Expiry or deletion cannot remove those independent copies.

8. Retention

  • Local app data: retained until you delete the item, clear the app's data, delete the app, or complete native account deletion.
  • Account and cloud content: retained while needed to provide the Service or until you delete the item or account, subject to successful completion of the deletion workflow.
  • Disabled recording-request-link records: inaccessible in version 1 and removed through account deletion.
  • Shared report and video links: available until their token expires or the underlying content or account is deleted; they have no separate v1 revocation control.
  • Security, diagnostic, and analytics records: retained for limited operational periods set according to security, reliability, consent, and provider requirements.
  • Billing and legal records: retained only as long as required for transactions, disputes, fraud prevention, tax, accounting, or other legal duties. Stripe may retain its own records independently.
  • Backups and recovery systems: deleted data may persist for a limited rotation period, protected from ordinary use, before being overwritten.

After account deletion, Clip QA is designed to retain a durable pseudonymous deleted-user entitlement record to prevent repeated free quotas or trials. It uses a cryptographically protected hash rather than the original email address and retains only abuse-prevention and prior-entitlement facts, not recordings, reports, profile data, or raw credentials.

9. Account Deletion

The in-app deletion workflow described below becomes operational only after the corresponding backend has been deployed and live-verified. Until that production gate is complete, or if the in-app control is unavailable, send a deletion request from the email address connected to your account to privacy@clip.qa.

Once deployed and live-verified, confirming account deletion records a durable deletion job that retries failed cleanup steps. The workflow is designed to disable access, remove disabled recording-request-link records and service credentials, remove cloud reports, recordings, screenshots, and related metadata, remove or anonymize collaboration records, cancel applicable Stripe billing, and erase the account identity. Every workspace owned by the deleted account is archived and all members lose access; the account is removed from workspaces it does not own.

On native mobile deletion, the app is also designed to clear its sandbox and secure local credentials. Deletion does not remove files previously exported outside the app sandbox, copies obtained by another person, data already sent to an external integration, or limited records Stripe or Clip QA must keep for legal purposes.

10. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy of data you provided; and withdraw consent at any time without affecting earlier lawful processing. You may also complain to your local data-protection authority.

Send a request from the email address connected to your account to privacy@clip.qa. We may need to verify your identity. Some rights are subject to legal exceptions. Data stored only on your device is controlled directly by you and may not be accessible to us.

11. International Processing

Clip QA and its providers may process data in countries other than the one where you live. Providers describe their own applicable international-transfer safeguards in their terms and data-processing documentation. Clip QA does not make a separate contractual-transfer-mechanism claim in this policy. Contact privacy@clip.qa for current provider and transfer information.

12. Security

We use measures appropriate to the nature of the data, including encrypted transport, access controls, scoped credentials, redaction, rate limiting, and deletion controls. No service can guarantee absolute security. Protect public links and report content as you would other confidential project information.

13. Children's Privacy

Clip QA is not directed to children under 13, and users must be at least 13 years old. We do not knowingly collect personal data from a child under 13. Contact us if you believe a child has provided data so we can investigate and delete it.

14. Changes to This Policy

We may update this policy when the Service or legal requirements change. We will change the date above and provide additional notice in the app, on the website, or by email when a change is material.

15. Contact

Controller identity and address: [LEGAL NAME], [POSTAL ADDRESS] — unresolved launch blocker.

Privacy questions and rights requests: privacy@clip.qa.

General support: hello@clip.qa.

Current policy: https://clip.qa/privacy/.