Privacy policy
Last updated: 1 October 2026
Who runs ClipEngine
ReplayRaven (ClipEngine) is run by Justin H in the Netherlands (the operator), who is the controller for the data described here. Contact: privacy@replayraven.com.
ClipEngine is the operator's private publishing software. It makes short clips from campaign videos and from the operator's own brand, and the operator approves every clip before it is posted to the operator's own accounts on YouTube, Instagram, X (@replayraven) and TikTok. It has no other users and no sign-up.
Posts on X and Instagram that nobody pays for are published automatically, through the operator's self-hosted copy of the scheduler Postiz. The operator publishes the rest by hand in the platform's own app: sponsored (paid) posts on X and Instagram, every post for a Vyro campaign, and all posts on TikTok and YouTube. For those posts ClipEngine only stores the link the operator pastes.
Data from the connected accounts
The operator connects each account through the platform's own sign-in and consent screen. ClipEngine never receives the password. After the connection, it holds:
- the access and refresh tokens the platform issues;
- basic profile information of the account: account ID, name, username and profile picture, for X also whether the account is verified, and for YouTube, once connected, the email address of the Google account;
- the IDs and links of the operator's posts, and their statistics: views, likes and the number of comments.
It uses this data to publish the clips the operator approved, to show the operator how those posts perform and to estimate what a campaign owes for them. The legal basis is the operator's legitimate interest in running his own accounts, and for the bookkeeping records the legal obligation to keep them. ClipEngine reads statistics four times a day during the first 30 days after a post goes out. For posts published by hand it reads no statistics, apart from the public counts of YouTube videos. The permissions requested per platform are:
- Instagram: read the basic profile, publish content and read insights. The standard permission set also covers comments; ClipEngine does not read or write comments;
- X: read the profile and post on behalf of the account. ClipEngine does not request access to direct messages;
- YouTube (not connected yet; posts are made by hand): manage the YouTube account, upload videos and read channel and video statistics (YouTube Data API and YouTube Analytics API);
- TikTok (not connected yet; posts are made by hand): read the basic profile and statistics, list the account's videos and upload and publish videos.
Data about other people
ClipEngine does not collect data about anyone else on these platforms. It does not read comments, messages, followers or other people's posts. The only numbers it reads are totals for the operator's own posts.
The campaign videos it works from are supplied by the campaign owners for clipping. ClipEngine transcribes them on the operator's server and detects where faces are in the frame so it can crop the picture. It does not identify anyone.
Where the data is kept
The tokens and profile information are stored only in the operator's self-hosted Postiz, on the operator's own server in the Netherlands. That server is not reachable from the internet. ClipEngine's own records of posts, statistics and earnings are kept in a database on the same server. Backups stay on the operator's own equipment in the Netherlands, and the database dumps on the server are normally deleted after 14 days.
Before Postiz publishes a clip, it stores the video in Cloudflare R2 under media.replayraven.com, at a random address that is not linked from anywhere. Instagram fetches the video from that address; for X, Postiz reads the file and sends it to X itself. Postiz also keeps a copy of the X account's profile picture there. Anyone who has the exact address can open a file, and every file is deleted 7 days after upload.
How long the rest is kept:
- campaign videos on the server: 7 days; finished clips: 30 days;
- the readings of each post's statistics over time: 12 months; the last reading stays with the post record;
- records of posts (link, caption, dates) and of earnings: 7 years, for the bookkeeping;
- tokens and profile information: until access is revoked, see below.
Who else receives data
- The platforms receive the published clips and captions, under their own terms and privacy policies.
- The campaign platform or client that commissioned a clip (Whop Content Rewards, Vyro or a direct client) receives the public link to the post, which the operator submits by hand on the campaign's site. The platform measures the views itself; ClipEngine sends it no statistics.
- Cloudflare provides DNS for replayraven.com, serves this website and stores the video files for 7 days.
- Anthropic (Claude) receives transcripts of the campaign videos and the campaign briefs, so it can pick moments, draft captions and check a draft against the brief. To suggest better moments it also receives up to five of the operator's best-performing hook lines from the last 14 days, each with its total view count. In the operator's Anthropic account, the setting that allows Anthropic to train its models on these chats is turned off. Anthropic keeps the requests under its own terms and privacy policy. It receives no tokens, no links to the operator's posts, no statistics other than the hook totals above, and no data read from the platforms about other people. The transcripts and briefs can contain the names and handles of the people in the campaign videos.
Anthropic and Cloudflare are based in the United States, as are the platforms. Data sent to Anthropic and Cloudflare is covered by the EU standard contractual clauses in their terms.
Data is not sold, shared for advertising or used to build profiles.
Google and YouTube
ClipEngine uses YouTube API Services. Connecting a YouTube channel means agreeing to the YouTube Terms of Service; Google's handling of data is described in the Google Privacy Policy. ClipEngine's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Access can be revoked at any time on the Google security settings page.
Revoking access and deleting data
Access can be revoked at any time in the connected-apps or security settings of the platform (for Google, see the link above). A revoked token no longer works. The operator then deletes the stored token and profile information within 30 days.
Anyone who wants to know whether ClipEngine holds data about them, or wants it deleted, can email privacy@replayraven.com. The request is answered within 30 days. Records the bookkeeping needs are kept for the 7 years mentioned above.
For X there is a shorter deadline. If a post is deleted, protected or withheld on X, the operator deletes or updates the stored X data for that post as soon as he learns of it, and within 24 hours of a request from X or the account owner.
Copies in backups disappear when the backups rotate (the database dumps normally after 14 days). Deleted data is never restored from a backup.
Under the GDPR you have the right to access, correct and delete your data and to object to its use. You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
This website
This site is a set of static pages. It sets no cookies and has no analytics, tracking or embedded content. Cloudflare, which serves it, may keep technical logs such as IP addresses for security, as described in Cloudflare's privacy policy.
Changes
When this policy changes, the date at the top changes with it.