Last updated: September 4, 2026
CleanCut ("we", "our", or "us"), operated by Content Cartel LLC, provides AI-powered video editing and social media management tools. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at cleaner.contentcartel.net (the "Service").
We collect information in the following ways:
When you connect your Facebook or Instagram account, we receive data through Meta's APIs ("Platform Data"). We handle this data in accordance with Meta's Platform Terms and Developer Policies:
When you connect your LinkedIn account, we receive data through LinkedIn's APIs and handle it under LinkedIn's Platform Guidelines and API Terms of Use:
w_member_social grant.openid, profile, email, w_member_social. Read-only analytics scopes are only requested after LinkedIn partner approval./api/linkedin/deauthorize if you remove the app from LinkedIn directly; we mark the connection revoked on receipt.CleanCut's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We additionally comply with the YouTube Terms of Service; by connecting your YouTube account you also agree to those terms. Google's privacy practices are described in the Google Privacy Policy.
Scopes we request and why:
youtube.upload — to publish videos you have prepared in CleanCut to your YouTube channel at the time you schedule. We never upload without an explicit user-scheduled publish action.youtube — to set metadata on videos you publish (title, description, tags, thumbnail, privacy status, playlist placement) and to manage scheduled publish times on your channel.youtube.readonly — to read your channel and existing videos so the Planner can show you what you have already published and help you avoid duplicate topics.yt-analytics.readonly — to read aggregate channel and video performance metrics (views, watch time, retention) and display them in the Analytics dashboard so you can see how your published content performed.What we store: the OAuth refresh token (encrypted at rest), the channel ID and channel name you connected, and the metadata of videos you scheduled or published through CleanCut. We do not store the raw bytes of videos already on YouTube, comments, viewer identity, or any data about other people's channels.
Limited Use disclosure (required by Google):
Retention & deletion: Google account tokens and YouTube data are retained while your YouTube connection is active. You can revoke our access at any time from Scheduler → Connections in CleanCut, which immediately deletes the stored refresh token and deactivates the connection on our side. You can additionally revoke our app at https://myaccount.google.com/permissions. To request deletion of all Google-derived data we have stored, email moisesoliveros@novaad.io; we will action the request within 30 days.
Security: OAuth refresh tokens are encrypted at rest using a Fernet-derived key managed outside the application database. Tokens are transmitted only over TLS and are decrypted only in-memory at the moment of an API call.
Connecting Google Calendar is optional, is available only to staff users of an agency workspace (client accounts cannot connect a calendar), and is separate from the YouTube connection described in Section 4b. It exists so the in-app assistant can tell you what is on your day and can put a meeting on your calendar after you approve it.
Scope we request and why:
calendar.events — to read the events on your calendar for the next few days, so the assistant can show your upcoming meetings and avoid proposing a time you are already busy; and to create a single event when you click Approve on an event the assistant has proposed. We request no other Google Calendar scope: we cannot list, create, modify, or delete calendars, and we cannot read your calendar settings.What we store: the OAuth refresh token for your calendar connection (encrypted at rest) and the identifier of an event we created on your behalf, so the app can link back to it. We do not copy your calendar into our database. Event titles, times, descriptions, and attendees are fetched live from Google when you open a surface that needs them, held in memory for that request, and discarded. Calendar content is never written into our search index, our vector store, or our AI Brain corpus.
Retention & deletion: the calendar token is retained while the connection is active. Disconnecting from Profile → Connections deletes the stored token immediately; you can also revoke CleanCut at https://myaccount.google.com/permissions. Because we do not retain calendar content, disconnecting leaves nothing of your calendar behind.
Affirmation. CleanCut does not use data obtained through Google Workspace APIs (including the Google Calendar API) or Google Photos APIs — in raw, aggregated, anonymized, or derived form — to develop, improve, train, fine-tune, or evaluate generalized or foundational artificial intelligence or machine learning models, and we do not transfer such data to any third party that would do so. This restriction applies to us and to every service provider we use. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Workspace API User Data and Developer Policy.
Where AI is used at all. CleanCut is a video post-production and content-planning product. Its AI features operate on media you upload to CleanCut and on text you write inside CleanCut. The one place any Google Workspace data reaches a model is the in-app assistant: when you ask it about your schedule, the events it has just fetched from your calendar are included in the prompt for that one answer, as inference context only. They are not stored by us beyond that request, not embedded, and not used for training by us or by the model provider.
Third-party AI services we integrate with, and whether they can see Google data:
No aggregators or model gateways. CleanCut calls each provider above directly, over that provider's own commercial API endpoint. We do not route requests through any AI aggregator, gateway, router, or model hub, and we do not use free, trial, or consumer tiers whose terms permit training on submitted data.
We do not sell your personal data. We may share information only in these circumstances:
We retain your data for as long as your account is active. Uploaded media files are retained for processing and deleted after export or at your request. Social media tokens are retained while your accounts are connected. You may request deletion of all your data at any time.
We implement industry-standard security measures including encryption in transit (TLS), secure token storage, and access controls. However, no method of electronic storage is 100% secure, and we cannot guarantee absolute security.
Depending on your jurisdiction, you may have the right to:
To exercise these rights, contact us at moisesoliveros@novaad.io.
The Service is not intended for individuals under the age of 13. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date.
If you have questions about this Privacy Policy, contact us at:
Content Cartel LLC
Email: moisesoliveros@novaad.io