Privacy Policy

CLICKABOOM PRIVACY POLICY Version 2.2 Last Updated: August 23, 2026 Clickaboom Inc. ("Clickaboom," "we," "us," or "our") is committed to maintaining robust privacy protections for its users. This Privacy Policy describes how we collect, use, share, and protect information about you when you access or use our website at https://www.clickaboom.com (the "Site") and our content production services, including thumbnail generation, video editing, and publishing to social platforms you connect — currently YouTube, TikTok, Instagram, and Facebook (the "Service"). This Privacy Policy explains our practices. Most of our processing is carried out to perform the contract you enter into with us, or on another legal basis described in Section VII.B — not on consent. Where we do rely on consent, we ask for it separately and you can withdraw it at any time. By accessing the Site or using the Service you acknowledge that you have read this Privacy Policy. If you do not agree with it, please do not access the Site or use the Service. I. INFORMATION WE COLLECT A. Personal Information We collect the following personal information when you register for and use our Service: - Account Information: Email address, first name, and last name (collected through our authentication provider, Clerk). - Payment Information: We do not directly collect or store your payment card details. All payment processing is handled by Stripe, Inc., a PCI-DSS compliant payment processor. We store only Stripe-assigned identifiers (customer ID, subscription ID, invoice ID) to manage your account and billing. - Support Communications: If you contact us via our support form, we collect the information you provide, including your name, email address, and any attachments you include. B. User-Uploaded Content To use our Service, you may upload the following content: - Persona Images: Photographs of individuals to be used as subjects in thumbnail generation. - Style Reference Images: Example thumbnails or images that define the visual style for generation. - Addon Images: Additional reference images for specific generation requests. - Audio Files: Audio content (e.g., extracted from videos) used to support thumbnail and title generation. - Text Instructions: Descriptions, captions, and other text input you provide for content generation. - Raw Video Footage (for editing and production): When you use our video production features, you upload raw video files, which may be submitted as a single file or as multiple pieces that we merge in the order you provide. This footage is the source material from which we produce your finished deliverables. It is stored in our file storage, processed on our own rendering infrastructure, and is never uploaded to YouTube. You may delete it at any time through the Service. - Video Uploads and YouTube URLs (for Auto-Persona Detection and Transcript Extraction): When you provide a video URL or upload a video for analysis, our Service may use facial detection and clustering technology to identify the most-frequent face appearing in the video, which is then used to create a "persona" image automatically. The detection runs only on videos you have explicitly submitted to the Service. The cluster output (a face crop) is stored as a persona image associated with your account, which you may delete at any time. We do not use this facial data to identify individuals across users, do not perform 1:1 facial recognition for authentication, and do not share facial data with third parties for identification purposes. Video content you submit may also be used for transcript extraction to support generation. B-1. Third Parties Appearing in Your Footage Raw video footage you upload may contain images, voices, or personal information of people other than you — for example guests, interviewees, co-hosts, or bystanders. We process that footage solely to produce the deliverables you have requested. We do not use it to identify those individuals, do not build profiles of them, do not match them across users or across your own uploads, and do not share it with third parties for identification purposes. You are responsible for having the necessary rights and permissions from anyone appearing in footage you upload, as set out in our Terms of Service. If a person appearing in footage you uploaded wishes to have that footage removed, you may delete it at any time through the Service, and either of you may contact us at support@clickaboom.com. B-2. In-Browser Recordings (Screen and Camera) The Service includes an optional in-browser recorder. Using it is entirely your choice; the Service works without it, and nothing is recorded unless you start a recording yourself. What is captured. When you record, your browser captures up to two separate streams: your camera together with your microphone, and — if you choose to record your screen — the screen surface you select, with your microphone audio included. The two streams are saved as separate video files, along with the measured timing offset between them so they can be aligned during production. Recording is available on desktop Chrome only. You choose what the screen recording sees. Your browser, not this Service, presents the picker that decides whether you share a single browser tab, one application window, or your entire screen. We receive only what you chose to share. We recommend sharing the narrowest surface that serves your purpose — a single tab or window rather than the whole screen. What a screen recording can contain. Screen capture records the selected surface as it appears, for the whole time you are recording. That can include material you did not intend to publish and would not have uploaded deliberately: other browser tabs and their contents, desktop and application notifications as they arrive, messages, email, documents, file names, calendars, account identifiers, and anything else visible on the shared surface — including credentials, if they are on screen. It may also capture information about other people, in which case Section B-1 applies to them as well. How we treat it. A recording is processed exactly like any other footage you upload: to produce the deliverables you requested, and for nothing else. We do not scan recordings for credentials, secrets, or personal data, and we do not extract, index, or catalogue anything shown on your screen. That also means we cannot detect sensitive material for you and cannot warn you about it — the judgement of what to put on screen is yours alone. Before you record, close or hide anything you would not want captured, silence notifications, and sign out of anything you do not want visible. Where it goes. Recordings are stored in your own storage area under the same access controls as your other uploads, and are retained with the request they belong to (see Section IV.B). You can delete a recording at any time through the Service. If you never send a take to production, it remains an unattached upload in your own area and you can delete it the same way. C. Generated Content Our Service produces the following content on your behalf: - Generated Thumbnails: AI-generated images created based on your inputs. - Generated Titles and Descriptions: AI-generated text created based on your inputs. - Edited Video Deliverables: A finished main cut assembled from your uploaded footage, and a set of vertical short-form videos derived from it. Production is performed entirely on our own infrastructure. - Captions and Transcripts: Word-level transcripts of your footage, used for caption rendering, pacing, and cut placement. - On-Screen Graphics: Supporting visual elements composited into your video. - Chapters, Timecodes, and Tags: Structured metadata generated to accompany your video. - Intro Music: Where you select the automatic option, a track from our bundled library of licensed music. D. YouTube Data We access YouTube data in two ways: Publicly Available Data (no authorization required): We use the YouTube Data API v3 with an API key to retrieve publicly available video metadata, including: - Video metadata (titles, descriptions, thumbnail URLs, view counts, like counts) - Channel information (channel name, channel ID) - Playlist information Private Data (with your authorization): If you choose to connect one or more YouTube channels, we request access to your YouTube account(s) through Google OAuth with the following scopes: - `youtube.readonly` — to read your YouTube channel data, including your uploaded videos and their metadata. - `yt-analytics.readonly` — to read your YouTube Analytics data, including per-video impressions, click-through rates (CTR), watch time, and view counts. - `youtube.force-ssl` — to manage your YouTube videos, including updating video titles, descriptions, and thumbnails, changing a video's privacy status at a time you have scheduled, and checking whether a caption track is available on your own videos. - `youtube.upload` — to upload the finished video deliverables we have produced for you to your own YouTube channel, at your direction. You may connect or disconnect any of your YouTube channels at any time through the Service. Connecting a channel is required only for features that read your channel data or publish to it; you can generate thumbnails, titles, descriptions, and edited videos without connecting a channel, and download the results instead. YouTube API Services: Clickaboom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. E. Automatically Collected Information When you visit our Site, we automatically collect certain information, including: - Usage Data: Pages visited, features used, interactions with the Service, referring URLs, and browser type. - Device Information: Device type, operating system, and screen resolution. - Cookies and Tracking Technologies: See Section VI (Cookies and Tracking) below. F. Guest Users (Unauthenticated Visitors) Visitors who try our Service before creating an account ("Guests") may submit a YouTube video URL to generate sample thumbnails. For Guests, we collect: - The YouTube URL provided - IP-derived approximate location (used for rate limiting and abuse prevention) - Public video metadata fetched via the YouTube Data API for the URL provided - Any thumbnails generated from the URL during the Guest session Guest data is retained for up to 30 days for service operation and abuse prevention, and is automatically purged thereafter — unless the Guest creates an account during that window, in which case the data is migrated to the new account and treated under the standard user data terms in this Policy. II. HOW WE USE YOUR INFORMATION We use the information we collect for the following purposes: - Provide and Operate the Service: To process your generation requests, produce your video deliverables, manage your account, and deliver generated content. - Video Production: To transcribe your uploaded footage, identify the segments used in your deliverables, render your main cut and short-form videos, and composite captions, graphics, and music. - YouTube Channel Management: If you connect one or more YouTube channels, to display your video analytics, and to update your video titles, descriptions, and thumbnails at your direction. - Publishing to YouTube: If you choose to publish through the Service, to upload your finished deliverables to your own channel and to carry out the publishing plan you confirm. See Section II-A below, which describes this in full. - Process Payments: To manage your subscription, process credit purchases, and maintain billing records. - Communicate with You: To respond to support inquiries, send service-related notifications, and provide updates about the Service. - Improve the Service: To understand how users interact with our Site and Service, identify issues, and improve functionality. - Ensure Security: To detect and prevent fraud, abuse, and unauthorized access. - Comply with Legal Obligations: To comply with applicable laws, regulations, and legal processes. We do not sell your personal information to third parties. We do not use your personal information for advertising or marketing purposes beyond communicating with you about our own Service. II-A. Scheduled Publishing Because this feature acts on your connected accounts over time rather than only at the moment you click, we describe it here in full. When you choose to publish through the Service, you set a publishing plan before anything is sent anywhere. You choose the title and description, the date and time your main video becomes public, the spacing between your short-form videos, and which of your connected platforms the short-form videos go to. Nothing is submitted until you confirm that plan. Once you confirm, we carry it out on your behalf: - We transfer the finished deliverables to our Publishing Partner and create one scheduled post per item — your main video to YouTube, and each short-form video to every platform you selected. - Each post is held by the Publishing Partner and released to the platform at the time you chose. Until then the content is not visible on your accounts. It is not placed on your channel early in a hidden state; it simply has not been sent yet. - Where a publishing path supports editing an already-published post, and you selected more than one thumbnail-and-title combination, we apply each in turn for an equal period and then permanently apply the one with the best click-through rate as reported by the platform. This comparative test is not available for publications made through the Publishing Partner; where it is unavailable, the single thumbnail and title you selected are used. These steps run on a schedule rather than on a further click from you. We want to be explicit about that. What the Service never does is choose a video, a title, a thumbnail, a description, a publishing time, or a destination platform that you did not select; it has no authority to act outside the plan you confirmed, and it acts only on deliverables we produced for you through this flow. You can stop it at any time. The order's publishing view has a control that ends the publication immediately. When you stop it, every scheduled post that has not yet been released is cancelled and will not publish. Anything already published stays published, exactly as it stands. Stopping reverts nothing and removes nothing from your accounts. Disconnecting a platform has the same halting effect for that platform and additionally revokes ongoing access. We do not remove content that is already live, except where removal is required by law, by valid legal process, or by a binding demand from the platform or a rights holder. III. HOW WE SHARE YOUR INFORMATION We share your information only in the following circumstances: A. Third-Party Service Providers We use the following third-party services to operate our platform. Each processes data only as necessary to provide their respective service: Clerk (clerk.com) — User authentication and identity management. Data shared: email address, name, authentication credentials. Stripe (stripe.com) — Payment processing and subscription management. Data shared: email address, payment method (handled directly by Stripe). Supabase (supabase.com) — Database hosting and file storage. Data shared: all user data, uploaded images, uploaded video footage, generated content, and rendered video deliverables. Modal (modal.com) — On-demand compute used to render your video deliverables. Data shared: your uploaded footage and the assets required to render it, transferred for the duration of the render job and not retained afterwards. Google AI Studio (Gemini API) (ai.google.dev) — AI image and text generation, and analysis of images and video frames. Data shared: uploaded images, frames extracted from your footage, and text instructions (processed in real-time; on the paid tier, Google does not retain inputs for training, per Google's Gemini API Additional Terms of Service). OpenAI (openai.com) — AI text generation and image analysis. Data shared: text instructions, context, and image URLs (processed in real-time per OpenAI's data usage policy). OpenAI Whisper API (openai.com) — Speech-to-text transcription of uploaded audio. Data shared: audio file content (processed in real-time, not retained per OpenAI API terms). ElevenLabs (elevenlabs.io) — Word-level speech-to-text transcription used for caption timing and cut placement in video production. Data shared: audio extracted from your uploaded footage. YouTube Data API (developers.google.com) — Public video metadata retrieval, and, where you have authorized it, reading and managing your own channel's videos and uploading your deliverables. Data shared: search queries; and, under your authorization, your OAuth tokens and the deliverables and metadata you have chosen to publish. YouTube Analytics API and YouTube Reporting API (developers.google.com) — Authorized analytics data retrieval, including impressions and click-through rate. Data shared: OAuth tokens; analytics data is retrieved on your behalf. Serper (serper.dev) — Image search used to find reference photographs of publicly known subjects where your source material does not show them. Data shared: search terms derived from your request. No user data or uploaded content is sent. Apify (apify.com) — YouTube video transcript retrieval. Data shared: YouTube video URLs for transcript extraction. Proxy network provider — Where we retrieve publicly available YouTube video content for research purposes, that traffic is routed through a commercial proxy network so it originates from a residential rather than a datacenter address. Data shared: the public YouTube URLs being retrieved. No user data or uploaded content is sent. Google Tag Manager (tagmanager.google.com) — Website analytics. Data shared: usage data, device information (see Section VI). FirstPromoter (firstpromoter.com) — Referral and affiliate tracking. Data shared: referral source information. Gmail SMTP (google.com) — Sending support-related emails. Data shared: email address, support message content. Vercel (vercel.com) — Frontend hosting and edge delivery. Data shared: request metadata, IP addresses, browser type. Render (render.com) — Hosting for our application programming interface and our background processing workers, together with the managed queue and cache instance those workers use. Because all production and publishing work runs here, uploaded footage, images, generated content, and job metadata pass through and are held on this infrastructure for the duration of processing. Data shared: all user data processed by the Service while a job is running. bundle.social (bundle.social) — Our Publishing Partner. Where you connect a social platform and publish through the Service, this provider holds the access credentials for your connected accounts and receives the finished deliverables together with the titles, descriptions, and scheduling instructions needed to publish them on your behalf. Data shared: your connected-account credentials and platform identifiers, your finished video and image deliverables, their titles and descriptions, and your chosen publishing times. See Section III-A-1. Grafana Cloud (grafana.com) — Application performance monitoring and error telemetry, where enabled. Data shared: operational traces and diagnostic metadata, which may include internal identifiers such as a request or user identifier. Uploaded content is not sent. A-1. Connected Social Platforms Connecting a platform is optional. When you connect one, you are sent to an authorization flow hosted by our Publishing Partner and then to the platform itself, where you grant permission directly. The resulting access credentials are held by the Publishing Partner, not by us. We receive only the fact that a connection exists, the name of the connected account or channel, and the ability to submit posts on your instruction. When you publish, the deliverable and its title, description, and scheduled time are transferred to the Publishing Partner and from there to each platform you selected. Once content reaches a platform, that platform's own privacy policy governs it, and we no longer control it. Each platform is a separate controller of the data it receives. You may disconnect any platform at any time through the Service, which stops future publishing and revokes the Publishing Partner's ongoing access; it does not affect anything already published. Note that our authorized access to YouTube for analytics (described in Section VIII) is separate from publishing and continues to run on our own credentials rather than through the Publishing Partner. B. Legal Requirements We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to: - Comply with a legal obligation or government request - Protect and defend the rights or property of Clickaboom - Prevent or investigate possible wrongdoing in connection with the Service - Protect the personal safety of users of the Service or the public C. Business Transfers If Clickaboom is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Site of any change in ownership or uses of your personal information. IV. DATA STORAGE AND RETENTION A. Where Your Data Is Stored Your data is stored primarily on servers operated by Supabase, and is processed on infrastructure operated by Render, which hosts our interface and background workers. Both are located in the United States. User-uploaded files (images, audio, and raw video footage) and generated content (thumbnails and rendered video deliverables) are stored in Supabase Storage. Database records are stored in Supabase PostgreSQL with Row Level Security (RLS) enforced to ensure users can only access their own data. While a video render is in progress, a copy of the material required for that render is transferred to our rendering compute provider for the duration of the job and is removed when the job completes. B. How Long We Retain Your Data - Account Data: Retained while your account is active. Inactive accounts (no login in 24 months) may be deleted with 30 days' email notice. When you delete your account, all associated data is permanently deleted. - Request Data and Generated Content: Retained until you delete the request or for 24 months after creation, whichever is sooner. You may delete individual requests and their associated files at any time through the Service. - In-Browser Recordings: The camera and screen files produced by the recorder are retained on the same terms as Raw Video Footage below. A take that is never sent to production is retained as an unattached upload in your own storage area until you delete it, or until your account is deleted. - Raw Video Footage: Retained with the request it belongs to, under the same terms as Request Data above, so that your deliverables can be re-rendered or revised. You may delete uploaded footage at any time through the Service, independently of the rest of the request. - Rendered Video Deliverables: Retained with the request they belong to, under the same terms as Request Data above, so you can download them again. Deleting the request deletes the deliverables held by us. It does not remove any copy you have already published to YouTube — see Section IV.C. - YouTube Data: Authorized YouTube data (channel metadata, video metadata, analytics) is retained for no more than 30 calendar days from the most recent authorization or refresh, in accordance with the YouTube API Services Developer Policies. If our access has not been refreshed within that period, the data is automatically deleted. Authorized YouTube data is also deleted when you disconnect the corresponding YouTube channel or delete your account. - Publishing Records: Records of a scheduled publication — the identifiers of the posts created for you, the schedule you set, the platforms you selected, and any click-through-rate figures used to decide a thumbnail test — are retained with the request they belong to. To the extent any part of that record is YouTube-derived data, it is retained under the same 30-day rule as all other authorized YouTube data and deleted on disconnection or account deletion on the same terms. - Biometric Identifiers (Retention and Destruction Schedule): Where you use the auto-persona feature, the face crops and the face-grouping data derived from your uploads are biometric identifiers. They are retained only for as long as needed to produce and re-produce the persona you asked for, and in no case longer than the request they belong to — that is, until you delete the persona, the source upload, or the request, or 24 months after creation, whichever comes first. They are destroyed when you delete your account, and are destroyed on the same schedule as the underlying request data otherwise. We do not sell, lease, trade, or otherwise profit from biometric identifiers, and we do not disclose them to any third party except the processing providers listed in Section III.A, which act on our instructions and are contractually barred from using them for their own purposes. This schedule is published here to satisfy the written-policy requirements of biometric privacy laws including the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and Washington HB 1493. - Publishing Partner Records: Where you publish through a connected platform, our Publishing Partner retains the post records and connected-account credentials for as long as the connection exists. Disconnecting the platform revokes that access. Content already delivered to a platform is thereafter governed by that platform's own retention practices, not ours. - Guest Data: As described in Section I.F, retained for up to 30 days unless migrated to a created account. - Payment Records: Transaction records are retained as required by applicable tax and financial regulations. - Support Communications: Retained for as long as necessary to resolve your inquiry and for our records. C. Data Deletion - You may delete individual generation requests and all associated files at any time through the Service. - You may delete uploaded persona images, style references, addon images, raw video footage, rendered deliverables, and audio files at any time through the Service. - You may stop any scheduled publication at any time from the order's publishing view. Stopping ends all further scheduled action immediately. - You may disconnect any connected YouTube channel at any time. If you disconnect a YouTube channel or otherwise revoke our access to YouTube user data, all stored YouTube user data associated with that channel is deleted within 7 calendar days, in accordance with the YouTube API Services Developer Policies. - You may request complete account deletion. Upon deletion, all your data — including account information, uploaded footage, generated content, rendered deliverables, YouTube data, and associated records — will be permanently deleted within 30 calendar days. - Videos already published to your YouTube channel are not affected by any of the above. Once a video has been uploaded to your channel it belongs to your channel and is under your control. We never delete, unpublish, or hide a video from your channel — not when you stop a publication, not when you delete a request, not when you disconnect the channel, and not when you delete your account. If you want a published video removed, you must remove it yourself in YouTube Studio. - To request account deletion, use the account settings page or contact us at support@clickaboom.com. V. DATA SECURITY We implement industry-standard security measures to protect your information, including: - Encryption: Data is encrypted in transit using TLS/SSL. - Access Controls: Row Level Security (RLS) policies enforce data isolation between users at the database level. All storage buckets use signed URLs with time-limited access, and every file path submitted for publication is verified as belonging to the requesting user before it is processed. - Authentication: Secure token-based authentication (JWT) for all API interactions. User sessions are managed by Clerk with industry-standard security practices. - OAuth Token Security: YouTube OAuth tokens are encrypted at rest at the application layer using Fernet (AES-128-CBC with HMAC-SHA256). The encryption key is held separately from the database, so access to the database alone does not yield usable credentials. Tokens are used only to access YouTube data on your behalf, are refreshed automatically while your channel remains connected, are purged automatically if unused for 30 days, and can be revoked at any time by disconnecting your YouTube channel. - Payment Security: All payment processing is handled by Stripe, which is PCI-DSS Level 1 certified. We never receive, store, or process your payment card details. - Infrastructure: Our database and storage are hosted on Supabase with managed security. While we take reasonable measures to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials. VI. COOKIES AND TRACKING TECHNOLOGIES A. What We Use We use the following cookies and tracking technologies: - Google Tag Manager (GTM): We use GTM to manage analytics and tracking scripts on our Site. GTM may set cookies to collect information about how you interact with our Site, including pages visited, features used, and user interactions. GTM Container ID: GTM-NCJHQLZH. - FirstPromoter: We use FirstPromoter for referral and affiliate tracking. It may set cookies to track referral sources. - Clerk: Our authentication provider may set cookies necessary for maintaining your login session and security. - Browser Storage: In addition to cookies, we use your browser's local storage, session storage, and IndexedDB to hold information the Service needs on your device — for example your session state, interface preferences, safeguards that prevent a payment or generation from being submitted twice, and, for visitors who have not created an account, the identifier that links a trial generation to your browser. This information stays on your device and is cleared when you clear your browser's site data. See our Cookie Policy for detail. B. Your Choices Most web browsers allow you to control cookies through their settings. You may choose to block or delete cookies, but doing so may affect the functionality of the Site and Service. Specifically: - Essential Cookies and Storage (authentication, security, duplicate-submission protection): Required for the Service to function. Disabling these will prevent you from using the Service. - Analytics Cookies (GTM, FirstPromoter): Used to understand usage patterns and improve the Service. You may disable these without affecting core functionality. VII. YOUR RIGHTS A. All Users Regardless of your location, you have the right to: - Access the personal information we hold about you - Request correction of inaccurate personal information - Delete your account and all associated data - Disconnect your YouTube channel and revoke our access to your YouTube data - Stop any scheduled publication before it completes - Opt out of non-essential communications B. European Economic Area (EEA) / UK Users If you are located in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including: - Right to Access: Request a copy of the personal data we hold about you. - Right to Rectification: Request correction of inaccurate or incomplete data. - Right to Erasure: Request deletion of your personal data. - Right to Restriction: Request that we restrict processing of your data in certain circumstances. - Right to Data Portability: Request your data in a structured, commonly used, machine-readable format. - Right to Object: Object to processing of your data for certain purposes. - Right to Withdraw Consent: Withdraw your consent at any time where we rely on consent as a legal basis for processing. - Right to Lodge a Complaint: You may lodge a complaint with your local data protection supervisory authority. In the EEA, a list of authorities is published by the European Data Protection Board; in the UK, the authority is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first, but you are not required to contact us before complaining. To exercise any of these rights, contact us at support@clickaboom.com. We will respond to your request within 30 days. International Transfers. We are established in the United States, and the providers listed in Section III.A are predominantly US-based. If you are in the EEA or the UK, your personal data is therefore transferred to, and processed in, the United States and potentially other countries whose data-protection laws may differ from those of your own. Where we make such a transfer we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) as the safeguard, together with the transfer terms in our providers' own data processing agreements. You may request further information about the safeguards applied by emailing support@clickaboom.com. EU/UK Representative. Where we are required under GDPR Article 27 to designate a representative in the European Union or the United Kingdom, the current designation and its contact details are published on this page. If no designation appears here, we have not yet appointed one; you may contact us directly at support@clickaboom.com in the meantime, and this does not limit any of the rights described above. Legal Basis for Processing (GDPR): - Contract Performance: Processing necessary to provide you with the Service you have requested, including producing your video deliverables and carrying out a publishing plan you have confirmed. - Legitimate Interest: Processing necessary for our legitimate business interests, such as improving the Service and ensuring security. - Consent: Processing based on your consent, such as analytics cookies and YouTube channel access. - Legal Obligation: Processing necessary to comply with applicable laws. Special Category Data: Where face-detection features process biometric identifiers (as described in Section I.B, "Video Uploads"), we rely on your explicit consent under GDPR Article 9. You may withdraw this consent at any time by deleting the resulting persona images and refraining from using auto-persona features. We do not use facial data for cross-user identification, do not perform 1:1 facial recognition for authentication, and do not share facial data with third parties for identification purposes. Raw footage uploaded for editing is not subjected to facial detection or clustering unless you use the auto-persona feature on it. C. California Users If you are a California resident, you have rights under the California Consumer Privacy Act as amended by the CPRA. Categories of personal information we collect. Identifiers (name, email address, account and referral identifiers, IP address); commercial information (subscription and credit purchase history, handled by our payment processor); internet or network activity (usage and device data described in Sections I.E and VI); audio, electronic, and visual information (the images, audio, and video footage you upload and the content we generate from them); professional information where you supply it (your channel and brand details); and sensitive personal information in the form of biometric information, where you use the auto-persona feature described in Section I.B. Business purposes. We use each category to provide and maintain the Service, produce and deliver your content, carry out publishing plans you confirm, process payments, provide support, secure the Service and prevent abuse, and comply with law. Section II describes these purposes in detail. Disclosure. We disclose each of these categories to the service providers listed in Section III.A, for the business purposes stated there and under contracts that limit them to those purposes. We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under 16. Your rights. You have the right to know what we collect, use, and disclose; to correct inaccurate personal information; to delete your personal information; to limit our use and disclosure of your sensitive personal information; to opt out of sale or sharing (which we do not do); and to be free from discrimination for exercising any of these rights. We will not deny you service, charge a different price, or provide a different quality of service because you exercised a right. Limiting sensitive personal information. We use biometric information only to produce the persona images you asked for. We do not use it to infer characteristics about you, and we do not disclose it for any purpose that would require a right-to-limit option beyond deleting it, which you may do at any time from the Service. How to exercise your rights. Email support@clickaboom.com from the address on your account, or use the deletion controls in the Service. We will verify your request against your account. An authorized agent may submit a request on your behalf by providing written permission signed by you; we may still ask you to verify your identity with us directly. VIII. YOUTUBE API SERVICES Our Service uses YouTube API Services in two ways: 1. Public Data Access: We use the YouTube Data API v3 to retrieve publicly available video metadata (titles, descriptions, thumbnails, view counts, channel information) to support content generation. This does not require your YouTube account authorization. 2. Authorized Access (optional): If you choose to connect your YouTube channel, we use Google OAuth to access: - YouTube Data API v3 (`youtube.readonly`, `youtube.force-ssl`): To read your channel's video list and metadata, to check whether a caption track is available on your own videos, to update video titles, descriptions, and thumbnails at your direction, and to change a video's privacy status at a time you have scheduled. - YouTube Data API v3 (`youtube.upload`): To upload the finished video deliverables we produced for you to your own channel, at your direction. We upload only finished deliverables you have reviewed. We never upload your raw source footage. - YouTube Analytics API v2 (`yt-analytics.readonly`): To retrieve per-video performance metrics including watch time and views. - YouTube Reporting API (`yt-analytics.readonly`): To retrieve thumbnail impressions and click-through rate through a daily report registered for your channel. These figures are shown to you in your dashboard and are used to decide which of your selected thumbnail-and-title combinations is kept after a test. By using features of our Service that interact with YouTube data, you are also bound by: - YouTube Terms of Service - Google Privacy Policy Data Handling: - Public YouTube data (video titles, descriptions, thumbnails, view counts, channel information) is accessed without authorization and stored within generation request metadata. - Authorized YouTube data (analytics, video management, publishing) is accessed only with your explicit consent via Google OAuth. - YouTube Analytics and Reporting data is stored within your account and is refreshed periodically while your channel remains connected. Authorized YouTube data is retained for no more than 30 calendar days from the most recent authorization or refresh, in accordance with the YouTube API Services Developer Policies. - Videos we upload to your channel at your direction become part of your channel and remain there. Disconnecting your channel, deleting your account, or stopping a publication does not remove them, and we never delete or unpublish content from your channel. - You may disconnect any connected YouTube channel at any time through the Service. Upon disconnection or revocation, stored YouTube data associated with that channel is deleted within 7 calendar days. - You may also revoke our access to YouTube API data at any time via the Google security settings page. Limited Use of YouTube Data: Clickaboom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: - We do not transfer YouTube user data to any third party except as required to provide and improve user-facing features (e.g., to AI service providers strictly to fulfill the user's own generation requests, or to our infrastructure providers under contractual data-protection terms). - We do not use YouTube user data for advertising, including retargeting, personalized advertising, or interest-based advertising. - We do not allow human beings to read YouTube user data unless: (i) we have obtained the user's affirmative agreement for specific data; (ii) it is necessary for security purposes (such as investigating abuse); (iii) it is necessary to comply with applicable law; or (iv) the data has been aggregated and is used for internal operations. - We do not sell or transfer YouTube user data to data brokers, information resellers, or any other party that uses it for advertising, credit-worthiness assessments, or similar purposes. - We do not use YouTube user data to develop, improve, or train generalized or foundational artificial intelligence or machine learning models. IX. AI-GENERATED CONTENT Our Service uses artificial intelligence (Google Gemini and OpenAI) to generate thumbnails, titles, and descriptions, and to make editorial decisions in video production, based on your inputs. - Inputs: Your uploaded images, video footage, audio files, and text instructions are sent to AI service providers for processing. These providers process your data in real-time and, per their respective policies, do not retain your inputs for training purposes when accessed via their API services. - Editorial Decisions: In video production, AI is used to transcribe your footage, identify which moments to feature, determine where cuts fall, generate captions, select supporting on-screen graphics, and choose an intro track from our bundled library where you have selected the automatic option. These are automated judgements about your material, not human editorial review. - Outputs: You retain ownership of the content generated through our Service. Clickaboom does not claim ownership of your generated thumbnails, titles, descriptions, or video deliverables. - No Training on Google Data: Clickaboom does not train, develop, or improve any generalized or foundational AI / ML model on YouTube user data, persona images, video uploads, or any other Google-API-derived data. AI features are provided exclusively via third-party APIs operating under their respective no-training data-processing terms. - Accuracy: AI-generated content may not always be accurate, appropriate, or free of errors. Transcripts and captions may misrender speech. Automated editing may cut material in ways you would not have chosen. You are responsible for reviewing and approving all generated content before use or publication. X. CHILDREN'S PRIVACY The Service is intended solely for adults: our Terms of Service require you to be at least 18 years old to access or use it, and it is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a child, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at support@clickaboom.com. Furthermore, our Service is not intended for use in producing or publishing video content, thumbnails, titles, or descriptions directed at children, and we do not knowingly process content related to Made-for-Kids YouTube channels. Our systems refuse to modify or publish to any video marked as Made for Kids. XI. THIRD-PARTY LINKS Our Site and Service may contain links to third-party websites or services, including YouTube. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party sites you visit. XII. CHANGES TO THIS PRIVACY POLICY We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date. For material changes that affect how we handle your personal data, we will provide notice via email or a prominent notice on our Site at least 30 days before the changes take effect. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy. XIII. CONTACT US If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: Clickaboom Inc. Email: support@clickaboom.com Website: https://www.clickaboom.com