Privacy Policy

What Overclip collects, why, who else processes it, what is sent to AI providers, how long we keep it, and how to get it back or deleted.

Last updated: 21 August 2026

01Who is responsible for your data

The data controller is HELIOS, SASU, société par actions simplifiée unipersonnelle, registered under 994 198 265 R.C.S. Montluçon, whose registered office is at 16 rue Joseph Proudhon, 03100 Montluçon, France.

For any question about this policy, or to exercise your rights, write to elio.brea@polyware.net. We answer within 30 days.

We are established in France, so the General Data Protection Regulation applies to everything described here, wherever you are based.

02What we collect

We collect only what the service needs to work. There is no advertising profiling and no data brokerage.

Account
Your email address, the date you signed up, and the workspace you belong to. We never hold a password: sign-in uses a one-time link.
Workspace content
The products, personas, hooks, scripts and agents you create, along with any image or asset you upload.
Generated media
The images and videos your agents produce, kept in your library until you delete them.
Connected accounts
The identifiers and access tokens for the social accounts you connect, so that posts can be published on your behalf.
Usage and billing
Run history, credit consumption, your plan and subscription status, and the invoices Stripe issues.
Technical data
Server logs and error traces produced when you use the service, including IP address and browser, kept for security and debugging.

We never see or store your card number. Card details are entered on Stripe's own pages and stay with Stripe.

03Why we use it, and on what legal basis

Running the service
Performance of our contract with you: creating your account, generating and storing media, publishing posts, counting credits.
Billing
Performance of the contract, and our legal obligation to keep accounting records.
Support
Performance of the contract, and our legitimate interest in answering you properly.
Security and abuse prevention
Our legitimate interest in keeping the service, our providers and other customers safe.
Service emails
Performance of the contract. These cover sign-in links, payment issues, and changes to these documents. They are not marketing and cannot be unsubscribed from while your account is open.

04What is sent to AI providers

This is the part most people want to understand, so it gets its own section.

When a run executes, the content needed for that step leaves our systems and reaches the provider running the model: product descriptions, personas, prompts, scripts, and any reference image you supplied. Without that transfer, generation cannot happen.

We do not send your email address, your billing data or your social account tokens to these providers. Prompts are not tied to your identity on their side beyond what our account with them requires.

We do not train any model on your content, and we ask our providers to process it only to return the requested result. Each provider applies its own retention period to the requests it receives.

05Who else processes your data

We use the following providers. They act on our instructions, under a data processing agreement, and only for the purpose listed.

ProviderLocationWhat it does
Vercel Inc.United StatesHosting of the website and the application, technical logs
Supabase Inc.United StatesDatabase, authentication, storage of generated files
Stripe, Inc. and Stripe Payments Europe LtdUnited States, IrelandPayments, subscriptions, invoices
Trigger.dev LtdUnited KingdomOrchestration of generation runs and scheduled runs
Features and Labels, Inc. (fal.ai)United StatesImage and video generation models
Anthropic PBCUnited StatesWriting of scripts, hooks and product descriptions
Upload-PostUnited StatesPublishing to your connected social accounts

We update this list when a provider is added or replaced. The date at the top of this page tells you which version you are reading.

We do not sell personal data, and we do not share it with advertisers.

06International transfers

Most of our providers are based in the United States, so your data is transferred outside the European Union. These transfers rely on the European Commission standard contractual clauses, or on the EU-US Data Privacy Framework where the provider is certified under it.

07How long we keep it

Account and workspace content
For as long as your account is open, then deleted within 30 days of a deletion request.
Generated media
Until you delete it, or until your account is deleted.
Social account tokens
Until you disconnect the account, and immediately revoked on deletion.
Invoices and accounting records
10 years, as French commercial law requires. This obligation survives account deletion.
Technical logs
12 months at most.

08Your rights

Under the GDPR you can ask us to:

  • give you a copy of the personal data we hold about you
  • correct anything inaccurate
  • delete your data, subject to the accounting records we are legally required to keep
  • export your data in a portable format
  • restrict or object to a processing operation based on our legitimate interest

Write to elio.brea@polyware.net from the address on your account. We answer within 30 days, free of charge.

If you are not satisfied with our answer, you can lodge a complaint with your local supervisory authority. In France that is the CNIL, 3 place de Fontenoy, 75007 Paris.

09Cookies

We use strictly necessary cookies only: the ones that keep you signed in. They carry your session and nothing else.

We run no advertising cookies, no third-party trackers and no analytics on this site. That is why you are not asked to accept anything: under EU rules, strictly necessary cookies do not require consent, and we have nothing else to ask you about.

10Security

Data is encrypted in transit. Access to workspace data is enforced at the database level, so a workspace cannot read another one. Access tokens for connected accounts and provider keys are held server side and are never exposed to the browser.

No system is perfect. If a breach affects your personal data and creates a risk for you, we notify you and the supervisory authority within the legal deadline.

11Children

The service is for professional use and is not available to anyone under 18. We do not knowingly collect data from minors. If you believe a minor created an account, tell us and we will delete it.

12Changes to this policy

We update this policy when our processing changes, in particular when a provider is added. The date at the top always reflects the version in force, and we notify account holders by email of any change that materially affects them.