Privacy Policy

Last updated: September 29, 2026

This is how Skapo handles your data. We wrote it to match what the product actually does today, including the parts that are still being switched on.

1. Who we are

Skapo is run by SkapoLabs (A.U. Kamble), a sole proprietorship registered in the Netherlands (KvK 42035842), Oder 20 G1369, 2491 DC Den Haag, the Netherlands. We are the controller of the personal data described here. Questions or requests: [email protected].

When you run client work through Skapo (for example in a White Label client workspace), you decide what footage goes in, and we process it on your behalf to deliver the clips.

2. What we collect

  • Account data: your email address, name and sign-in details.
  • Your content: the YouTube links and video files you submit, and what we make from them: clips, thumbnails, transcripts, captions, the analysis behind each clip, post copy, brand kits, logos, fonts and client workspace details.
  • Billing data:what you bought, when, in which currency, and Paddle's transaction and subscription ids. We never see or store full card numbers.
  • How you found us: when you sign up we store the campaign you arrived from with your account: the UTM parameters (source, medium, campaign, term, content), the page you first landed on and, when measurement is allowed in your region, the Google Ads click id (gclid, gbraid or wbraid) and your Google Analytics client id.
  • Usage and device data: pages viewed, buttons clicked, errors, browser and device type, and a country derived from your IP address. See section 5.
  • Messages: emails and contact-form messages you send us, and whether our emails were delivered and opened.

3. What we use it for, and why we are allowed to

  • Turning your videos into clips, storing them, and running your account and billing. Legal basis: performing our contract with you.
  • Keeping the service safe: automated checks that block illegal, sexual or violent uploads, fraud and abuse prevention, and fixing errors. Legal basis: our legitimate interests, and legal obligations where content must be preserved and reported.
  • Understanding how people use the site and which ads bring customers. Legal basis: your consent where your region requires it, otherwise our legitimate interest in measuring our own marketing, always with the opt-out in section 6.
  • Service emails (your clips are ready, billing) and, if you have not unsubscribed, tips and offers. Every marketing email has an unsubscribe link.
  • Tax and accounting records. Legal basis: legal obligation.

We do not use your videos, transcripts or clips to train AI models, and we do not sell your data.

4. Who processes your data for us

Skapo runs on the providers below, and each only gets what it needs for its job. Your uploads go straight from your browser to our private storage, but processing a video does involve other companies: the ones below that receive video or audio handle it along the way.

Vercel

Hosts the website, the app and its API.

Receives: Every request to skapo.io, including your IP address and browser details.

Cloudflare

Network in front of the site, and Cloudflare R2 for file storage.

Receives: Your requests and IP address (used to tell us your country); in R2, your uploaded videos, rendered clips, thumbnails, transcripts, brand logos and fonts.

Neon

Our database.

Receives: Your account record, jobs, clip metadata, credit history and settings.

Clerk

Sign-in and account security.

Receives: Your email address, name, sign-in method and session data.

Paddle

Merchant of record: takes payments, handles tax and invoices.

Receives: What you buy, your email, country and billing details. Your card or bank details go to Paddle, never to us.

Modal

The GPU servers that process your video.

Receives: Your video (downloaded from your link or read from your upload) and the settings for the job. Working copies are removed when the job finishes.

Google (Gemini API)

AI analysis of what is said and shown.

Receives: The audio and short low-resolution segments of your video, and its transcript; for White Label brand kits, the public text of a website you ask us to read.

OpenAI

Backup AI provider, used only when the primary one is unavailable.

Receives: The transcript text of your video.

Google (YouTube Data API)

Reads a video's title and length before you spend credits.

Receives: The YouTube video id you paste.

A video download service (via RapidAPI)

Fetches public YouTube videos you link to.

Receives: The YouTube link you submit.

Resend

Sends our emails.

Receives: Your email address, first name and the content of the email.

PostHog

Product analytics and error reports.

Receives: The events described in section 5.

Google Analytics and Google Ads

Website analytics and ad measurement.

Receives: The events and identifiers described in section 5.

Your browser's push service (Google, Mozilla, Apple or Microsoft)

Delivers a "your clips are ready" notification, only if you turned them on.

Receives: The notification text and a device address your browser created.

Several of these providers are based in, or process data in, the United States. Where data leaves the European Economic Area, it is covered by the safeguards in each provider's data processing terms, such as the EU Standard Contractual Clauses.

5. Analytics, ad measurement and cookies

We use three measurement tools. What they may do depends on your region (section 6).

  • Google Analytics 4 counts page views and key steps such as signing up, starting a video, opening checkout and completing a purchase. It uses the _ga cookies.
  • Google Ads conversion measurement tells Google Ads which ad clicks led to a sign-up or purchase. When you arrive from an ad, the link carries a click id (gclid, gbraid or wbraid); we keep it in a skapo_gclid cookie for up to 90 days, Google keeps it in its _gcl_* cookies, and it is stored with your account when you sign up, so a later purchase can be credited to the ad that brought you. When a payment completes, our server reports it to Google Analytics using your Google Analytics client id and, if we have it, the session in which you checked out.
  • PostHog records product events (pages, clicks, errors, job steps). With measurement allowed it sets a cookie, links events to your account, and may record your session with every form field masked. Without it, PostHog runs in a cookieless mode: events are counted without storing anything on your device and are not linked to you.

Your first campaign touch (UTM parameters and landing page) is kept in your browser's local storage as skapo_first_touch for up to 90 days, so it can be attached to your account when you sign up. Your consent choice is stored as cookie_consent. Sign-in uses Clerk's session cookies, which are strictly necessary.

Some things happen on our server regardless of these choices because they are part of running your account: we record sign-ups, jobs and purchases against your account id, including in PostHog.

6. Your choices, by region

United States and Canada (except Quebec): analytics and ad measurement are on by default. Ad personalization stays off. We treat a Global Privacy Control signal from your browser as an opt-out automatically. If we cannot tell your Canadian province, you get the opt-in banner described below.

Everywhere else, including Quebec, the UK and the EU:nothing beyond strictly necessary storage runs until you click "Accept all" on the cookie banner. "Essential only" keeps it that way.

"Do not sell or share my personal information", in the footer of every page, works wherever you are. It records an opt-out in your browser, switches Google Analytics and Google Ads to denied for all four consent signals (analytics storage, ad storage, ad user data and ad personalization), moves PostHog to its cookieless mode, and deletes the skapo_gclid, _gcl_* and _gacookies and your stored first touch. We do not sell personal data for money; Google Ads conversion measurement can count as "sharing" under some US state laws, which is what this link turns off. The choice lives in your browser, so repeat it on each device or browser you use. Information already on your account, such as a click id captured at sign-up, is not sent anywhere new because of the opt-out; email us if you want it removed.

7. Browser notifications

If you ask to be notified when your clips are ready, your browser creates a push address that we store with your account, together with your language. We only use it for that notification. Turn notifications off in your browser settings, or delete your account, and it stops.

8. How long we keep things

  • Rendered clips stay available for 7 days on the free plan, 30 days on Freelancer Pro and 90 days on White Label (or the 30, 90 or 365 days set on a client workspace). After that we stop serving them: no preview, no download, no link that works.
  • Deleting expired files from storage: the automatic cleanup that erases expired clips from our storage is built but not switched on yet. Until it is, expired files sit in private storage that nobody can reach through the app, and we delete them on request.
  • Source uploads are kept in private storage so you can edit and re-render your clips. There is no automatic deletion schedule for them today; they are deleted when you delete your account, or sooner on request.
  • Working copies on our processing servers are removed when the job finishes.
  • Account data, sign-up attribution and job history are kept until you delete your account.
  • Payment records are kept by Paddle, as merchant of record, for as long as tax law requires.
  • Analytics data is kept by Google and PostHog under their retention settings for our projects.

Deleting your account (Settings, then Danger Zone) erases your clips, source uploads, transcripts, brand assets and account record from our storage and database straight away. The law can require us to preserve and report content that was flagged as illegal; where it does, that duty comes first.

9. Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable format. Where we rely on consent, you can withdraw it at any time with the footer link. Email [email protected] and we will answer within one month. US residents can use the same address for requests under their state privacy law; we will not treat you differently for making one.

You can also complain to a data protection authority. Ours is the Dutch Autoriteit Persoonsgegevens; you can also go to the authority where you live.

10. Children

Skapo is a tool for creators and businesses and is not meant for children under 16.

11. Changes

When we change how we handle data, we update this page and the date at the top.