Legal
Privacy Policy
Effective September 27, 2026. This policy describes the personal information ClickPop handles for the public site, ClickPop Studio, the API, and the MCP connector.
ClickPop operates the ClickPop website and ClickPop Studio. The public site does not require an account. The signed-in product is ClickPop Studio. Questions and requests go to hello@clickpop.ai.
This policy is written in plain language so a person, and a platform reviewer, can see what we collect and why. It is the operator’s description of the product. It is not a law-firm opinion.
Who operates ClickPop
ClickPop is the operator of this website, ClickPop Studio, the ClickPop API, and the ClickPop MCP connector. Write to hello@clickpop.ai.
What the service is
ClickPop is an AI video and influencer studio. With an account you can:
- Describe a fictional character and keep a reference set for later videos.
- Generate scripts, images, and videos, and upload product photos, logos, and other reference images.
- Save a brand profile (niche, tone, audience, example posts, colors, and logo) that later scripts and captions can use.
- Connect social accounts and publish or schedule posts you ask for, including to Instagram and Facebook.
- Call the REST API, or use the MCP connector with an API key you create, so an agent can list your studio, create a character or video, and publish when that key is used to do so.
The MCP connector is a tool that runs with your API key. It can read the same account, character, video, and connected-account information the API can read, and it can create or publish content only when a call is made with that key. See the MCP documentation and the Terms of Service.
Information we collect
Account
- Name, email address, and a date of birth. Signup and the birthday step reject a date of birth that makes the person under 13.
- Sign-in method. Email and password are handled by Supabase. We do not see your password. If you continue with Google, Microsoft, or GitHub, we receive the email that provider shares, a name, a provider account id, and a profile image when the provider sends one. We do not see that provider’s password.
- Whether the email is verified, the plan, the credit balance, and the time the account was created.
- Workspace name, timezone, and how many hours before a scheduled post a video should render.
Content you put in the studio
- Character descriptions, scripts, captions, prompts, and generated images and videos.
- Uploaded images, including reference photos, product photos, and brand logos.
- Brand profile fields: niche, tone, audience, example posts, words you want left out, a style note, colors, and the logo file.
- Products, affiliate details, schedules, and posts you create in the studio.
Social accounts you connect
If you connect a network from the Social page, ClickPop stores the account id, username or handle, display name, profile photo, account type when the network provides it, connection status, and which characters you assign to that account. For posts published through ClickPop, we also store the post record and, when the publishing provider returns them, performance numbers such as views, likes, and shares for those posts.
Connection tokens for Instagram, Facebook, and the other networks stay with our publishing provider, Post for Me. ClickPop does not store your Instagram, Facebook, or other social password. Bluesky connections use an app password that is sent to Post for Me to open the connection. We do not keep a copy of that app password in the studio record.
API keys and connector use
On the API keys page you can create a key. The full secret is shown once. We store a hash of the key, a short prefix, the last four characters, the name you gave it, and when it was created and last used. Requests made with the key, including through the MCP connector, are tied to your account.
Billing
Paid plans are monthly subscriptions processed by Stripe. Credit top-ups are one-time payments, also processed by Stripe. We store a Stripe customer id and, when you subscribe, a subscription id, your plan, and a credit ledger (charges, grants, and credits returned when a render fails). Stripe handles the card. We do not receive or store the full card number.
Security and usage
We keep a session so you stay signed in, and we keep short-lived counters for sign-in, signup, and verification attempts. Those counters can include an IP address and the email address used on that attempt, so we can slow repeated tries. We also record credit use and API activity needed to run the account.
The email ClickPop sends is the account verification message, through Supabase. We do not send launch, waitlist, or marketing email. The contact form on this website opens your own email app addressed to hello@clickpop.ai. It does not store the form on our servers. In-studio notices, such as a failed render, stay inside the product.
Where information comes from
- From you, when you create an account, type a date of birth, upload a file, write a prompt, or fill in a brand profile.
- From Google, Microsoft, or GitHub, when you choose that sign-in method.
- From a social network, including Instagram or Facebook, when you connect it. The fields we receive are the profile and posting fields described above, returned through Post for Me.
- From Stripe, when a payment or subscription succeeds: the customer id, subscription id, and the plan that payment applies to.
- From the service itself: generated videos, credit ledger entries, and post results for posts you asked us to publish.
How we use information
We use personal information to:
- Create and secure your account, including the 13-or-older check and the verification email.
- Render the videos and images you request, store them in your library, and show them back to you.
- Publish and schedule posts to the accounts you connect, and show analytics for posts published through ClickPop.
- Run the API and the MCP connector under your API key.
- Bill you, apply monthly plan credits, apply top-ups, and return credits when a render fails.
- Rate-limit sign-in and signup, and enforce the product’s content rules (for example, the character builder treats a human character as a fictional adult, 21 or older).
Where a privacy law asks for a reason, we rely on these:
- Contract. Account, content, billing, posting, and API data are processed to provide the service you asked for.
- Consent. You provide a date of birth to pass the age check, and you start each social-account connection. You can ask us to remove a connection or the account, as described under data deletion.
- Legitimate interests. Limited sign-in and security data is used to protect accounts, prevent abuse, and keep the service available. You can object by emailing hello@clickpop.ai. We will consider the request.
ClickPop does not use your characters, prompts, uploads, or videos to train a model of its own. Prompts and images are sent to the providers named below so they can fulfill the request you made. Those providers apply their own terms to a request they receive.
Meta, Instagram, and Facebook
You can connect Instagram, Facebook, and Threads from the Social page in ClickPop Studio. Connection is optional. If you do not connect an account, we do not receive that account’s platform data.
When you connect one of those accounts, ClickPop asks Post for Me to open that network’s login. The permission requested for the connection is permission to publish posts. From the connection, ClickPop stores the account id, username or handle, display name, profile photo, account type when Instagram or Facebook provides it (for example, whether an Instagram account is personal, business, or creator), and connection status.
We use Meta platform data only to provide the features you asked for:
- Show you which Instagram, Facebook, or Threads account is connected.
- Publish or schedule the post, caption, and video you select for that account.
- Read results for posts published through ClickPop, such as views, likes, and shares, and show them in your studio.
- Let an API or MCP call list those connected accounts or publish a ready video when your API key is used to make that call.
We do not sell Meta platform data. We do not use it for advertising, and we do not share it for cross-context behavioral advertising. We do not use it to train a ClickPop model. We do not access your Instagram or Facebook password, your private messages, or your friends list for this product. The login token that lets a scheduled post go out is held by Post for Me, not stored as a social password in ClickPop.
Instagram posting through this product expects a Business or Creator account. A personal Instagram account can be connected and still be unable to receive posts. That limitation comes from Instagram.
How to disconnect a Meta account
ClickPop Studio does not have a disconnect button on the Social page. To disconnect Instagram, Facebook, or Threads, email hello@clickpop.ai from the address on your ClickPop account. Use the subject “Disconnect social account” and name the network and the handle. We will remove the connection record we store and stop using it to publish.
You can also remove the app’s access in your Instagram or Facebook settings. That revocation is between you and Meta. Posts that already went live on Instagram or Facebook stay on that network until you delete them there. Deleting a post inside ClickPop removes it from the studio list. It does not delete a live post on the network.
Meta’s own terms apply to your Instagram, Facebook, and Threads accounts. ClickPop’s use of platform data is also described in the Terms of Service.
Service providers and sharing
We share personal information with service providers that perform a function for ClickPop, and with a social network when you ask us to publish there. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
The providers this product actually uses are:
- Supabase for authentication, including email sign-in and Google, Microsoft, and GitHub sign-in, and for the verification email.
- Stripe for checkout, subscriptions, and the billing portal. Card numbers stay with Stripe.
- Vercel for hosting the application.
- Segmind for image and video generation. A render sends the prompt and the reference or product images needed for that job.
- OpenRouter for text requests such as scripts and captions. OpenRouter routes the request to a model for that job.
- Post for Me (postforme.dev) for social-account connection and publishing, including Instagram, Facebook, and Threads.
- The social network you select, including Meta (Instagram, Facebook, and Threads), TikTok, YouTube, X, LinkedIn, Pinterest, and Bluesky, receives the post, caption, and media you choose to publish.
Each provider receives what it needs for that function. We do not give them your studio so they can advertise to you on other sites. If we add a provider that handles personal information in a new way, we will update this policy.
We may also disclose information if the law requires it, or to respond to a valid legal request, or to protect users, the public, or the service from abuse or fraud.
Retention
We keep account information, content, brand profiles, social connection records, and API key records while the account is open and the item has not been deleted. Sign-in sessions last up to 30 days. Verification links expire after one day. Rate-limit counters used for sign-in and signup are short-lived.
When you delete a character, video, schedule, post, or logo in the studio, we delete that item from ClickPop. Deleting a character removes its reference photos. Finished videos stay in the library until you delete them there. A post already published on a social network stays on that network.
After we complete an account deletion request, we delete the studio content tied to the account. We keep records we still need for billing, fraud prevention, security, or a legal duty. Stripe keeps payment records under Stripe’s own policy. We do not keep Meta platform data after the connection and the account content that held it have been deleted, except a record of the deletion request itself if we need it to show the request was handled.
Security
We use HTTPS in production, an httpOnly session cookie, hashed session tokens, and hashed API keys. Social passwords are not stored in ClickPop. Card numbers are not stored in ClickPop. No method of transmission or storage is perfectly secure. If you believe your account or API key has been exposed, revoke the key on the API keys page and email hello@clickpop.ai.
International transfers
ClickPop and the service providers listed above may process information in the United States and in other countries where those providers operate. Those countries may have different privacy laws from the country where you live. We use those providers to host the product, authenticate you, take payment, render video, and publish posts you request.
Your rights
You can ask to access, correct, delete, or receive a copy of the personal information we hold about you. You can also ask us to stop a particular use where the law gives you that right. Email hello@clickpop.ai from the address on the account, with the subject “Privacy request”, and say what you want. We will respond, and where we can complete the request we will do it within 30 days. If we need to confirm it is your account, we will ask.
There is no download-my-data button in ClickPop Studio. The Usage page shows the credit ledger for the signed-in account. A copy of the rest of your personal information is provided by email when you ask.
Depending on where you live, you may have additional rights, including the right to appeal a refusal. Email us and we will tell you what we can do under the law that applies. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no separate sale to opt out of.
How to delete your data
This is the deletion path for your ClickPop account, including information received from Meta, Instagram, or Facebook. You do not need to be signed in to send the request. There is no delete-account control in ClickPop Studio.
- Email hello@clickpop.ai from the email address on the ClickPop account.
- Use the subject “Data deletion”.
- Include the account email. If you connected Instagram, Facebook, or Threads, include the handle and the network so we can match the connection.
We will delete the ClickPop account and the studio data tied to it: profile, date of birth, characters, videos, uploads, brand profile, schedules, studio post records, social connection records we store (including Instagram, Facebook, and Threads), and API keys. We will do that within 30 days of a request we can match to the account. We may keep billing records in Stripe, credit and payment records we must keep, and short security logs, as described under Retention.
You can delete individual items yourself while the account is open:
- Characters, in the character studio. Deleting a character removes its reference photos. Videos already in the library stay until you delete them.
- Videos, in the Library.
- Schedules, in Automations.
- Posts, on the Social page. A post that is already live on Instagram, Facebook, or another network stays there until you remove it on that network.
- A brand logo, in Settings.
- An API key, on the API keys page, by revoking it.
To disconnect a social account without deleting the whole ClickPop account, use the subject “Disconnect social account”, as described in the Meta section above. Canceling a paid plan is separate: signed-in users cancel from Billing, which opens Stripe. Canceling a plan does not by itself delete personal information.
Children
ClickPop is not directed to children under 13. Signup requires a date of birth, and the product blocks anyone under 13. We do not knowingly collect personal information from a child under 13. If you believe a child under 13 has an account, email hello@clickpop.ai with the subject “Data deletion” and we will delete it.
The account age check is 13. Separately, the studio’s content rules treat human characters as fictional adults. That is a rule about what the product will generate, not an extra age gate on the account.
Changes
We may update this policy. The new version will be posted on this page with a new effective date. If you have an account, continued use of ClickPop Studio after that date means the updated policy applies. The prior contact address remains hello@clickpop.ai.
Contact
Privacy questions, a copy of your information, a correction, a disconnect request, or a deletion request: hello@clickpop.ai.
Related pages: Terms of Service, Copyright notices, Contact.