Privacy Policy
Last updated: August 30, 2026
ClutchCut Studio ("we", "us") builds native macOS, iOS, and visionOS apps including ClutchCut Shadow, ClutchCut Video, ClutchCut Audio, ClutchCut Loop, and KongFu Mahjong. We don't track you. We don't sell your data. We don't use third-party analytics or advertising SDKs. Most of what our apps do happens entirely on your device.
1. What our apps don't collect
None of our apps collect, transmit, or share:
- Personal information beyond what you voluntarily provide (e.g., your email when activating a license)
- Device identifiers, advertising IDs, or fingerprinting data
- Location, contacts, calendar, or photo library content
- Microphone or screen recordings — these stay on your device
- Project files, audio recordings, video footage, or any creative content you produce
- Browsing or search history
- Crash reports beyond Apple's standard diagnostics (which you can opt out of via macOS Privacy settings)
2. What we do collect (and why)
License verification
When you activate a paid license key (CCA-, CCV-, CCM- or similar), the app sends the key to our server (clutchcut.studio) to verify it's valid. We store the license key, the email address used at purchase, and the activation timestamp. We use this only to honor your purchase across re-installs and to provide customer support.
In-App Purchases
When you purchase a subscription or unlock via Apple's App Store, the transaction is handled entirely by Apple. We receive only an anonymous entitlement token confirming you're a Pro user — we don't see your name, billing address, or payment details.
Direct purchases via Stripe (clutchcut.studio only)
When you buy a license directly from clutchcut.studio (not via the App Store), Stripe processes the payment and sends us your email address and the product purchased. We use the email to deliver your license key and for customer support. Stripe's own privacy policy applies to payment processing: stripe.com/privacy.
Support requests
When you contact support via clutchcut.studio/support, we receive your name, email, and message. We use this only to respond to your request.
YouTube account access (ClutchCut Loop)
ClutchCut Loop can publish live streams to your own YouTube channel. This is optional — the app works with any RTMP or HLS destination — and nothing happens until you choose to connect a channel.
If you connect one, ClutchCut Loop uses YouTube API Services under the YouTube Terms of Service. You authorise it through Google's own sign-in screen; we never see or handle your Google password. The access it requests is limited to a single scope, used only to manage the broadcasts you create in the app:
- Create a live broadcast, with the title, description and privacy setting you entered
- Create and bind its stream, so the app has somewhere to publish
- Upload the custom thumbnail you selected
- Start it, confirm it actually went live, and end it when you stop
- Read its status, so the app can show accurate health and stop publishing if the broadcast ended elsewhere
Your Google account data stays on your Mac. The authorisation tokens are stored in your macOS Keychain on your own machine. They are never transmitted to us, we operate no server that receives them, and we cannot read your account. Video and audio you stream go directly from your Mac (or from a Linux server you own and control, if you choose to export a stream to one) to YouTube — never through us.
We do not use YouTube data for advertising, we do not sell or transfer it, and we do not combine it with data from other sources. You can revoke ClutchCut Loop's access at any time — inside the app by signing out of the connected account, or from your Google Account at myaccount.google.com/permissions. Revoking immediately ends the app's ability to manage your broadcasts. Google's own handling of your data is covered by the Google Privacy Policy.
YouTube public data (ytgap research console)
ytgap, the topic-research console on this site, uses YouTube API Services under the YouTube Terms of Service. It works differently from ClutchCut Loop above, and it is worth being precise about the difference.
It never accesses your YouTube account.There is no Google sign-in, no OAuth authorisation, and no access token — not for you, and not for anyone else. The console reads only data that YouTube already publishes openly: public search results, and the public statistics of public channels and videos (channel creation date, subscriber count, upload counts, video titles, view counts and durations). It cannot see private or unlisted content, anyone's analytics, or anyone's account.
What we store: a scan's results are cached on our server for 24 hours and then automatically deleted. The cache exists solely to avoid asking YouTube the same question twice in a day. It holds public figures about public channels — no personal data about you, and no data belonging to any YouTube account holder.
We do not use this data for advertising, and we do not sell, licence, syndicate or redistribute it to anyone. Every channel and video the console displays links back to its source on YouTube. Google's own handling of your data is covered by the Google Privacy Policy.
Magic-link authentication (clutchcut.studio account features)
Some features of the website (such as podcast pages and ClutchCut Reach dashboards) require sign-in via magic-link. We store your email address and a hashed session cookie on the website only.
3. Optional cloud features (you control)
Some apps (the direct-distribution version of ClutchCut Audio and ClutchCut Video, downloadable from clutchcut.studio) include optional integrations with third-party AI services. These features are off by default and require you to enter your own API key in the app's settings:
- Microsoft Azure Cognitive Services (text-to-speech)
- Google Cloud Text-to-Speech
- Google Gemini (image generation, AI Director scripting)
- Replicate, DeepInfra, SiliconFlow (image generation)
When you use these features, the data you supply (text or image prompts) is sent directly from your device to the third-party service using your API key. We do not see, store, or proxy this data. Each service's own privacy policy applies. The App Store versions of our apps do not include any of these integrations.
4. App permissions
Some apps request access to your microphone, screen recording, and Speech Recognition. These permissions are used strictly for the feature you trigger (recording audio, capturing screen, transcribing audio you provide). All processing happens on your device. Nothing is uploaded.
5. How we protect your data
This section describes the technical and organisational measures that protect the data described above, including Google user data obtained through Google OAuth and the YouTube Data API.
Google user data (ClutchCut Loop)
- Encryption in transit. Every request to Google's authorisation and YouTube Data API endpoints is made over HTTPS with TLS 1.2 or higher, using the operating system's certificate validation. The app makes no plaintext HTTP request to any Google endpoint.
- Encryption at rest. OAuth access and refresh tokens are written only to the macOS Keychain on the user's own machine, as generic-password items protected by the Keychain's system-managed encryption and by macOS FileVault where the user has enabled it. They are marked accessible only after first device unlock and are excluded from iCloud Keychain synchronisation, so they never leave the machine that created them. Tokens are never written to preference files, logs, project files, or any other location on disk.
- No server-side storage. We operate no server that receives, stores, relays, or processes Google user data. Tokens are never transmitted to ClutchCut Studio or to any third party, and no employee, contractor, or system of ours can read them. Because we never hold this data, there is no ClutchCut-side database, backup, or log for it to be exposed from.
- Access control on the device. Keychain items are scoped to a single service identifier and are readable only by the signed ClutchCut Loop application running under the user's own macOS account, enforced by macOS Keychain access control and code signing. The app runs inside the macOS App Sandbox and is code-signed with the hardened runtime enabled.
- Authorisation handled by Google. Sign-in runs in a system-provided secure web view (
ASWebAuthenticationSession) against Google's own sign-in page, using the OAuth 2.0 authorization-code flow with PKCE. The app never sees, receives, or stores a Google password, and it holds no client secret. - Least privilege. Loop requests a single scope,
https://www.googleapis.com/auth/youtube, which is the minimum required to create, bind, start, monitor, and end the live broadcasts the user initiates in the app. No additional Google scope is requested, and Google user data is never used for advertising, sold, transferred, or combined with data from other sources. - Retention and deletion. Tokens are retained on the user's device only while an account remains connected. Choosing Sign out for that account in the app deletes its Keychain token immediately, and revoking access at myaccount.google.com/permissions invalidates them at Google. Uninstalling the app and deleting its Keychain entries removes them entirely. There is no retention period on our side because we never receive the data.
Data we do hold (website and licensing)
- All traffic to clutchcut.studio and its APIs is served over HTTPS with TLS 1.2 or higher and HSTS; there is no plaintext endpoint.
- License records, user records, and support tickets are stored in managed databases (Neon Postgres and Upstash Redis) that are encrypted at rest and reachable only over TLS with per-service credentials held as server-side environment secrets, never shipped in any client app.
- Administrative access is limited to the sole operator of ClutchCut Studio, protected by two-factor authentication on every underlying provider account. Session cookies are HMAC-signed, HTTP-only, and Secure.
- We never receive card numbers or bank details: payments are processed entirely by Apple or by Stripe, both PCI-DSS compliant.
- API rate limiting and daily spend caps are applied to public endpoints to limit abuse.
- If we ever become aware of a breach affecting personal data we hold, we will notify affected users by email at the address on file without undue delay.
6. Data storage and retention
- License records and user records are stored on Upstash Redis (encrypted at rest, US region) for as long as you may need to re-verify your purchase.
- Support messages are retained until the issue is resolved, then archived in our email system.
- You may request deletion of your data at any time by emailing clutchcut.studio@gmail.com.
7. Children
Our apps and website are not directed at children under 13. We do not knowingly collect personal information from children.
8. Changes to this policy
We may update this policy. Material changes will be reflected by an updated "Last updated" date at the top of this page. Continued use of the apps after a change constitutes acceptance.
9. Contact
Questions, deletion requests, or concerns: clutchcut.studio@gmail.com