Privacy
What zaclip does with your data
Different parts of this site work very differently, and lumping them together would hide the thing that matters most: the encoder never sends your video anywhere, and the feature that does need a server is the one you have to switch on yourself.
The short version
- Encoding a video — happens entirely inside your browser tab. The file is never uploaded, never seen by us, never stored.
- Checking or downloading a posted video — the link you paste reaches our server. We fetch what TikTok publishes for it. We do not record who asked.
- Posting to TikTok — optional, and the only feature with an account. It stores the access TikTok gives us, and your video passes through our server on its way to them.
- No analytics, no tracking, no advertising cookies at the time of writing. There is no third-party script of any kind on this site.
Encoding a video
The file you drop on the home page is read by JavaScript running in your own browser. It is not uploaded, because there is nothing to upload it to — the site is a set of static files, and the rebuilt video is assembled on your device and saved from there.
We therefore have no copy of your video, no way to obtain one, and nothing to hand over if somebody asked. This is a property of how it is built rather than a promise about how we behave, which is the only kind of privacy claim worth much.
Checking or downloading a posted video
These features need a server, because the work is fetching something from TikTok. When you paste a link:
- The link is sent to our own service running on Cloudflare.
- We ask TikTok for the public information it publishes about that video, and read the first part of the video file to measure it.
- The measurements are cached for up to an hour, keyed on the TikTok video id. Results that represent a temporary failure are kept for five minutes instead.
That cache holds the video’s details, not yours. We do not store the fact that you looked, we do not keep a log of submitted links, and there is no account or identifier attached to a request. Cloudflare, as the provider running the service, processes requests on our behalf and keeps its own operational logs.
Posting to TikTok
This is the only part of zaclip that involves signing in, and you have to choose it — encoding a video and saving it yourself never touches it.
If you connect your TikTok account:
- What we store: the access and refresh tokens TikTok issues, and the account identifier they belong to. Tokens are held only so the upload can be completed and so you do not have to reconnect on every visit.
- What we never receive: your TikTok password. Sign-in happens on TikTok’s own pages; we are handed a token afterwards and nothing else.
- Your video: passes through our server because TikTok’s upload endpoint does not accept requests made directly by a browser. It is forwarded to TikTok as it arrives and is not written to storage or retained afterwards.
- Permissions: we ask only for the ability to send a video to your account. We do not read your videos, your followers, your messages or your profile beyond what is needed to complete a post.
Disconnecting. You can disconnect at any time from the posting page, which deletes the stored tokens. You can also revoke access from inside TikTok, under Settings and privacy → Security and permissions → Apps and services, which works whether or not you visit us again.
Storage in your browser
One value is kept on your device: whether you chose the light or dark theme. It never leaves your browser. If you connect a TikTok account, a session identifier is also set so that your browser can be matched to the tokens stored for it.
What we do not do
- No analytics, no tracking pixels, no fingerprinting, no third-party scripts.
- No selling or sharing of data, because there is nothing to sell.
- No email collection. There is no newsletter and no account to create.
Advertising is something we may add to help cover costs. If that happens this page will be updated before it goes live, and it will say plainly what the provider sets and what it sees.
Children
This site is not directed at children under 13, and we do not knowingly collect anything from them. There is nothing here that requires an age or an identity to use.
Changes and contact
If this page changes in a way that affects what is collected, the change will be described here rather than quietly applied. Questions about any of it can go to [email protected].
Last updated 28 September 2026.