Clockit Media (“Clockit”, “we”) provides a marketing workspace at https://clockit.media for planning, writing and reviewing social media content. This policy explains what we collect, why, who we share it with, and the choices you have.
What we collect
- Account details: your name, email address and a salted hash of your password (we never store the password itself). If you turn on two-factor authentication we store an encrypted secret and hashed recovery codes.
- Workspace content: brand information, drafts, campaigns, images you upload, team member names and roles, and invitations.
- Connected social accounts: when you connect an account (Facebook, Instagram, LinkedIn, X, YouTube or TikTok) we receive the account’s identifier, display name and handle, and the access tokens you authorise. Tokens are encrypted at rest and are never shown in the browser.
- Security records: an activity log of sign-ins (including failed attempts and the IP address), password and two-factor changes, team changes, billing events and deletions.
- Billing: payments are processed by Paystack. We store your plan and subscription status and Paystack’s customer and subscription references. We never see or store your card number.
How we use it
- To run the service: sign you in, keep your workspace, and show your content to your team.
- To act on connected accounts only as you direct: for example reading account details and, as features launch, publishing content you have scheduled and showing you that account’s performance figures.
- To generate drafts when you ask: the brief and brand details you submit are sent to our AI provider.
- To protect accounts and investigate abuse, using the security records above.
We do not sell your data. We do not use your content or connected-account data to train AI models.
Data from Google and other networks
Clockit’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from a connected network is used only to provide the features you see in Clockit, is not sold, is not used for advertising, and is not shared with third parties except the service providers below, as needed to run the service.
Who we share it with
- Amazon Web Services, which hosts our servers, database and uploaded files.
- Anthropic, which processes the text you submit when you ask for an AI draft or plan.
- Paystack, which processes subscription payments.
- The networks you connect, when you ask us to act on those accounts.
- Authorities, when the law requires it.
Retention and deletion
You can disconnect any social account at any time in Settings → Connections, which deletes the stored tokens immediately. You can remove content and media yourself. To delete your account and its data, follow the steps on our data deletion page. Security records may be kept for a limited period after deletion where needed to prevent fraud and meet legal obligations.
Security
Data is encrypted in transit. Social tokens and two-factor secrets are encrypted at rest, the production database is not reachable from the internet, and workspaces are isolated from each other. No system is perfectly secure; if we learn of a breach affecting you we will tell you.
Your rights
You may ask to access, correct, export or delete your personal data. Email us at support@clockit.media and we will respond within 30 days.
Children
Clockit is for businesses and is not directed at anyone under 18.
Changes
We will update this page when our practices change and revise the date above.
Contact
Clockit Media — support@clockit.media