Privacy Policy

Effective and last updated: 19 September 2026

This policy explains how Man Sarip, the developer of Obiklip ("Obiklip", "we", "us"), handles personal data through the Obiklip website and web application.

Bahasa Melayu: Baca Dasar Privasi.

1. The short version

Obiklip runs no server of its own. The website and the app are static files, and everything the app does happens in your browser on your own API key.

2. Data we process

Obiklip holds no personal data of its own. There is nowhere for it to be held: no account, no database and no application server.

Account None. Obiklip has no accounts, so there is no email address, password or profile to collect.
AI requests None. Transcription, analysis, translation and post copy are requests your browser makes to OpenAI with your own key. Obiklip is not in that path, so it holds no audio, no transcript, no prompt, no result and no usage or token count for any of them.
Hosting logs The host serving the two sites records ordinary web-server information - the requested address, a timestamp, an IP address and a browser user agent - for delivery, security and abuse prevention. Obiklip adds nothing to it and builds no profile from it.
Page counts Vercel Web Analytics counts visits to each page of the website and of the app. It sets no cookie and stores nothing in your browser: the count is worked out from the request itself, with a value Vercel rebuilds each day that is of no use on any other site. What it reports is the page, where the visit came from, a country and a rough device type - never who you are, and never a video, a transcript, a clip or an API key, none of which reach it.
Support payments Handled by Stripe on a page Stripe hosts. Stripe collects what it needs to take a payment and issues the receipt. Obiklip receives no card number, no name, no address and no notification that a payment happened.
Messages you send If you write on Telegram, that conversation and whatever you put in it exist in Telegram. Please do not send a source video unless it is specifically asked for.

3. Data kept in your browser

Saved analysis sets, translations and generated post copy remain in your local browser projects. Your OpenAI API key is stored in IndexedDB for the current browser profile and is sent only to OpenAI for API requests. Removing a key from Obiklip does not revoke it at OpenAI; revoke it there if you want to stop its use.

Obiklip stores an internal source reference, filename, content fingerprint, duration, language, transcript, clips, titles, edits, export records, cached results and settings locally. A source opened from disk stays where it is and is not copied. The stored file handle, where the browser supports one, may let you grant access again after a reload.

Obiklip creates audio chunks and thumbnails locally as needed. The audio it extracts to transcribe a video, and the clips it finishes exporting, are kept in the browser's private file storage so a run that stops partway does not have to cut the same audio again and a finished clip can be downloaded again after a reload. Both are made from your own video, both stay in this browser profile, and neither is ever sent anywhere. Settings → Storage shows how much is kept and clears it; clearing it costs nothing but the time to make it again.

Deleting a project removes its IndexedDB records and the audio and exports Obiklip kept for it, but does not delete the source video or files already downloaded. Clearing site data can remove every local project, setting and saved API key in that browser profile. Nothing is copied anywhere else, so cleared data is gone.

4. AI processing

Obiklip is not in this path. The app sends the required audio, transcript text, instructions and translation or post copy requests from your browser directly to OpenAI, with your own API key. Results return to your local project.

When you select Analyze Video, Obiklip extracts compressed mono audio on your computer and sends those chunks to OpenAI for transcription. Relevant transcript text, and any instructions you provide, is then sent to OpenAI for the clip suggestions. Responses return to your local project.

When you select Translate, the transcript is sent to OpenAI in batches, followed by the titles and descriptions of the clips the project has at that moment, and the translated text returns to your local project. A batch carries only the text being translated and a position number for each item; it does not carry the source filename, project title, file path, timings or any other clip data.

When you select Generate post copy, the clip transcript and language are sent the same way. The generated hook, title, caption, quote and hashtags are saved with your clip on your computer.

OpenAI's retention and data use depend on the endpoint, model and the controls on your API account, which is the one making every request. Your own OpenAI settings and agreements apply and Obiklip does not control them. Check OpenAI's API data controls.

5. Service providers

OpenAI Processes audio and text needed for the AI feature you request, including transcription, clip suggestions, titles, translation and post copy. Every one of those requests uses your own OpenAI account, directly from your browser. Obiklip is not a party to them and discloses nothing to OpenAI.
Vercel Hosts the static website and the static web app, keeps the ordinary request logs described above, and provides the cookieless page counts through Vercel Web Analytics.
Stripe Operates the support payment page end to end, collects and processes payment details, and sends receipts. Obiklip never receives your card number and is told nothing about the payment.
Telegram Carries messages you choose to send to the developer.

We may also disclose information to professional advisers or authorities where reasonably necessary to comply with law, protect rights or security, or resolve a dispute - noting that there is almost nothing to disclose. We do not disclose your content to advertisers or data brokers.

6. International processing

These providers may process data outside Malaysia, including in the United States and other countries where they or their subprocessors operate. We take reasonable steps to use providers that provide protection comparable to applicable Malaysian requirements. By asking the app to process content, or by supporting Obiklip, you acknowledge the transfers necessary to fulfil that request.

7. Retention

8. Security

Both sites are served over encrypted connections, and the only script either one loads is the Vercel page-count tag, served from the site's own address rather than from a third party's. The app declares a Content Security Policy that permits connections to its own origin and to OpenAI, and to nothing else. Your API key and your projects never leave your browser, so the strongest protection here is that there is no central store to breach. No system is completely secure.

9. Your choices and rights

Subject to applicable law, you may ask to access, correct or delete personal data we hold. In practice we hold none: local data is yours to delete in your own browser, and payment data is held by Stripe, which you can contact directly using the receipt it sent you.

Message @mansarip on Telegram. You may also lodge a complaint with Malaysia's Personal Data Protection Commissioner. Obiklip sends no email at all, so there is no marketing list to opt out of.

10. Automated decisions

Automated systems suggest clips and titles, but you decide what to edit, export or publish. No automated decision is made about you.

11. Children

Obiklip is for people aged 18 or older.

12. Changes and contact

We may update this policy when the product, providers or law changes. The date above will change.

The data controller is Man Sarip, developer of Obiklip. Privacy and data requests: @mansarip on Telegram.