// Trust & Security Report
Clideo
Browser-based video editing and media conversion tools including video editor, subtitles, compression, resizing, merging, and format conversion (50+ tools); 5M monthly users.
Certifications held
1
Maturity
Growth
Trains on your data
Unknown
Trust center
No
// Certification ledger
Each held certification is backed by a verbatim quote from the vendor's own trust or security page. “Not confirmed” means we could not verify it publicly, not that the vendor lacks it.
Verify on clideo.com“As used in this Policy, 'personal data' is as defined in the General Data Protection Regulation”
> Show 6 unconfirmed / not-held certifications
No mention found on vendor domain. Nudge Security claims compliance but no vendor-domain proof of certification.
source: clideo.comNo vendor-domain proof. Unifab.ai claims 'ISO 27001 Certification through hosting providers and data centers' but Clideo's privacy policy only mentions 'reasonable organizational, technical and administrative measures' without certifying to ISO 27001 standard.
No mention found on vendor domain. Nudge Security claims HIPAA compliance with no vendor-domain proof; inappropriate for video editing tool without healthcare data handling.
No mention found on vendor domain. Nudge Security claims PCI compliance but no vendor-domain proof.
No mention found on vendor domain. Nudge Security claims FedRAMP compliance; highly implausible for unfunded startup video editor (FedRAMP costs hundreds of thousands and applies only to US government cloud services).
No mention found on vendor domain. Nudge Security claims CSA STAR Level 1 with no vendor-domain proof.
// Privacy & AI training
Trains on customer data
Not stated
Data processing agreement
Not offered
Data region
Cyprus-based company; privacy policy allows international data transfers outside user's country of residence. No specific data center locations disclosed.
No AI training policy found. Privacy policy does not address whether customer videos or data are used for model training or product improvement.
// Security controls
Encryption in transit
TLS (Transport Layer Security) mentioned in third-party sources; HSTS enforcement noted.
Organizational security measures
Privacy policy states: 'We seek to use reasonable organizational, technical and administrative measures to protect personal data within our organization.' Also acknowledges: 'no transmission or storage system can be guaranteed to be completely secure.'
clideo.comFile retention and deletion
Free tier: automatic deletion after 24 hours (third-party sources claim this; not explicitly stated on vendor domain). Paid users: retention until account closure or legal requirement.
International data transfers
Privacy policy allows transfers outside user's country with statement: 'data protection and privacy regulations may not offer the same level of protection as in other parts of the world' but claims reasonable security measures.
clideo.com// Products & data scope
Data it handles: User uploads video/image files; edits performed client-side and server-side; files stored temporarily (24 hours for free users)
Core product; handles personal creative content (videos, images). No explicit mention of whether data is used for training or product analytics.
Data it handles: User uploads media files; converted and returned; temporary storage
GIF maker, audio/video converters, subtitle generator, text-to-speech, etc. Standard conversion workflow.
// What to watch
- Nudge Security's vendor profile lists seven certifications (SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, CSA STAR, GDPR), but Clideo's own privacy policy and terms mention only GDPR compliance explicitly; no SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, or CSA STAR certifications are claimed on the vendor's domain.
- The FedRAMP claim in the Nudge Security profile is highly suspect: FedRAMP is exclusively for US government cloud services, costs hundreds of thousands of dollars to obtain, and is an implausible certification for a small video-editing startup.
- A Unifab.ai review claims 'Clideo is headquartered in Germany', but evidence shows Clideo Ltd is a Cyprus-registered company (Larnaca) and its terms are governed by Cyprus law, not German law. This discrepancy raises questions about Unifab's accuracy.
- Unifab.ai distinguishes that ISO 27001 applies to hosting providers and data centers, not Clideo itself; this is the host's certification, not the vendor's.
- No dedicated trust center or security page was found on clideo.com. All security claims on the vendor's own site are generic (e.g., 'reasonable measures'), with no commitment to transparency or audit documentation.
- The privacy policy uses vague security language ('seek to use reasonable measures') with an explicit caveat that 'no transmission or storage system can be guaranteed to be completely secure', and discloses no specific technical practices.
- The privacy policy makes no statement about whether customer-uploaded videos or data are used for training, model improvement, or product analytics; for a video platform, this is a critical gap.
- No Data Processing Agreement was found on the vendor's site, which matters for enterprise and B2B use.
- Nudge Security's extensive certification list (7 certifications) appears unsupported by the vendor's own documentation, and there is no independent confirmation via SEC filings, audit reports, or certifier databases.
// At a glance
Pricing model
Freemium: free tier with ads/watermark/24-hour deletion; paid tier (no details on pricing or features on public pages)
Self-hostable
No
// How we verified this
Every certification marked HELD is confirmed against a verbatim quote on Clideo Ltd (Cyprus)'s own trust, security, or privacy pages. We reject certifications claimed only on third-party aggregators, on a cloud host's behalf, or by a similarly named company.
Last verified 2026-07-06. Compliance changes over time. Always confirm directly with the vendor before relying on any certification for a purchasing or compliance decision.
clideo.com