Privacy Policy
This Privacy Policy describes how Short Studio ("we," "us," or "our") collects, uses, and retains information when you use the Service. By using the Service you agree to this policy.
1. Information We Collect
- Account data: email address, password (hashed), account creation date, and an optional full name and country you may provide at sign-up
- Job inputs: topics, configuration options, and any text you submit to create a video
- Uploaded files: music files and voice reference recordings you upload
- Generated content: the video files and associated metadata produced by the Service
- Payment and subscription data: transaction records (amount, date, credits granted) and, for subscriptions, your active plan, renewal date, and auto-renewal status. Card details are processed by Stripe and never stored by us.
- YouTube connection data: if you connect a YouTube channel, the channel ID and name and an encrypted OAuth token that authorizes uploads (see the YouTube API Services section below)
- Usage and audit logs: actions you take in the Service (sign-up, login, job creation, downloads, ToS acceptance) including timestamps, IP address, and browser user agent
- Terms of Service acceptance: version accepted, timestamp, IP address, user agent, and the exact checkbox text shown at the time of acceptance
2. How We Use Your Information
- To provide and operate the Service (generate videos, manage credits, and process subscription and one-time payments)
- To enforce our Terms of Service and detect abuse
- To respond to support and legal requests
- To maintain audit trails for payment disputes and refunds
3. Content Memory and Analysis
Important disclosure: Generated content produced through the Service (including video topics, scripts, and associated metadata) is ingested into a service-side memory system. This system is used by the operator to analyze content trends, improve the pipeline, and avoid duplicate work across generations. By using the Service you consent to your generated content being retained and processed in this manner.
This memory system operates at the service level and is not a user-facing feature. It is not shared with third parties. Data obtained through YouTube API Services (including channel information, access tokens, and YouTube publishing metadata) is strictly excluded from this memory system and is used solely as described in section 5.
4. Voice Cloning
If you use the voice cloning feature (where available), you upload a short voice recording as a reference. By uploading a voice reference you affirm that:
- You are the owner of the voice in the recording, or
- You have the explicit, informed consent of the person whose voice is being cloned
Voice reference files are stored privately, used solely to generate the narration for your job, and subject to the same retention policy as other uploaded assets.
5. YouTube API Services
Short Studio uses YouTube API Services to offer optional publishing of your videos to a YouTube channel you connect. When you connect a channel we store its channel ID and name and an encrypted OAuth refresh token that lets us upload on your behalf; we request only upload permission and read access to your channel's basic details, and we do not access, store, or process any other YouTube data. Uploads happen only when you request them. Google's handling of your data is described in the Google Privacy Policy, and your use of YouTube is subject to the YouTube Terms of Service. You can revoke our access at any time by disconnecting the channel in Account Settings or via your Google security settings; disconnecting revokes the stored token.
Short Studio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, the channel details and access token we receive from Google are used only to upload the videos you ask us to publish. They are never used for advertising and are never sold. They are not read by our staff except where necessary to investigate abuse or where required by law, and they are processed only by the infrastructure providers listed in section 7, which operate the Service on our behalf.
6. Data Retention
- Generated video files: retained for approximately 30 days, then permanently deleted
- Uploaded files (music, voice references): retained for the duration of the associated job plus a short buffer, then deleted
- Account data, job metadata, payment records, audit logs: retained indefinitely for legal, support, and dispute resolution purposes
- ToS acceptance records: retained indefinitely as legal records of consent
- YouTube connection data: retained while the channel is connected. When you disconnect, we revoke the token with Google and erase the stored token immediately; the connection record is kept as an audit record with no credential in it
- Account deletion: you can delete your account at any time from Settings. We delete your login, remove your generated videos and uploaded files, revoke and erase any connected YouTube token, and delete your personal data (including your email, name, and country) from your account record. We may retain certain information where required or permitted for legal, tax, dispute-resolution, and fraud-prevention purposes, such as transaction and payment records, records of consent, and security and audit logs
7. Data Sharing
We do not sell your personal data. We share data only with:
- Stripe: for payment processing. Subject to Stripe's Privacy Policy.
- Cloudflare: for application hosting, video file storage, and automated screening of submitted topics and style descriptions. Subject to Cloudflare's Privacy Policy.
- Supabase: for database and file storage hosting. Subject to Supabase's Privacy Policy.
- Google / YouTube: when you use YouTube publishing, video files and metadata you choose to publish are transmitted to YouTube. Subject to the Google Privacy Policy.
- Law enforcement or legal authorities: when required by applicable law or valid legal process.
8. Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), row-level access controls, and server-side-only handling of sensitive keys. OAuth tokens for connected YouTube channels are encrypted at rest with AES-256-GCM; the encryption key is held server-side and is never exposed to the browser. No system is completely secure; you use the Service at your own risk.
9. Cookies and Local Storage
We store a small amount of information on your device, using your browser's local and session storage rather than tracking cookies. This is limited to what the Service needs to function: an authentication session that keeps you signed in, and short-lived flow state such as remembering that you returned from connecting a YouTube channel. We do not use third-party advertising or tracking cookies, and we do not build advertising profiles. On the landing page, the embedded YouTube preview player loads only after you click to play and uses YouTube's privacy-enhanced (no-cookie) mode, so YouTube does not set cookies on your device until you choose to watch.
10. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, or delete your personal data. To make a request, contact us at support@shortstudio.io. We will respond within a reasonable timeframe. You can also delete your account yourself at any time from Settings (see Data Retention above).
11. Children
The Service is not directed at children under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. Material changes will increment the version number and update the effective date. Continued use of the Service after a version change constitutes acceptance of the updated policy.
13. Contact
For privacy questions, data requests, or abuse reports: support@shortstudio.io