Privacy policy
Last updated: 12 September 2026
This policy explains the current YTClip application and these public information pages. YTClip is operated by Ben, @BenjaminIannotta on YouTube, for personal video processing and publishing. It currently connects one authorised account and does not offer public account registration.
Information the application handles
- Google authorisation: the OAuth client details, a refresh token, temporary access tokens and the authorised destination channel ID. Google handles sign-in; YTClip does not receive the Google account password.
- YouTube data: video and channel identifiers, titles, source URLs, upload dates, duration, available view and subscriber counts, upload-playlist information and video processing or visibility status. Searches and account operations use YouTube API Services where configured.
- Source and generated content: imported or acquired video and audio, transcripts, word timestamps, proposed excerpts, generated titles and descriptions, captions, rendered clips and technical check results.
- Operating records: automation settings, job status, errors, timestamps, file hashes, upload-session information, publication records and activity history. These support retries, duplicate prevention and inspection.
- Access information: the private studio's session cookie and security records, including the client address used to limit repeated failed sign-ins. If the operator supplies a YouTube browser-session cookie file for source access, it is stored on the operator's system and used for those requests.
What the information is used for
YTClip uses this information to find sources matching the operator's filters, transcribe speech, select and caption excerpts, check output files, confirm control of the destination channel, upload videos and manage their visibility. Job and publication records help resume interrupted work and avoid duplicate posts.
The current application uses YouTube's youtube.force-ssl permission for authorised channel and video operations. Its upload flow starts with private visibility. Public posting requires the operator's publishing settings and the application's release checks. The studio's Unpublish action makes a video private; it does not delete it from YouTube.
Local AI processing
Source audio is processed by a speech transcription service on the operator's server. Transcript text and the relevant source settings are processed by a locally hosted Qwen language model to propose and assess clips. Results are cached on that server for reuse.
This processing is inference using existing models. YTClip does not use Google user data or source content to train, fine-tune or improve a general-purpose AI model. These processing steps do not send the content to an external AI provider.
Sharing and access
Google and YouTube receive the authorisation requests, search or account queries, uploaded video files and associated titles, descriptions and settings needed to provide their services. Material made public on YouTube is available to its viewers under the chosen visibility settings.
The operator controls the server and may inspect source content, transcripts, generated clips and logs to operate the application or resolve a problem. The server hosting provider supplies the computing and storage infrastructure. YTClip does not sell personal information, use it for advertising or share it with advertising networks.
Google and YouTube handle information under their own policies. Read the Google Privacy Policy, the YouTube Terms of Service and the Google API Services User Data Policy, including its Limited Use requirements.
Storage and retention
Application data and credential files are stored on the operator's system and self-hosted server. The private studio requires authentication. The current default cleanup settings are:
- Managed source media: eligible for removal after two days once no active job needs it. Queued, running or blocked work can keep a source longer. Files imported from outside the managed source directory are not deleted by this cleanup.
- Rendered videos: eligible for removal 14 days after their latest update once posted, unpublished, refused or expired. In-progress uploads and unresolved public verification can retain files longer.
- Derived audio: the application's extracted audio intermediate is removed after a complete transcript has been saved. The local transcription service can retain its own job data separately.
- Other records: transcripts, cached model responses, caption files, manifests, source metadata, job and publication history have no automatic deletion deadline in the current application. They remain until the operator removes them. Credentials remain until removed or replaced; Google can revoke or expire their authorisation.
Cleanup runs periodically while the scheduler is operating; these settings are not a guarantee of deletion at an exact time. Removing a local file does not remove an uploaded YouTube video. The operator must include any retained copies when handling a deletion request.
Revoke access or request deletion
- To stop future processing or uploads, the operator can pause the engine or disable the automation and its publishing setting.
- To revoke Google's authorisation, open Google's security permissions page or Google Account third-party connections, select YTClip and remove its access. See Google's connection-management guidance.
- To request removal of stored account information, media or processing records, contact Ben, the operator identified by @BenjaminIannotta. Identify the relevant account, channel or content without posting passwords, tokens or other private information publicly.
Revocation does not automatically erase existing YTClip data. The current application has no self-service account-deletion page or automatic deletion triggered by revocation. The operator handles removal of credentials and stored records directly. Published YouTube content must be removed or made private separately by the channel owner, including through YouTube Studio.
Public pages, cookies and links
These public information pages contain no analytics scripts, advertising trackers, embedded videos or forms. They do not set application cookies or use browser local storage. The web server records ordinary request details, including IP address, request time, requested page, response status and browser information, in operational access logs. Error logs record service problems. The operator uses these logs to maintain availability and security; they are managed under the server's log-rotation settings.
The separate private studio sets an essential sign-in cookie with a one-day lifetime. Following a link to Google or YouTube takes you to another service, which may collect information or set cookies under its own policy.
Questions and changes
For privacy questions or removal requests, contact Ben, @BenjaminIannotta on YouTube. This policy will be updated when the application's data practices change; the revision date appears above.