Privacy, Security & Credential Protection

Privacy Policy

Last Updated: August 17, 2026

1. Overview & Our Commitment

FacelessShorts ("we", "our", or "us") operates https://facelessshorts.app and provides an automated AI short-form video generation and multi-channel social publishing platform.

We respect your privacy, your digital identity, and your account safety. This Privacy Policy details our data collection policies, our strict credential protections, and our full compliance with Google, YouTube, TikTok, and Meta API Developer Policies.

Zero Credential Abuse Guarantee

How We Safeguard Your Social Accounts & Private Credentials

Your trust is our highest priority. We operate under strict principles of data minimization and zero-trust security:

We NEVER Store or See Your Passwords

We never request, see, or store your Google, YouTube, TikTok, or Instagram account passwords. Connection is handled exclusively through official OAuth 2.0 token delegation.

We NEVER Post Unauthorized Content

We will never post unauthorized videos, spam comments, likes, or change your channel configuration. The system only uploads the exact videos you schedule or manually publish.

We NEVER Read Private Emails or Personal Data

We never access your private emails, personal messages, YouTube watch history, search history, playlists, or personal financial details.

We NEVER Sell, Rent, or Share Your Data

Your account information, generated video files, and channel tokens are never sold, rented, or transferred to third-party data brokers or advertising networks.

We NEVER Use Your Content to Train Public AI Models

Your private script prompts, custom voiceovers, and generated videos remain 100% your property and are never used to train public machine learning models.

AES-256 Military-Grade Token Encryption

All third-party OAuth tokens are encrypted at rest using AES-256-GCM symmetric encryption. You can unlink and revoke access with a single click at any time.

3. Google API Services & YouTube API User Data Policy Compliance

FacelessShorts uses YouTube API Services to allow you to upload and publish your generated video content to your authorized YouTube channel.

"FacelessShorts' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."

What Google & YouTube Data We Access:

  • Basic Profile & Channel ID: Channel title, handle, and avatar to identify your channel in your dashboard.
  • Video Upload Permissions (youtube.upload): Used solely to upload video reels generated or approved by you.
  • Read-only Channel Metadata (youtube.readonly): Used strictly to verify channel identity during initial connection.

How to Revoke Access:

You can disconnect your YouTube channel at any time in your Connected Channels page, or revoke permissions globally via the Google Security Settings Page .

By using our YouTube integration, you also acknowledge and agree to be bound by the YouTube Terms of Service and the Google Privacy Policy.

4. Information We Collect

  • Account Credentials: Email address and authentication identifiers when you register via Supabase Auth.
  • Video Prompts & Configuration: Custom instructions, topic selections, voice selections, and subtitle preferences chosen for your video series.
  • Generated Media Assets: Generated scripts, audio narrations, images, and final rendered video MP4 files stored in secure Supabase Cloud Storage.
  • Encrypted Social OAuth Tokens: All OAuth tokens (YouTube, TikTok, Instagram) are encrypted at rest using industry-standard AES-256-GCM encryption.
  • Payment Data: Subscription orders are processed securely via Paddle. We never store or process raw credit card numbers on our servers.

5. Security & Encryption Standards

We implement enterprise-grade security measures to safeguard your account:

  • AES-256-GCM Encryption: All third-party OAuth tokens and secrets are stored in encrypted form using symmetric key cryptography.
  • Row Level Security (RLS): All database queries are isolated per user ID using PostgreSQL RLS policies in Supabase.
  • HTTPS/TLS 1.3: All communications between your browser and our servers are encrypted via HTTPS with modern TLS certificates.

6. Data Retention & Right to Erasure (GDPR / CCPA)

You retain complete ownership over your account data. You may request permanent deletion of your account and all associated video files, tokens, and records at any time:

  • Delete individual video series or connected accounts instantly from your dashboard.
  • Request full account termination and data erasure by emailing support@facelessshorts.app. All data will be permanently deleted within 30 days.

7. Contact Our Privacy Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

FacelessShorts Privacy & Compliance Team

support@facelessshorts.app