Legal

Privacy Policy

This policy explains what data FlowForge collects, why we collect it, and how we protect it while you use our AI-powered YouTube automation platform.

Last updated: July 7, 2026

1. Overview

FlowForge ("we", "us") provides a platform that turns a prompt into a finished YouTube video — generating scripts, voice-over, visuals, and Shorts with AI, and publishing them to your connected YouTube channels. This policy covers the data involved in delivering that service.

By creating an account or using the service, you agree to the practices described here.

2. Information we collect

Account information

  • Your name and email address when you register with email or Google Sign-In.
  • A securely hashed password (we never store plaintext passwords). Google SSO accounts use an unusable password hash.

YouTube connection data

  • OAuth access and refresh tokens for the YouTube channels you connect. These are encrypted at rest and never stored or logged in plaintext.
  • Channel metadata such as channel ID, handle, and thumbnail used to display your connected accounts.

Content and generation data

  • The ideas, prompts, language, and settings you submit to generate videos.
  • AI-generated outputs: scripts, SEO metadata, thumbnails, rendered videos, and Shorts.
  • Publishing details such as scheduled times, video IDs, and upload status.

Technical data

  • Request logs including a request ID, method, path, status, and duration for reliability and security.
  • Standard device and browser information sent with each request.

3. How we use your information

  • To operate the generation pipeline — writing scripts, creating voice and video, cutting Shorts, and publishing to YouTube on your behalf.
  • To authenticate you and keep your session secure.
  • To display your projects, queue, uploads, and analytics.
  • To maintain, debug, and improve the service.
  • To communicate service updates, security notices, and support responses.

We do not sell your personal data, and we do not use the content of your prompts or videos to train our own models.

4. Third-party services

We rely on trusted providers to deliver core functionality:

  • Google / YouTube — for sign-in (SSO) and for publishing and managing videos on your connected channels, subject to Google's API Services User Data Policy.
  • OpenAI — to generate scripts, images/thumbnails, and video (Sora-2). Prompts required to fulfill your request are sent to these APIs.
  • Infrastructure and database providers used to host the application and store your data.

Each provider processes data only as needed to perform its function.

5. Data security

  • YouTube OAuth tokens are encrypted at rest using Fernet symmetric encryption.
  • Passwords are hashed with bcrypt; refresh tokens are stored only as SHA-256 hashes and rotate on every use.
  • Access tokens are short-lived (15 minutes) and transmitted over HTTPS only.
  • Security headers, rate limiting, and strict CORS are enforced across the API.

No method of transmission or storage is perfectly secure, but we apply industry-standard, defense-in-depth safeguards.

6. Your rights and choices

  • Access, correct, or delete your account data at any time.
  • Disconnect a YouTube channel, which revokes and removes its stored tokens.
  • Request export or deletion of your personal data by contacting us.
  • Revoke FlowForge's access from your Google Account security settings at any time.

7. Data retention

We retain your data for as long as your account is active. Deletion and retention specifics are described in our Data Retention Policy.

8. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated, and the “Last updated” date above will always reflect the current version.


Questions about this policy? Contact us at legal@flowforge.in or via our contact page.