Privacy policy
Auto Content — last updated 5 September 2026
Auto Content is a self-hosted internal tool. It is installed and operated by a single team on infrastructure that team controls. It has no public sign-up, no shared backend, and no operator other than the team running it. This policy describes what the software does with data when that team uses it.
Who the "operator" is
The operator is the team that installs and runs its own copy of Auto Content. The operator controls the server, the database and the connected accounts. Questions about a particular installation go to the operator of that installation, reachable at huonglong5388@gmail.com.
What the tool accesses, and why
| Data | Why |
|---|---|
Google account identifier (OpenID sub), email address and display name |
To recognise which Google account is connected, to show it in the interface, and to keep a single stored credential per Google account instead of duplicating it. |
| Google Drive file metadata: file identifiers, names, sizes, checksums and modification times, limited to the folder the operator selects | To list the operator's own videos, detect new or changed files, and identify duplicates without downloading the same content twice. |
| Google Drive file content, downloaded temporarily | Only when technical details cannot be read from metadata. The file is written to a temporary directory, inspected for duration, dimensions and audio, used to generate a thumbnail, and then deleted. |
| OAuth access and refresh tokens | To keep the connection working without asking the operator to sign in repeatedly. |
Drive access is requested as read-only. Auto Content does not create, modify, move or delete anything in Google Drive.
Where the data is kept
- All data stays in a database file on the operator's own server. There is no shared cloud service and no data is sent to the authors of the software.
- Access and refresh tokens are encrypted at rest with AES-256-GCM. The encryption key is held on the operator's machine and is never stored in the database alongside the data it protects.
- Temporary downloads are removed as soon as processing finishes, and any file left behind by an interrupted run is deleted automatically.
- Tokens, encryption material and authorisation values are never written to logs, API responses or audit records.
What is not done with the data
- It is not sold, rented or shared with third parties.
- It is not used for advertising, profiling or training machine-learning models.
- It is not transferred to anyone outside the operator's team.
How long it is kept
Data is kept until the operator deletes it or disconnects the account. Disconnecting an account removes its stored credentials. Expired authorisation records and orphaned temporary files are cleaned up automatically.
Withdrawing access
Access can be revoked at any time from Google Account permissions, which immediately stops the tool from reading any further data. The same can be done inside the tool by disconnecting the account.
YouTube API Services
When YouTube publishing is enabled, Auto Content uses YouTube API Services to upload videos to channels the operator owns and to manage those uploads. Use of those features is additionally governed by the YouTube Terms of Service, and data handled by Google is covered by the Google Privacy Policy. YouTube data obtained through the API is used only to publish and manage the operator's own content, is not shown to anyone outside the operator's team, and is removed when the account is disconnected.
Other platforms
Where Facebook Pages or TikTok accounts are connected, the same principles apply: access is granted through each platform's official OAuth flow, tokens are encrypted at rest, no platform password is ever stored, and the tool acts only on accounts the operator already manages.
Children
Auto Content is a workplace tool. It is not directed at children and is not intended for use by anyone under 16.
Changes
If this policy changes, the date at the top of this page changes with it.