How CF handles information

Privacy policy

Effective date
2026-09-29
Policy version
2026-09-29-1
Operator
Idi0tDev
Contact and deletion requests
Idi0tDev42@gmail.com
App information page
https://cf-info-68e4d2a1.pages.dev/

CF — Content Factory ("CF") is a Windows desktop app privately used by its sole owner and operator. It keeps its creative workspace on that owner's computer and Data drive. Optional features use YouTube API Services when the owner connects a channel, requests Analytics, searches public videos after configuring an API key, or approves an upload. Google explains its own handling of information in the Google Privacy Policy. This information site has no CF account or login.

CF's source has a versioned privacy-policy gate: after the public policy address and version are configured in the app, the owner must agree to that version before opening the workspace, and a changed address or version calls for renewed agreement. The complete gate and connected-account behavior have not yet been checked with a live Google grant.

Information CF uses

Use, sharing, and local copies

CF uses local and YouTube information to organize the workspace, verify the chosen channel, avoid duplicate uploads, resume interrupted transfers, and display requested results. Google and YouTube receive the OAuth and API requests needed for those actions over HTTPS; the one-time OAuth return uses a loopback address on the owner's computer. CF does not use YouTube API data for advertising. Cloudflare Pages delivers this static information site, so page requests pass through Cloudflare; see Cloudflare's Privacy Policy. The site contains no CF sign-in or data-entry form.

Optional model-assisted actions can send the owner's request and relevant workspace details to Codex or an OpenAI API provider under those services' terms and privacy policies. Depending on the action, those details may include channel settings and feedback, ideas and project titles, completed upload titles, approved sound names, Blender scene and story labels, reviewed export facts, timeline text, transcripts, or scene markers. The reviewed text prompt builders are designed not to automatically include OAuth credentials, Analytics snapshots, or YouTube video IDs; text entered by the owner may contain details they choose to include. A video file is not sent for a text request. CF also supports loopback-only Ollama addresses. A separate Ollama vision action sends one still frame to that local endpoint, which another local service or proxy could forward. These model routes have not yet been confirmed end to end with a live connected account.

The active workspace, encrypted credential vault, and Studio browser profiles are local. CF's default backup script makes a sanitized project and media copy that excludes copied browser sessions and vault data and removes YouTube API account data and manually confirmed Studio identities from copied Studio records. Its optional full-copy mode can include encrypted credentials and signed-in browser state. Older full backups and cleanup recovery bundles may also contain account data. New archived-media recovery proofs copy the reviewed media and paths, which can themselves contain personal details; CF does not automatically remove those proofs. Neither an in-app deletion control nor a new sanitized backup changes earlier independent copies. CF does not operate a cloud backup service for the Data folder.

The operator has selectively cleared browser state from known older copies. That scoped cleanup did not clear the active Studio browser profile, saved Studio records, or any unknown copies. Each retained copy still needs separate review when a deletion request applies to it.

Retention and account controls

In Settings, Revoke access and delete API data asks Google to revoke the saved upload and Analytics grants and removes their API account data from CF's active workspace, current recovery snapshot, and credential vault. It also removes the discovery API key and saved upload-session links and cancels pending API uploads. Delete local API data only removes the same CF data without asking Google to revoke access; use that after separately revoking CF in the Google Account. An active upload must be finished or canceled first. These controls leave local creative work, YouTube-hosted videos, the separate Studio browser session, and independent backups in place. If deletion reports an error or is interrupted, the result requires review. After uncertain Google revocation, CF keeps a reminder and pauses API actions until the owner checks Google's security permissions page and revokes CF there if it remains listed. Recording that check clears the reminder but does not prove revocation.

Clear selected Studio sign-in in Settings shows the CF channels linked to one browser profile, removes their saved manual confirmations, and attempts to clear that profile's cookies, site storage, cache, and HTTP authentication cache. It does not revoke API grants or clear other profiles. Archiving a channel does not clear its profile. If clearing reports an error, treat that profile as potentially signed in. Whether a successful clear forces a fresh Google sign-in has not yet been tested with a live session.

CF schedules local age-based cleanup at startup and every six hours while running. Public discovery candidates and Analytics snapshots have a 29-day age threshold. CF also checks saved API-upload video IDs and status against YouTube when eligible, removes missing or mismatched IDs, and removes details that cannot be refreshed by day 29. Completed or canceled uploads clear their resumable-session URLs; a queued or failed session can retain a URL for manual resume until 29 days after it began. The current recovery snapshot and completed migration journals in Data are included when safe to update. Interrupted recovery or file maintenance can delay a pass, and independent backups are outside it.

With a current policy agreement, CF schedules authorization and destination-channel checks after seven days while it can run; a grant that remains unverified at day 29 triggers scoped local cleanup and blocks new API actions. A confirmed invalid grant also starts local deletion. These are scheduled attempts, not a guarantee that the computer is available at an exact deadline. CF has an optional owner-run one-shot maintenance helper for the live Data folder while its window is closed, but no automatic Windows task has been installed. Neither the app nor that helper can work while the PC is off or the Data drive is unavailable.

How to request deletion

To request deletion, email Idi0tDev42@gmail.com and say whether the request covers YouTube API account data, the separate Studio browser session, specific local creative data, or the whole CF workspace. The operator monitors this address and will make the PC and Data drive available to handle a request. The operator will inspect the active Data folder and controlled backups or recovery proofs, remove the requested data from those copies, verify the result, and confirm completion as soon as possible and within seven calendar days of the request. After an in-app revocation, the operator will separately clear retained controlled copies of the associated YouTube Authorized Data within seven calendar days. If a copy cannot be safely edited, the operator will preserve needed creative recovery before removing it. CF's in-app controls do not automatically locate or clear independent copies, and copies outside the operator's control cannot be cleared by CF.

The owner may also revoke CF directly through Google's security permissions page. Under YouTube's developer policies, API data associated with a grant revoked there must be deleted within 30 calendar days. CF cannot detect that Google-side change while the PC or Data drive is unavailable. If revoking there while CF is closed, email the operator as well so local Data and controlled copies can be reviewed promptly. A later startup cannot make an already missed deadline timely.

Deleting data from CF does not delete a video or other data held by YouTube; manage that in YouTube Studio. An imported original left outside CF's Data folder also needs separate removal. The controls described here have local and synthetic checks, but a real Google grant, private API upload, complete deletion across controlled copies, and live Studio sign-out have not yet been exercised end to end. An error or unresolved copy must be handled before completion is claimed.

Changes and questions

If CF starts using YouTube data for a new purpose, the operator will update this policy and ask for renewed agreement before that use. Send privacy questions or deletion requests to Idi0tDev42@gmail.com.