Privacy Policy

Last updated: August 27, 2026

Editorial Transform ("we", "our", "the Service") is a B2B publishing tool operated by Michael Krivda as an individual sole operator (referenced as "we" / "our" throughout this document as a legal convention only). This Privacy Policy explains what data we collect from our partner publishers, how we use it, and how we protect it.

The Service is not offered to individual end-users. We work exclusively with verified news publishers who authorize our platform to publish content on their own YouTube channels.

1. Information we collect

From the partner publisher, when they onboard Editorial Transform:

From end-users viewing publisher content via our embedded widget on publisher websites, we collect only what is necessary to operate the widget:

We do not collect names, emails, IP addresses beyond what is required for request routing, or any other personal identifiers from widget viewers. The widget does not integrate with third-party analytics or advertising trackers.

2. How we use OAuth data

Access granted through OAuth 2.0 is used solely for the following actions on the granting publisher's own YouTube channel:

We do not:

3. Google API Services User Data Policy

Editorial Transform's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Third-party services and data sharing

We do not sell, rent, or share personal information or OAuth credentials with third parties. The following third-party services are used strictly as infrastructure providers — each receives only the minimum data required to perform its function, and none receives OAuth credentials or channel identifiers:

Service Purpose What is sent
Anthropic (Claude API) Text summarization of publisher's own articles into short-form video scripts Article title and body text (publisher's own editorial content). No personal, publisher-account, or OAuth data.
ElevenLabs Ukrainian voice-over synthesis from the approved script The approved script text only. No personal, publisher-account, or OAuth data.
Google (YouTube Data API v3) Uploading approved videos to the publisher's own YouTube channel Publisher's OAuth access token (never their refresh token), the video file, title, description, tags, and thumbnail. All data flows into the publisher's own channel.
Hetzner Cloud (Germany, EU) Application hosting, PostgreSQL database, S3-compatible object storage for generated video files All data at rest. Encrypted OAuth refresh tokens stored here.
Unsplash, Pexels Optional stock imagery/video licensed for commercial use, used only when a publisher's own article does not include sufficient imagery Search keyword only. No publisher, viewer, or OAuth data.
IPRoyal (residential proxy) Proxying image download requests from publisher article URLs to bypass geo-restrictions on the publisher's own CDN Article URLs of the publisher's own site. No personal, publisher-account, or OAuth data.

5. Data retention

Data category Retention period
OAuth refresh tokens Until the publisher revokes access via Google Account, or the partnership formally ends. Deleted within 7 days of either event.
Generated video files (final MP4) Configurable per publisher. Default 14 days for horizontal video, indefinite for vertical Shorts unless publisher requests otherwise.
Source article text (input to AI summarization) Retained in application database indefinitely as part of the reel record (for editorial history and audit). Publisher may request deletion at any time.
Publisher OAuth audit logs (upload attempts, success/failure) 90 days. Sufficient for troubleshooting and compliance review; anonymized statistics may be retained longer.
Widget viewer analytics (aggregated) 13 months, then aggregated to monthly totals for historical reporting.
Anonymous widget session cookie 12 months from last activity, then automatically expired.

6. Publisher rights

Every partner publisher may at any time:

7. Security

OAuth refresh tokens are stored using Fernet (AES-128-CBC) symmetric encryption at rest. All API communication uses TLS 1.2+. Database access is restricted to the application server; no external network access is permitted to the database. Infrastructure runs on EU-based Hetzner Cloud (Germany) with data residency in the European Union.

8. GDPR compliance

Because our infrastructure is located in the European Union and we serve publishers whose audiences may include EU residents, we align our practices with the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"):

9. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be communicated to partner publishers via email with at least 30 days' notice.

10. Contact and legal notices

For questions about this policy, data requests, or security concerns:
michael.krivda@gmail.com