Privacy Policy
Last updated: March 25, 2025
At ShortsFlow, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your information when you use the ShortsFlow desktop application and related services (the "Service").
By using ShortsFlow, you agree to the collection and use of information as described in this policy. We will not use or share your information except as described here.
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address: Used for account authentication, communication, and support
- Password: Securely hashed and stored (we never see your actual password)
- Profile information: Any optional profile details you choose to provide
OAuth Tokens
When you connect your YouTube account, we receive OAuth tokens that allow the app to access YouTube data on your behalf. These tokens:
- Are stored securely in our database
- Are used only to fetch YouTube data you've authorized
- Can be revoked at any time through your YouTube account settings
- Follow YouTube API Services Terms of Service
Usage Data
We collect anonymous usage data to improve the Service:
- Feature usage statistics (which features you use and how often)
- Error reports and crash logs
- App performance metrics
- Subscription and billing events
Content Data
When you use our AI features, we process:
- Script prompts and generated scripts (temporarily processed, not permanently stored on our servers)
- Voiceover text (sent to voice synthesis services)
- Research queries and competitor data you request
2. How We Use Your Information
We use the collected information to:
- Provide the Service: Authenticate your account, enable features, and deliver functionality
- Process payments: Manage subscriptions and billing through our payment provider
- Improve the Service: Analyze usage patterns to enhance features and fix bugs
- Communicate with you: Send important updates, respond to support requests, and notify you of changes
- Ensure security: Detect and prevent fraud, abuse, and security threats
3. Third-Party Services
ShortsFlow integrates with the following third-party services. Each has their own privacy policies that govern how they handle your data:
Supabase
We use Supabase for authentication and database storage. Your account data, OAuth tokens, and app data are stored securely in Supabase infrastructure.
LemonSqueezy
We use LemonSqueezy to process payments and manage subscriptions. They handle your payment information directly — we do not store your credit card details.
Anthropic (Claude AI)
We use Anthropic's Claude AI for script generation features. Your prompts and generated content are processed through their API. Anthropic may retain data as described in their privacy policy.
ElevenLabs
We use ElevenLabs for AI voiceover generation. Text you submit for voiceovers is sent to their service for processing.
YouTube API Services
ShortsFlow uses YouTube API Services. By using our Service, you are also bound by the YouTube Terms of Service and Google Privacy Policy.
4. Data Storage & Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using TLS/SSL
- Passwords are hashed using secure algorithms
- OAuth tokens are stored securely and encrypted at rest
- We use secure, reputable cloud infrastructure
- Access to user data is restricted to essential personnel only
While we take security seriously, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but strive to protect your information using commercially acceptable means.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained until you delete your account
- Usage data: Retained in anonymized form for analytics
- AI-generated content: Not permanently stored on our servers
- Payment records: Retained as required by law for accounting purposes
When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal obligations.
6. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a portable format
- Objection: Object to certain processing of your data
- Withdraw consent: Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at support@shortsflow.io.
7. Revoking YouTube Access
You can revoke ShortsFlow's access to your YouTube data at any time through the Google Security Settings page. Once revoked, we will no longer be able to access your YouTube data, and related features will be disabled.
8. Children's Privacy
ShortsFlow is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately and we will take steps to delete such information.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using the Service, you consent to the transfer of your information to these countries.
10. Cookies & Local Storage
As a desktop application, ShortsFlow uses local storage to save your preferences and session data. This data is stored locally on your device and is not transmitted to our servers unless necessary for the Service to function.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via email or through the application. The updated policy will be effective when posted, and your continued use of the Service constitutes acceptance of the changes.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Email: support@shortsflow.io
Company: ShortsFlow