Privacy Policy
What Nightshift collects, what it does with your Google and YouTube data, who processes it, how long it is kept, and how to remove it.
- Operator
- NOT CONFIGURED · NEXT_PUBLIC_LEGAL_NAME
- Country
- NOT CONFIGURED · NEXT_PUBLIC_LEGAL_COUNTRY
- Contact
- NOT CONFIGURED · NEXT_PUBLIC_CONTACT_EMAIL
- Effective date
- NOT CONFIGURED · NEXT_PUBLIC_LEGAL_EFFECTIVE_DATE
1. Who we are
Nightshift (the “Service”) is an automated video production tool: a web dashboard on this domain and a pipeline that researches, writes, narrates, renders and uploads videos to YouTube channels its users connect. The Service is operated by NOT CONFIGURED · NEXT_PUBLIC_LEGAL_NAME (“we”, “us”), NOT CONFIGURED · NEXT_PUBLIC_LEGAL_COUNTRY. Contact: NOT CONFIGURED · NEXT_PUBLIC_CONTACT_EMAIL.
This policy explains what information the Service collects, how it is used and shared, and the choices you have. It applies to this website and to the automated pipeline that acts on your behalf.
2. Information we collect
- Account information: your email address and a password, handled by our authentication provider (Supabase Auth). We never see or store your password in readable form.
- Configuration you enter: channel names, niche, language, voice and style choices, schedules, series, team membership and roles, and your review decisions (for example, approving a video), which are recorded with your user id as an audit trail.
- API keys you enter for third-party services: they are encrypted in our server the moment they arrive, written to our pipeline's encrypted secret store (GitHub Actions secrets), and discarded. They are never saved in our database, shown back to you, or logged.
- Google user data you authorise us to access, described in section 3.
- Technical data: our hosting and database providers record standard request logs (such as IP address, browser type and time of request) to operate and secure the Service. We do not use analytics, advertising or tracking tools.
3. Google user data we access
When you connect a YouTube channel, you are sent to Google’s own consent screen, where you choose the Google account and see exactly what is requested. We request the following OAuth scopes and use each one only for the purposes listed:
| Scope | What Nightshift does with it |
|---|---|
youtube.upload | Uploads the videos Nightshift produced for your channel, and sets their thumbnail. Uploads are private unless you choose otherwise for that channel — for example, by turning on auto-publish, which is off by default. |
youtube.readonly | Reads your channel’s identity (channel id and title) to confirm which channel you connected, lists your channel’s recent uploads (ids and titles) so the same video is never uploaded twice, and reads basic details and public statistics of your videos for your dashboard. |
youtube.force-ssl | Adds a caption track to videos Nightshift uploaded; adds a published video to your series playlist; posts one comment from your channel (a question to viewers) under a video Nightshift published; and reads the comments on your channel’s videos to find topics your audience asks for. This scope also technically permits editing and deleting videos — Nightshift never deletes anything and never edits your existing videos, playlists or comments; it only adds the items listed here. |
yt-analytics.readonly | Reads YouTube Analytics reports for your channel’s videos: views, watch time, average view duration and percentage, likes, comments, shares, subscribers gained and lost, impressions, click-through rate and audience retention. These figures are shown in your dashboard and used to choose better topics for future videos. |
yt-analytics-monetary.readonly (optional) | Requested only if the operator explicitly turns on revenue tracking. Reads your videos’ estimated revenue for the dashboard. It is not requested otherwise. |
We do not request access to your Gmail, Google Drive, contacts or any other Google service, and we do not read your YouTube watch history, subscriptions or private messages.
4. How we use Google user data
Google user data is used only to provide and improve the user-facing features you see in the Service: uploading and captioning your videos, adding them to your playlists, posting the engagement comment, preventing duplicate uploads, showing your channel’s performance in your dashboard, and choosing future topics from what performed well and what your audience asked for.
To produce those insights, the text of comments on your videos and your videos’ performance figures may be sent to our AI text provider (Google’s Gemini API) to be classified and summarised for your channel. We store the result — for example, a topic your audience requested and how often — not the comment text itself.
5. Limited Use
Nightshift’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Google user data only to provide or improve the user-facing features described above;
- we transfer it to others only as necessary to provide those features (the processors in section 7), to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you;
- we do not use or transfer it to serve advertisements, including personalised or retargeted ads;
- we do not sell it, and we do not use it to determine creditworthiness or for lending purposes;
- we do not allow humans to read it unless you give us affirmative consent for specific data, it is necessary for security purposes (such as investigating abuse), it is needed to comply with applicable law, or it has been aggregated and anonymised for internal operations;
- we do not use it to develop, improve or train generalised artificial intelligence or machine-learning models.
6. How your Google access is stored
After you consent, Google returns an access token and a refresh token to our server. Where they are kept depends on whose channel it is:
- Channels operated by us (our own organization): the token is immediately encrypted (sealed to our pipeline repository’s public key) and stored as an encrypted GitHub Actions secret, which only the pipeline can read when it runs.
- Channels that your organization connects: only the refresh token is kept, encrypted at rest in Supabase Vault. The dashboard can store or delete it but can never read it back — not for you, and not for anyone in your organization; only our pipeline reads it, with a server-only key, while a run for that channel is in progress, and it is held in memory or in a file readable only by the pipeline that is deleted when the run ends. When you disconnect the channel, the stored token is destroyed.
In both cases tokens are never sent to your browser and never written to a log. What the dashboard shows is only non-secret connection information: which YouTube channel is connected, when and by whom, and which permissions were granted. Our OAuth client credentials are kept in server-only configuration.
During the connection a short-lived, http-only cookie (10 minutes) protects the flow against cross-site request forgery.
7. Service providers
We use the following providers to run the Service. Each receives only what it needs for its task.
| Provider | Purpose | Data it receives |
|---|---|---|
| Supabase | Database, sign-in and file storage | Account data, configuration, video records (YouTube video id, title, privacy), performance figures, review copies of videos; for channels your organization connects, the encrypted Google refresh token (Supabase Vault) |
| Vercel | Hosting of this website (EU region) | Web requests and request logs |
| GitHub (Actions) | Runs the video pipeline; encrypted secret store | Encrypted Google tokens and API keys; pipeline logs and output files |
| Google — YouTube Data and Analytics APIs | Acting on your channel as described in section 3 | Your videos, captions, thumbnails and the requests described above |
| Google — Gemini API | Research, script writing, fact-checking, and analysis of comments and performance figures | Topics, scripts, comment text and performance figures of your videos |
| ElevenLabs; Microsoft Edge text-to-speech | Narration (voice), whichever the channel is set to | Script text |
| Pexels, Pixabay | Stock footage and photos | Search terms derived from the script |
| Optional media generators, only if the operator enables them: Google Veo, Leonardo.Ai, Higgsfield, Kling, MiniMax, Seedance (ByteDance), Wan (Alibaba Cloud) | Generated images and video clips | Prompts derived from the script |
| vidIQ (optional) | Keyword and title research | Topic keywords and draft titles |
| Telegram, Slack (optional) | Notifications to the operator | Run status, video titles and links |
| Google Fonts, Amazon CloudFront | Fonts and background media on these web pages | Your IP address and browser details, as with any web request |
| Paddle (Paddle.com) | Our online reseller and Merchant of Record for credit purchases: checkout, payment processing, tax, receipts and refunds | The payment and billing details you enter in Paddle’s checkout, which Paddle handles itself; from us, your account email address (to fill in the checkout) and the ids of your organisation and user account |
Only Supabase, GitHub, Google and the notification services in this list receive Google user data, and only for the purposes above. We do not sell personal information to anyone.
Payments. Credits are sold through Paddle, our online reseller and Merchant of Record: when you buy credits, you enter your payment and billing details in Paddle’s own checkout, and Paddle processes them as the seller under the Paddle Privacy Notice. We never receive or store your card details or billing address. Paddle sends us only what we need to credit a purchase and to reverse it on a refund: the transaction and refund ids, the amount and currency paid, the credits bought, and the organisation (and, where known, the user) the purchase is for. We keep these records with your organisation’s credit history for as long as its account exists, or longer where tax or accounting law requires it.
8. Retention and deletion
- Google tokens are kept while your channel is connected. They stop working the moment you revoke access, and we delete them when you disconnect the channel or ask us to.
- Review copies of videos in our storage are limited to the five most recent per channel; older copies are deleted automatically.
- Pipeline output (the rendered video, thumbnails and run log) is kept by GitHub Actions for 7 days and then deleted automatically.
- Account data, configuration, video records and performance figures are kept while your account is active, and deleted within 30 days of a verified deletion request.
- Audit records of approvals and other decisions are kept as long as the account exists, because they are the record of who authorised an action on a channel.
You can revoke Nightshift’s access to your Google account at any time at https://myaccount.google.com/permissions. To delete your account and the data we hold, email NOT CONFIGURED · NEXT_PUBLIC_CONTACT_EMAIL.
10. Security
Traffic is encrypted in transit (HTTPS). Database access is restricted per user by row-level security, the website uses only a restricted public key, and secrets are encrypted before they are stored. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
11. Your choices and rights
You can disconnect a channel, revoke Google access, and ask us to access, correct, export or delete your personal data by emailing NOT CONFIGURED · NEXT_PUBLIC_CONTACT_EMAIL. Depending on where you live, you may have further rights under local law, including the right to complain to a data-protection authority.
12. International transfers
Our providers operate in the European Union, the United States and other countries, so your data may be processed outside your country. Where the law requires it, we rely on the providers’ standard contractual safeguards.
13. Children
The Service is not directed to children and may not be used by anyone under 13, or by anyone below the minimum age YouTube requires to manage a channel in their country.
14. YouTube and Google
Nightshift uses YouTube API Services. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service. Google’s handling of your data is governed by the Google Privacy Policy.
15. Changes to this policy
We will post any change on this page and update the effective date (NOT CONFIGURED · NEXT_PUBLIC_LEGAL_EFFECTIVE_DATE). If a change materially affects how we use Google user data, we will tell you in the Service and ask for your consent again where required.
16. Contact
NOT CONFIGURED · NEXT_PUBLIC_LEGAL_NAME, NOT CONFIGURED · NEXT_PUBLIC_LEGAL_COUNTRY. Email: NOT CONFIGURED · NEXT_PUBLIC_CONTACT_EMAIL.