Skip to content
StorySpool
HomeSign in

On this page

InformationYouTube accessService providersBrowser and storageRetention and deletionContact

StorySpool / Private beta

Privacy policy

Updated September 24, 2026 · Version beta-2026-09-24

This policy describes information processed by StorySpool at storyspool.app and in its connected video-creation service. StorySpool is an independent service, not a Google or YouTube product. For privacy questions, contact josh.c.aguirre@gmail.com or use our support form.

Information we process

  • Account information: your name, email address, password hash, sign-in sessions, email verification and recovery records, invitations, and recorded policy acceptance. We do not store your StorySpool password as plain text.
  • Creation information: submitted URLs and extracted article content, campaign settings, prompts, scripts, narration, captions, selected footage, generated videos, and creation or publishing status.
  • Operations and support: usage and credit records, provider costs, job failures, activity history, support messages, and security events such as sign-in attempts. Security events can include IP addresses, user-agent information, request paths and timestamps.

We use this information to operate your workspace, create and deliver requested videos, manage authorized uploads, prevent misuse, resolve problems, and send account or service notifications. Public article access does not mean the content is free of copyright or other rights.

Google and YouTube access

StorySpool uses YouTube API Services. When you connect a channel, Google asks you to authorize access. StorySpool receives authorization tokens and channel information, not your Google password. It does not request access to your Gmail messages, contacts, or Google Drive files.

  • Channel identity: we use your channel ID and display name to associate the correct channel with your account and campaigns. While connected, channel identifiers also help detect repeat trial use.
  • Uploads: we send the completed video, title, description, relevant metadata and your authorized visibility to YouTube. We retain the upload result and video identifier/link to show status and avoid duplicate submissions.
  • Performance: with analytics permission, we request reports such as views, watch time, likes and subscribers gained. These reports are requested for the dashboard rather than stored as a separate permanent analytics database.
  • Authorization: encrypted access and refresh tokens allow the service to perform the actions you approve. A manual render is not approval to publish. Time-limited founder automation requires separate approval of the run and its uploads.

Google user data is used for these user-facing functions, not sold, used for advertising profiles, or used to train generalized AI models. We do not send YouTube authorization tokens or dashboard analytics to our content-generation providers. StorySpool's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Google handles its services under the Google Privacy Policy. You can revoke StorySpool's access through Google Account permissions.

Service providers and sharing

We share the information needed to perform the operations you request with these providers:

  • Google Cloud: application hosting, databases, private media storage and operational logging. Where AI video is enabled for a test account, visual prompts are sent to Google's video-generation service.
  • OpenAI: article content, script instructions, scripts, narration text/audio and visual analysis inputs as needed for drafting, safety checks, voice generation, caption timing and selecting relevant visuals.
  • Pexels: topic-based search queries and requests to retrieve stock footage. Footage may be reviewed with an AI provider for relevance.
  • Resend: recipient email addresses and message content for account verification, recovery and service notifications.
  • YouTube: authorized uploads and channel or analytics requests described above. Upload visibility determines who can view the video on YouTube.

Fetching an article also makes a request from our service to the source website. Do not submit URLs containing private access tokens, confidential material, or sensitive personal information. Providers may process data outside your country. We do not sell personal information or serve behavioral advertising. Authorized operators may access records when needed for support, security, or service operation. Information may also be disclosed when required by law or to protect users and the service.

Browser storage and safeguards

The application uses browser local storage for its sign-in session and workspace preferences. Signing out clears the app's active session. We do not embed advertising trackers in these public pages. Following an external link takes you to a service with its own privacy practices.

Hosted connections use HTTPS, stored Google authorization tokens are encrypted, and generated media is kept in private storage with authenticated or time-limited access. Anyone who receives a valid time-limited preview link may be able to use it until it expires; do not share it with unintended recipients. These safeguards reduce risk but cannot guarantee absolute security.

Retention, disconnection and deletion

Account and creation records are retained to provide your workspace and support the operations described here. The current private beta does not promise automatic deletion of all records or videos after a fixed number of days. Media cleanup is a separate operational process; canceling a post or archiving a campaign is not an account-deletion request.

Disconnect YouTube: in Accounts, use Disconnect YouTube and confirm your password. A completed disconnect removes saved YouTube tokens, channel identifiers, trial-link associations and saved YouTube post links, and pauses related automation. An upload with an unresolved result must be checked before disconnection can complete. You can revoke permission directly in your Google Account at any time. Disconnecting does not erase your StorySpool account, campaigns or generated media, or delete videos already on YouTube.

Request deletion: sign in and use Accounts → Request account deletion, or contact josh.c.aguirre@gmail.com if you cannot access the account. You may also request correction or access to your information. We verify identity and handle deletion requests manually. A submitted account-deletion request pauses new automation and cancels queued work; work already in progress may finish.

Deletion requires checking the application database and stored media, not simply marking a support ticket resolved. Limited records may need to be retained to address security incidents, disputes or legal obligations. Backups can retain earlier copies until their configured expiration. Contact support for the status and scope of your request. Manage or delete published YouTube videos in YouTube itself.

Contact and updates

Send privacy questions or complaints to josh.c.aguirre@gmail.com or the StorySpool support form. Do not send passwords, API keys, or payment card details.

We will update this page when our practices change and identify the revision date above. Material changes will be communicated through the application or account email where appropriate.

StorySpool

HomeTermsContactSign in