Scripiora legal
Privacy Policy
Effective
This Privacy Policy explains how Scripiora, operated by OneSimple ("OneSimple", "we", "us"), collects, uses, stores, shares, retains and deletes information when you use Scripiora, including information we access through YouTube API Services, and the choices you have.
At a glance
- Scripiora uses YouTube API Services. Google processes YouTube data under the Google Privacy Policy, and by using Scripiora you agree to the YouTube Terms of Service.
- We collect only what we need to run Scripiora: your account details, the content you create, payment status and limited technical logs.
- We do not sell personal information, we do not use it for advertising, and we do not use Google or YouTube data to train AI models.
- Connecting a YouTube channel is limited to the operator's own channel in Scripiora Studio, and access can be revoked at any time from Scripiora or from the Google Account security settings page.
- Your data is stored in our own self-hosted PostgreSQL database, and YouTube access tokens are encrypted with AES-256-GCM.
1. Who we are and what this policy covers
Scripiora is an AI video-script service operated by OneSimple (onesimple.ai). You can create an account with an email address and password or with Google Sign-In, generate and edit video scripts, research public YouTube videos, transcribe videos and buy credits. OneSimple is responsible for (the "controller" of) the personal information processed through Scripiora.
Scripiora uses YouTube API Services, which are provided by Google. When Scripiora accesses YouTube data, Google processes that data under the Google Privacy Policy. By using Scripiora you also agree to be bound by the YouTube Terms of Service.
This policy applies to the Scripiora website and application (the "Service"). It does not cover third-party websites or services we link to, such as YouTube, Google or Stripe, which have their own policies.
2. Information we collect
Information you give us
- Account details: your name, email address and password. Passwords are stored only as a salted one-way hash; we never store them in readable form.
- Profile details you choose to add, such as a profile photo or your YouTube handle.
- Content you create or submit: topics, prompts, outlines, ideas, scripts, folders, and the videos you ask us to research, transcribe or translate.
- Messages you send us, for example when you contact support.
Information from Google Sign-In
If you sign in with Google, Google shares your name, email address, whether that email address is verified, and your profile picture with us (the basic "openid", "email" and "profile" permissions). We use this only to create your account, sign you in and show your profile picture. Google Sign-In does not give Scripiora access to your YouTube channel, Gmail, Google Drive or any other Google data, and we never receive your Google password.
Payment information
Credit purchases are processed by Stripe. You enter your card details on Stripe's checkout page; we never receive or store your full card number. We keep a record of each order: the credit package, amount, currency, status, date and the Stripe identifiers needed to match the payment.
Usage and technical information
- Your credit balance and credit transactions, and records of the AI requests you make (the feature used, the AI model, the amount of text processed and the cost). We need these for billing, usage limits and abuse prevention.
- Server logs: IP address, browser user agent, requested address, response status and time of each request. We use them to keep the Service secure and working, and keep them for 30 days.
3. YouTube API Services and Google user data
Scripiora uses YouTube API Services to provide some of its features. This section explains which YouTube data we access, why, and how it is used, stored, shared and deleted. Please also review the YouTube Terms of Service and the Google Privacy Policy.
Public YouTube data (available to all users)
When you research a video, a channel or a topic, Scripiora uses the YouTube Data API with our own API key to retrieve public information: video titles, descriptions, thumbnails, channel names, publication dates, durations, public statistics such as view, like and comment counts, and publicly visible comments on the videos you choose to analyze. This does not involve any access to your YouTube account.
Transcripts are available only for videos on the channel owner's connected YouTube channel (see "Connected YouTube channel (Scripiora Studio)" below). Scripiora retrieves them through the official YouTube Data API captions endpoints, with the channel owner's authorization, and deletes stored transcripts after 30 days. Transcripts, public comments and video details are sent to our AI provider only to produce the transcript, translation, analysis or script you asked for.
Public YouTube data is shown to you in your research results. The YouTube data we store, including saved transcripts with their translations and edits, research and trend data, and YouTube video details and transcripts used as knowledge-vault sources, is deleted (or stripped of YouTube data) after 30 days. Video details you attach when generating a script are sent to our AI provider to write it and are not stored separately.
Connected YouTube channel (Scripiora Studio)
Scripiora Studio is a video-production workspace available only to the operator of Scripiora, to manage OneSimple's own YouTube channel. Studio access is limited to accounts on an allow-list that OneSimple controls. Other Scripiora users cannot connect a YouTube channel, and we never ask them for access to their YouTube accounts.
When the channel owner chooses to connect a YouTube channel, Google shows its consent screen and asks the owner to grant the permissions below. We request only the permissions that Studio features use:
- YouTube channel management
https://www.googleapis.com/auth/youtube.force-ssl - Read the channel's identity, branding and list of videos; upload videos produced in Studio as private, unlisted, public or scheduled uploads, as the channel owner chooses for each video; update video titles, descriptions, tags, privacy status and scheduled publishing times; set custom thumbnails; upload caption files; create and manage playlists; and update the channel description and branding.Read the comments posted on the channel's videos, post replies that the channel owner has approved, and apply moderation actions (such as holding a comment for review or rejecting it) when the channel owner chooses to. Every change is made only when the channel owner makes it in Studio.
- Channel analytics (read-only)
https://www.googleapis.com/auth/yt-analytics.readonly - Read YouTube Analytics reports for the channel's own videos. This permission is read-only and cannot change anything on YouTube.
From the connected channel we store:
- Channel details: channel ID, title, handle, thumbnail, uploads playlist ID, subscriber, view and video counts, and branding settings.
- Video details: video ID, title, description, tags, category, privacy status, scheduled and actual publication time, duration, whether it is a Short, the made-for-kids setting, thumbnail, upload and processing status, and view, like and comment counts.
- Analytics: daily figures for each video, namely views, watch time, average view duration and percentage viewed, subscribers gained and lost, likes, comments, shares, impressions and impression click-through rate.
- Comments on the channel's videos: comment and thread IDs, comment text, the commenter's public display name, channel ID and avatar, like and reply counts, publication time, and our own workflow information (such as the AI-drafted reply, whether it was approved and posted, and the ID of the posted reply).
- OAuth access and refresh tokens, the permissions granted and the token expiry time. Tokens are encrypted with AES-256-GCM before they are written to our database, and the encryption key is kept outside the database.
How we use connected-channel data
- To operate the Studio features the channel owner uses: uploading and scheduling videos, uploading captions and thumbnails, managing playlists, updating the channel description and branding, the analytics dashboard and the comment inbox.
- Comment replies: Scripiora uses AI to draft a reply to a comment. To do so, the comment text, its thread context and the video title are sent to our AI provider. A reply is posted to YouTube only after the channel owner has reviewed it, optionally edited it, and approved it. Scripiora never posts comments, applies moderation actions, likes, subscribes or takes any other action on YouTube automatically.
- Topic suggestions: to help the channel owner decide which videos to make next, Scripiora builds aggregated summaries of the channel's own performance (for example, which recent topics and formats earned the most views, watch time or new subscribers) and sends them, together with candidate topic ideas, to our AI provider so that it can rank those ideas for the same channel. The ranked suggestions are shown only to the channel owner in Studio.
What we never do with YouTube data
- We do not sell YouTube data or other Google user data, and we do not transfer it to advertising platforms, data brokers or information resellers.
- We do not use it for advertising, including personalized or interest-based advertising and retargeting.
- We do not use it to develop, train, fine-tune or improve artificial intelligence or machine learning models, ours or anyone else's, and we use only AI providers that do not use our requests for training.
- We do not show connected-channel data to anyone other than the channel owner and people the owner expressly authorizes, and we do not combine it with data from other channels.
- We do not use it to determine credit-worthiness or for lending purposes.
Scripiora's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep connected-channel data
- Analytics data and channel statistics are kept while the channel remains connected, to power the channel owner's dashboard and topic suggestions. At least every 30 days, Scripiora confirms with Google that its authorization is still valid.
- Other channel data (video details and comments) is refreshed from YouTube whenever Studio synchronizes the channel. Anything that has not been refreshed within 30 days is deleted.
- Access and refresh tokens are kept only while the channel is connected.
Revoking access and deleting YouTube data
- Disconnect in Scripiora: choosing "Disconnect" in Studio revokes Scripiora's access at Google straight away and immediately deletes the stored tokens and all stored data for that channel (channel details, videos, analytics and comments) from our database.
- Revoke in your Google Account: you can remove Scripiora's access at any time from the Google Account security settings page. Scripiora then stops all activity for that channel and deletes all stored data for it within 30 days of the revocation.
- Delete your Scripiora account: all YouTube data stored for your account is deleted along with it (see "Your choices and rights").
- Backups: copies of deleted data in encrypted backups, if any, are overwritten within 30 days.
4. How we use information
- To provide the Service: create and secure your account, sign you in, generate and store your scripts, run research and transcription, and keep your work available to you.
- To process purchases and keep your credit balance accurate.
- To send account notices, such as password-reset links or important changes to the Service, when email delivery is enabled. We do not send marketing email.
- To keep the Service secure, prevent fraud and abuse, enforce our Terms and fix problems.
- To comply with legal obligations.
To generate scripts and other results, Scripiora sends the prompts and content you submit to AI models through our AI provider. We do not use your content to train AI models.
We use Google user data (your Google Sign-In profile and YouTube data) only for the purposes described in this policy.
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases: performing our contract with you (providing the Service and processing purchases); our legitimate interests in keeping the Service secure, preventing abuse and improving the Service, balanced against your rights; your consent where we ask for it (for example, when you connect a Google account), which you can withdraw at any time; and compliance with legal obligations (for example, keeping tax records).
6. Where and how we store information
Scripiora is self-hosted: our PostgreSQL database and uploaded files are stored on servers that OneSimple administers. We do not use a third-party database service.
- Connections to Scripiora are encrypted with HTTPS (TLS).
- Passwords are stored only as salted one-way hashes.
- YouTube access and refresh tokens are encrypted with AES-256-GCM, with the key stored separately from the database.
- Access to production systems is limited to authorized OneSimple personnel.
No method of storage or transmission is completely secure, but we work to protect your information, and we will notify you and the relevant authorities of a data breach where the law requires it.
Our service providers may process information in other countries, including the United States. Where the law requires it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. How long we keep information
- Account and content
- While your account is open. After you ask us to delete your account, we delete it and your content within 7 days.
- Payment records
- As long as tax and accounting laws require (up to 10 years). These are order records only, never card numbers.
- Server logs
- 30 days.
- Saved transcripts and research
- Deleted (or stripped of YouTube data) after 30 days: saved transcripts with their translations and edits, YouTube research and trend data, and YouTube video details and transcripts used as knowledge-vault sources. You can delete saved transcripts sooner.
- Connected YouTube channel data
- As described in "YouTube API Services and Google user data": analytics while the channel is connected, other channel data refreshed or deleted within 30 days, and everything deleted when access is revoked.
- Backups
- Deleted data may remain in encrypted backups for up to 30 days before it is overwritten.
8. Your choices and rights
- Review and update your profile at any time in Settings, and delete scripts, ideas and saved transcripts inside the app.
- Delete your account by emailing team@onesimple.ai from the email address on your account. We will delete your account and all associated data, including any YouTube data, within 7 days and confirm when it is done.
- Remove Scripiora's access to your Google Account at any time from the Google Account security settings page.
- Depending on where you live, you may have the right to access, correct or delete your personal information, to restrict or object to its processing, to receive a copy of it in a portable format, and to withdraw your consent. To exercise these rights, contact us; we respond within 30 days. You can also complain to your local data protection authority.
- We do not sell or "share" personal information for cross-context behavioral advertising, as those terms are defined in California law.
10. Children
Scripiora is not directed to children. You must be at least 13 years old to use it, or older where your local law requires (for example, 16 in some European countries). We do not knowingly collect information from children; if you believe a child has given us information, contact us and we will delete it.
11. Changes to this policy
We may update this policy. We will change the effective date at the top of this page and, for material changes, notify you in the app before the change takes effect. We will ask for your consent before using Google user data in a new way.
12. Contact us
For questions, requests or complaints about this policy or our privacy practices, contact OneSimple at team@onesimple.ai. Our Terms of Service explain the rules for using Scripiora.