Scripiora legal

Privacy Policy

Effective

This Privacy Policy explains how Scripiora, operated by OneSimple ("OneSimple", "we", "us"), collects, uses, stores, shares, retains and deletes information when you use Scripiora, including information we access through YouTube API Services, and the choices you have.

At a glance

  • Scripiora uses YouTube API Services. Google processes YouTube data under the Google Privacy Policy, and by using Scripiora you agree to the YouTube Terms of Service.
  • We collect only what we need to run Scripiora: your account details, the content you create, payment status and limited technical logs.
  • We do not sell personal information, we do not use it for advertising, and we do not use Google or YouTube data to train AI models.
  • Connecting a YouTube channel is limited to the operator's own channel in Scripiora Studio, and access can be revoked at any time from Scripiora or from the Google Account security settings page.
  • Your data is stored in our own self-hosted PostgreSQL database, and YouTube access tokens are encrypted with AES-256-GCM.

1. Who we are and what this policy covers

Scripiora is an AI video-script service operated by OneSimple (onesimple.ai). You can create an account with an email address and password or with Google Sign-In, generate and edit video scripts, research public YouTube videos, transcribe videos and buy credits. OneSimple is responsible for (the "controller" of) the personal information processed through Scripiora.

Scripiora uses YouTube API Services, which are provided by Google. When Scripiora accesses YouTube data, Google processes that data under the Google Privacy Policy. By using Scripiora you also agree to be bound by the YouTube Terms of Service.

This policy applies to the Scripiora website and application (the "Service"). It does not cover third-party websites or services we link to, such as YouTube, Google or Stripe, which have their own policies.

2. Information we collect

Information you give us

  • Account details: your name, email address and password. Passwords are stored only as a salted one-way hash; we never store them in readable form.
  • Profile details you choose to add, such as a profile photo or your YouTube handle.
  • Content you create or submit: topics, prompts, outlines, ideas, scripts, folders, and the videos you ask us to research, transcribe or translate.
  • Messages you send us, for example when you contact support.

Information from Google Sign-In

If you sign in with Google, Google shares your name, email address, whether that email address is verified, and your profile picture with us (the basic "openid", "email" and "profile" permissions). We use this only to create your account, sign you in and show your profile picture. Google Sign-In does not give Scripiora access to your YouTube channel, Gmail, Google Drive or any other Google data, and we never receive your Google password.

Payment information

Credit purchases are processed by Stripe. You enter your card details on Stripe's checkout page; we never receive or store your full card number. We keep a record of each order: the credit package, amount, currency, status, date and the Stripe identifiers needed to match the payment.

Usage and technical information

  • Your credit balance and credit transactions, and records of the AI requests you make (the feature used, the AI model, the amount of text processed and the cost). We need these for billing, usage limits and abuse prevention.
  • Server logs: IP address, browser user agent, requested address, response status and time of each request. We use them to keep the Service secure and working, and keep them for 30 days.

3. YouTube API Services and Google user data

Scripiora uses YouTube API Services to provide some of its features. This section explains which YouTube data we access, why, and how it is used, stored, shared and deleted. Please also review the YouTube Terms of Service and the Google Privacy Policy.

Public YouTube data (available to all users)

When you research a video, a channel or a topic, Scripiora uses the YouTube Data API with our own API key to retrieve public information: video titles, descriptions, thumbnails, channel names, publication dates, durations, public statistics such as view, like and comment counts, and publicly visible comments on the videos you choose to analyze. This does not involve any access to your YouTube account.

Transcripts are available only for videos on the channel owner's connected YouTube channel (see "Connected YouTube channel (Scripiora Studio)" below). Scripiora retrieves them through the official YouTube Data API captions endpoints, with the channel owner's authorization, and deletes stored transcripts after 30 days. Transcripts, public comments and video details are sent to our AI provider only to produce the transcript, translation, analysis or script you asked for.

Public YouTube data is shown to you in your research results. The YouTube data we store, including saved transcripts with their translations and edits, research and trend data, and YouTube video details and transcripts used as knowledge-vault sources, is deleted (or stripped of YouTube data) after 30 days. Video details you attach when generating a script are sent to our AI provider to write it and are not stored separately.

Connected YouTube channel (Scripiora Studio)

Scripiora Studio is a video-production workspace available only to the operator of Scripiora, to manage OneSimple's own YouTube channel. Studio access is limited to accounts on an allow-list that OneSimple controls. Other Scripiora users cannot connect a YouTube channel, and we never ask them for access to their YouTube accounts.

When the channel owner chooses to connect a YouTube channel, Google shows its consent screen and asks the owner to grant the permissions below. We request only the permissions that Studio features use:

YouTube channel managementhttps://www.googleapis.com/auth/youtube.force-ssl
Read the channel's identity, branding and list of videos; upload videos produced in Studio as private, unlisted, public or scheduled uploads, as the channel owner chooses for each video; update video titles, descriptions, tags, privacy status and scheduled publishing times; set custom thumbnails; upload caption files; create and manage playlists; and update the channel description and branding.Read the comments posted on the channel's videos, post replies that the channel owner has approved, and apply moderation actions (such as holding a comment for review or rejecting it) when the channel owner chooses to. Every change is made only when the channel owner makes it in Studio.
Channel analytics (read-only)https://www.googleapis.com/auth/yt-analytics.readonly
Read YouTube Analytics reports for the channel's own videos. This permission is read-only and cannot change anything on YouTube.

From the connected channel we store:

  • Channel details: channel ID, title, handle, thumbnail, uploads playlist ID, subscriber, view and video counts, and branding settings.
  • Video details: video ID, title, description, tags, category, privacy status, scheduled and actual publication time, duration, whether it is a Short, the made-for-kids setting, thumbnail, upload and processing status, and view, like and comment counts.
  • Analytics: daily figures for each video, namely views, watch time, average view duration and percentage viewed, subscribers gained and lost, likes, comments, shares, impressions and impression click-through rate.
  • Comments on the channel's videos: comment and thread IDs, comment text, the commenter's public display name, channel ID and avatar, like and reply counts, publication time, and our own workflow information (such as the AI-drafted reply, whether it was approved and posted, and the ID of the posted reply).
  • OAuth access and refresh tokens, the permissions granted and the token expiry time. Tokens are encrypted with AES-256-GCM before they are written to our database, and the encryption key is kept outside the database.

How we use connected-channel data

  • To operate the Studio features the channel owner uses: uploading and scheduling videos, uploading captions and thumbnails, managing playlists, updating the channel description and branding, the analytics dashboard and the comment inbox.
  • Comment replies: Scripiora uses AI to draft a reply to a comment. To do so, the comment text, its thread context and the video title are sent to our AI provider. A reply is posted to YouTube only after the channel owner has reviewed it, optionally edited it, and approved it. Scripiora never posts comments, applies moderation actions, likes, subscribes or takes any other action on YouTube automatically.
  • Topic suggestions: to help the channel owner decide which videos to make next, Scripiora builds aggregated summaries of the channel's own performance (for example, which recent topics and formats earned the most views, watch time or new subscribers) and sends them, together with candidate topic ideas, to our AI provider so that it can rank those ideas for the same channel. The ranked suggestions are shown only to the channel owner in Studio.

What we never do with YouTube data

  • We do not sell YouTube data or other Google user data, and we do not transfer it to advertising platforms, data brokers or information resellers.
  • We do not use it for advertising, including personalized or interest-based advertising and retargeting.
  • We do not use it to develop, train, fine-tune or improve artificial intelligence or machine learning models, ours or anyone else's, and we use only AI providers that do not use our requests for training.
  • We do not show connected-channel data to anyone other than the channel owner and people the owner expressly authorizes, and we do not combine it with data from other channels.
  • We do not use it to determine credit-worthiness or for lending purposes.

Scripiora's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How long we keep connected-channel data

  • Analytics data and channel statistics are kept while the channel remains connected, to power the channel owner's dashboard and topic suggestions. At least every 30 days, Scripiora confirms with Google that its authorization is still valid.
  • Other channel data (video details and comments) is refreshed from YouTube whenever Studio synchronizes the channel. Anything that has not been refreshed within 30 days is deleted.
  • Access and refresh tokens are kept only while the channel is connected.

Revoking access and deleting YouTube data

  • Disconnect in Scripiora: choosing "Disconnect" in Studio revokes Scripiora's access at Google straight away and immediately deletes the stored tokens and all stored data for that channel (channel details, videos, analytics and comments) from our database.
  • Revoke in your Google Account: you can remove Scripiora's access at any time from the Google Account security settings page. Scripiora then stops all activity for that channel and deletes all stored data for it within 30 days of the revocation.
  • Delete your Scripiora account: all YouTube data stored for your account is deleted along with it (see "Your choices and rights").
  • Backups: copies of deleted data in encrypted backups, if any, are overwritten within 30 days.

4. How we use information

  • To provide the Service: create and secure your account, sign you in, generate and store your scripts, run research and transcription, and keep your work available to you.
  • To process purchases and keep your credit balance accurate.
  • To send account notices, such as password-reset links or important changes to the Service, when email delivery is enabled. We do not send marketing email.
  • To keep the Service secure, prevent fraud and abuse, enforce our Terms and fix problems.
  • To comply with legal obligations.

To generate scripts and other results, Scripiora sends the prompts and content you submit to AI models through our AI provider. We do not use your content to train AI models.

We use Google user data (your Google Sign-In profile and YouTube data) only for the purposes described in this policy.

If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases: performing our contract with you (providing the Service and processing purchases); our legitimate interests in keeping the Service secure, preventing abuse and improving the Service, balanced against your rights; your consent where we ask for it (for example, when you connect a Google account), which you can withdraw at any time; and compliance with legal obligations (for example, keeping tax records).

5. How we share information

We do not sell or rent personal information. We share it only with the service providers below, which process it on our behalf to run the Service, and only as much as each one needs:

OpenRouter
AI model access. Receives the prompts and content needed to generate your results. In Studio this includes comment text for drafting replies and aggregated channel-performance summaries for ranking topic ideas. OpenRouter forwards each request to the AI model provider that serves it. OpenRouter privacy policy
ElevenLabs
Text-to-speech, used only in Studio. Receives the narration text of the operator's own videos to produce voice-over audio. ElevenLabs privacy policy
Stripe
Payments. Processes credit purchases and receives the payment details you enter at checkout. Stripe privacy policy
Google
Google Sign-In and YouTube API Services. Receives the requests needed to provide these features, for example the videos, captions, thumbnails and approved replies the channel owner publishes. Google Privacy Policy
Email delivery (when enabled)
Scripiora does not send email yet. If we enable account email, your email address and the content of each message will be shared with an email delivery provider (we plan to use Resend). We will update this policy before email is enabled.

We may also disclose information when required by law or valid legal process; to protect the rights, property or safety of our users, the public or OneSimple, including to investigate abuse; or as part of a merger, acquisition or sale of assets, in which case we will notify you, and Google user data will be transferred only with your prior consent.

Access to personal information by OneSimple staff is limited to what is needed to operate and support the Service, keep it secure or comply with the law. Staff do not read your content or YouTube data unless you ask us to (for example, for support), it is needed to investigate security issues or abuse, or the law requires it.

Scripiora does not show advertising, and no third party serves content or advertisements through Scripiora. Thumbnails of YouTube videos are loaded from YouTube's servers, so Google may receive your IP address when they load.

6. Where and how we store information

Scripiora is self-hosted: our PostgreSQL database and uploaded files are stored on servers that OneSimple administers. We do not use a third-party database service.

  • Connections to Scripiora are encrypted with HTTPS (TLS).
  • Passwords are stored only as salted one-way hashes.
  • YouTube access and refresh tokens are encrypted with AES-256-GCM, with the key stored separately from the database.
  • Access to production systems is limited to authorized OneSimple personnel.

No method of storage or transmission is completely secure, but we work to protect your information, and we will notify you and the relevant authorities of a data breach where the law requires it.

Our service providers may process information in other countries, including the United States. Where the law requires it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

7. How long we keep information

Account and content
While your account is open. After you ask us to delete your account, we delete it and your content within 7 days.
Payment records
As long as tax and accounting laws require (up to 10 years). These are order records only, never card numbers.
Server logs
30 days.
Saved transcripts and research
Deleted (or stripped of YouTube data) after 30 days: saved transcripts with their translations and edits, YouTube research and trend data, and YouTube video details and transcripts used as knowledge-vault sources. You can delete saved transcripts sooner.
Connected YouTube channel data
As described in "YouTube API Services and Google user data": analytics while the channel is connected, other channel data refreshed or deleted within 30 days, and everything deleted when access is revoked.
Backups
Deleted data may remain in encrypted backups for up to 30 days before it is overwritten.

8. Your choices and rights

  • Review and update your profile at any time in Settings, and delete scripts, ideas and saved transcripts inside the app.
  • Delete your account by emailing team@onesimple.ai from the email address on your account. We will delete your account and all associated data, including any YouTube data, within 7 days and confirm when it is done.
  • Remove Scripiora's access to your Google Account at any time from the Google Account security settings page.
  • Depending on where you live, you may have the right to access, correct or delete your personal information, to restrict or object to its processing, to receive a copy of it in a portable format, and to withdraw your consent. To exercise these rights, contact us; we respond within 30 days. You can also complain to your local data protection authority.
  • We do not sell or "share" personal information for cross-context behavioral advertising, as those terms are defined in California law.

9. Cookies and local storage

Scripiora uses only the cookies and browser storage needed for the Service to work. We do not use advertising or third-party analytics cookies.

Session cookie
Set when you sign in, to keep you signed in. It is removed when you sign out and expires after a period of inactivity.
Sign-in security cookies
Short-lived cookies that protect the Google Sign-In and YouTube connection flows against forgery. They expire within about 10 minutes.
Local storage
Your light or dark theme preference and an unsaved draft of the script form, stored only in your browser.
Session storage
Temporary details passed between pages, for example from a research result to the script form. It is cleared when you close the tab.

Google sets its own cookies on its sign-in and consent pages, and Stripe sets its own cookies on its checkout pages, under their own policies.

10. Children

Scripiora is not directed to children. You must be at least 13 years old to use it, or older where your local law requires (for example, 16 in some European countries). We do not knowingly collect information from children; if you believe a child has given us information, contact us and we will delete it.

11. Changes to this policy

We may update this policy. We will change the effective date at the top of this page and, for material changes, notify you in the app before the change takes effect. We will ask for your consent before using Google user data in a new way.

12. Contact us

For questions, requests or complaints about this policy or our privacy practices, contact OneSimple at team@onesimple.ai. Our Terms of Service explain the rules for using Scripiora.