ShortsFactory
Privacy Policy
This policy describes the current data practices of ShortsFactory, a locally operated Windows creator workflow and publishing application, with specific disclosures for its Google/YouTube integration.
Last updated: · Policy revision: 2026-09-10.1
1. Scope and this website
ShortsFactory is currently a private, local application, not a public software-as-a-service platform. It is intended for creator-owned or creator-authorized media and explicitly authorized social-media accounts. It supports publishing providers beyond YouTube; the Google-user-data disclosures below describe the YouTube integration.
This informational website has no analytics, advertising, tracking pixels, tracking scripts, contact forms, or newsletter forms. Its pages do not set cookies or use browser storage. Visiting this site does not connect a Google account or initiate an upload.
The hosting provider receives ordinary web requests needed to serve these pages. The absence of site analytics does not mean that hosting infrastructure processes no request information.
2. Google/YouTube user data accessed
ShortsFactory uses YouTube API Services and accesses information needed for its user-facing connection and publishing functions. This may include:
- The authorized YouTube channel ID and channel title/name.
- The channel handle or custom URL when returned by the API.
- Upload/video IDs created by user-requested publications.
- Upload processing state and visibility/publication state needed to reconcile a requested upload.
- OAuth authorization credentials needed to maintain the user's authorized connection.
The integration requests these exact OAuth scopes:
https://www.googleapis.com/auth/youtube.uploadhttps://www.googleapis.com/auth/youtube.readonly
The current implementation uses channels.list(mine=true) to identify the authorized channel, videos.insert for approved uploads, and videos.list to reconcile upload processing and visibility.
The current integration does not read or collect Gmail/email, contacts, Google Drive data, search history, general browsing history, YouTube watch history, subscriptions, comments, private messages, advertising data, or analytics.
Google and YouTube handle information under their own policies. Read Google's Privacy Policy.
3. How Google user data is used
Google/YouTube data is used only to provide the user's requested YouTube connection and publishing functions:
- Authenticate an explicitly authorized Google/YouTube connection.
- Identify the exact authorized destination channel and display it to the operator.
- Upload media explicitly selected and approved by the operator, with the operator-approved title, description, tags, and settings.
- Track and reconcile processing and visibility for that requested upload.
- Maintain the authorized connection where permitted by Google OAuth.
Uploads are resumable. Every publishing action requires a user-controlled publication plan, metadata review/preflight, approval, and explicit confirmation. The application currently enforces private-only YouTube uploads while the Google/YouTube API project awaits approval; public/unlisted publishing and scheduling remain disabled by application policy until the corresponding Google approval/configuration exists.
4. Local storage and copies
ShortsFactory stores its application database and application-owned database backups in a dedicated per-user Windows application-data directory. Windows access permissions are checked so this application-owned database boundary permits the operating Windows user, SYSTEM, and Administrators.
OAuth credentials, including access tokens, refresh tokens, and client-secret material, and resumable-session secrets are stored in Windows Credential Manager for the current Windows user. OAuth token contents are not intentionally stored in normal SQLite application tables or displayed in the normal application interface.
The local database holds non-secret connection and publication information, credential references, policy-consent metadata, and workflow history. Stored YouTube API-derived information is subject to the lifecycle and deletion controls below.
Database access control is not a claim that SQLite files or all YouTube data are encrypted. Accounts with administrator or SYSTEM privileges can access the protected database boundary.
Imported token files and copies you control
An authorized-user OAuth token file may be imported from outside the ShortsFactory project. After successful import, working OAuth credentials are stored in Windows Credential Manager, and the original external token-file path is not retained. You may securely remove that external token export when it is no longer needed.
ShortsFactory does not automatically find or delete arbitrary external copies. Manually exported databases, operating-system snapshots, cloud backups, and manually copied token files remain under your control; they are outside the application-owned database and backup cleanup boundary.
6. AI and machine learning
ShortsFactory may exist alongside AI-assisted creator workflows. Google user data received through Google APIs is not used to train, develop, or improve generalized or non-personalized AI or machine-learning models. This disclosure concerns Google user data; it does not state that creator content or creator workflows never use AI.
7. Google API Services User Data Policy
ShortsFactory's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. API-data lifecycle and local history
A 29-day operational safety threshold
YouTube API-derived copies managed by ShortsFactory in its application database and application-owned backups are individually aged based on their observation history. The application uses a 29-day operational safety threshold. Expired API-derived channel identity, remote video identifiers and status information, and legacy API-derived bindings or hashes are removed or neutralized. Merely viewing locally stored data does not renew its observation age.
Historical workflow records
This does not mean that everything is deleted every 29 days. Independently local workflow facts may remain, including:
- Local media and render references.
- Authored titles, descriptions, and settings.
- Local publication plans and operator approval/action history.
- Local attempt/history identifiers and local-only operational references or bindings.
API-derived channel display information, YouTube video IDs, processing status, and visibility are lifecycle-bounded. After associated API-derived data is removed, a retained record represents historical local workflow only, with current YouTube status unavailable. It does not assert a video's current processing or visibility.
When the application is closed or the device is powered off
ShortsFactory is a local Windows desktop application and has no cloud backend retaining YouTube API data. Its cleanup and validation code does not execute while ShortsFactory is completely closed or the device is powered off. It cannot guarantee that code executes or data is deleted during that time.
When ShortsFactory next starts, overdue API-data cleanup occurs before affected YouTube API-derived data is made ordinarily available. Pre-use checks also run before YouTube API operations. If cleanup fails, access to affected data and new YouTube operations remains blocked.
This is an architectural limitation to be disclosed to Google's reviewer. It is not a claim of an exemption from Google's calendar-based data requirements or a guarantee of deletion while the device is powered off.
9. Disconnect, revocation, and local deletion
Accounts & connections provides two distinct controls:
Disconnect YouTube & remove authorization
After explicit confirmation, ShortsFactory blocks further local use, requests Google authorization revocation, removes the locally stored OAuth credential, and removes or sanitizes associated stored YouTube API-derived data in the application database and application-owned database backups.
Delete local YouTube API data
This removes the local OAuth credential and removes or sanitizes associated locally stored YouTube API-derived data, including application-owned database backups. It does not request revocation of the Google grant. Use the disconnect control or Google's account controls if you also want to revoke that grant.
Neither action deletes videos or other content stored on YouTube. Use YouTube Studio to manage your hosted content. Independently local workflow records and externally controlled copies have the boundaries described in the storage and lifecycle sections above.
Revoke access through Google
You can also revoke ShortsFactory's access through your Google Account connections and third-party access controls. Select ShortsFactory, review its access, and remove that access. Google requires sign-in. See Google's instructions for managing third-party connections.
Google's account controls manage the Google grant; they do not execute local code on a closed application or powered-off device. Use the ShortsFactory controls above for local removal, subject to the application-owned copy boundary and next-run limitation.
10. Security
ShortsFactory separates OAuth credentials and resumable-session secrets in Windows Credential Manager from normal application database records. It checks Windows access permissions for its per-user database and application-owned backups. These access controls do not encrypt SQLite by themselves or prevent access by administrator or SYSTEM accounts.
Protect access to your Windows account, computer, and external copies. These measures do not guarantee that any system is free from security risks.
11. Policy acceptance and changes
Before using YouTube Direct, you must affirmatively accept the current ShortsFactory Privacy Policy and Terms notice. ShortsFactory records appropriate consent metadata: policy version, policy links, environment, and acceptance time. A material policy identifier or configuration change requires renewed acceptance.
By using ShortsFactory's YouTube integration, you agree to be bound by the YouTube Terms of Service. The ShortsFactory Terms of Service also explain your publication and platform responsibilities.
This page describes current ShortsFactory 1.28 behavior. It may be updated when actual data practices change. The revision above identifies this notice; visiting this website does not record acceptance on your behalf.
12. Support and privacy contact
For privacy questions or help with authorization revocation or local YouTube API-data deletion, contact the developer: