Overview
MP3 Video Kit can create a video without requiring an account. If you explicitly connect a YouTube channel, we use YouTube API Services and process only the Google and YouTube data needed to establish the connection and perform actions you request.
Information we process
- Source files: the MP3 and optional cover image you upload.
- Generated files: the MP4 created for your private job.
- Job data: format choices, file sizes, processing state, timestamps, and error codes.
- Technical data: IP address, browser and device information, request logs, and security signals used to operate and protect the service.
- Google and YouTube connection data: Google account identifier, YouTube channel ID and title, granted permission scopes, connection and validation timestamps, and an encrypted OAuth refresh token. We do not request your Google email address, name, or profile photo.
- YouTube publishing data: title, description, tags, category, privacy status, audience and synthetic-media selections, subscriber-notification, embedding and license settings, upload and processing status, encrypted resumable-session URI, and resulting video ID.
How we use information
We use this information to receive uploads, generate and deliver the MP4, identify and display the channel you selected, load assignable video categories, upload a video and check its processing status after your explicit confirmation, prevent abuse, troubleshoot failures, measure reliability, and meet legal obligations. We do not receive your Google password, and we do not use uploaded audio, artwork, or Google user data to train generative AI models.
MP3 Video Kit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for advertising, sold to data brokers, or made available to other users.
Storage and deletion
- Source media, cover images, intermediate files, and generated MP4 files are removed automatically within approximately 24 hours. You can delete an active job sooner from its private result page.
- Non-media task and publishing records used for recovery may remain for up to 30 days after the media expires, then are deleted.
- Browser account sessions last for up to 30 days unless you sign out or delete the related account data.
- A YouTube connection is retained until you disconnect it, request deletion, or Google authorization is revoked or becomes invalid. Disconnecting in MP3 Video Kit deletes the stored authorization and related YouTube API data immediately. Requests sent to our privacy contact are completed as soon as possible and within seven calendar days after verification.
- We periodically revalidate active Google authorizations and refresh stored channel data. If access is revoked outside MP3 Video Kit, related Authorized Data is deleted as soon as the revocation is detected and no later than 30 days after the last validation.
Short-lived access tokens are not stored. Refresh tokens, channel titles, upload settings, video IDs, and resumable upload session URIs are encrypted at rest where applicable. Limited operational, fraud-prevention, and security logs may be retained longer when reasonably necessary, but they do not contain uploaded media, OAuth tokens, titles, descriptions, channel titles, or video IDs.
How we protect sensitive and Google user data
We use the following technical safeguards to protect the confidentiality and integrity of sensitive data, including data received from Google APIs:
- Encryption in transit: data sent between your browser, MP3 Video Kit, Google, and YouTube is protected using HTTPS/TLS.
- Application-level encryption at rest: before database storage, OAuth refresh tokens, YouTube channel titles, video titles, descriptions, tags, video IDs, and resumable-upload session URIs are encrypted using AES-256-GCM. Encryption keys are maintained separately from the encrypted data as deployment secrets and are not stored in the database or public source code.
- Private media access: uploaded and generated media is stored in non-public object storage. Private jobs require a cryptographically random capability token, and media playback and download links are signed and time-limited rather than permanent public URLs.
- Protected authentication: account-session cookies are Secure, HttpOnly, and SameSite protected. Only hashes of account-session and private-job capability tokens are stored server-side. Google authorization uses short-lived, single-use state values and PKCE to protect the OAuth flow.
- Limited access and exposure: Google user data is available only to the authenticated account and the service components required to provide the requested feature. We apply trusted-origin checks, rate limits, automated abuse checks, least-privilege permissions, and data-minimization and deletion controls.
YouTube API Services and Google
Google processes authorization and YouTube API requests under the Google Privacy Policy and the YouTube Terms of Service. We request YouTube permissions only after you choose to connect a channel. During the private beta, direct uploads are created as Private videos and only after you confirm the channel, metadata, audience setting, and publishing rights.
Sharing and processors
Cloudflare provides hosting, database, file storage, delivery, and security services and processes data on our behalf to operate MP3 Video Kit. When you confirm a YouTube upload, Google and YouTube receive the generated MP4 and the publishing settings you selected. We may disclose limited information when required by law or necessary to protect users and the service. We do not sell uploaded media, personal information, or Google user data, and we do not share Google user data with advertisers or data brokers.
Cookies and browser storage
We use a secure, HttpOnly account-session cookie to keep you signed in. A private job capability is kept in session storage so the job can be reopened in the same browser session, and your theme preference may be kept in local storage. These technologies are used for authentication, security, job recovery, and preferences—not advertising.
Your choices
Do not upload private or sensitive content. You can disconnect a YouTube channel from your dashboard, account menu, or private job page. You can also review or revoke access in Google's third-party access settings. You may request access or deletion through our contact page. See Data Deletion for the fastest options.
Changes
We may update this policy as the service develops. Material changes will be posted here with a revised effective date.