Privacy
Privacy Policy
Effective: September 2, 2026
KRAIVOS combines a web control plane with a local media agent on the user's device. Project sources and media remain on the device unless the user chooses a transfer, while the Google/YouTube refresh token is retained only as an encrypted server-side envelope.
1. Scope
This policy applies to kraivos.com, the authenticated KRAIVOS web control plane, and the KRAIVOS Lite/Full installed software. The public information website does not use payments, advertising trackers, or first-party analytics cookies.
2. Website inquiries
If you email us, we may process the name, email address, and message you provide to respond, review a partnership, and maintain necessary security records. We retain this information only as needed.
3. Hybrid service data
Supabase Auth processes the email address required for application sign-in, while the KRAIVOS control plane uses only the authenticated account UUID. Projects, source and generated media, renders, settings, diagnostic logs, and browser sessions remain on the user’s computer unless the user explicitly chooses an upload, share, or external-service transfer. The local media agent does not receive or store the Google OAuth client secret or Google refresh token.
- KRAIVOS does not request or store Google passwords, recovery email addresses, or verification phone numbers.
- OAuth codes, tokens, cookies, raw states, and PKCE verifiers are excluded from application, diagnostic, and audit logs.
- The sign-in email is processed by the authentication provider for authentication and is not stored in KRAIVOS control-plane application records or audit logs.
4. Google and YouTube data; least privilege
KRAIVOS uses youtube.readonly to display the selected channel and owned content, youtube.upload for a video upload reviewed and approved by the user, youtube.force-ssl for user-reviewed and approved metadata, comment, live-broadcast, and live-chat actions, and yt-analytics.readonly to display channel analytics on a read-only basis. KRAIVOS does not request permissions for unimplemented future features or the broader youtube scope.
Data received from Google APIs is used only to provide the channel connection, upload, management, live, and analytics features requested by the user. It is not used for advertising, sale, credit decisions, surveillance, or general-purpose AI model training. It is not sold or shared with third parties except processors necessary to provide a user-requested feature or where legally required. KRAIVOS use and transfer of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements.
- Disconnecting attempts Google revocation and immediately deletes the encrypted server-side token envelope and connection record regardless of the revocation result.
- Deleting the KRAIVOS account removes the control-plane account and dependent records.
- These actions do not delete the Google Account, YouTube channel, published videos, or projects and media on the user’s device.
5. User-selected third parties
When you invoke Suno, Google, YouTube, or another AI/publishing service, the prompt, file, or metadata required for that action may be sent directly from your computer to that provider. Their terms and privacy policies apply. KRAIVOS does not relay account passwords.
6. Infrastructure and international processing
Google Cloud provides the control plane, cryptographic keys, and secret handling; Supabase provides application authentication and PostgreSQL; and Cloudflare provides DNS, edge security, and website delivery. Each processor may handle technical connection information and service data only as needed to provide the service. Google/YouTube and other providers you select may process data in other countries.
7. Your choices
Use the KRAIVOS YouTube disconnect or account-deletion control, or revoke KRAIVOS directly from your Google Account permissions page. Contact contact@kraivos.com to request access, correction, or deletion of website inquiry records. See the Data Deletion page for details.
8. Safeguards for Google user data
KRAIVOS applies the following technical and organizational safeguards to Google OAuth authorization data and YouTube API data.
- In transit: Communications among the browser, KRAIVOS control plane, Google OAuth, and YouTube APIs use HTTPS/TLS. OAuth requests are protected by PKCE S256 and an unpredictable one-time state.
- Temporary authorization state: The server indexes only a SHA-256 digest of the state. The PKCE verifier is retained in a KMS-protected envelope for no more than ten minutes and is deleted after one use or expiry.
- At rest: Each Google refresh token is encrypted with AES-256-GCM using a new 256-bit data key and nonce. The data key is wrapped by a Google Cloud KMS symmetric key. The account UUID, Google subject, and YouTube channel ID are bound as authenticated additional data.
- Data minimization: Access tokens and authorization codes are not persistently stored. The OAuth client secret is held only in Google Secret Manager. Application records and audit logs exclude email addresses, Google tokens, client secrets, request bodies, and RTMP stream keys.
- Access control: The Cloud Run runtime service account receives only the minimum access to required Secret Manager secrets and specific KMS keys. Public origin APIs require both the trusted edge boundary and user bearer authentication.
- Logs, retention, and deletion: Disconnecting attempts Google revocation and immediately deletes the server-side token envelope and connection record. A revocation network failure does not delay deletion of the server copy.
- Incident response: If unauthorized access or disclosure is suspected, KRAIVOS suspends the integration, revokes or rotates tokens, client secrets, or cryptographic keys, investigates impact, and applies corrective measures. KRAIVOS notifies affected users and Google when required by law or Google policy.
9. Policy changes
We update this policy and its effective date when processing, safeguards, or legal requirements change. If the purpose or handling of Google user data changes, users will be notified and any required consent will be obtained before the change takes effect.