Privacy

Last updated 2026-09-06

The short version

  • Your service videos are never used to train AI models.
  • Transcription and speaker recognition run on our hosted infrastructure (see Third parties below). Your videos and transcripts are not shared with any third party for the purpose of training their AI models.
  • Source video files are automatically removed from our storage after 90 days.
  • When you connect a YouTube, Vimeo, or Google Drive account, we store encrypted OAuth tokens and request only the scopes needed for the connected workflow.
  • We do not sell your data. Ever.

What we collect

Your name and email when you sign in via magic link. The name of your organization. The metadata of each upload (filename, size, duration, thumbnails, and the destinations and publish settings you chose). Transcripts and speaker labels you create. Assistant chat messages you choose to send, plus the assistant responses saved in your chat history. Logs of which destination publishes succeeded or failed. If you add another account on this device, we keep that sign-in in a cookie on this browser so you can switch without a new code each time.

Google Drive

Connecting Google Drive is optional. When you connect it, we request drive.readonly, drive.file, and userinfo.email.

Those scopes let us:

  • List and watch folders you choose as watch folders, so new recordings can be imported automatically.
  • Read file metadata in those folders (name, type, size, file ID, and modification time) to detect new source media.
  • Download and read the source media content of those files so we can transcribe, section, and publish them through uploads.run.
  • Accept a one-off file you pick in our Drive picker (drive.file).
  • Read the connected account’s email so we can label the connection in your workspace.

We do not use Drive for general browsing, search, or access to files outside the watch-folder and picker workflow you set up. We do not create, edit, share, or delete files in your Drive.

YouTube

Connecting YouTube is optional. When you connect it, we request youtube.upload, youtube.readonly, and youtube.force-ssl.

Those scopes let us:

  • Upload videos and Shorts you choose to publish from uploads.run.
  • Set title, description, privacy, schedule, thumbnail, playlist, chapters, and Made for Kids as you configure in the product.
  • Read channel and video metadata so we can show the connected channel, confirm a publish, update details on a video we uploaded, and avoid uploading the same destination twice.
  • List playlists on the connected channel, add a published video to playlists you select, and optionally upload a playlist graphic you provide.

We do not browse, delete, or otherwise manage your YouTube channel beyond the publishes you send through uploads.run.

How we handle Google user data

Google user data includes OAuth tokens, Drive file metadata and media we ingest, and YouTube channel, video, and playlist metadata we read or write for publishing.

Storage. OAuth access and refresh tokens are encrypted at rest in our database (Supabase) and used only to call Google APIs for the connected workflow. Drive-sourced media is copied into Cloudflare R2 so we can process it. Upload metadata, transcripts, publish records, and connection labels are stored in Supabase, scoped to your organization.

Processing. Source media is transcribed and sectioned on our hosted transcription infrastructure. The web app runs on Vercel. YouTube uploads may pass through Cloudflare Workers. Transcript text — not the source video — may be sent to xAI to suggest titles, descriptions, clips, or assistant replies inside the product.

Sharing. Drive and YouTube-sourced media and metadata may be processed or stored by the subprocessors listed under Third parties, only to run uploads.run. We do not sell Google user data. We do not use it for advertising. We do not use it to train third-party AI models.

uploads.run’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Who can see your data

Members of your organization can see the workspace’s uploads, transcripts, publish status, and connected account labels. Owners and admins can connect or disconnect YouTube, Drive, and other accounts. People outside your organization cannot see that data through uploads.run.

Retention

  • Encrypted OAuth tokens are kept while the connection is active so we can watch folders and publish. After you disconnect, we stop using those tokens.
  • Google-sourced media copies in our storage follow the same rule as other source files: they are removed after 90 days.
  • Transcripts, titles, publish records, and other workspace data stay until you delete them or ask us to delete the organization.

Disconnect and revoke

Owners and admins can disconnect YouTube or Google Drive from Connections. After disconnect, uploads.run no longer reads Drive or publishes to YouTube with that account. You can also revoke access in your Google Account permissions. Email hello@uploads.run to delete your organization, including stored tokens and Google-sourced copies.

What we don’t collect

Personal information about people named in your sermons, beyond what appears in files you upload or connect. Drive files outside the folders and picks you connect. YouTube channel content we did not publish through uploads.run, except the metadata needed to confirm those publishes.

Third parties

Cloudflare (R2 object storage and Workers used to store and publish media), Supabase (database, auth, realtime), Vercel (hosting), our hosted transcription infrastructure, Mailgun (transactional email — magic-link OTPs, upload notifications), Stripe (billing), and xAI (assistant, title, and clip suggestions). YouTube, Vimeo, and Google Drive are connected only when you authorize them.

Your rights

Email hello@uploads.run to request a copy of your data or to delete your organization. We respond within 30 days.