Privacy policy

Last updated 13 August 2026

What Framecast is

Framecast is a private video production tool operated by its owner. It is not a public service and has no self-registration. Accounts exist only for people the operator has explicitly authorised.

Data collected when you sign in

Signing in with Google gives Framecast your email address, name and profile picture. These are used only to identify your account and to display who is signed in. Signing in with an email address and password stores that address and a hashed password — the password itself is never stored.

YouTube data, when you connect a channel

Connecting a YouTube channel is a separate, optional step with its own consent screen. Framecast requests two permissions:

  • Read your channel — channel name, thumbnail, subscriber and view counts, and the list of videos published through Framecast. Used to display your channel in the studio.
  • Upload videos — used only to publish a video you have explicitly approved. Framecast never uploads, edits, deletes or comments on anything without that approval.
  • Read your channel's analytics — views, watch time, average view duration, impressions, click-through rate and subscribers gained. Used to show how your videos performed inside the studio, so you can see which topics and thumbnails worked.
  • Read your estimated revenue — the earnings figure YouTube reports for your own videos. Displayed back to you alongside what each video cost to produce. It is never shared, aggregated with anyone else's data, or used for any other purpose.

Framecast's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never shared with third parties, never used for advertising, and never used to train machine-learning models.

Where data is stored

The application and its private PostgreSQL database both run on a single dedicated server rented from OVH, in London. The database accepts no connections from the internet: it is reachable only by the application running beside it on that same machine, over the host's own internal network. Uploaded and generated files — narration audio, video clips, thumbnails and finished videos — are stored on that server's disk, not with a third-party storage provider.

Access tokens for connected accounts, and any third-party API keys you enter, are encrypted at rest with AES-256-GCM before being written to the database.

The database is backed up nightly to Cloudflare R2 object storage, so that a failure of the server itself is recoverable. Those backups contain the same data as the database, including the encrypted values described above, and are deleted after 30 days.

Third-party services

Producing a video sends the topic and script text you create to the AI providers configured by the operator, in order to generate the script, narration audio and thumbnail image. It does not send your Google account details or your YouTube channel data to those providers.

Retention and deletion

Data is kept while the account exists. You can disconnect a YouTube channel at any time from the studio, which deletes the stored tokens. You can also revoke Framecast's access directly from your Google account at myaccount.google.com/permissions. To have an account and all associated data deleted, contact the operator at the address below.

Contact

Questions about this policy, or requests to delete data, can be sent to eramdevteam@gmail.com.