Privacy
What Uplora stores, what it never touches, and how to make all of it disappear.
What we store
The complete inventory. If it is not in this list, we do not have it.
- sealed-box encrypted
- id · title · thumbnail · subscriber count
- last-verified timestamp
- email · name
- masters · thumbnails · metadata
What we never access
Your Google password. OAuth hands Uplora tokens, never credentials, so there is no password to see. Beyond that, the grant simply does not include: channel revenue or AdSense data, YouTube Analytics, your existing videos, your comments, your subscribers’ identities, or anything else in your Google account outside the two scopes listed on the security page.
No Google user data is sold, used for advertising, or transferred to anyone. Humans at Uplora cannot read your tokens; the key that decrypts them never touches the database.
Google API Services — Limited Use
Uplora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking is real deletion, not a flag. Disconnect a channel in Uplora — the button opens a dialog naming the channel, so it is never an accident — and we call Google's revoke endpoint and destroy the stored token ciphertext. The destruction happens even if the revoke call fails, so a dead ciphertext can never outlive the connection. Your channel's picture and subscriber count go with it. We keep the channel's name and id, because your published videos point at them — that is your record of where each one went.
Revoke from Google's side instead, at , and the verification job detects the dead grant, stops the channel publishing, notifies you, and destroys the ciphertext all the same.
Your content
Masters stay masters. The file your editor uploads is the file that reaches YouTube: original bytes, never transcoded, checked against a checksum on arrival and again before publish. It is your content — Uplora publishes it to your channel when you approve, and does nothing else with it.
Export any time: the master, the metadata JSON, the thumbnail — the same package your approval locked. That includes after you cancel. Read-only mode still exports.
Third parties
Uplora runs on a small set of processors. What each one sees:
- Clerk
- Supabase
- AWS S3
- Paddle
- Telegram · email
Paddle is the odd one out, and the difference matters to you: it is not a processor acting on our instructions but our merchant of record — the seller on your receipt. It decides what billing data the tax rules of your country oblige it to keep, and it holds that data as its own controller under its own privacy notice. Nothing about your videos, your channel or your team is sent to it — a workspace id and an email address are the whole of it.
Deletion
Deleting a workspace is a hard delete: packages, masters, thumbnails, metadata, cached channel data, and encrypted tokens are destroyed. One honest exception: the append-only audit log survives for 30 days after deletion, so a disputed approval can still be answered. Then it is deleted too.
Disconnecting a single channel deletes its token, picture and subscriber count immediately, as described above.
Contact
Questions, corrections, or a deletion request we should hurry: contact@uplora.io. A human reads it.