Privacy
Last updated September 2026
What is stored
Your email address, because that is how you sign in. If you sign in with Google, also the name and profile picture Google returns with it — see below. There is no password to store either way. For each project: the topic or script you gave, the generated scene breakdown and caption timings, and the rendered video. If you uploaded a video, that file too. A ledger of credits bought, spent and refunded.
No analytics, no tracking pixels, no advertising identifiers, no third-party scripts on the page.
Google user data
ShortPulse receives data from Google in two places, and only when you start it.
Signing in with Google. Google returns your email address, your name and your profile picture (the openid, email and profile scopes). The email identifies your account and is where receipts go; the name and picture are shown only to you, in the app. None of it is used for anything else.
Connecting a YouTube channel. ShortPulse asks for one YouTube permission, youtube.upload, which lets it upload a video to your channel and nothing more — it cannot read your channel, your existing videos, your comments or your analytics. It is used for exactly one thing: uploading a video you made in ShortPulse, with the title and description you gave it, when you press Publish, or automatically after a render if you turned that on for the channel. Nothing is ever uploaded that you did not make and ask to publish.
How it is used
- To sign you in and keep your projects under your account.
- To upload the videos you choose to your YouTube channel.
It is not used for advertising, not sold, not used to build profiles, and not used to train or improve any AI or machine-learning model — ours or anyone else's.
Who it is shared with
Nobody, beyond what is needed to provide the two features above. The videos you publish go to YouTube, which is Google. Your account record is stored with Supabase, the database provider named below, which processes it on ShortPulse's behalf and may not use it for anything else. Google user data is not transferred or disclosed to any other party, except where the law requires it.
How it is protected
- Every connection to ShortPulse, and from ShortPulse to Google, is encrypted in transit (HTTPS/TLS).
- The YouTube access and refresh tokens are encrypted before they are written to the database (Fernet: AES-128 with an HMAC, so a tampered token is rejected rather than used). The key is held in the server's environment, never in the database, so a copy of the database does not contain usable tokens.
- Tokens are never written to logs or sent to the browser, and only the server process that performs uploads can decrypt them.
- Access to the production database and server is limited to the operator named below.
Keeping and deleting it
Disconnecting a channel in ShortPulse deletes its stored tokens straight away; a record of which videos were published is kept so your library stays accurate. Deleting your account deletes your Google profile data, your connections and their tokens. You can also withdraw ShortPulse's access at any time from your Google Account, at myaccount.google.com/permissions.
ShortPulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What leaves the server
Only these, and only what each one needs:
- Supabase — sign-in and the database. Holds your email and your projects.
- Stripe — payments. Card details go straight to Stripe and never reach this application.
- Pexels — receives the search keywords for each scene when you use the stock footage mode. Not your topic, and nothing that identifies you.
- OpenAI — receives the topic or script to write the scene breakdown from, on the hosted service. Self-hosted installs use a local model and send nothing.
- Replicate — receives one image prompt per scene, and returns the generated image, when you pick the AI-stills mode on the hosted service. Those prompts are written from your topic, so unlike the Pexels keywords above they usually describe what your video is about. Nothing that identifies you is sent with them. Self-hosted installs with a GPU generate the images on your own machine and send nothing.
- YouTube, Instagram, Facebook and TikTok — receive a video, its title and its description when you publish to an account you connected, and nothing when you have not. Each connection's tokens are stored encrypted as described above.
- Sentry — crash reports, if enabled. Configured not to include request contents.
Voice and video
Voiceovers are synthesised locally with Piper, and captions are timed locally with Whisper. Neither your script nor your uploaded video is sent to a speech service.
How long
Projects and their videos stay until you delete them. Deleting a project removes the video and every file it produced, not just the database row. Working files are discarded automatically as soon as a render finishes.
The credit ledger is append-only and is kept for as long as the account exists, because it is also the record of what you paid.
Who is responsible
This service is run by Mehmet Emirhan Kocer, Warsaw, Poland, who is the data controller for everything described here.
Contact for anything on this page, including the requests below: contact@shortpulse.app.
Your rights
You can ask for a copy of your data, for it to be corrected, or for the account and everything in it to be deleted. Write to the address above and it will be done. If you think the law has been broken, you can also complain to your national data protection authority.
Where it is
Data is held in the EU (Frankfurt). Stripe, OpenAI and Replicate process some of it outside that region under their own transfer safeguards.