Privacy Policy
Effective date: July 12, 2026
isalootu operates isalootu. This Privacy Policy explains how we collect, use, store, disclose, and delete information when you use the service to create short-form clips from supported sources such as YouTube, Twitch, TikTok, Bluesky, and Snapchat, store generated artifacts, and connect third-party accounts such as YouTube, Google Drive, TikTok, Twitch, or Bluesky.
Information We Collect
- Account information. We collect the email address and password hash you provide when creating an account.
- Session and security information. We use a session cookie to keep you signed in and to protect forms from cross-site request forgery.
- Clip job information. We store submitted video URLs, monitored live source URLs, including supported YouTube, Twitch, TikTok, Bluesky, and Snapchat URLs, job settings, status, errors, created clips, generated captions, metadata, and artifact records.
- Generated content. We may process downloaded source segments, audio transcripts, visual summaries, captions, MP4 files, JSON sidecars, share-page links, and upload results.
- YouTube connection data. If you connect YouTube, we store encrypted OAuth credentials and token metadata needed to upload videos you explicitly request. The default scope is YouTube upload access.
- Google Drive connection data. If you connect Google Drive, we store encrypted OAuth credentials and token metadata needed to upload generated clip files you explicitly request. The default scope is Drive file access for files this app creates or files explicitly shared with it.
- TikTok connection data. If you connect TikTok, we store encrypted OAuth access data, refresh data when provided, open ID, scopes, and token expiration metadata needed to upload or publish generated clips to TikTok when you request it.
- Twitch connection data. If you connect Twitch, we store encrypted OAuth access data, refresh data when provided, scopes, token expiration metadata, Twitch user ID, channel login, and display name needed to identify and monitor your connected channel when you enable monitoring.
- Bluesky connection data. If you authorize Bluesky, we store encrypted OAuth tokens, the OAuth DPoP key, account DID, handle, service URL, and display metadata needed to publish generated clips when you request it. Bluesky handles authorization on its own site; this app does not receive your Bluesky password.
- Provider and infrastructure data. Our hosting, storage, queue, database, LLM, and logging providers may process IP addresses, request metadata, error logs, and operational telemetry needed to run the service.
How We Use Information
- Provide the website, accounts, dashboard, job queue, worker, clip generation, and download links.
- Download and process videos you submit, generate transcripts and clip plans, render clips, and store completed artifacts.
- Upload clips to YouTube, Google Drive, TikTok, or Bluesky only when you choose that option and have connected the relevant account.
- Create signed public share pages for generated clips when you choose to share a clip to Snapchat or another destination that uses link sharing.
- Monitor YouTube, Twitch, or TikTok live source URLs you add and start clip jobs when those sources appear live.
- Secure the service, prevent abuse, debug errors, enforce usage limits, and maintain reliability.
- Comply with applicable law, platform rules, and valid legal requests.
Google, YouTube, and Drive Data
isalootu uses Google APIs, including YouTube API Services and Google Drive API features, only to provide user-facing features that are visible in the app, such as connecting a YouTube or Google Drive account and uploading a generated clip when you request an upload. Google's own privacy practices are described in the Google Privacy Policy.
The use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, transfer it to data brokers, or use it to determine creditworthiness or eligibility for financial products.
We request the minimum Google permissions needed for the selected feature. If our use of Google, YouTube, or Drive data changes, we will update this policy and request any consent required before using that data for a new purpose.
TikTok Data
isalootu uses TikTok OAuth data to connect your TikTok account and upload or publish generated videos to TikTok when you request it. Depending on the app configuration, connected scopes, and TikTok platform rules, TikTok may publish directly or require you to finish review inside TikTok.
Twitch Data
isalootu uses Twitch OAuth data to identify your connected Twitch channel, monitor that channel's public live URL when you enable channel monitoring, and create native Twitch clips when you request Twitch clip creation. The app does not upload rendered MP4 files back to Twitch.
Bluesky Data
isalootu uses Bluesky session data to publish generated video posts when you request Bluesky posting. Bluesky video-post URLs may also be used as clip sources through public Bluesky APIs.
Snapchat Sharing
isalootu does not store Snapchat OAuth credentials. Snapchat sharing creates a signed public page for a generated clip and opens Snapchat's share flow with that page URL. Anyone with the signed share-page link may be able to view the page and access a short-lived signed download URL while it is valid.
Storage and Security
OAuth tokens are encrypted before storage. Generated media is stored in the configured object storage bucket and is made available through signed URLs. Snapchat share pages use unguessable signed links but are public to anyone who has the link. We use reasonable technical and organizational safeguards, but no internet service can guarantee absolute security.
Sharing and Processors
We share information only as needed to operate the service, complete actions you request, comply with law, investigate abuse, or transfer the service as part of a merger, acquisition, financing, or sale of assets. Service providers may include hosting, database, queue, object storage, LLM, video processing, Google/YouTube/Drive, TikTok, Bluesky, Snapchat link sharing and source access, Twitch source access through video tooling, and logging providers. We do not sell your personal information.
Your Choices
- You can disconnect YouTube, Google Drive, TikTok, Twitch, or Bluesky from the dashboard. Disconnecting removes stored OAuth or session credentials from our database. For YouTube and Google Drive, the app also attempts to revoke the Google token when you disconnect. For Twitch, the app attempts to revoke the Twitch token when you disconnect. You can also revoke Google access directly from Google's app permissions page.
- You can delete completed, failed, or queued jobs from the dashboard when deletion is allowed by the app.
- You can request account deletion, OAuth token deletion, clip artifact deletion, or a copy of account data by contacting us.
Retention
We keep account records while your account is active. OAuth credentials are kept until you disconnect the integration, delete your account, or request deletion. Job records and generated artifacts are kept until you delete them, request deletion, or we no longer need them to provide the service, maintain security, or comply with legal obligations. Temporary rendering files are intended to be short-lived and may be deleted automatically by the worker environment.
Children
The service is not directed to children under 13. Do not use the service if you are not old enough to use it under the laws that apply to you or the connected third-party platforms.
International Use
The service may process and store information in the United States or other countries where our providers operate. By using the service, you understand that information may be transferred to countries with different data protection laws than your country.
Changes
We may update this Privacy Policy from time to time. If changes materially affect how we use personal information or connected account data, we will provide notice appropriate to the change and, where required, request consent.
Contact
Questions, deletion requests, and privacy requests can be sent to isalootu.n5fls@passmail.net.