Policy

Privacy Policy — Verumthea

Effective date: 27 July 2026

1. Who operates the service

Verumthea is an independent project operated by an individual creator based in France. The public-facing application described by this policy is Verumthea Media Automation.

2. Scope of this policy

This policy covers the public Verumthea website, Verumthea Media Automation, its use of Google OAuth, and YouTube API data handled by the application after explicit authorization.

3. Data collected by the public website

This static site does not intentionally use cookies and does not include analytics, advertising pixels or account registration. When the website is deployed, Cloudflare may process standard network, diagnostic and security data needed to serve and protect the site under its own infrastructure and policies. This means routine infrastructure logs may exist even though Verumthea does not add tracking to these pages.

4. Google account and YouTube data

After the operator explicitly authorizes access, the application may process:

  • Google account authorization identifiers needed for OAuth;
  • OAuth access and refresh tokens;
  • the selected YouTube channel identity;
  • video identifiers and metadata;
  • captions;
  • upload, processing and publication status; and
  • limited API response information required for validation and receipts.

The application does not request or process the operator’s Google password.

5. Why data is used

Relevant data is used only to authenticate the operator, bind the correct account and channel, perform explicitly authorized YouTube operations, validate state, prevent duplicate or incorrect operations, preserve bounded operational evidence, and maintain security and troubleshooting records.

6. Sensitive Google scope

The application requests https://www.googleapis.com/auth/youtube.force-ssl. In plain language, this scope can permit management of YouTube resources such as videos, captions, ratings and comments. Verumthea Media Automation uses only the features necessary for the operator-controlled workflow; the scope does not mean that every available permission is exercised continuously.

7. Token storage and security

OAuth tokens are stored in protected operating-system credential storage. They are not published in source code, public documents or website files. Access is limited to the authorized operator and the application runtime. Data is transported using HTTPS, and least-privilege and account-and-channel binding controls are applied to reduce unauthorized or incorrect use.

8. Sharing and sale

Personal data is not sold. Google user data is not used for advertising and is not shared with unrelated third parties. Infrastructure providers may process limited data as necessary to provide hosting, security or Google API functionality. Information may also be disclosed when legally required.

9. Retention

Operational records are retained only as long as reasonably necessary for security, validation, troubleshooting and legal obligations. OAuth credentials remain until revoked, expired or deleted by the operator. Failed or obsolete credentials are removed through controlled procedures.

10. Revocation and deletion

The operator can revoke the application’s Google access through their Google Account security settings. To request deletion or ask a privacy question, contact verumthea@gmail.com.

11. International processing

Google and Cloudflare may process data in multiple jurisdictions under their respective safeguards, terms and policies. Where applicable, data-protection requirements governing international transfers continue to apply.

12. Data-protection rights

Depending on the circumstances and applicable law, individuals may have rights of access, rectification, erasure, restriction, objection, and portability. These rights are not absolute and may not apply in every circumstance. A person may also lodge a complaint with the competent supervisory authority, including France’s CNIL where applicable.

13. Children

The application is not directed to children and does not offer public account creation.

14. Google API Services User Data Policy

Verumthea Media Automation’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements, where applicable.

15. Changes to this policy

Material changes will be published on this page, and the effective date will be updated to show when the revised policy takes effect.

16. Contact

For privacy questions or requests, email verumthea@gmail.com.