Privacy policy
Last updated: 6 October 2026
Core Clips is operated by Allen Anant Thomas of The Growth Engine for his private video workflow. It is not available for public account registration. Contact: allen@thegrowthengine.net.
What the application accesses
The application requests the Google Drive scope https://www.googleapis.com/auth/drive. This permits access to all files in the consenting account. Application checks restrict its workflow to the verified owner account and configured Core Clips archive folders.
Connection validation reads Google account identifiers and archive metadata, including folder and file identifiers, names, ancestry, permissions, sizes, checksums and application properties where available. It can also check a token's account, application, granted permissions and expiration with Google. The archive workflow can read or download video and related project files and upload new project files when those operations are enabled.
Core Clips also uses YouTube API Services. Its separate YouTube connection requests https://www.googleapis.com/auth/youtube.force-ssl to verify the authorized channel, upload finished videos and thumbnails, update publication metadata and check processing and privacy status. This scope can also view, edit or permanently delete videos, ratings, comments and captions; the application does not use the grant to manage comments or captions or automatically delete existing publications.
YouTube data used by the workflow includes the authenticated channel identifier, video identifiers, titles, descriptions, thumbnail references, upload processing status, privacy and scheduled-publication settings, and responses needed to verify a specific upload. Google's handling of this data is described in the Google Privacy Policy.
Why it uses this data
The data supports account and folder verification, locating existing archives, preserving source media, avoiding duplicate work, resuming transfers and checking that retained copies match their source. The dedicated connection's initial validation is read-only and does not automatically activate production writes.
Storage and access
OAuth credentials are stored in restricted private files on the owner's VPS. Credentials are not included in public pages, project reports or routine logs. The VPS retains operational metadata and verification receipts; local media may be retained while it is needed for the workflow. Google Drive retains the archive files.
Google processes authorization, Drive and YouTube requests. Hostinger provides the VPS hosting the application and its private files. Neither provider's service is represented as having been independently certified by this project.
AI-assisted work
Core Clips is an AI-assisted workflow. When its editorial stages are enabled under the owner's instructions, selected source excerpts, audio, frames, transcripts and related context may be supplied to Codex/OpenAI to help analyze or edit that specific material. Initial Drive connection validation does not send file content for AI processing.
Google user data must not be used to train general-purpose AI models. Any AI processing of that data must stay within the owner's authorized Core Clips task and use provider settings and arrangements consistent with that restriction. This statement does not claim that the AI stages are currently enabled or accepted.
Sharing and limited use
The application does not sell Google user data, use it for advertising, or provide it to data brokers. It uses and transfers data only to provide the disclosed Core Clips workflow under the owner's instructions. Connecting Drive does not itself publish archive files or change their sharing permissions.
When separately enabled after its access and quality checks pass, the wider Core Clips workflow can send finished videos, thumbnails, titles, descriptions and related publication metadata to YouTube/Google for private upload checks and scheduling or public release under the owner's instructions. Public releases make the selected material visible to viewers. YouTube connection and publication acceptance checks remain incomplete, and publishing is disabled until they pass. Initial Drive connection validation does not perform these transfers.
Core Clips's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
The additional Google Workspace user data and developer policy also applies to Drive data, including its restrictions on transfers and general-purpose model training.
Retention, revocation and deletion
Credentials are retained while the connection is needed. Operational records and source material are retained for continuity, verification and recovery; there is no claimed automatic deletion schedule. The owner can stop the worker and revoke this application's access through Google Account connections.
Revoking access prevents future authorized requests but does not delete files already stored in Drive or on the VPS. The owner can request removal of local credentials or retained project data by contacting the address above. Deletion is handled deliberately so it does not remove protected originals or unrelated files.
YouTube API response data is refreshed or deleted within 30 calendar days. Requests to delete stored YouTube API data are handled as soon as possible and within seven calendar days. Revocation-related data removal is handled as soon as possible and within 30 calendar days. These limits apply to data obtained through YouTube API Services, independently of the retention of owner-provided original media and project files. Deleting the application's local API data does not delete videos or account data held by YouTube.
To revoke access, use Google Account security permissions. To request removal or ask a privacy question, email allen@thegrowthengine.net and identify the connection or project involved. No Google password is requested or stored by Core Clips.
This information site
These pages have no account forms, payment processing, tracking scripts or analytics. A hosting provider may process ordinary connection and access logs to serve the pages.
Changes
This policy will be updated before materially different data use is enabled. Any additional permission requiring the owner's consent must be requested explicitly.