Privacy Policy
Contact and privacy requests
Privacy, deletion, billing, takedown, or API questions: [email protected].
Cookies and similar technologies
- __Host-ysf_guest_session: signed guest workspace cookie. HttpOnly, Secure in production, SameSite=Lax, path=/, 7-day lifetime.
- __Host-ysf_account_remember: issued after you sign in with Google so you stay signed in across visits. HttpOnly, Secure in production, SameSite=Lax, path=/, 30-day lifetime, rotates after 7 days of use.
- cf_dfp: a SHA-256 hash of browser signals (canvas rendering, WebGL renderer, screen, timezone, language) used only as an anti-abuse signal. Readable by browser scripts, SameSite=Lax, 30-day browser lifetime; the server-side abuse record is swept after 90 days.
- Cloudflare edge cookies such as __cf_bm or cf_clearance may additionally be set by Cloudflare's bot-management and challenge layer when traffic is proxied through Cloudflare.
What marly.studio collects
- Cookies and similar identifiers (listed above) used to keep you signed in, persist login across sessions, and surface abuse signals. marly.studio does not use any advertising or cross-site tracking cookies.
- Server-side remember-token records are stored as hashes, pruned when expired, and capped per account so old sign-in devices do not accumulate indefinitely.
- If you connect Google, account identifiers such as your Google subject ID, email address, email verification state, and basic profile fields returned during sign-in.
- If direct YouTube publishing is restored and you later authorize it, an encrypted Google refresh token, the granted Google scope list, the YouTube channel IDs and names returned for your account, and the video ID and URL returned after a successful upload. Authorization and channel records expire after 29 days unless you reconnect; each upload-returned video ID and URL is scrubbed 29 days after that upload regardless of reconnection.
- If you create agent tokens, hashed bearer-token grants including the display name you choose, selected scopes, audience, token prefix and suffix, expiry and revocation timestamps, last-used route, and last-used IP and user-agent hashes used for abuse monitoring and token management. The full raw token is shown once at creation and is not stored.
- Uploaded videos or submitted source URLs, source titles or names, platform hints, server-side import probe and download metadata such as duration, uploader, dimensions, chapter or heatmap availability, generated clips, clip titles and descriptions, transcripts, scheduling metadata, and related processing records needed to run the service.
- Diagnostic LLM traces when trace persistence is enabled, including prompt and response excerpts derived from transcripts, source titles, source URLs, engagement summaries, model or provider IDs, attempt metadata, and errors.
- Billing and payment records such as Stripe customer, checkout, portal, subscription, price, webhook event, one-time support payment, charge, refund, and dispute identifiers or audit references when paid plans or optional support payments are enabled.
- Operational and security data such as rate-limit keys, hashed IP and browser fingerprint signals, login events, revocation markers, audit events, failure reasons, short diagnostic snippets, object keys or source URLs needed for debugging, and feedback submissions.
- When first-party product analytics is enabled, short-lived event records containing a coarse app surface, normalized acquisition source and campaign code, bounded active-engagement increments, fixed landing interaction labels or scroll-depth bands, and workflow actions such as review, download, or publish requests. These records do not contain raw page paths, full referrers, search terms, emails, transcript text, media, mouse coordinates, keystrokes, or session replay.
How marly.studio uses that information
- Authenticate users and persist a workspace across devices.
- Ingest videos uploaded directly by users or submitted through approved non-YouTube source URLs, probe and fetch importable non-YouTube media with server-side import tooling, generate clips, queue jobs, play outputs back in the app, and provide MP4 downloads. YouTube audiovisual URL import and download are unavailable.
- Direct YouTube OAuth connection and publishing are temporarily paused during Google's compliance and quota review. If Google restores access, any separately reviewed restoration will be limited to user-initiated channel-target selection and explicit user-requested uploads; automated or public channel discovery, audiovisual import, and automatic publishing will remain unavailable.
- Process paid-plan billing, subscription changes, and optional one-time support payments through Stripe when those flows are enabled.
- Prevent abuse, investigate incidents, monitor system health, troubleshoot failures, and keep short-lived diagnostic traces when configured.
- Measure acquisition quality, landing-page clarity, workflow progress, review engagement, downloads, publishing, and retention using first-party aggregate analytics when that collection is enabled.
How marly.studio protects sensitive data
- Stored Google refresh tokens are encrypted at rest before they are written to marly.studio's database.
- In production, marly.studio is served over HTTPS and uses secure, HttpOnly, SameSite session cookies to protect authenticated sessions.
- Access to connected-channel records, jobs, source media, and generated clips is restricted to the authenticated workspace that owns them.
- Agent bearer tokens are stored as hashes with scoped permissions; raw token values cannot be recovered after creation and can be revoked from Settings.
- Account-changing requests are protected with trusted-origin checks, CSRF validation, signed session cookies, and rate limits.
- Operational abuse and sign-in monitoring uses hashed IP and browser-fingerprint signals instead of storing those values in raw form for those controls.
- Authorized media access links are signed, short-lived, and served with private no-store cache controls.
- Disconnecting Google or deleting an account immediately removes stored Google OAuth credentials used for YouTube features and connected-channel records. marly.studio attempts Google token revocation immediately; if Google is temporarily unavailable, an encrypted token-only request with no account, email, or channel identifier is retried. Its ciphertext expires after six days and is removed by the recurring retention sweep with material operational margin before the seven-calendar-day deletion commitment. Provider failure never blocks local deletion.
Data retention and deletion
- Basic Google sign-in identity remains with the workspace. YouTube authorization credentials, granted-scope records, channel IDs, and channel names expire after 29 days unless you reconnect. Each upload-returned video ID and URL is scrubbed 29 days after that upload even if you reconnect. Scope loss, Google disconnect, and account deletion trigger immediate deletion or scrubbing.
- Automated or public YouTube channel-discovery API data is not collected. If publishing is restored, the app will store the user's own channel IDs and names after explicit authorization only as needed for publishing-target selection, and will temporarily store the video ID and URL returned after a requested upload. Channel data follows the reconnectable 29-day authorization window; each upload result has its own non-extendable 29-day scrub deadline. New audit events and automatic ops alerts do not store or transmit returned video IDs or URLs, and legacy discovery identifiers are removed by the compliance migration.
- Agent-token grant records are kept while the account exists. Revoked or expired grant metadata remains as an operational security record, including the last-used route plus hashed last-use IP and user-agent metadata.
- Uploaded source objects are normally deleted after successful processing and completed output upload; abandoned pending uploads are recovered and cleaned by the worker's abandoned-upload sweep.
- Generated clip media and related output artifacts are retained for a limited rolling period, configured for up to seven days in normal operation, before expired artifacts are swept from object storage.
- Diagnostic LLM trace rows, when enabled, are retained for a short operational window, configured for up to seven days in normal operation.
- Actor-linked first-party product analytics events are retained for up to 45 days and are deleted with the related actor. De-identified aggregate reports may be retained for up to 13 months. Browser session replay is not collected.
- Production backup policy applies a four-day age cutoff, checked by a daily persistent backup-and-prune job, to encrypted database backups in both local and offsite storage. Before a disaster-restored database can replace live data, an unconditional compliance scrub removes Google and YouTube Authorized Data and invalidates OAuth-linked browser sessions, remember tokens, and device mappings. After a restore, you may need to sign in again and, if those features are available, reconnect Google or YouTube.
- Rate-limit and browser-fingerprint records have operational expiry windows. Security, audit, billing, dispute, abuse-prevention, login, revocation, and similar integrity records that do not contain Google or YouTube API Data may be retained as long as needed for those purposes, legal compliance, debugging, or dispute handling. Google and YouTube API Data remain subject to the shorter deletion and retention limits described above.
- You can delete your marly.studio account from the Danger Zone at the bottom of Settings. Account deletion starts removal of the app account and workspace data, attempts required Google and billing cleanup, and queues associated object-storage purges where needed. Media object deletion may complete asynchronously through the purge retry queue, and failed purge work may require operational follow-up. If your account is flagged or suspended so the in-app button is disabled, email [email protected] and we will handle the request manually. Some security, audit, billing, dispute, or legal-compliance records that do not contain Google or YouTube API Data may be retained as described above. Deleting your marly.studio account or app data does not delete data or content held by YouTube, including videos published to your channel; manage or delete that content separately in YouTube or YouTube Studio.
Google and YouTube data
Current service status: Google login is separate from YouTube publishing. Basic sign-in remains available, but direct YouTube OAuth connection and publishing are temporarily paused while Google reviews API compliance and quota access. YouTube audiovisual URL import and download are unavailable. Users can still upload source files, use approved non-YouTube source URLs, create clips, and download finished MP4 files. The continuity path is to upload those MP4 files manually in YouTube Studio.
If Google restores access, YouTube connection and publishing will remain paused until a separately reviewed restoration is deployed. Any restored YouTube API use will be limited to user-initiated target selection through channels.list?mine=true and explicit publishing through videos.insert. Public or Unlisted publishing will remain unavailable unless Google confirms or restores the API project's YouTube API upload-audit verification status. Before an upload request, the user must explicitly choose one listed owned channel target, Public, Private, or Unlisted, and an allowed YouTube video category; none of those choices has a preselected default. The user must also certify that they have the rights to upload the content and acknowledge their responsibility to immediately declare Made-for-Kids content on YouTube desktop. The action will be labeled Upload to YouTube, and the exact saved title, description, tags, and selected category will be sent without appending, truncating, stripping, inferring, or otherwise rewriting them; invalid values will be rejected for explicit correction. Before any restored YouTube OAuth flow begins, the user must explicitly accept the current version of this Privacy Policy and Terms and the YouTube Terms of Service. That restoration will not enable channel scanning, automatic publishing, or YouTube audiovisual import or download.
marly.studio requests the identity scopes below for the Google sign-in that remains available. Only if the separately reviewed YouTube restoration is activated will it also request the YouTube OAuth scopes below:
openid,email,profile: to identify you at sign-in and keep your workspace attached to your Google account.https://www.googleapis.com/auth/youtube.readonly: requested only when you explicitly start the restored YouTube authorization flow, to callchannels.list?mine=trueand show only the channel targets on your Google account. It is not used for channel discovery, channel scanning, or audiovisual import.https://www.googleapis.com/auth/youtube.upload: requested only when you explicitly start the restored YouTube authorization flow, and used withvideos.insertonly for clips you explicitly choose to publish.
marly.studio uses Google API data for sign-in. If the separately reviewed YouTube restoration is activated, it will also use Google API data for the limited user-initiated channel-target lookup and publishing operations described above, plus the status, audit, troubleshooting, and abuse-prevention records needed to operate them. YouTube authorization and channel data expire after 29 days unless reauthorized; each upload-returned identifier is scrubbed 29 days after its upload regardless of reauthorization. Automated or public YouTube channel discovery and audiovisual import are disabled. marly.studio does not sell Google API data or use it for advertising.
marly.studio is operated by a very small team. A human may read Google user data only when you have affirmatively agreed to the reading of specific data for a specific support purpose, when necessary for security or abuse investigation, when required by law, or after the data has been aggregated and anonymized for internal operations. For example, during a necessary security investigation into a suspected abuse pattern, marly.studio's internal admin dashboard may surface the email addresses of linked accounts to the operator. Billing and dispute records that are not Google API Data follow the separate handling and retention terms on this page.
marly.studio's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For more information about how Google handles data, see the Google Privacy Policy.
If you disconnect Google inside marly.studio, the app removes the Google credentials and connected-channel records stored by marly.studio for YouTube publishing. Revoking Google access stops future API access but does not itself delete other marly.studio workspace data. Deleting or disconnecting marly.studio data does not delete data or content held by YouTube, including videos already published to your channel. You do not need to disconnect to trigger expiry: authorization and channel records are deleted after 29 days unless you reconnect, while upload-returned video IDs and URLs are scrubbed 29 days after each upload regardless of reconnection. If provider token revocation cannot finish synchronously, the identifier-free encrypted retry ciphertext expires after six days and is swept with material operational margin before the seven-calendar-day deletion commitment. Security, billing, dispute, and legal-compliance records that are not Google API Data follow the separate retention periods described on this page. You can revoke access from your Google account permissions.
How information is shared
- Google and YouTube APIs: Google identity APIs remain available for sign-in. Direct YouTube OAuth connection and publishing are temporarily paused during Google's compliance and quota review. If access is restored and a separately reviewed restoration is activated, YouTube APIs will be used only to list the authorized user's own channel targets and upload clips that the user explicitly chooses to publish. Automated or public channel discovery, audiovisual import, and automatic publishing remain unavailable.
- Stripe: for subscription checkout, billing, customer portal, webhook synchronization, subscription management, optional one-time support payments, and billing-dispute handling. For subscription billing, Stripe receives account email plus internal account, actor, plan, and metadata identifiers needed to reconcile billing. For support payments, Stripe receives the selected support amount and bounded session or payment metadata. Stripe handles payment details directly on its own surfaces; marly.studio never stores card numbers.
- Cloudflare: for DNS and content delivery, for object storage (Cloudflare R2) of uploaded videos, generated clips, and encrypted offsite database backups when backup storage is configured, and for outbound egress proxying (Cloudflare Warp or regional proxy paths) that the worker can use when fetching imported videos. Cloudflare Web Analytics may also be enabled at the Cloudflare edge.
- OpenRouter (and, through it, the OpenAI-compatible inference providers and downstream model infrastructure it routes to, such as DeepInfra): used for AI analysis that finds interesting moments. It receives transcript text, video title, and engagement-signal summaries for each analyzed chunk. Request payloads are designed not to include your email, account ID, or IP address. We may change or add OpenAI-compatible inference providers over time.
- Remote transcription providers such as Soniox or Groq: used only when a provider is configured and local transcription is overloaded or unsuitable for a given job. When invoked, the provider receives the extracted audio track of your upload or imported video, transcription parameters such as model, language, or timestamp granularity, and any configured transcription prompt. Request payloads are designed not to include your email, account ID, or IP address. When Soniox is used, marly.studio asks Soniox to delete both the audio and the transcription record after use.
- Non-YouTube video import providers and platform endpoints: submitted non-YouTube source URLs may be probed and fetched server-side with provider-specific import helpers. YouTube audiovisual URLs are rejected and are not downloaded, cached, or processed.
- Discord: the in-app Feedback widget posts the text you write (and any contact string you voluntarily add) to a private Discord channel. Separate ops Discord channels may receive automatic job, publish, backup, digest, and failure alerts containing internal identifiers, source or clip titles, status and failure reasons, and redacted or hashed object-storage references where configured, but they do not receive upload-returned YouTube video IDs or watch URLs and are configured not to receive your email.
- Sentry: error, trace, and log monitoring when a DSN is configured. Browser replay recording is disabled; client, server, edge, and worker events are configured not to send default PII, and request cookies, headers, body data, and query strings are stripped before events are sent.
- Self-hosted infrastructure (our reverse proxy, application server, worker, and PostgreSQL database) used to run the service itself. User data held on that infrastructure is not transferred to third parties beyond those listed here.
marly.studio does not transfer or disclose Google user data to third parties for purposes other than providing the requested service, protecting the service, or using the infrastructure and processing providers described on this page.
marly.studio does not sell personal information or Google API data for advertising.
Where marly.studio runs
- marly.studio's primary application infrastructure (web, worker, PostgreSQL database) runs on self-managed VPS infrastructure. The deployment region may change as the service is moved for latency, reliability, capacity, or provider reasons.
- Object storage (Cloudflare R2) is distributed across Cloudflare's global edge; no specific region is pinned.
- Third-party processors named above (Google, Stripe, OpenRouter, Soniox, Groq, Discord, Sentry, Cloudflare) are primarily based in the United States or operate on global infrastructure.
- marly.studio is operated from New Zealand. New Zealand residents may contact us to exercise access, correction, or deletion rights under the Privacy Act 2020; residents of other jurisdictions with applicable privacy rights (for example, the EU/UK GDPR or California's CCPA) may also contact us to exercise those rights.