Curio Factory · PulseCurio
Privacy Policy
This policy covers all of Curio Factory, including PulseCurio. The canonical version is published at curiofactory.online/privacy.
1. Who we are
Curio Factory is an independent content operation run by a single individual, who owns and operates the YouTube channels PulseCurio, BotCurio and StatCurio and the websites pulsecurio.com, botcurio.com, statcurio.com and curiofactory.online. In this policy, "we" and "our" refer to that operator. You can reach us at privacy@curiofactory.online.
2. What this policy covers
This policy covers the Curio Factory application — a private, internal tool used by its operator to produce and publish videos to the operator's own YouTube channels. The application has no public interface, no user accounts and no sign-up process. It is used by one person: its owner.
3. We do not collect personal data from you
The Curio Factory application is not a service offered to the public. It does not have visitors or users other than its operator. It collects no personal information from viewers of our videos, from visitors to our websites, or from any other person. We operate no advertising network, set no tracking cookies of our own, and maintain no mailing list, customer database or user profiles.
If you watch our videos on YouTube, your relationship is with YouTube, and Google's own privacy policy governs the data YouTube collects about you. We have no access to your identity, and we do not attempt to obtain it.
4. Data we access through Google APIs
With the operator's own authorisation, and only for the operator's own Google account, the application accesses:
- the identifiers and titles of the three YouTube channels the operator owns;
- records of the videos the operator has uploaded — IDs, processing status and visibility state;
- aggregate performance statistics for those videos, such as view counts, average view duration and audience retention.
The application does not access, request or store data about any other channel, any other creator, or any individual viewer. It does not read comments, subscriber identities, or any personal data about identifiable people.
5. Why we access it
Solely to publish our own videos and to understand how our own videos perform, so that we can make better ones. There is no secondary purpose. We do not use this data for advertising, profiling, resale or any purpose unrelated to running our own channels.
6. Limited use of Google user data
Curio Factory's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Concretely, this means we:
- use Google user data only to provide and improve the functions described in this policy;
- do not transfer Google user data to any third party, except as required by law;
- do not use Google user data for advertising purposes of any kind;
- do not sell, rent or licence Google user data;
- do not allow humans to read Google user data, except the operator acting on their own account, or where required for security purposes or to comply with applicable law.
7. How we store and protect it
Data is held in a managed PostgreSQL database in the European Union and on a private virtual server controlled by the operator. Access credentials, including OAuth tokens, are stored encrypted at rest and are never committed to source control — a check enforced automatically on every code change. Administrative access requires a password plus two-factor authentication over an encrypted connection. Credentials are rotated on a quarterly schedule.
8. Third-party services we use
We use third-party providers for content production: Anthropic (script generation), JSON2Video (video composition and speech synthesis), Pexels (licensed stock media), Supabase (database hosting), Google Drive (file storage) and Telegram (the operator's private notifications). None of these providers receives any data obtained from the YouTube API, and none receives any Google authorisation token. They receive only the content we are producing.
9. Retention and deletion
Performance statistics about our own videos are retained for a rolling period of 24 months; API request logs for 90 days; rendered video files for a rolling 12 months. OAuth tokens are held until revoked or rotated. If the operator ceases to run the channels, all stored data obtained from Google APIs is deleted and the authorisation is revoked.
10. Revoking access
The operator may withdraw the application's access to their Google account at any time at myaccount.google.com/permissions. Doing so immediately ends all access; any data already stored is deleted on request to the address below.
11. Children
The application is an internal production tool and is not directed at children. It knowingly collects no data from anyone, including children.
12. Changes to this policy
If this policy changes, the revised version will be published at this address with an updated effective date. Material changes affecting how Google user data is handled will be reflected here before they take effect.
13. Contact
Questions about this policy or about data handling: privacy@curiofactory.online.