Data and permissions
Privacy Policy
1. Application and responsible operator
CLIPOPS is an internal content-production application used by its operator for the Zyvrix brand, not a public service for connecting other people's accounts. The primary business direction is paid clipping assignments and campaigns, currently in gaming; supplementary uses include properly licensed esports recordings and original productions from owned, licensed or generated materials. Single-operator use does not mean exclusively operator-owned media. The full autonomous original-production workflow is a target, not a claim of a currently implemented feature. This notice covers the local media workflow, YouTube integration and informational website. Bohuslav Horký, a natural person in the Czech Republic, operates CLIPOPS and is responsible as controller for personal-data processing that he determines through it. Zyvrix is a brand, not a separate legal entity.
Privacy and support: clip.ops11@gmail.com. Website domain: zyvrixmedia.com.
2. Information handled by CLIPOPS
- Supplied media: source video and audio, source paths or URLs, source identity, rights evidence and campaign association. Rights evidence should identify the specific source or campaign and the valid scope of permitted acquisition, processing, commercial use and destinations; it is not permission inferred from a public URL. Derived files include extracted audio, timestamped transcripts, subtitles, rendered clips and preview frames.
- Production records: titles, descriptions, proposed visibility, file hashes, selected segments, evaluation reasons, moderation results, publishing drafts, action history and error/status records.
- Google authorization: OAuth access and refresh tokens, granted scopes, expiry information and client configuration. Authorization is handled by Google; the application does not ask for a Google account password.
- YouTube API data: authorized channel ID, handle, title and account-status fields; for managed videos, external video ID and URL, visibility, processing state, publication time and available view, like and comment counts. Comment counts are different from comment text; the inspected publisher does not collect viewers' comment bodies.
CLIPOPS uses these records to organize campaign and source information, process supplied content, identify the appropriate thematic channel, check account availability, assess a clip, preserve the approved upload parameters, track upload outcomes and retrieve basic performance observations. These purposes support the operator’s paid-clipping business direction and permitted supplementary content activities; they do not establish that any particular campaign or source has been authorized. A support or privacy email also supplies the sender's contact details and request, used to respond and document its handling.
Historical test material
Earlier test media and derived transcripts may contain other people's gaming nicknames, usernames or voices. The operator has no separately documented legal basis for processing those people's data. These materials are classified solely as non-public historical test data. They are not authorized for public publication or reuse as production sources, and are not evidence that the production data-processing requirements have been met. This classification does not establish a legal basis for their retention, resolve past processing or mean that the files have been erased.
Production sources and legal bases
Before any new external source is used in production, the operator must document the basis for the intended acquisition, editing, commercial use and destinations, and separately address any processing of identifiable people for that specific use case. This includes relevant nicknames, usernames and voices, derived transcripts and any proposed external AI processing. Neither a licence, public availability nor a campaign brief automatically establishes that basis. The actual terms and supporting evidence must cover the intended use. If the necessary evidence is missing or its scope is unclear, the source must not be used in production or published. Evidence may cover further clips only while the source and proposed processing remain within its documented scope.
Other processing purposes
This business description does not establish licences, consent from people appearing in recordings or the terms applicable to external recipients. Copyright permission and Google OAuth authorization are not automatically consent under data-protection law for every person appearing in a recording. A source or campaign permission may cover multiple clips within its valid scope; that does not remove separate personal-data obligations.
- Account operation and protection, website availability and security, and ordinary non-contractual support: Article 6(1)(f) GDPR — the operator's legitimate interests in running and protecting the service and responding to enquiries. Processing is limited to the identifiers, technical information and correspondence needed for those purposes. The operator has assessed the purpose, necessity and balance of interests: limited expected use, no visitor profiling, access limited to the operator and necessary providers, and the right to object. Support that is necessary for a contract with the individual, or for steps taken at that individual's request before a contract, falls under the next basis instead.
- Negotiating and performing an assignment with an individual: Article 6(1)(b) GDPR — performance of a contract or steps before entering into a contract at that individual's request, limited to the data necessary for that purpose.
- Handling GDPR data-subject requests: Article 6(1)(c) GDPR — compliance with the operator's obligations under the GDPR, including Articles 12–22 where applicable, limited to the information needed to verify and handle the request.
These bases do not authorize processing people appearing in media, including their nicknames, usernames or voices. The source-specific and use-case-specific evidence requirement above continues to apply. They do not retrospectively authorize historical test processing.
3. Google and YouTube permissions
CLIPOPS uses YouTube API Services. Its active declared OAuth scopes and the grant verified in the latest authorization flow are limited to:
https://www.googleapis.com/auth/youtube.upload— permits video uploading.https://www.googleapis.com/auth/youtube.readonly— permits reading YouTube account and video information.
Possessing a scope is not permission for every possible action. Publishing is currently disabled. The Google authorization screen, OAuth verification and YouTube API compliance audit are separate processes; this document does not claim approval of any of them.
Google's processing is described in the Google Privacy Policy.
4. Storage and access
Operational records are stored in a local PostgreSQL installation. Media and processing artifacts are stored on the Windows project host. Database backups cover the operational, workflow and memory databases and can contain copies of stored records.
The YouTube token document is encrypted with Windows DPAPI for the current Windows user and saved in the project's restricted secret location. The Desktop OAuth client configuration is a separate local JSON file protected by filesystem access controls; it is not the same encrypted token file. These mechanisms do not establish encryption of all media, database contents or backups.
The project owner and authorized technical operators with host or database access can access operational data. Workers use restricted database interfaces. These controls reduce access but are not a guarantee against every security incident.
5. External recipients
- Google / YouTube: receive authorization and account-check requests. When separately permitted and enabled, uploading sends the final video, title, description and visibility to YouTube. This website does not upload anything.
- Previous Nous Research inference route (disabled): the previous route could receive transcript and caption text, candidate excerpts, duration and quality context for selection, evaluation and metadata assistance. The inspected text-review route does not send the whole video file. Local transcription does not mean every later review stays on the device.
- Previous OpenAI ChatGPT-plan fallback in Hermes (disabled): the previous fallback could receive the same text evidence. OpenAI describes using a ChatGPT plan in other apps and lists Hermes Agent in its supported apps directory. The installed integration uses Hermes's own OAuth credential mechanism and ChatGPT transport. General support does not certify this installation or its account-specific terms. This route is distinct from API-key moderation; API retention rules must not be applied to it by assumption.
- Direct OpenAI API (active): management, content research, text review, context compression and memory extraction use the direct OpenAI API. Relevant inputs can include instructions, transcript and caption excerpts, production context, tool results and text used for memory extraction or embeddings. The text-review route does not send the whole video file. The previous Nous and ChatGPT-plan routes are disabled and are not fallbacks. Responses are requested with response storage disabled; this does not mean zero retention. Replacing a provider does not remove information previously sent to it.
- OpenAI Moderation API: a separately approved moderation action can send transcript text, final captions, title/description and sampled frames from the final video. It is not a continuous scan of all footage. The current integration requires approval tied to those inputs; a safe service smoke test is not approval to send personal footage.
- Website hosting — Cloudflare Pages: Cloudflare provides static hosting for this informational website. The website domain is zyvrixmedia.com; the Pages address is zyvrixmedia.pages.dev. Cloudflare Web Analytics is not enabled. Cloudflare processes technical visitor information, such as IP addresses and traffic/routing metadata, to deliver and protect the website, as described in its Privacy Policy. Disabling Web Analytics does not eliminate this infrastructure processing. The hosting contains only the public static files, not the CLIPOPS database, media or credentials.
No advertising, analytics or data-sale integration is included in these static pages or the inspected publishing modules. The following settings are confirmed by the operator:
- Nous: Privacy Mode enabled for the account previously used by CLIPOPS.
- ChatGPT/Codex: “Improve the model for everyone” and “Include environments” disabled.
- OpenAI API: voluntary sharing of feedback, evaluation/fine-tuning data and inputs/outputs disabled for the organization/project used by CLIPOPS.
These settings do not mean zero retention or deletion of earlier requests. The Nous Privacy Policy describes Privacy Mode limits on inference-payload use and storage, with operational metadata and security/legal exceptions. ChatGPT controls and OpenAI API data controls apply to different services.
Under the standard OpenAI Services Agreement, the Data Processing Addendum covers personal data processed on the customer's behalf. OpenAI acts as processor for that data. This differs from its handling of its own account and billing information. API content is not used for training by default. Default abuse-monitoring retention for Responses and embeddings is up to 30 days, with stated legal and safety exceptions; response-storage settings do not eliminate every retention category. No Zero Data Retention approval is claimed.
International processing
Local processing does not mean EU-only processing. OpenAI's DPA provides for EEA customer processing through OpenAI Ireland and safeguards for onward transfers, including standard contractual clauses or adequacy decisions. No EU-only configuration is claimed. Cloudflare is the selected infrastructure provider and publishes a data-processing addendum describing its processing and transfer safeguards. No EU-only hosting or account-specific retention exception is claimed.
Disabling the previous Nous and ChatGPT-plan routes does not remove obligations concerning information already sent to those services. These historical obligations remain separate from the active API service. No separately negotiated provider agreement or account-specific retention exception is claimed. Any sharing of Google-derived information must separately meet applicable Google/YouTube restrictions; copyright permission does not resolve that question.
6. Retention: local media and operational files
Scoped local lifecycle recording and automatic cleanup are active. The following rules apply to registered files in the managed working areas:
- Unneeded previews and temporary files: eligible for cleanup 30 days after they are recorded as no longer needed.
- Working sources and transcripts: eligible 90 days after the relevant work and its dependencies are documented as closed. Completing a single render does not close all follow-on work.
- Reusable originals: retained while a documented purpose remains, with a review every three calendar months. The review itself does not authorize deletion.
- Ordinary operational logs without API data: eligible 30 days after the writer closes the recorded log segment, not merely after a file's modification date.
Before removal, the system rechecks file identity, current dependencies and holds. Active work, shared files and documented reuse protect a file from routine cleanup. Historical or unclassified files without the necessary lifecycle evidence are not deleted merely because they are old; their purpose and disposition still need to be resolved. Final clips without an approved retention rule are outside this cleanup.
Eligibility is not a guarantee of removal at an exact instant. Scheduled processing is bounded and a failed or uncertain check postpones deletion. These safeguards do not justify retaining personal data indefinitely. Separate applicable deletion duties still require handling.
7. YouTube API records, tokens and other copies
The local-media rules above are not a blanket retention schedule for YouTube API data, authorization tokens, audit records, repository history or backups. Tokens are held for authorized account access and must be addressed when access is disconnected or no longer needed; they are not removed by media cleanup.
The YouTube Developer Policies require most stored API data to be refreshed or deleted within 30 days. Authorized statistics have a separate rule permitting longer storage subject to regular verification of authorization and video availability. A new backup or an account-health check does not refresh all copied API data.
Operator tools for API-record removal, removal of identified API values from audit and workflow copies, and recovery after interrupted disconnection are installed. They preserve non-payload evidence of the removal. Their destructive execution is not automatically enabled, and periodic all-copy API maintenance is not active.
Existing backups and repository history can contain API copies. A complete removal must address the affected copies and keep an independent recovery record so a later restore does not return erased data to use. The existing procedure requires a verified recovery location and a scoped decision about affected backups and history before it can complete this process. Those conditions remain unresolved. No request to erase the current active account has been made; this does not suspend ongoing freshness or data-minimization duties.
8. Requests and account disconnection
Contact clip.ops11@gmail.com for access, correction, disconnection or deletion requests. Identify the channel or material concerned and the requested scope. The operator may need proportionate information to establish identity and authority; do not send passwords or tokens.
You can also remove CLIPOPS access through Google Account security settings. Google revocation affects authorization, not the automatic removal of local copies or YouTube videos. The operator's disconnection procedure first establishes the affected project grant and accounts, then records revocation and resumes local removal from the recorded state if interrupted.
YouTube's rules require deletion of applicable stored data within seven days of a user's deletion request; revocation through Google settings requires deletion within 30 days. An application-initiated revocation requires immediate token revocation and deletion of related data within seven days. These are obligations, not evidence that the currently incomplete all-copy procedure already meets them. The contact address is not a substitute for resolving the conditions in section 7.
Removing CLIPOPS-held data does not automatically delete published videos. Manage those videos using YouTube's own controls.
9. Your data-protection rights
Where the GDPR applies, you may request access to and correction of your personal data, erasure, or restriction of processing. You may object to processing based on legitimate interests. Portability applies in the circumstances specified by law, including certain automated processing based on consent or contract. If processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. These rights are subject to their legal conditions.
Requests must be handled without undue delay and normally answered within one month. A lawful extension for complexity or the number of requests must be explained within that first month. A shorter applicable YouTube data-deletion deadline is separate from this response period.
You may complain to the Czech Office for Personal Data Protection or another competent supervisory authority. See the European Commission's information on individual rights. The described clip-scoring workflow evaluates media for the operator; it is not designed to make decisions about individuals with legal or similarly significant effects.
10. This website and effective date
The selected hosting is static Cloudflare Pages. Cloudflare Web Analytics remains disabled; the operator adds no analytics, cookies, forms, login, embedded media, advertising or third-party fonts. The operator has not enabled the separate Pages Web Analytics feature. Following an external link involves the linked service and its own policies. Cloudflare still processes infrastructure traffic data as described in section 5; the absence of analytics or operator-set cookies does not mean zero processing or zero retention.
This notice takes effect on the effective date shown above. Changes to the described processing will be reflected in an updated notice. Domain ownership, this notice and OAuth consent do not establish Google verification or YouTube API audit approval.