HQ privacy policy
Owner-operated workflow: YouTube connection, publication and data maintenance are restricted to the private HQ dashboard and authorized server processes. Their status must be checked separately; publishing this information page does not activate a connection or confirm that an upload, publication or maintenance operation has completed.
Version: 2026-09-10. Hofudstodvarnar (HQ) is a private, owner-operated creative-work tool, not a public service.
Information used by the YouTube connection
HQ uses YouTube API Services. It receives authorization tokens, the permissions actually granted and their expiry, available channel IDs and names, and the selected channel. For an approved upload it processes the video’s ID, title, description, category, visibility, audience and disclosure settings, processing status and publication link. Some response fields are used only to verify the upload and preserve existing video settings.
The owner supplies the original video and publication text. HQ also keeps approval and workflow records, including the connection, status, timestamps and limited publication evidence. Tokens and resumable-upload addresses are kept server-side in Supabase Vault. Vault encrypts secrets at rest; authorized server processes can decrypt them. This is not end-to-end encryption.
Purposes and recipients
This information supports channel selection, owner-approved uploads, result verification and connection maintenance. Google/YouTube receives authorization and upload requests. Vercel runs the web application; Supabase provides its database, private media storage and secret storage. The owner and her authorized server processes can access the information needed for these functions.
The owner’s authorized AI assistant uses OpenAI’s Codex. The assistant may process publication text and workflow context supplied by the owner. The YouTube upload, continuation and reconciliation commands return only the internal job ID, state and publication link; OAuth tokens are not included in those command results. Information included in the assistant’s conversation is also processed by OpenAI; see the OpenAI Privacy Policy. HQ does not itself call an AI model to maintain the YouTube connection.
Limited Use
HQ’s use and transfer of information received from Google APIs must adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google data must be used only for the disclosed, owner-facing features, and must not be sold or used for advertising profiles, credit decisions or general-purpose AI training. The owner does not authorize training on her information. Before Google API data is supplied to an AI-assisted publishing workflow, its operator must ensure that the AI service’s data controls exclude general-purpose model training. Processing a request and training a model are separate uses. This policy does not certify the current account-level settings of the separately operated AI service.
Cookies and browser storage
HQ uses a session cookie to protect the private dashboard and short-lived, HTTP-only cookies to bind Google’s callback and channel selection to the owner’s browser. These public information pages do not add advertising or analytics cookies. Google applies its own policies during authorization; see the Google Privacy Policy.
Revocation, deletion and retention
You can revoke HQ’s access in your Google Account permissions and request deletion of HQ’s stored YouTube API data by contacting mdottirhelga@gmail.com. Google revocation can affect all permissions granted by that Google account to the same OAuth project, not just one channel.
Authorized API-data deletion requests must be completed as soon as possible, within seven days. Other stored YouTube API data must be refreshed or deleted within 30 days; data associated with access revoked through Google must also be removed within that limit. Authorization tokens are retained only while required for the connection or completing its revocation. An unsuccessful revocation or cleanup must not be presented as completed.
Removing HQ’s API data does not delete videos on YouTube or the owner’s original media, authored text and unrelated project work. Those are separate from API-derived connection and publication data. This policy does not promise instantaneous removal from infrastructure backups or from a separately operated assistant’s conversation history.
Backups and local testing
The hosted HQ database has daily Supabase backups with access to the most recent seven days; point-in-time recovery is not enabled. These database backups do not include media files stored through Supabase Storage. Seven days of accessible backups is not a guarantee that every infrastructure copy is permanently erased on day seven.
The local test database is stored separately on the owner’s computer and is not covered by that hosted backup setting. A deletion request must account for the relevant local or hosted API-data copies. Original media and separately retained assistant conversations require their own handling; a database cleanup does not erase them.
Contact
Privacy questions and deletion requests: mdottirhelga@gmail.com.