Legal

Privacy Policy

Last updated: 3 July 2026

Chillframe is a small product made by a small team. We collect only what we need to run it, we don't sell your data, and we want this policy to actually be readable.

1. Scope & controller

This Policy explains what personal data we process when you use Chillframe, the web service at chillframe.com that generates lofi YouTube videos with AI and (optionally) publishes them to a YouTube channel you own.

For the purposes of the EU and UK General Data Protection Regulations, the data controller is Chillframe. You can reach us at hi@chillframe.com for any privacy-related question. If you're in the EU/EEA or UK and we can't resolve a complaint, you can lodge it with your local supervisory authority.

2. Data we collect

What you give us directly

  • Account data. Your email address, and (if you sign in with Google) your name and profile image. We don't see your Google password.
  • Workspace data. The workspaces you create, the YouTube channels you connect to them, and the plan tier and subscription status you've chosen.
  • Inputs. The prompts, references, channel presets, and uploaded files you submit to generate videos.
  • Support & feedback. Anything you send us by email or via in-app feedback.

What we collect automatically

  • Usage events. Pages visited, videos generated, credits consumed, sign-in and billing events. We use this to run the product and to debug.
  • Device & log data. IP address, browser type, referrer, and timestamps for requests. These are kept in short-lived server logs.
  • Cookies. Strictly necessary cookies for authentication and security, plus consent-gated analytics and advertising cookies. See section 11.

What we get from third parties

  • Stripe. Billing status and the last four digits of your card. The full card number stays inside Stripe; we never see it.
  • YouTube. If you connect a channel, we receive the OAuth scopes you grant (typically channel ID, upload, and read-only analytics access). We don't read or store your private viewing history.

3. How we use data

We use the data above to:

  • create and operate your account, including signing you in via magic link or Google;
  • run the generative pipeline: turn your prompts into videos, schedule renders, and bill you the credits;
  • publish videos to YouTube channels you've connected, and read back basic performance data so the dashboard can show it;
  • charge subscriptions and trials, handle refunds, and meet our tax and accounting obligations;
  • send transactional emails (magic links, trial-ending notices, billing receipts, breach notifications);
  • monitor for abuse, fraud, and acceptable-use violations and keep the service secure;
  • improve the product: measure which features are used, debug errors, and prioritise new work.

4. Legal bases (EU/UK GDPR)

We rely on the following legal bases under Article 6 GDPR:

Contract
Running the service you signed up for: account, generation, publishing, billing, support.
Legitimate interest
Product analytics, abuse prevention, model and service improvement, and protecting our legal rights. We balance these against your privacy interests and limit what's collected.
Legal obligation
Tax records, fraud-prevention reporting, and responses to valid legal requests.
Consent
Analytics and advertising cookies (see section 11), optional marketing communications (if any), and any use of data outside the purposes listed above. You can withdraw consent at any time — for cookies, via the cookie-settings link in the footer — without affecting prior lawful use.

5. Sub-processors

We don't sell your data. We share it only with vendors that help us run the service, each under a data-processing agreement. Current sub-processors:

Cloudflare
Hosting, edge networking, DDoS protection, transactional email delivery.
PlanetScale
Managed Postgres for the application database.
Stripe
Payment processing, subscription management, billing portal.
Google (YouTube)
Sign-in (OAuth), and, if you connect a channel, uploads and analytics access. Subject to Google's privacy policy.
Advertising & analytics partners
Where the Analytics and Advertising choices in our cookie settings require your consent, we share conversion events and pseudonymous identifiers — cookie IDs, ad click IDs, IP address, browser user-agent, and a hashed form of your email address — with Google (Analytics and Ads), Meta, and TikTok only after you allow them, to measure our ad campaigns and build ad audiences. Where consent isn't required, the same sharing runs by default and you can opt out at any time; we also honour Global Privacy Control as an opt-out for advertising, unless you've explicitly turned Advertising on.
AI model providers
We use third-party generative models for music, image, and video synthesis. Inputs sent for generation may transit these providers' infrastructure. We contractually require them not to retain your prompts beyond what's needed to return the output and to honour deletion requests.
Error logging
Captures error stack traces and minimal request context. We scrub email and IP from error payloads where reasonably possible.

We disclose data outside these sub-processors only when we're legally required to (court order, lawful police request) or with your explicit instruction.

6. AI training

We do not train foundation models on your prompts or videos. We may use aggregated, de-identified usage data (for example: "the average user generates 4 videos per week") to improve prompt-handling heuristics and product UX.

Where a sub-processor's model would by default retain prompts for its own training, we configure the integration to opt out of training on user content. Where opt-out isn't supported, we don't use that provider.

7. YouTube data

Chillframe uses YouTube API Services. By connecting a channel, you agree to the YouTube Terms of Service and acknowledge the Google Privacy Policy.

Chillframe's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we access

With your permission, we request three YouTube OAuth scopes and no others. We never ask for access to your private playlists, subscriptions, or watch history.

youtube.upload
Upload videos to your channel and set the thumbnail, title, description, and visibility on the videos we publish for you.
youtube.readonly
Read your channel's public profile (channel ID, title, handle, thumbnail) and lifetime statistics (subscriber, view, and video counts) so we can identify the connected channel and show its headline numbers in the app.
yt-analytics.readonly
Read aggregate performance figures for the videos we publish (views, watch time, and subscriber change) so the dashboard can show how your content is doing.

How we use it

  • Publishing. We upload and publish videos on your behalf, only when you ask us to or have configured a series to do so.
  • Displaying performance. We read channel and video statistics solely to display them back to you inside Chillframe.

How we store it

  • Your OAuth refresh token (the credential that lets us upload on your behalf) is encrypted at rest using AES-256-GCM, with a fresh initialisation vector per encryption.
  • Channel and video statistics are cached so the dashboard loads quickly; this cache is refreshed periodically and is the only YouTube performance data we retain.
  • We re-verify your authorization at least every 30 days. Cached statistics are refreshed on this cycle; if your authorization is no longer valid we stop syncing and prompt you to reconnect.
  • For each successful channel connection we keep a permanent connection record — the workspace, the connecting user, the YouTube channel ID, and a timestamp. This record contains no statistics and no credentials; we retain it after disconnection or account closure to enforce Google's per-application connected-channel limits and to prevent abuse. It is never used for any other purpose.

How we share it

  • We do not use any data obtained from the YouTube Data API or other Google APIs — including your channel data, video metadata, analytics, or OAuth-derived information — to create, train, or improve any machine-learning or artificial-intelligence model. The models that generate your music and visuals are operated by third-party providers and are not trained on your YouTube account data.
  • We do not sell YouTube data, and we do not transfer it to third parties except as needed to provide the service (for example, our hosting and database sub-processors listed in section 5), or when legally required.

Who can access it

  • We restrict human access to data obtained from Google APIs. Our personnel do not read your YouTube account data except where you have given specific consent (for example, for support you request), where necessary for security or abuse investigation, where required by law, or where the data has been aggregated and anonymised for internal operations.

How to revoke access

  • In Chillframe. Open Settings → Channels and choose Disconnect on the channel. This revokes our access with Google and hard-deletes the cached YouTube data for that channel within 7 days.
  • In Google. Visit your Google account permissions page and remove Chillframe. Doing so disables uploads from Chillframe for that channel; we hard-delete the corresponding cached YouTube data within 30 days of detecting the revocation.
  • On request. You can ask us to delete the YouTube data we hold for your channel at any time by emailing hi@chillframe.com; we delete it within 7 days.

We never delete or modify videos already on your YouTube channel when you disconnect or close your account; that content is yours.

8. International transfers

Chillframe is operated from the United Kingdom, but several of our sub-processors are based in the United States. When personal data is transferred from the EU/EEA or UK to the US or to other countries without an adequacy decision, we rely on the EU Standard Contractual Clauses (and the UK addendum where relevant) and, where applicable, the EU–US Data Privacy Framework certification of the receiving party.

9. Retention

Account & workspace data
While your account exists, plus 30 days after deletion to recover from accidental deletes.
Generated videos
While your subscription is active. Once it ends, they remain downloadable for 30 days, then are deleted.
YouTube data
The cached channel and video statistics described in section 7 are hard-deleted when you disconnect a channel or close your account (within 7 days), or within 30 days of our detecting that you revoked access from your Google account.
Billing records
6 years after the transaction, as required by UK tax and accounting law.
Server logs & error reports
30 days.
Backups
Up to 35 days. Deletion requests are honoured in live databases immediately; affected backups age out within this window.

10. Your rights

Depending on where you live, you may have some or all of the following rights over your personal data:

  • Access the personal data we hold about you;
  • Correct data that's inaccurate or incomplete;
  • Delete your account and the data tied to it (subject to legal-retention exceptions, such as billing records);
  • Restrict or object to certain processing, especially anything we do under legitimate interest;
  • Portability: receive a machine-readable copy of the data you've provided and have us transmit it elsewhere where technically feasible;
  • Withdraw consent at any time for processing we do under consent;
  • Opt out of any "sale" or "sharing" of your personal information. We don't sell your data; the advertising cookies described in section 11 may count as "sharing", and you can opt out at any time via the "Do Not Sell or Share My Personal Information" link in the footer or a Global Privacy Control signal, both of which we honour;
  • Lodge a complaint with your data-protection authority.

To exercise any of these rights, email hi@chillframe.com. We aim to respond within 30 days. We may need to verify your identity before fulfilling certain requests.

11. Cookies & tracking

We use a small number of strictly-necessary cookies to keep you signed in, to remember the workspace you last used, and to protect the site from CSRF attacks. These are essential for the service to function and are always on.

Analytics and advertising cookies are optional, in two categories:

Analytics
Product analytics via PostHog and Google Analytics, so we can see which features get used and what to improve.
Advertising
Conversion measurement for Google Ads, Meta, and TikTok, so we can tell which campaigns actually work.

Where opt-in consent is required, both categories stay off until you allow them; otherwise they run by default and you can opt out. We honour Global Privacy Control signals as an opt-out for advertising — unless you've explicitly turned Advertising on. You can review or change your choice at any time from the cookie-settings link in the footer (labelled "Cookies", or "Do Not Sell or Share My Personal Information" where that applies).

We also set cf_first_touch, a first-party attribution cookie that remembers the UTM source, medium, and campaign plus the landing content path from your first visit, for 30 days. It contains nothing personally identifying. Where opt-in consent is required, it's only set after you grant Analytics consent; otherwise it's set on your first visit like the rest of our first-party analytics.

When advertising is enabled, we set a small set of first-party advertising identifiers so we can measure ad performance without a third-party pixel: cf_xid, a random visitor id kept for up to 365 days; _fbp, a random browser id; and, when you arrive from an ad, _fbc and ttclid, the ad click ids — each kept for up to 90 days. None of them carry your name, email, or other directly identifying information. If you turn Advertising off, we expire them.

12. Security

We take reasonable technical and organisational measures to protect personal data: TLS in transit, encryption at rest for secrets and OAuth tokens, scoped credentials per service, audit logging, and least-privilege access controls. No system is perfectly secure; if a breach affects you, we'll notify you and the relevant supervisory authority within 72 hours of becoming aware of it, as required by GDPR.

13. Children

Chillframe isn't for under-18s. We don't knowingly collect data from minors. If you believe a minor has signed up, contact us and we'll delete the account.

14. Changes

When we change this Policy, we update the "Last updated" date and, for material changes, give you at least 14 days' notice by email or in-product banner before the new version takes effect.

15. Contact

Privacy questions, data-access requests, complaints, or anything you'd want a human to see: hi@chillframe.com. The same address handles general support.