Privacy Policy

Last updated: February 17, 2026

EidosStack is a self-hosted software platform that helps content creators manage and distribute their video content across multiple platforms. Our product ecosystem includes EidosClip (video editing), EidosONE (content management), EidosLumina (AI-powered video generation), and other tools. This Privacy Policy applies to all EidosStack products and explains how we handle your data when you use our services, including integrations with third-party platforms like YouTube, TikTok, Instagram, and Facebook.

1. Information We Collect

1.1 Google User Data

When you connect your YouTube account to EidosStack, we access the following Google user data: • YouTube Channel Information: Channel name, channel ID, subscriber count, and channel description • Video Metadata: Video titles, descriptions, tags, thumbnails, and publishing status • Upload Permissions: Authorization to upload videos to your YouTube channel on your behalf • Analytics Data: Basic video performance metrics (views, likes, comments) for videos uploaded through EidosStack We ONLY access data necessary for the core functionality of uploading and managing your video content on YouTube.

1.2 Other Platform Data

When you connect other social media accounts (TikTok, Instagram, Facebook) through any EidosStack product (EidosClip, EidosONE, EidosLumina, etc.), we collect similar data: • Account profile information (username, profile picture, follower count) • Authorization to post content on your behalf • Basic analytics for content posted through EidosStack applications All platform integrations require your explicit authorization through OAuth consent screens. Specifically for TikTok: • When you connect your TikTok account through EidosClip, EidosONE, EidosLumina, or other EidosStack products, we access your TikTok profile information and authorization to upload videos • We only access the minimum permissions required for video upload functionality • Your TikTok credentials and content are never shared with third parties • All EidosStack products use the same secure OAuth integration for TikTok

1.3 License and Account Data

• Email address (for license delivery and account management) • License key and activation status • Product tier and purchase information • Hardware identifiers (for license validation only)

1.4 Technical Data

• Software version and product identifier • Anonymized usage telemetry (feature usage, error reports) • IP address (for license validation and security) • Session data (for active license management) We do NOT collect: • Your video content files • Audio or image files • Scripts or project files • Any media you create or edit

2. How We Use Your Data

2.1 Google User Data Usage

We use your YouTube data ONLY for the following purposes: • Uploading videos: To publish your videos to your YouTube channel when you initiate an upload through any EidosStack product (EidosClip, EidosONE, EidosLumina, etc.) • Managing uploads: To track upload status, update video metadata, and manage your content library • Analytics display: To show you performance metrics for videos uploaded through our platform • Account verification: To verify your YouTube channel ownership and permissions We DO NOT: • Access your YouTube data without your explicit action • Modify or delete your existing YouTube content • Share your YouTube data with third parties (except as required for the upload functionality) • Use your YouTube data for advertising or marketing purposes • Train AI/ML models with your YouTube data

2.2 License Management

• Validate your software license • Enforce concurrent session limits based on your tier • Provide customer support • Send license-related notifications

2.3 Service Improvement

• Improve software stability and performance • Fix bugs and technical issues • Develop new features based on usage patterns • Ensure security and prevent abuse

3. Data Sharing and Third Parties

3.1 Google User Data Sharing

We DO NOT share your Google user data with any third parties, except: • YouTube API: We transmit your video content and metadata directly to YouTube's servers when you initiate an upload. This is necessary for the core functionality of the service. • No other sharing: Your YouTube account information, channel data, and video metadata are never shared with advertisers, data brokers, or other third parties. Your Google user data is used ONLY within EidosStack software running on your own infrastructure.

3.2 Payment Processors

• Lemon Squeezy (payment processing): We share your email and purchase information with our payment processor to complete transactions. We do not store your credit card information.

3.3 Service Providers

We may use the following service providers: • Cloud infrastructure (for license server only): AWS or similar providers host our license validation server • Email service: For sending license keys and account notifications • Analytics: Anonymized usage data for product improvement These providers are contractually obligated to protect your data and use it only for the specified purposes.

3.4 Legal Requirements

We may disclose your information if required by law, court order, or government regulation.

4. Data Storage and Protection

4.1 Self-Hosted Architecture

EidosStack is designed as self-hosted software: • Your video content, projects, and media files are stored ONLY on your own computer or server • We do not have access to your content files • All video processing happens locally on your infrastructure

4.2 License Server Data

Our license validation server stores: • License keys and activation status • Email addresses (encrypted) • Hardware identifiers (hashed) • Session data (temporary, expires after 24 hours of inactivity) This data is stored on secure servers with: • Encryption at rest (AES-256) • Encryption in transit (TLS 1.3) • Regular security audits • Access controls and authentication • Automated backups

4.3 Google User Data Storage

YouTube OAuth tokens and refresh tokens are stored: • Locally on your device/server (encrypted) • Never transmitted to our servers • Used only for API calls to YouTube on your behalf • Automatically refreshed as needed We implement industry-standard security measures to protect your OAuth credentials.

5. Data Retention and Deletion

5.1 Retention Periods

• Google OAuth tokens: Stored until you disconnect your YouTube account or revoke access • License data: Retained for the lifetime of your license plus 7 years for legal compliance • Session data: Automatically deleted after 24 hours of inactivity • Telemetry data: Aggregated and anonymized after 90 days • Email communications: Retained for 2 years

5.2 Your Right to Delete Data

You can request deletion of your data at any time: • YouTube connection: Disconnect your YouTube account in EidosStack settings or revoke access at https://myaccount.google.com/permissions • License data: Email privacy@eidosstack.com to request account deletion • Right to be forgotten: We will delete your personal data within 30 days of your request (except data required for legal compliance) To delete your data: 1. Email privacy@eidosstack.com with subject "Data Deletion Request" 2. Include your email address and license key 3. We will confirm deletion within 30 days

5.3 Automatic Deletion

• Inactive licenses: Data for licenses inactive for 3+ years may be archived • Revoked licenses: Associated data deleted after 90 days • Failed sessions: Automatically cleaned up after 24 hours

6. Your Rights and Controls

You have the following rights regarding your data: • Access: Request a copy of your data at any time • Correction: Update or correct your information • Deletion: Request deletion of your data (subject to legal requirements) • Portability: Export your data in a machine-readable format • Revocation: Revoke OAuth access at any time through Google Account settings • Objection: Object to certain data processing activities To exercise these rights, contact privacy@eidosstack.com

7. Google API Services User Data Policy Compliance

EidosStack's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: • We only request the minimum scopes necessary for functionality • We do not use Google user data for serving advertisements • We do not allow humans to read Google user data unless: - We have your explicit consent - It's necessary for security purposes - It's required for legal compliance • We do not transfer Google user data to third parties (except as necessary for core functionality) • We do not use Google user data for AI/ML model training For more information, see: https://developers.google.com/terms/api-services-user-data-policy

8. Children's Privacy

EidosStack is not intended for users under 13 years of age. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact privacy@eidosstack.com.

9. International Users and GDPR

EidosStack is used globally. For users in the European Economic Area (EEA): • Legal basis: We process data based on legitimate interest, contractual necessity, or your consent • Data transfers: If data is transferred outside the EEA, we use standard contractual clauses • GDPR rights: You have additional rights under GDPR, including the right to lodge a complaint with a supervisory authority For GDPR-related inquiries, contact privacy@eidosstack.com

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by: • Posting the updated policy on our website • Sending an email notification (for material changes) • Displaying an in-app notification Continued use of EidosStack after changes constitutes acceptance of the updated policy.

11. Contact Information

For privacy-related questions, concerns, or requests: Email: privacy@eidosstack.com Website: https://www.eidosstack.com Response time: We aim to respond within 48 hours For data deletion requests or GDPR inquiries, please use the subject line "Privacy Request" for faster processing.

This privacy policy complies with Google API Services User Data Policy and GDPR requirements.