Privacy Policy
Deese Publisher is a private, internal tool operated by Billy Deese (Deese Real Estate) to publish finished Deese Explains videos to channels he owns. It is not offered to the public, and public sign-up is turned off. This policy explains what the app handles and why. See also the Terms of Service.
Who uses the app
Only the owner account (billy@deeserealestate.com) can sign in and see any data. Sign-in uses email and password. We store the account email, a securely hashed password, and sign-in session records needed to keep you signed in.
Google and YouTube data
When the owner connects a YouTube channel, the app asks Google for two permissions:
- youtube.upload — to upload videos the owner has approved to that channel.
- youtube.readonly — to read the connected channel's name and ID, so the owner can confirm the right channel is connected.
From Google we store:
- a refresh token, kept only on the server in a restricted table that no browser or signed-in user can read;
- the granted permission list and the Google account email returned during connection;
- the channel name and channel ID;
- for each published video, the YouTube video ID and link returned by YouTube.
We do not read, download or store your other YouTube videos, comments, subscribers, analytics or any other Google account data. Google data is used only to upload approved videos and confirm channel identity. It is not sold and not used for advertising. It is stored and processed by the app's hosting provider, Lovable Cloud, to operate this app, and sent to Google/YouTube as needed. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Videos and publishing details
- Finished MP4 files are kept in a private storage area that is not publicly readable. The app's own server can read them. Other parties get access only through short-lived signed links the server creates: the owner (to review or download), the separate opening-check tool, and the separate intro-assembly tool (which receives a one-time upload link). The server itself sends the stored file to YouTube.
- The app's server does not change a stored file after it is uploaded; it sends exactly the stored bytes. Separately, an intro-assembly tool that runs outside the app can combine the approved intro with a rendered video. That step uses ffmpeg and re-encodes the video and sound, and only the finished result is uploaded to the app.
- Each job stores its title, description, tags, hashtags, privacy setting, made-for-kids setting, planned times, source article link, file fingerprint (SHA256) and size, validation results and opening-check results.
- An audit log records each action (for example approval, edits and publishing) with who did it and when.
- Approved Deese Explains intro files are kept in private storage as reference files.
Service providers and connected tools
The app runs on Lovable Cloud, which hosts the website, database, sign-in and file storage. Videos and their details are sent to YouTube (Google) only for jobs the owner has approved. Today the owner starts each upload by hand. The app also contains a scheduled-publishing feature that could upload an approved job at its planned time, but it is switched off; even when on, it would only send jobs the owner approved, with the exact details approved.
The owner may connect ChatGPT to the app's tool interface after signing in as the owner. Those tools can list and read jobs, create jobs and upload links, run checks, save proposed titles and descriptions, record a publish request, and read published Learning Center articles. They have no way to approve a job or send anything to YouTube.
Facebook, Instagram and TikTok
These platforms are not connected. The app can store draft wording for them, but it holds no credentials for them and sends nothing to them. If they are connected in the future, this policy will be updated first.
How long data is kept
Data is kept until the owner deletes it or disconnects the channel. There is no automatic deletion schedule.
Revoking access and deleting data
- Disconnecting a channel in the app deletes its stored refresh token and asks Google to revoke it.
- You can also remove access at any time at myaccount.google.com/permissions.
- Videos already published to YouTube stay on YouTube until removed there.
- To request deletion of any other stored data, email billy@deeserealestate.com.
Security
Access is limited to the owner account by database rules. Tokens and secrets stay on the server. No method of storage is perfectly secure, but we take reasonable steps to protect this data.
Changes and contact
If this policy changes, the effective date above will be updated. Questions: billy@deeserealestate.com.