Privacy Policy
Last updated: August 13, 2026
1. What we collect
- Account data — your email address and, if you sign in with Google, your basic Google profile (email, name).
- Content you create — channel configurations, video topics, scripts, thumbnails, rendered videos, and notes you write in the app.
- Provider keys you connect — stored encrypted; used only to run jobs you approve; never shown back in full, never shared.
- Usage and technical data — standard logs (IP, browser type, pages, errors) to keep the Service secure and working.
2. What we do with it
We use your data to provide the Service: authenticate you, run the generation jobs you request, show you your work, bill you (when payments launch), and fix problems. We do not sell your personal data and we do not use your private content to advertise to anyone.
We do not train AI models on your content. Your prompts, scripts, and generated material are processed only to produce your outputs; the AI providers we use are accessed via business APIs that exclude your data from their consumer training programs.
We may send you product updates about your own account and the Service; marketing emails always include one-click unsubscribe.
3. Who processes it for us
Running AnvilGen involves a small set of infrastructure providers:
- Supabase — database, authentication, and file storage
- Vercel — website hosting
- Anthropic — AI text generation (your prompts/scripts are processed to generate outputs)
- Google — image generation and sign-in with Google, if you use it
- HeyGen — avatar video rendering, when you run renders
- Stripe — payments, once billing launches (we never see full card numbers)
Each processes data only to provide their function. AI providers used by AnvilGen are configured for business/API use, which excludes your content from consumer-product training programs.
4. Google user data (YouTube connection)
If you connect your YouTube channel, AnvilGen accesses — with your explicit consent via Google OAuth — read-only data from your Google account, limited to: your YouTube channel's basic information (name, thumbnail, public statistics) and your channel's YouTube Analytics reports (views, watch time, audience retention, subscriber changes, traffic sources, top videos).
- How it is used — solely to display your own analytics to you inside AnvilGen and, when you request it, to generate an AI summary of those numbers for you. It is never used for advertising, never sold, and never shared with other users or third parties.
- How it is stored — analytics are fetched live from Google and are not retained; the OAuth tokens that authorize access are stored server-side under access controls that make them unreadable from the browser.
- Revoking access — click Disconnect in AnvilGen (this deletes the stored tokens) or remove AnvilGen at any time from your Google account permissions.
AnvilGen's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. AnvilGen uses YouTube API Services; by connecting your channel you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
5. Cookies and tracking
We use essential cookies only: keeping you signed in. No third-party advertising or cross-site tracking cookies, and currently no third-party analytics or session-recording tools. If we ever add an analytics tool, this policy will name it before it goes live.
6. Retention and deletion
Your data stays while your account is active. Delete your account and we delete your personal data and content within 30 days, except minimal records we must keep for legal or billing reasons. You can also email us to request deletion or a copy of your data.
7. Security
Data is encrypted in transit, database access is restricted per-account at the database layer, and connected API keys are stored in an encrypted vault. No system is perfectly secure, but security decisions in AnvilGen are made conservatively by design.
8. Your rights
Depending on where you live (including the EU/EEA), you may have rights to access, correct, export, restrict, or delete your personal data. Email us and we will honor them: AnvilWorksYT@protonmail.com.
9. Children
The Service is not directed at children and requires users to be at least 16 (or the age of digital consent where they live). We do not knowingly collect data from children under 13; if we discover it, we delete it.
10. Changes
If this policy changes materially, we will notify you by email or in-app before the change applies.
AnvilGen — an AnvilWorks product · Questions: AnvilWorksYT@protonmail.com