Mage Cuts Privacy Policy
Mage Cuts ("the App") helps creators edit their own talking-head videos and publish them to their own connected social media accounts. This policy explains what data we handle, who we share it with, and how we protect it.
Information we collect
-
Google account data (sign-in). If you sign in with
Google, we receive and store your Google account identifier, email
address, name, and profile picture URL. We use the
openid,email, andprofilescopes for this. This is the only information we use to identify your Mage Cuts account. -
Google account data (YouTube publishing). If you
connect YouTube, we receive an OAuth access token and refresh token
scoped to
https://www.googleapis.com/auth/youtube.upload. This scope permits uploading a video to your channel and nothing else — it cannot read, edit, or delete your existing videos, and it grants no access to your Gmail, Drive, Contacts, Calendar, or any other Google service. - Other connected account data. When you connect Instagram or TikTok, we receive an access token and basic profile information (for example, your display name, username, or account ID) so we can show which account is connected and publish on your request.
- Video content. Videos you upload for editing, and the edited output Mage Cuts produces.
We do not collect analytics, advertising identifiers, or browsing activity, and we do not use tracking cookies. The only cookie Mage Cuts sets is a session cookie required to keep you signed in.
How we use your information
- To identify your account so you can return to the videos you made.
- To edit the videos you upload (removing silences and filler words, adding captions, and optionally adding b-roll).
-
To publish a video to your own connected account when you request it.
For Instagram, Mage Cuts uses
instagram_business_basicto identify the connected professional account andinstagram_business_content_publishto publish your approved video as a Reel after you click publish. -
For TikTok, Mage Cuts uses the Content Posting API
(
video.uploadscope) to send your video to your TikTok inbox, where you review and publish it yourself. - To display which account is connected.
We do not post anything without your explicit action in Mage Cuts.
How we share, transfer, and disclose Google user data
We do not sell your data. We do not share Google user data with advertisers, data brokers, or analytics providers, and we do not use it to train machine learning or AI models. No human at Mage Cuts reads your Google user data except where required to resolve a support request you initiate, to investigate abuse, or to comply with applicable law.
Google user data is disclosed only to the following service provider, which processes it on our behalf and is contractually restricted to that purpose:
- Railway Corp. (privacy policy) — our hosting and database provider. Railway operates the servers and the PostgreSQL database where your account record, session, and OAuth tokens are stored. Railway acts as a data processor and does not use this data for its own purposes.
We also transfer data to Google itself at your direction: when you click publish, your edited video is uploaded to your own YouTube channel using the token you granted.
Beyond the above, we disclose Google user data only when legally compelled (for example, a valid subpoena or court order), or if Mage Cuts is involved in a merger or acquisition — in which case we will give notice before your data becomes subject to a different privacy policy.
Other processors, which do not receive Google user data
The editing pipeline uses third-party services to process the content of the video you upload. These services never receive your Google account data, OAuth tokens, email address, or name:
- OpenAI (privacy policy) — receives the audio track extracted from your video for transcription, and the resulting transcript text to detect filler words, restarts, and b-roll opportunities. OpenAI does not use data submitted through its API to train its models.
- Google Programmable Search and Pexels — if you enable b-roll, short search phrases derived from your transcript are sent to find stock imagery. Your video itself is never sent to these services.
How we protect your data
We apply the following safeguards, with particular attention to sensitive data — meaning your OAuth access and refresh tokens, and the Google account information that identifies you:
- Encryption in transit. All traffic between your browser and Mage Cuts is encrypted with HTTPS (TLS 1.2 or higher). Connections between the App and its database, and between the App and every third-party API listed above, are likewise encrypted with TLS.
- Encryption at rest. The database and file storage that hold your account record, session, tokens, and video files are hosted on Railway, which provides encryption at rest and maintains SOC 2 Type 2 certification (see Railway's Trust Center).
-
Tokens are never exposed to the browser. OAuth access
and refresh tokens are held server-side only. Your browser receives
only an opaque session identifier, set as an
HttpOnly,SameSite=Lax,Securecookie so it cannot be read by JavaScript or sent from another site. -
Least-privilege scopes. We request the narrowest
scope that makes each feature work. Sign-in uses only
openid,email, andprofile. YouTube publishing uses onlyyoutube.upload, which cannot read or delete anything on your channel. - Access control. Production database credentials and API secrets are stored as encrypted environment secrets in our hosting provider, never in source code. Access to the production environment is limited to the App's maintainer and protected by a Google account with two-factor authentication enabled.
- Session hygiene. A new session identifier is issued at the moment you sign in, so a session identifier observed before sign-in cannot be reused afterwards. Sessions expire after 30 days.
- Deletion on disconnect. Revoking a connection in Mage Cuts deletes the stored token for that platform immediately.
No system is perfectly secure, but if we ever become aware of a breach affecting your Google user data, we will notify affected users by email without undue delay.
Data retention and deletion
Your Mage Cuts account record (Google account identifier, email, name, profile picture URL) is kept until you delete your account. Sessions and the OAuth tokens they hold expire after 30 days, and sooner if you log out or disconnect the platform. Uploaded and edited video files are retained only as long as needed to deliver the edit and any publish you request.
You can disconnect any platform at any time from Mage Cuts, which removes its stored access token. You can delete your Mage Cuts account and everything associated with it — the account record, the session, and all stored tokens — from the user data deletion page. Deletion is immediate and cannot be undone. You may also email us to request removal of any uploaded or edited video files.
You can independently revoke Mage Cuts' access to your Google account at any time at myaccount.google.com/permissions.
Google API Services Limited Use disclosure
Mage Cuts' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Third-party platforms
When you publish to a third-party platform, that platform's own privacy policy and terms govern how it handles the content once it is delivered to your account.
Contact
Questions or deletion requests: jason.zhxn@gmail.com.