Privacy Policy
The Russian version of this document is legally binding.
This policy governs the processing of personal data of Goutub users within the Kyrgyz Republic.
1. Legal Framework of the Kyrgyz Republic
- The Constitution of the Kyrgyz Republic (the right to privacy and protection of personal data).
- The Law of the Kyrgyz Republic "On Personal Data."
- The Law of the Kyrgyz Republic "On Personal Information" and other applicable regulations in the field of digital data and electronic interaction.
2. What Data We Process
We only collect what's needed to run the service. Below is the full list by category.
- Account data: login, email address, password hash (the password itself is never stored), profile settings (display name, profile avatar, interface language, time zone), and — if two-factor protection is enabled — an encrypted TOTP secret.
- Content you create in the service: video topics and categories, generated scripts and chapters, voice-over, images, thumbnails, subtitles, and finished video files; materials you upload — B-roll clips, personal inserts (intro, mid-roll, outro), speech samples for tone tuning, video for a presenter avatar, background music.
- Biometric images (optional): if you upload a video of your face for a presenter avatar, we store that file and the clips generated from it. Upload is only possible after confirming that it's your face or that you have the consent of the person shown; such entries go through manual moderation.
- YouTube and Google data when you connect a channel — see Section 7.
- Payment metadata: selected plan, payment amounts and statuses, payment provider transaction IDs, subscription start and end dates. The service never receives or stores card numbers, CVC codes, or other card details — these are entered directly on FreedomPay or in the Apple App Store.
- Technical data: IP address and the country derived from it, browser user agent, session identifier, login time, in-account activity logs (security audit), errors and processing times for generation tasks.
- Visit origin data: UTM tags, referrer, affiliate link, and promo code used on your first visit to the site (for tracking traffic sources and affiliate payouts).
- Support requests: support ticket text, consultation requests, comments on agency orders, and correspondence via the service's Telegram bot (if you've connected it).
- Cookies and analytics: see Section 8a.
3. Purposes of Processing
- Creating video content at your request — script, voice-over, visuals, editing, and packaging. To do this, your topics, texts, and uploaded materials are shared with the AI providers listed in Section 5, strictly to the extent required for the specific task.
- Publishing to YouTube and channel analytics — only if you've connected your channel yourself (Section 7).
- Contract fulfillment: tracking your plan, limits, payments and renewals; sending receipts and notifications about task and subscription status (email, Telegram, push notifications in the mobile app).
- Support: responding to inquiries, troubleshooting generation errors.
- Security: protection against hacking and abuse (rate limiting, login audits, bot blocking), backups.
- Service improvement: anonymized feature-usage statistics, A/B testing of pages, measuring ad campaign conversions.
- Accounting and reporting to the extent required by the laws of the Kyrgyz Republic.
We do not use your content, uploaded faces, or voices to train models, and we do not show them to other users, except for entries you've explicitly marked as "shared."
4. Legal Grounds for Processing
- User consent to the processing of personal data.
- Necessity for the performance of a contract to which the user is a party.
- Compliance with obligations established by the laws of the Kyrgyz Republic.
5. Disclosure to Third Parties
Data is shared only with the providers required to deliver the service, and only to the extent necessary. We do not sell personal data or share it with ad networks.
- AI generation providers (receive the topic text, script, prompts, and, when needed, uploaded images and video for the task): language models via OpenRouter and OpenAI; speech and music synthesis — Lumean (api.lumean.app, built on ElevenLabs and HeyGen); images and video — Fast Gen AI, ModelsLab, Muapi, Alibaba DashScope (WAN); avatar animation — fal.ai (LatentSync); stock footage — Pexels. These providers process data under their own policies and never receive your email, login, or payment details.
- Payments: FreedomPay (Kyrgyzstan) — for card payments; Apple — for purchases in the iOS app. We only receive the payment status and identifier from them.
- Google / YouTube: when you connect a channel, data is shared with the YouTube API on your instruction (Section 7).
- Notifications: an email provider for service emails; Telegram — if you've linked the bot; Firebase Cloud Messaging — push notifications in the mobile app.
- Analytics and advertising: Google Analytics and Meta Pixel on public pages (Section 8a); no ad pixels are embedded in the dashboard.
- Infrastructure: the server is hosted with a data center hosting provider; backups are stored encrypted.
- Government authorities of the Kyrgyz Republic — only upon a lawful request.
6. Payments and FreedomPay
Payments are processed through FreedomPay. Goutub does not accept or store full bank card details from users. Payment processing is carried out by the payment organization in accordance with its own rules and the laws of the Kyrgyz Republic.
7. Google and YouTube Data (YouTube API Services)
To publish videos and retrieve statistics, the service uses YouTube API Services. When you connect a YouTube channel, you authenticate via Google OAuth 2.0 and grant the service the following access permissions:
- Uploading and managing videos on your channel (youtube.upload) — used exclusively to publish videos you've created to your own channel.
- Viewing YouTube account data (youtube.readonly) — channel name and ID, video list and statuses, for display in the dashboard.
- Viewing YouTube Analytics reports (yt-analytics.readonly) — channel and video statistics for the analytics section.
How we handle this data:
- OAuth access tokens are stored encrypted and used only for the functions listed above.
- Google account data is never sold, shared with third parties, or used for advertising or any purpose unrelated to the service's features.
- Data is retained for as long as the channel is connected to the service. When you disconnect the channel from the "YouTube" tab in the dashboard, OAuth tokens and channel data (video list, statistics) are deleted immediately; only the log of publications made through the service is retained.
- Videos are published to your channel only at your explicit command via the publishing form, with the visibility you select (public, unlisted, private) and with a synthetic-content disclosure enabled by default. The service never publishes, deletes, or modifies videos on your channel without your action.
- YouTube Analytics data is used solely to display information in your dashboard and in the weekly digest for your channel; aggregated metrics from other channels are not collected.
- We do not read your comments, messages, or subscriptions, do not request access to other Google services, and do not use YouTube data for ad targeting, creditworthiness assessment, or sharing with ad platforms.
- Service staff can access your channel data only with your consent when handling a specific support request, or as required by law, or to investigate abuse.
- You can also revoke access in your Google security settings: myaccount.google.com/permissions.
By using YouTube features in the service, you also agree to the YouTube Terms of Service. Processing of Google data is governed by the Google Privacy Policy.
Google API Services (English). Goutub uses YouTube API Services. When you connect your YouTube channel via Google OAuth 2.0, we access: the ability to upload and manage videos on your channel (youtube.upload), your channel details and video list (youtube.readonly), and your YouTube Analytics reports (yt-analytics.readonly). OAuth tokens are stored encrypted and used solely to provide these features. We do not sell Google user data, do not share it with third parties, and do not use it for advertising. Data is retained only while your channel is connected: disconnecting the channel in the panel immediately deletes stored tokens and channel data; only the log of uploads performed through the service is kept. You can also revoke access at Google security settings. See the Google Privacy Policy and the YouTube Terms of Service.
Goutub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Data Retention Period
- Finished videos and project files (voice-over, images, YouTube package) are stored for 7 days after task completion, then deleted automatically; your plan may set a different period, shown in the dashboard. Download or publish your results within this window.
- Topic generator history — 30 days.
- Uploaded materials (B-roll, inserts, speech samples, avatars) are stored until you delete them in the dashboard or until your account is closed.
- YouTube data — for as long as the channel is connected; deleted immediately upon disconnection (Section 7).
- Login session lasts 24 hours (30 days with "Remember me" enabled) and ends on logout; security and audit logs are stored for 180 days.
- Payment metadata and account data — for the duration of the contract and thereafter for the periods required by the laws of the Kyrgyz Republic for accounting and tax purposes.
- Account deletion: you can delete your account in the "Profile" section of the dashboard. Login is blocked immediately, and after 7 days (a grace period in case of error — contact support to cancel), your data is permanently erased: profile, tasks and project files, uploaded materials and avatars, tone settings, calendar, subscriptions, and YouTube connections; Google access is revoked via the Google API. Only anonymized payment records are retained to the extent required by law. Backups are overwritten within 30 days.
8a. Cookies and Analytics
- Essential cookies: session identifier (dashboard login), cross-site request forgery (CSRF) protection, temporary two-factor verification token, selected interface language and theme, page A/B-variant tag. The service does not work without them.
- Visit-source cookies: UTM tags, affiliate link, and promo code from your first visit — 30 days.
- Analytics on public pages: Google Analytics (GA4) and Meta Pixel count visits and conversions anonymously; on purchase, we share the fact of the purchase and its amount with them, without your personal data. You can restrict these using browser extensions or Google/Meta settings; this doesn't affect the service's functionality.
- Proprietary statistics: anonymized events (page views, task launches, payments) are stored on our server to evaluate the funnel and are not shared with third parties.
9. Rights of the Data Subject
- Obtain information about what data about you is being processed, and request a copy of it.
- Correct your profile data yourself in the dashboard or through support.
- Delete your content, uploaded materials, avatars, and connected channels yourself in the dashboard; delete your entire account in the "Profile" section.
- Withdraw consent to processing, provided no other legal grounds apply; revoke Google access in your Google account settings.
- Request the blocking or deletion of data in cases provided for by law, and appeal the Operator's actions to the authorized personal data protection agency of the Kyrgyz Republic.
Requests are accepted at support@goutub.kg from the address registered on your account, or via the support form in the dashboard; we respond within 10 business days.
9a. Children
The service is intended for individuals over 18 years of age. We do not knowingly collect data from children; if you become aware that a child has registered an account, please contact us — the account and its data will be deleted.
10. Information Security
We apply organizational and technical safeguards (access control, logging, permission restrictions, network and application security tools) to prevent unauthorized access, alteration, disclosure, or destruction of data.
11. Contacts and Policy Updates
For questions about personal data processing, contact the Operator: support@goutub.kg, phone and WhatsApp +996 779 591 007, requisites in Section 12. This policy may be updated to reflect changes in the laws of the Kyrgyz Republic and the evolution of the service; the current version is always available at goutub.kg/legal/privacy, with the last update date shown below. We will notify you of material changes by email to your account address.
Revised September 13, 2026.
12. Operator Details
Sole proprietor «Asanov Usonbek»
- Registration address: State Tax Service Office for Pervomaisky District, Bishkek, Igemberdiyeva St., 34a
- Email: support@goutub.kg
- OKPO: 30628150
- TIN: 20810199701331
- Settlement account: 1180000135997341
- BIC: 118013
- Bank: "Demir Bank"