Privacy Policy
Last updated: September 27, 2026
zerohand (“we”) provides software that creates short-form videos and publishes them to social accounts you connect. This policy explains what we collect, why, and the choices you have.
What we collect
- Account data: your email address, name, and the sign-in provider you use (Google, Apple, GitHub, Facebook or email).
- Connected platform data: when you connect Instagram, YouTube or TikTok, we store access tokens and basic account details (handle, account ID) needed to publish on your behalf, and read performance metrics (views, likes, comments) for content we published.
- Content settings: channels, niches, brand settings, scripts and videos created in your workspace.
- Usage and technical data: logs of jobs our system runs, and link-click events on pages we host for you. Click events record a coarse country and region derived from the IP address; we do not store the IP address itself.
- Telegram: if you connect Telegram, your chat ID, used only to send you approvals and alerts.
How we use it
- To create, schedule and publish content you configure, and to report its performance to you.
- To secure the service, prevent abuse and fix problems.
- To contact you about your account. We do not sell personal data and do not use it for advertising.
Google and YouTube data
zerohand uses YouTube API Services. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Through YouTube API Services we access your channel information, your video list and video metadata, and channel and video analytics, and we upload video content on your instruction. This data is used only to operate the features you enabled.
By connecting YouTube you also agree to the YouTube Terms of Service. Google’s handling of your information is described in the Google Privacy Policy.
You can revoke zerohand’s access to your YouTube data at any time from the Google security settings page.
- If you revoke access using zerohand’s own disconnect control, we delete all data obtained through YouTube API Services under that authorization within 7 days.
- If you revoke access through the Google security settings page, we delete that data within 30 days.
Deleting data from zerohand does not in any way affect data stored by YouTube or Google.
Meta and TikTok data
Instagram and Facebook data is used only to publish content, manage comments and messages you enable, and read performance insights for your connected accounts. TikTok data is used only to upload videos you approve and read their performance. We do not share this data with other parties except the service providers listed below. You can revoke access at any time from your Meta or TikTok account settings, and you can request deletion of the data we hold — see Data deletion.
Service providers
We use Supabase (database and authentication), Vercel (hosting), Cloudflare (file storage), Resend (email), Anthropic (AI text generation) and GitHub (background processing). They process data only to provide their services to us.
Storage and security
Platform access tokens are encrypted at rest. Access to your workspace data is restricted to members of your workspace.
Retention and deletion
We keep your data while your account is active. You can delete your account at any time in Settings, which permanently deletes your workspace, channels, connected-account tokens and history. Rendered video files are deleted from our storage within 30 days of publishing. See Data deletion for other ways to request deletion.
Your rights
You can access, correct, export or delete your personal data. Email ibrahim@getzerohand.com and we will respond within 30 days.