Paw Studio

Privacy policy

Last updated 2026-09-28.

Paw Studio is a private tool: one operator uses it to produce and schedule music videos for their own YouTube channels. It is not a public service, and it does not collect data about, or serve, anyone other than that operator.

What it stores

Channel and video metadata (titles, descriptions, tags, schedules), generated or uploaded media (images, audio, video), and the studio's own operational data (jobs, notifications, budgets). None of this is shared with any third party, sold, or used for advertising — it exists solely so the operator can produce and publish their own videos.

Google and YouTube data

When a channel is connected to YouTube, the studio requests Google OAuth access with these scopes:

  • youtube.upload — to upload videos on the operator's behalf.
  • youtube — to manage those videos once uploaded (thumbnails, playlists, privacy and scheduling settings).
  • youtube.readonly and yt-analytics.readonly — read-only, to show the operator their own channel's statistics: public counters (views, likes, comments, subscribers) and YouTube Analytics reports (views, watch time, subscribers gained and lost, likes, comments, shares), for the channel as a whole and for the videos published from the studio. No revenue or monetary data is ever requested.

The studio only ever acts on channels the operator explicitly connects, only uploads and manages videos the operator created in this same tool, and never modifies or deletes any other content on the channel. Statistics are stored in the studio's own database, shown only to the operator, and never shared or sent anywhere else. The OAuth refresh token used to keep that access alive is encrypted at rest in the studio's own database (never stored or logged in plain text) and is never transmitted anywhere except directly to Google's own API.

To revoke access at any time, either disconnect the channel from within the studio (Channel → YouTube → Disconnect), or remove Paw Studio's access directly from your Google Account's third-party access settings. Either way, the studio's own copy of the refresh token is deleted immediately.

Other providers

Image, lyrics and metadata generation may use OpenAI's or OpenRouter's API (OpenRouter forwards the request to the model vendor chosen); song generation may use musicapi.ai's API. Only the specific prompt or request needed for that generation is sent, never YouTube account data or credentials.

Contact

Questions about this policy or a request to review or delete stored data: contact paws@foohx.com.