Privacy Policy
Last updated Aug 24, 2026 Effective date: Aug 12, 2026
This policy covers the phoenixtools.dev website, the Phoenix Clips web
panel, the licence service behind the panel subscription, and the
Phoenix Clips software you install on your own machine. The short version:
almost everything stays on your computer, and the little we do keep is listed
below, exactly.
Who is the data controller
The controller is the seller identified in the Seller details section at the bottom of this page. For anything in this policy, write to the email address listed there.
One exception: if you deploy the self-hosted Phoenix Clips service on your own infrastructure, you are the controller of the data that deployment processes. See Self-hosted deployments.
What we collect, and where it comes from
The website (phoenixtools.dev)
The website runs no analytics and no trackers — no Google Analytics, no advertising pixels, no fingerprinting. What remains:
- Hosting logs. The site is hosted on Vercel, which keeps standard server logs (IP address, user agent, requested URL) to operate the service.
- The services request form. If you submit the form on the Services page, the fields you fill in (name, email, project details) are delivered to us through Web3Forms, a form-delivery provider, and arrive in our support mailbox. We use them only to answer you.
The licence service
When you buy the panel subscription, our licence service (hosted on Railway) stores the minimum needed to run your subscription:
- Your licence record: the licence key, your Paddle subscription and customer identifiers, the subscription status, and the paid-period dates.
- Browser seats: an anonymous, randomly generated browser identifier for each browser you use the panel in, with first-seen and last-seen timestamps. This enforces the limit of 5 concurrent browsers per key; a browser not seen for 30 days stops counting and its record becomes inert. The identifier is not derived from your hardware and identifies nothing outside our own service.
- Webhook bookkeeping: identifiers of payment events already processed, so a retried delivery from Paddle is not applied twice.
We do not store your name, email, or address on the licence service. When we email your licence key after purchase, your email address and country are read from Paddle at the moment of sending and are not saved on our side.
Payments
Payments are handled entirely by Paddle.com Market Ltd as merchant of record. Paddle collects and stores your payment details, billing address, and invoices; we never see your card number. Paddle’s processing is governed by Paddle’s privacy policy.
The Phoenix Clips software on your machine
The local install keeps everything on your computer:
- your clips, captions, and publishing history live in a local library folder;
- platform access tokens (TikTok, Instagram, YouTube, Facebook, X) and your Anthropic API key are stored in the Windows Credential Store on your machine;
- media you publish is uploaded to your own storage bucket, configured with your own credentials — not to ours.
None of this passes through Phoenix Tools servers. The only network call the panel makes to us is licence validation: your licence key plus the anonymous browser identifier described above.
Data from the TikTok API
If you connect a TikTok account, the software requests exactly these scopes and uses them only as described:
- user.info.basic — your display name and avatar, shown in the panel so you can see which account is connected;
- video.publish — publishing a clip to your account, only when you explicitly trigger it;
- video.list — view, like, comment, and share counts of your own published videos, shown on the panel’s Analytics screen.
TikTok data is stored locally on your machine, refreshed periodically while the service runs, and deleted together with the installation. You can revoke the app’s access at any time in your TikTok settings under Settings and privacy → Security → Apps and services (this article is a courtesy pointer; the exact menu location is TikTok’s and may change); revoking invalidates the stored tokens immediately.
The same principle applies to the other platforms you connect: tokens are stored locally, used only to publish what you approved and to fetch the statistics of your own posts.
Data from Google and the YouTube API
If you connect a YouTube channel, Phoenix Clips accesses data from your Google Account through the YouTube Data API v3. This section is the full disclosure of what is accessed, what it is used for, who it is shared with, and how it is protected.
What Google user data we access. Exactly three OAuth scopes are requested, and nothing beyond them:
| Scope | Google user data accessed |
|---|---|
youtube.upload | Permission to upload a video you produced to your own channel. No data is read with this scope. |
youtube.readonly | The identity of your connected channel (channel id, channel title, the id of your uploads playlist); the title, description, tags, publication date, duration, thumbnail and privacy status of videos on that channel; and the view, like and comment counts of those videos. |
youtube.force-ssl | Permission to delete a video from your own channel when you ask for it. It is requested because youtube.upload allows uploading and nothing else. |
We do not request — and cannot read — your name, your email address, your
contacts, your watch or search history, or any other data in your Google
Account. The only Google API our app calls is the YouTube Data API v3, and
only these endpoints: videos.insert, videos.list, videos.delete,
channels.list, playlistItems.list.
How we use it. Only to provide the features you asked for, in your own copy of the software:
- the channel title and id are shown in the panel so you can see which channel is connected, and are used to address an upload to that channel;
- an upload happens only when you explicitly press Publish or Schedule on a clip for which you selected YouTube as a destination. Title, description, tags, privacy status and audience are shown to you and remain editable before the request, and nothing is changed after you confirm;
- video metadata and statistics are displayed back to you — and only to you — on your own panel, labelled as coming from YouTube;
- a video is deleted only when you ask for it on a clip you published and confirm the deletion.
We do not use Google user data for advertising, do not profile you with it, do not combine it with data from other users, and do not use it to train AI or machine-learning models — ours or anyone else’s. Where the panel suggests a title, description or tags through an AI provider you configured yourself, the input for that suggestion is your own clip, not data read from YouTube.
With whom we share, transfer, or disclose it. With nobody. Google user data is never sold, rented, or handed to any third party — no advertiser, no data broker, no analytics provider, no other customer. It moves between your own installation of Phoenix Clips, your browser, and Google’s API, plus the one transient step described next, which exists solely to deliver your own authorisation back to your own installation. The only exception we would ever make is a legally binding order from a competent authority, and it could only concern data we actually hold — which, for Google user data, is nothing.
The connection broker, and why it exists. Every buyer runs their own copy
of the Phoenix Clips service, on their own machine or their own cloud account.
Google only redirects back to addresses registered in advance, so the
registered address has to be ours: auth.phoenixtools.dev. That service
exchanges the one-time code Google returns for tokens and hands them to the
installation that started the connection. What it does not do matters more:
- tokens exist there in memory only, inside a single-use grant that expires after two minutes and is destroyed the moment your installation claims it;
- the broker has no database; no token is written to disk or into any log;
- refreshing an expired token passes through the same service because it requires the confidential client secret — that request stores nothing at all;
- revoking a token needs no secret, so your installation does it directly with Google, without us in the middle.
How Google user data is protected. Everything below is in force today, not an aspiration:
- all traffic to Google, to the broker, and between the panel and your service
runs over TLS (HTTPS); the OAuth callback address is registered and fixed,
and the
stateparameter of the exchange is signed and time-limited so a response cannot be replayed or redirected elsewhere; - on a Windows install, the refresh token is encrypted at rest with Windows DPAPI under your user account, alongside your other platform credentials — never in a plain configuration file;
- on a self-hosted install, the token lives in your own database, on your own infrastructure, reachable only through your own service, which is protected by your licence key and admin token;
- the client secret of our Google client is held only as an environment variable of the broker service and is never shipped inside the installer;
- YouTube-derived data cached for display (channel title, video metadata, statistics of your own videos) stays in your own library and is deleted with it.
How to revoke access and delete the data. Press Disconnect on the YouTube card in Settings: your installation revokes the token with Google first and only then forgets it, so nothing keeps working after you disconnect. You can also revoke access at any time from your Google Account, under Third-party apps with account access — revocation invalidates our tokens immediately. Uninstalling the software, or deleting your self-hosted instance, removes the tokens and everything cached from YouTube together with it. If you would like us to confirm that nothing of yours remains on our side, write to the address in Seller details below.
YouTube API Services. Phoenix Clips uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service; Google’s own handling of your data is described in the Google Privacy Policy.
Limited use. Phoenix Tools’ use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Self-hosted deployments
If you deploy the Phoenix Clips service to your own infrastructure instead of running the local installer, that deployment — its database, its storage, its platform tokens — runs under your accounts and your control. You are the data controller for it; this policy covers only what reaches the systems we operate, which for self-hosted deployments is licence validation and nothing else.
Legal basis
Under the GDPR we process:
- licence and subscription data to perform our contract with you (Art. 6(1)(b));
- the anonymous browser identifier out of legitimate interest in preventing licence sharing and fraud (Art. 6(1)(f)) — the least intrusive mechanism we found for it;
- form submissions to answer your request (Art. 6(1)(b), pre-contractual steps).
Who we share data with
We do not sell personal data, and we do not share it for advertising or for anyone else’s marketing. Data leaves our systems in only three ways:
- To the subprocessors listed below, each for the single operational task named in the table, under their data-processing terms.
- To you, when data you asked for is delivered to your own installation — which is how platform tokens, including YouTube tokens, reach the software running on your machine.
- When the law requires it, in response to a binding order from a competent authority.
Data received from Google APIs is outside all of this: it is shared with no subprocessor, no advertiser and no other party, and it is not used to train AI or machine-learning models. See Data from Google and the YouTube API.
How we protect your data
- In transit. Every connection — the website, the panel, the licence service, the connection brokers, and every call to a platform API — runs over TLS. Plain HTTP is accepted only on the loopback address of your own machine, where there is no network to intercept.
- At rest on your machine. Platform tokens and API keys are encrypted with Windows DPAPI under your user account. On a self-hosted deployment they live in your own database on your own infrastructure.
- At rest on our side. The licence service stores licence keys, Paddle identifiers, anonymous browser identifiers and webhook bookkeeping — and nothing else. It holds no platform tokens, no media, no names and no addresses. Its database is managed, access-controlled and not exposed publicly; administrative endpoints require a separate admin token.
- Minimised by design. Sensitive credentials that must pass through us (the OAuth exchange) are held in memory for at most two minutes, in a single-use grant, by a service that has no database and logs no token values.
- Access. Phoenix Tools is run by its owner alone. Production systems are reached through each provider’s own console under a single owner account with two-factor authentication enabled; there are no shared logins and no third-party staff with access.
- Incidents. If a breach ever affects personal data we hold, we notify the Dutch supervisory authority within 72 hours and inform affected users without undue delay, as the GDPR requires.
Subprocessors
| Provider | What for | Where |
|---|---|---|
| Paddle.com Market Ltd | Payments, invoicing, tax (merchant of record) | UK / EU |
| Vercel Inc. | Website hosting | USA / EU edge |
| Railway Corp. | Hosting of the licence service and of the OAuth connection broker (which holds no data at rest) | USA / EU region |
| Cloudflare, Inc. | DNS, content delivery, transactional email (licence key delivery) | USA / EU |
| Web3Forms | Delivery of the services request form | USA |
| Google LLC (Workspace) | Support mailbox | USA / EU |
Retention
- Licence records are kept while your subscription or licence is valid, and afterwards as long as tax and accounting law requires.
- Platform access tokens, including YouTube tokens, are kept only inside your own installation, for as long as the connection stays active; on our OAuth broker they exist for at most two minutes and are never written down.
- Browser-seat records stop counting toward the seat limit after 30 days of inactivity and are removed with the licence record.
- Form submissions are kept in the support mailbox as long as needed to handle the request and any follow-up.
- Everything stored on your own machine is yours: it is retained until you delete it or uninstall the software (the uninstaller asks whether to delete the library and saved credentials).
International transfers
Some subprocessors process data outside the EEA (notably in the USA). Where they do, transfers rely on the EU–US Data Privacy Framework or on Standard Contractual Clauses, per each provider’s data-processing agreement.
Your rights
You have the right to access, correct, delete, and receive a copy of your personal data, to object to processing based on legitimate interest, and to lodge a complaint with a supervisory authority (in the Netherlands: Autoriteit Persoonsgegevens). To exercise any of these, email the address in Seller details below; we respond within one month.
Note that most product data never reaches us — clips, captions, and platform tokens live on your machine, and deleting them is in your hands directly.
Cookies
The website sets no tracking cookies and no third-party cookies. Your theme and language preferences, and — in the Clips panel — your licence key and session, are kept in your browser’s local storage, which stays on your device and is sent to no one. Clearing your browser’s site data removes all of it.
Changes to this policy
If the policy changes, the new version is published at this address with an updated date above. Material changes to what we collect will be announced in the changelog before they take effect.
Seller details
- Legal name
- Dmitrii Mikhailovich Shchepetkov
- Trade name
- Phoenix Tools
- KvK number
- 42135418
- VAT ID
- NL005523937B50
- Registered address
- Jan Wolkerslaan 211, 1112 ZH Diemen
- Country
- Netherlands
- support@phoenixtools.dev
- Merchant of record
- Paddle.com Market Ltd