Skip to main content
WasNowForward Publisher
Overview Privacy Terms Support

Policy

Privacy Policy

This policy explains how WasNowForward Publisher, operated by WasNowForward, handles information when the authorized operator uses Publisher version 1.1.0rc1 and this public validation site.

Effective: August 4, 2026   Policy identity: draft-2026.07.28-2   Status: development

1. Scope and application identity

WasNowForward Publisher is a private, single-operator Linux desktop and command-line application. It helps the authorized operator prepare original media and upload selected videos, metadata, and thumbnails to an authorized YouTube channel. It is not a public user-upload service and does not provide public account registration.

The application uses YouTube API Services and Google OAuth 2.0. It is not made, endorsed, sponsored, or operated by Google or YouTube.

2. Information the application accesses

Google OAuth authorization data

The local application receives an OAuth authorized-user credential that can include an access token, refresh token, granted scopes, token endpoint information, OAuth client identity, and expiry metadata. The application does not request, receive, or store the operator's Google password.

YouTube channel and processing information

Using youtube.readonly, the application calls channels.list(mine=true) to retrieve the authenticated channel ID and title and refuse a mismatched destination. After an upload, it calls videos.list only for the just-uploaded video to record processing success, failure, termination, or an unavailable result.

Media and release metadata supplied by the operator

The operator supplies or generates the video file, thumbnail, title, description, tags, category, language, audience designation, subscriber-notification setting, visibility, and any future publication timestamp. The application sends selected fields and media to YouTube only after explicit confirmation.

Upload response and local evidence

YouTube can return a video identifier, channel identity, thumbnail result, and processing status. Publisher stores private, hash-bound upload receipts and publication claims locally to support recovery, exact input verification, and duplicate prevention. These receipts do not contain OAuth secrets.

3. OAuth permissions

ScopePurpose
https://www.googleapis.com/auth/youtube.uploadCall videos.insert for the operator-selected video and thumbnails.set for its selected custom thumbnail.
https://www.googleapis.com/auth/youtube.readonlyCall channels.list(mine=true) for exact channel verification and videos.list for the just-uploaded video's processing status.

The implementation does not use these scopes for general browsing, analytics, comments, subscriptions, search, content downloads, advertising, or profiling.

4. How information is used

  • Authorize the local application to call YouTube API Services on behalf of the operator.
  • Verify the exact destination channel before an upload.
  • Upload operator-selected original media, metadata, and thumbnails.
  • Confirm or report processing status for the just-uploaded video.
  • Maintain strict local receipts, prevent unintended duplicates, recover partial success, and support security auditing.

Authorized data is not sold, shared for advertising, used for unrelated profiling, or used for unrelated analytics.

5. Storage and security

OAuth credentials are stored through an approved concrete operating-system credential backend, such as Secret Service or KWallet on a supported Linux desktop. Publisher rejects null, failing, plaintext-capable, unknown, or unapproved credential backends.

Credential values are written under fresh immutable version accounts. The active credential is selected only when the OS-keyring marker, accepted-head pointer, immutable commitment, private filesystem anchor, and append-only event chain agree. Inactive historical credential versions may remain in the OS keyring because the generic keyring interface does not provide an atomic compare-and-delete operation. Retired versions are not selected for provider use.

Private non-secret credential-index metadata, acceptance records, receipts, claims, and revocation records are stored locally with restrictive permissions. Relevant private JSON records and event files use mode 0600. Rendered media, thumbnails, presets, and metadata remain local files under operator control.

This public site contains no OAuth client secret, access token, refresh token, API key, scheduler secret, or Cloudflare credential.

6. Retention

  • Active OAuth authorization: retained in the OS keyring until replaced, revoked, confirmed invalid, or logically retired.
  • Inactive credential history: immutable historical versions can remain in the OS keyring after replacement or revocation; they are not used as active credentials.
  • Upload receipts and API-derived status: retained locally for recovery, integrity, duplicate prevention, and audit until purged by a matching revocation operation or removed by the operator under an applicable retention decision.
  • Local media and metadata: retained until the operator deletes or archives them; programmatic OAuth revocation does not delete them.
  • Support messages: retained under the operator's email-account settings as reasonably needed to address the request, protect the service, or document completion.

7. Revocation and deletion

The preferred RC1 procedure is the application's confirmed revocation command described on the support page. It records a durable revocation intent, revokes the provider grant, deactivates the exact local authorization, and purges matching profile-bound authorized API receipts and cache data. It does not delete operator media or YouTube-hosted videos.

The operator can also remove access through Google Account permissions. External revocation does not itself complete Publisher's local cleanup; run the supported local reconciliation or revocation procedure before resuming use.

Because inactive immutable credential versions may remain in the OS keyring, the revocation result distinguishes active authorization deactivation from physical deletion of historical keyring records. Those inactive records are not selected for use.

A request concerning retained application data may be sent to wasnowforward@gmail.com. Never send credentials or tokens.

8. Sharing and service providers

Information is sent to Google and YouTube only as necessary to authorize the application, verify the channel, upload operator-requested content, set the selected thumbnail, and check processing for the just-uploaded video. Google and YouTube process that information under their own terms and privacy practices.

This validation site is hosted through Cloudflare Pages. Cloudflare may process ordinary connection and security information, such as IP addresses and request headers, to deliver and protect the site. WasNowForward has not added analytics, advertising, session replay, fingerprinting, or tracking scripts.

Support email is processed by the operator's email provider. Authorized data is not sold or shared with advertisers or unrelated third parties.

9. Cookies and browser storage

This static site does not intentionally set application cookies, local-storage identifiers, advertising identifiers, or analytics identifiers. Cloudflare or external sites reached through links may apply their own necessary security technologies and policies.

10. Children

The publisher application is an operator tool and is not directed to children. It does not offer public accounts or invite children to authorize YouTube write actions. The operator separately selects the made-for-kids designation for each uploaded video.

11. External policies

  • Google Privacy Policy
  • Google Account permissions and revocation
  • YouTube Terms of Service

12. Contact

Questions, complaints, revocation assistance, and deletion requests may be sent to wasnowforward@gmail.com. Include “WasNowForward Publisher” in the subject line and do not include credentials or tokens.

13. Changes to this policy

Material changes will be posted here with a revised effective date and policy identity. Publisher requires acceptance of its current embedded policy identity before live authorization or upload.

WasNowForward Publisher

Operated by WasNowForward. This application is not made, endorsed, sponsored, or operated by Google or YouTube.

Privacy Policy Terms of Service Support wasnowforward@gmail.com