Paul · Google data

For OAuth and YouTube API review

Google & YouTube data

A plain description of the Google user data we request, why, and how it is limited.

Last updated 15 August 2026 · Same facts as the Privacy Policy

What the app is

shorts is a desktop publisher. The operator runs it on their own computer, authorizes their Google account once, and uploads vertical videos they created to the kuroshibacyberpunk YouTube channel. PAUL is the public website for that channel. Website visitors never see a Google sign-in.

OAuth scope we request

One scope: https://www.googleapis.com/auth/youtube (YouTube Data API v3 — manage your YouTube account). We use it only to:

Narrower scopes such as youtube.upload do not cover thumbnail and status fields we set in the same flow. We do not request Gmail, Drive, or profile scopes.

YouTube API Services

The publisher and this website use YouTube API Services. Required notices:

Public catalog on this site

PAUL stores a cache of public kuroshibacyberpunk videos (ID, title, thumbnail, URL) in Cloudflare D1 so the site can list them. That cache is filled with an API key, not with a visitor’s Google account. Private and unlisted uploads are not listed.

What we do not do

Revoke and delete

  1. Open Google Account → Third-party access
  2. Remove shorts / PAUL
  3. Delete tokens/youtube_token.json on the operator machine
  4. Email ezioxxk@gmail.com to clear the site’s video cache