Privacy Policy
1. Who is responsible
LionAI is software operated by Lionel Mele, Im wiessler 5b thurgau schweiz ("the operator", "we"). Contact for all privacy matters: lionelmelee@gmail.com.
The operator uses LionAI to create short videos for the operator's own business projects and to publish them on social media accounts the operator owns or is authorized to manage. LionAI is not a public service: third parties cannot sign up or connect their own accounts.
2. Which data LionAI processes
LionAI processes data only for accounts the operator connects through the platform's official authorization screen:
| Category | Examples | Source |
|---|---|---|
| Account identity | Account or channel ID, username or handle, display name, account type | Platform API after authorization |
| Granted permissions | The permission scopes the account owner approved | Platform API |
| Access credentials | Access and refresh tokens issued by the platform | Platform authorization |
| Content records | Video file fingerprint, the title, caption and hashtags LionAI wrote, disclosure settings, the business project the content belongs to | Created in LionAI |
| Publishing status | Video or media ID, upload and processing status, privacy status, timestamps, error codes returned by the platform | Platform API |
| Performance statistics | Aggregated figures of the operator's own posts where the platform provides them, e.g. views, likes, comments | Platform API |
| Technical logs | Timestamps, actions and outcomes of connection, publishing and measurement steps – never token values | LionAI |
LionAI does not collect data about individual viewers, subscribers or followers, does not read private messages or the content of comments, and does not process payment data.
3. Purposes
- Show the operator which account is connected and which permissions were granted.
- Publish content the operator approved – directly or through a policy the operator enabled – to the account bound to the matching business project.
- Confirm that a publication succeeded, check its processing status and prevent duplicate posts.
- Measure the performance of the operator's own content to plan future content.
4. Google and YouTube data
LionAI uses the YouTube API Services through an OAuth 2.0 client named "LionAI". By using LionAI's YouTube features, you agree to be bound by the YouTube Terms of Service; Google's handling of data is described in the Google Privacy Policy.
Permissions requested
youtube.upload– to upload the operator's own videos to the operator's own channel.youtube.readonly– to identify the connected channel and to read the status and statistics of the operator's own uploads.
LionAI does not request the YouTube Analytics or YouTube Reporting API, and it does not request permissions to manage comments, playlists of other users, memberships or monetization.
API calls and what they are used for
| API call | Used for |
|---|---|
channels.list (own channel only) | Identify the connected channel and confirm, before every upload, that it is the channel bound to the business project |
videos.insert | Upload a video with title, description, privacy status and the paid-promotion disclosure |
videos.list (own uploads only) | Confirm processing, privacy status and the published title/description; read view, like and comment counts of the operator's own videos |
playlistItems.list (own uploads playlist) | After a network timeout, check whether an upload already arrived instead of uploading it a second time |
| Google OAuth token revocation | Revoke LionAI's access when the operator disconnects the channel in LionAI |
Storage and use of YouTube data
- YouTube data is stored only on the operator's computer, never sold, never used for advertising and never shared with third parties.
- Statistics (e.g. view counts) of the operator's own videos are kept only while LionAI's authorization has been confirmed within the last 30 days; otherwise they are deleted.
- Other data received from the YouTube API (for example the status, title and description as returned by YouTube) is refreshed during normal use and deleted when it has not been refreshed for 30 days.
- When access is revoked, all data LionAI received from the YouTube API under that authorization is deleted – immediately when the operator disconnects in LionAI, otherwise as soon as LionAI detects the revocation at its next contact with Google (see Retention and deletion). LionAI's own records (for example that a video was published and the title LionAI wrote) remain until deletion is requested.
Revoking access
In addition to disconnecting the channel in LionAI, you can revoke LionAI's access to your Google account at any time on the Google security settings page: security.google.com/settings/security/permissions.
LionAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Storage and protection
- All data listed above is stored on the operator's own computer. LionAI does not operate a cloud database for it.
- Tokens and application secrets are encrypted with the operating system's data protection (Windows DPAPI, bound to the operator's user account). Program parts access them only through an internal secret broker; they are never shown in the interface, written to logs or returned by LionAI's interfaces.
- Each connected account is bound to exactly one business project. LionAI refuses to publish one project's content to another project's account.
- Temporary media hosting (only when publishing to Instagram is enabled): Instagram fetches videos from a web address. For this, LionAI uploads the video to a private Cloudflare R2 storage bucket under a random name and gives Instagram a signed link that expires after at most one hour. The copy is deleted once Instagram has processed it; a storage rule additionally deletes any remaining copy after one day.
6. Platforms and service providers
Data is exchanged only with the platform concerned, through its official API, when the operator performs an action or a scheduled status or measurement step runs:
- Google / YouTube (YouTube Data API) – Google Privacy Policy
- TikTok (Login Kit, Content Posting API) – TikTok Privacy Policy
- Meta / Instagram (Instagram API with Instagram Login) – Instagram Privacy Policy
- Cloudflare (R2 storage, temporary video copies only, see section 5) – Cloudflare Privacy Policy
LionAI does not sell or rent data and does not use it for advertising.
7. Retention and deletion
- Disconnecting an account in LionAI deletes all stored tokens of that account immediately and revokes them at the platform where the platform offers revocation (Google, TikTok). Instagram Login offers apps no revocation; the account owner removes LionAI in Instagram's settings.
- YouTube: on disconnection – or when Google reports that access was revoked – LionAI also deletes the channel identity, the video IDs, status data and statistics it received from the YouTube API under that authorization, at the latest within 7 days. See also section 4.
- Instagram and TikTok: the connection record (account ID and name, marked as revoked), publishing records and performance figures are kept for the operator's records until deletion is requested.
- Posts already published remain on the platform until they are deleted there.
How to request deletion: see Data deletion.
8. Cookies and tracking
This website uses no cookies, no analytics, no tracking and no third-party content. LionAI itself does not place cookies or similar technologies on anyone's device.
9. Your rights
Depending on the data protection law that applies to you (for example the Swiss Federal Act on Data Protection or the EU General Data Protection Regulation), you may have the right to access, correct or delete your data, to object to or restrict its processing, and to lodge a complaint with a data protection authority. Please send requests to lionelmelee@gmail.com.
10. Changes
We update this policy when LionAI's data processing changes. The current version is always available at https://lionai.ch/privacy.