← Shortform

Privacy Policy

Last updated October 3, 2026

Written for the private beta as a reasonable, accurate draft -- not reviewed by a lawyer. Have it reviewed before public launch.

What we store

Account info
Your email address, display name, time zone, and whether you want failure/reconnect emails.
Connected-platform tokens
The access and refresh tokens for each platform you connect (Twitch, YouTube, TikTok, Instagram), encrypted at rest. They're used only to import clips, publish what you schedule, refresh themselves when they're about to expire, and read performance numbers for posts made through the app. They're never sent to your browser.
Clips and posts
The video file (stored on Cloudflare R2), its title, duration and dimensions, and the caption, schedule time and per-platform settings you set for each post.
Publishing history
What happened each time we tried to publish a post -- when, whether it succeeded, and the error if it didn't.
Performance numbers
Daily view/like/comment/share counts (and a few platform-specific extras, like Instagram saves) for posts made through the app, for 90 days after each one goes live. We only ever show you a real number or say we don't have one yet -- never a made-up figure.

Why we ask for each platform's permissions

Each platform requires us to request specific permissions ("scopes") before we can do anything on your behalf. We request the narrowest set each one offers for what the app actually does:

Twitch
Your email address (to identify your account) and permission to manage your clips, which we use only to read and download your existing clips for import -- we never edit, delete or create anything on your Twitch channel.
YouTube (Google)
Permission to upload videos (to publish your scheduled posts), read your channel's videos (to show view/like/comment counts), and read your YouTube Analytics (to show shares and watch time). We never read or touch anything on your channel beyond what you post through the app.
TikTok
Permission to post on your behalf (Direct Post), basic profile info (your nickname and avatar, shown in the composer), and permission to query your videos' stats for analytics.
Instagram
Basic account info, permission to publish Reels on your behalf, and permission to read insights (views, likes, saves, reach) for posts made through the app.

How we use it

Shortform uses your data only to run the service: publishing what you schedule, when you schedule it, and showing you how it performed. We never post anything you did not schedule, and we never use your videos for advertising or to train any model.

We don't sell your data.

How long we keep it

A clip's video file is deleted 30 days after its scheduled publish time (or, if it's reused across several scheduled posts, 30 days after the latest one). A clip that's never scheduled is deleted 30 days after upload. Performance numbers are kept for 90 days after a post goes live, then stop updating. None of this deletes the post that's already live on YouTube, TikTok or Instagram -- it only removes what we store.

Disconnecting a platform in Settings immediately revokes and deletes that platform's tokens. It doesn't delete your clips, posts or performance history -- those follow the retention rule above, or you can delete your whole account (next section).

Deleting your account and data

There isn't a self-serve "delete account" button yet -- email us at support@example.com and we'll delete your account, connected-platform tokens, stored clips and performance history within a few business days. Posts already live on a platform aren't affected; you'd remove those from that platform directly.

Who we share it with

Vercel
Hosts the app.
Supabase
Database, authentication and sign-in.
Cloudflare (R2)
Stores your video files.
Trigger.dev
Runs scheduled publishing and analytics jobs.
Resend
Sends failure and reconnect-needed emails.
Twitch, YouTube/Google, TikTok, Instagram/Meta
Only the platforms you connect, and only to do what you asked (import, publish, read stats).

Children

Shortform is not directed at children under 13, and we don't knowingly collect data from them.

Questions: support@example.com