Privacy Policy
Last updated: 3 September 2026
Coppola is an autonomous video studio operated by UpWoof at
coppola.upwoof.ai. This policy sets out what the service records about you,
where that information goes, and what you can do about it. It covers the website and the
background pipeline that produces and publishes videos. It does not cover YouTube, Slack or
any other site you reach from here, each of which has its own policy.
1. Information you give us
- Your account. An email address and a password. The password is never stored; what we keep is a bcrypt hash of it. We also record when you confirmed your address, and a count of consecutive failed sign-in attempts so an account can be locked after repeated guesses.
- Two-factor authentication, if you turn it on. Your TOTP secret, encrypted at rest. Backup codes are stored only as SHA256 digests, so we cannot show you a code you have lost and can only tell whether one you present is valid.
- Your time zone. Captured from your browser at sign-up and editable afterwards. Publishing schedules run in it.
- What you create. Channels, themes, topics, video titles and descriptions, and any images you upload for a channel's banner, avatar or title cards.
2. Information we record as you use the service
- Views on published videos. When a video's watch page is served we record that it was watched. The viewer is identified by a salted SHA256 digest of their IP address and browser user-agent string. We do not store the address itself. The digest exists to stop one person reloading a page from counting twice inside thirty minutes, and it cannot be reversed to identify anyone. Automated traffic is excluded before any of this happens.
- Ratings. If you press thumbs up or thumbs down on a published video, we store your account, the video and which way you pressed. Changing your mind updates that record. Withdrawing it deletes it.
- Subscriptions. Which channels you follow, and when you started.
- Content policy findings. If something you submit is refused under our content policy, we record the category of rule it broke and when. We do not keep a copy of the text that was refused. Five findings inside twenty-four hours suspend the account, and these records are deleted once they age out of that window.
- Server logs. Ordinary web server and application logs, including IP addresses, for security and diagnosis. Rate limiting keeps its own short-lived counters in memory, never in the database.
3. YouTube
Coppola uses YouTube API Services to upload videos to a channel you connect. By connecting a YouTube channel you are agreeing to the YouTube Terms of Service, and Google's own handling of your data is governed by the Google Privacy Policy.
When you connect a channel we ask Google for the youtube scope and store the
resulting refresh token encrypted at rest, together with the channel's YouTube ID and title.
The token is what lets the pipeline upload on your behalf while you are not signed in. We
also record when we last confirmed the authorization was still valid, so we can tell you
when it has expired rather than failing quietly.
We use that access to upload videos Coppola produced for the channel you filed them under, to set their title, description, tags and category, and to read back a listing when we need to repair one. We do not read your other videos, your subscriber list, your comments or your analytics.
You can disconnect a channel from your account page at any time, which deletes our copy of the token. You can also revoke our access directly from Google's security settings. Videos already uploaded stay on YouTube and are yours to delete there.
4. How we use what we hold
To run the service: authenticating you, generating and rendering videos, publishing them on Coppola, syndicating them where you have asked us to, and telling you what the pipeline did. To keep the service safe: locking accounts after failed sign-ins, rate limiting, and enforcing the content policy. To keep the catalogue working: counting views and ratings, and indexing published titles so they can be searched.
We do not sell your information. We do not use it to build advertising profiles, and we do not send marketing email. The only email we send is transactional: address confirmation, password resets and account unlock links.
5. Who else sees it
Coppola relies on a small number of outside services, each for one job:
- Anthropic receives the prompts that generate themes, topics and video titles. These carry the genre and the catalogue entries being built on, not your account details.
- Google and YouTube receive an uploaded video and its listing, for channels you have connected. See section 3.
-
Amazon Web Services stores uploaded images and rendered video files, in
an S3 bucket in the
us-east-1region. - Postmark delivers transactional email, so it handles your address and the contents of those messages.
- Slack receives pipeline notifications, but only into a workspace and channel you have connected yourself. Without that connection nothing is sent.
- Cloudflare sits in front of the site and terminates TLS, so requests pass through it.
Video rendering, narration and search run on hardware we operate ourselves rather than on a third-party platform. Beyond the services above, we disclose information only where the law requires it.
6. Cookies and analytics
The site sets a session cookie to keep you signed in and a token used to block cross-site request forgery. Both are necessary for the site to work.
We also run Google Analytics on every page, including pages you can reach without an account. It sets its own cookies and reports page views to Google, which we use to see which videos are being watched. If you would rather it did not, Google publishes a browser opt-out add-on, and most browsers offer their own controls.
Embedded YouTube players are loaded from youtube-nocookie.com, which sets no
tracking cookie until you press play.
7. How it is protected
Traffic to the site is encrypted in transit. The fields that would do the most damage if they leaked are encrypted at rest rather than stored in the clear: YouTube refresh tokens, Slack webhook URLs and TOTP secrets. Those same fields are filtered out of application logs, because an encrypted column is still readable to anything that prints the record.
A content security policy restricts what can execute on a page, and text you submit is escaped before it is rendered. Optional two-factor authentication is available on every account and we suggest turning it on. No system is impossible to breach, and we do not claim otherwise.
8. How long it is kept
Account information is kept while the account exists. Videos and channels are kept until you delete them. View records and ratings persist for as long as the video does, since they are what its counts are made of. Content policy findings are deleted once they fall outside the rolling twenty-four hour window they are counted in. Uploaded files that are never attached to anything are purged after two days.
Deleting a channel releases the videos filed under it rather than destroying them, because a video may already be published at a public address. Ask us if you want those removed as well.
9. Your choices
You can change your email address, time zone and two-factor settings from your account page, and disconnect YouTube or Slack there at any time. You can delete channels, themes, topics and videos you own. To see a copy of what we hold about you, correct it, or have your account and its contents deleted, write to us at the address below and we will act on it.
10. Children
Coppola is not intended for children. We do not knowingly create accounts for, or collect information from, anyone under 18. Individual videos carry their own classification, which may restrict them further.
11. Changes
When this policy changes we update the date at the top of the page. If a change materially affects what we do with your information, we will tell account holders directly before it takes effect.
12. Contact
Write to [email protected] with any question about this policy or about the information we hold.