← video-goblin

Privacy Policy

Last updated 3 August 2026

The short version

video-goblin is a video editor that runs in your browser. Your videos, images, audio and projects stay on your own machine — they are never uploaded to our servers. We hold your Google account details and your AI settings, and nothing else. There is no analytics, no tracking, and no advertising anywhere in this app.

Who we are

video-goblin (“we”, “us”) is operated by Sergej Popov. For anything in this policy, contact aspopov8@gmail.com.

What we collect

Account information

If you sign in with Google, we receive your name, email address, profile picture and Google account identifier through Firebase Authentication. We use these only to identify your account and to show who is signed in.

AI settings

If you add an OpenAI or Google Gemini API key, it is stored server-side against your account, together with your model preferences. Your key is never sent back to the browser and is never shown again after you save it — the app only ever displays whether a key is present. It is used solely to make the AI requests you ask for.

Technical logs

Our hosting and server functions (Google Firebase) keep standard operational logs — IP address, timestamp, and which request was made — used to run and debug the service.

What stays on your device

Your media files, projects, timeline state and interface preferences are stored in your browser using localStorage and IndexedDB. They do not reach our servers. Clearing your browser storage deletes them, and we cannot recover them.

Exporting a video happens entirely in your browser. The exported file is never uploaded to us.

Google Drive

Connecting Google Drive is optional and the app works fully without it. When you connect it, we request a single permission scope, https://www.googleapis.com/auth/drive.file. This is deliberately the narrowest Drive permission available: it gives the app access only to

  • files you explicitly choose in Google's own file picker, and
  • files the app itself creates, such as projects you save to Drive.

The app cannot browse, list or read the rest of your Drive, and cannot see the contents of a folder you merely select. Files move directly between your browser and Google — they do not pass through our servers. Your Drive access token is held in memory for the duration of your session, is never written to storage, and is never sent to us. You can disconnect at any time from the Drive menu, which revokes the permission.

video-goblin's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI providers

When you use the AI agent, the content needed for that request is sent to the provider you configured — OpenAI or Google Gemini — using your own API key. Depending on what you ask for, this may include your chat messages, frames captured from your video, or audio to be transcribed. That content is handled under the provider's own terms and privacy policy, not ours:

  • OpenAI Privacy Policy
  • Google Privacy Policy

We do not keep copies of your prompts, generated output, or the frames sent for analysis. If you never configure an AI key, none of this applies to you.

Cookies and tracking

We use no analytics, no advertising, and no third-party tracking of any kind. Firebase Authentication stores sign-in state in your browser so you are not signed out on every reload. That is the only such storage, and it exists purely to keep you signed in.

Where your data is held

Account details and AI settings are stored using Google Firebase, in Google Cloud data centres in the United States. Google acts as our infrastructure provider.

Keeping and deleting data

We keep your account details and AI settings for as long as your account exists. You can:

  • remove a stored API key at any time by clearing that field in AI Settings and saving;
  • disconnect Google Drive from the Drive menu, revoking our access;
  • revoke this app's access to your Google account entirely at myaccount.google.com/permissions;
  • delete local projects and media by clearing your browser's site data;
  • ask us to delete your account and everything stored against it by emailing aspopov8@gmail.com. We will action this within 30 days.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold about you, and to object to how we handle it. Email aspopov8@gmail.com and we will respond. If you are in the UK or EU and are unhappy with our response, you may complain to your data protection authority.

Children

This service is not directed at children under 13, and we do not knowingly collect their personal data.

Changes

We may update this policy. The “last updated” date above will change, and material changes will be signalled in the app.

Terms of Service Back to the editor