Introduction
Longwave ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our service at longwave.media.
Data Controller
The data controller responsible for your personal information is:
Signal Group Limited
5 Essex Street, Vogeltown
New Plymouth 4310, New Zealand
Companies Office No: 1396666
NZBN: 9429035771678
Incorporated: 17 September 2003 · NZ Limited Company
For privacy enquiries contact privacy@longwave.media.
Information We Collect
When you use Longwave, we collect:
- Account Information: When you sign in with Google, we collect your name, email address, and Google profile information.
- YouTube Channel Data: When you connect your YouTube account, we access and store your YouTube channel name, channel ID, channel thumbnail, subscriber count, view count, video count, channel description, custom URL, creation date, and banner URL. We use these solely to display your channel information in the dashboard, to upload videos on your behalf, and to update the title and description of videos we have just uploaded (using AI-generated content from transcription).
- OAuth Access Tokens: We store encrypted OAuth tokens (access token and refresh token) to authenticate API calls to YouTube on your behalf. These tokens are encrypted using AES-256-CBC before storage and are never transmitted to third parties.
- X (Twitter) Account Information: If you connect your X account, we collect your X username and display name, and store encrypted OAuth tokens to post videos on your behalf.
- Instagram Account Information: If you connect your Instagram account, we collect your Instagram username, profile image, and Instagram Business account ID, and store encrypted OAuth tokens to post content on your behalf.
- Geolocation Data: When you sign in, we capture your approximate geographic location (country and city derived from your IP address via Vercel's edge geolocation) and your IP address. This data is stored on your customer record for fraud prevention and account security. On first sign-in, we may also send your IP address to proxycheck.io for VPN/proxy detection (see "Data Sharing and Third Parties" below).
- Usage Data: We collect information about how you use our service, including videos processed and uploads scheduled, to improve our service.
- API Call Logs: We log every YouTube upload API call (outcome, timestamp, and the YouTube video ID on successful uploads) in an internal audit log. This is used solely for quota reconciliation with Google and operational monitoring. These logs are retained for the life of your account.
- Upload History and Clip Metadata: We store metadata about every clip generated and published through the Service (titles, descriptions, tags, scheduling times, platform video IDs). This is retained for the life of your account to power your history view and analytics.
- Anonymous Visitor Analytics: If you visit our demo page (
/demo) before signing in, we collect anonymous interaction data to understand how visitors use the demo. This includes: pages viewed, sample card clicks, URL paste attempts, terminal interactions, and sign-in gate impressions. We also capture your approximate country (from your IP address via Vercel edge headers), browser type, operating system, device type (mobile/desktop/tablet), screen resolution, and language preference. This data is tied to a random identifier stored in your browser's localStorage — not to any personal information. We use this data solely to improve the demo experience and measure product-market fit. You can opt out by clearing your localStorage for our domain; this will not affect any other functionality. - Billing and Auto-recharge: We store your Stripe Customer ID and a reference to your saved payment method (held by Stripe - we never store card details) to enable automatic credit top-ups if you opt in to auto-recharge. We store your configured top-up amount and monthly spend cap. This data is retained until you disable auto-recharge or delete your account.
- Affiliate and Referral Data: If you join the affiliate program, we store your referral code, commission balance, tier status, and payout history. We record which customers were referred via your link using a first-party cookie (
ss_ref, 1-year duration) set when a visitor arrives via your referral URL. We retain affiliate commission records for the life of your affiliate account for financial compliance and audit purposes. - Podcast Content: If you use the podcast feature, we extract audio from your uploaded video files, along with podcast metadata (show title, description, author, category, language, cover art). This content is used to generate RSS feeds and distribute to podcast directories.
Public Profile Pages (Link in Bio)
If you enable the Link in Bio feature, a public page is created at yourname.longwave.media. This page displays information pulled from your connected platforms:
- Publicly displayed information: Your YouTube channel name, profile image, subscriber count, and recent videos; recent X posts; podcast episodes from your Apple Podcasts or RSS feed; and Substack newsletter posts.
- Visitor data: We log page views for analytics purposes. If a visitor subscribes to your page, we collect their email address solely to notify you and/or to forward it to a newsletter platform you have authorised (e.g. Substack).
- No tracking of visitors: We do not use cookies or persistent tracking on public Link in Bio pages beyond a first-party analytics counter.
- Disabling the page: You can disable your public page at any time from your account settings. On disabling, the page is immediately removed from public access. Visitor subscription emails previously collected are retained unless you request deletion.
How We Use Google User Data
Longwave uses YouTube API Services and is not endorsed by or affiliated with Google.
Longwave's use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we use Google user data only for the following purposes:
- YouTube Uploads: We use your YouTube OAuth credentials to upload short-form video clips and full-length episode videos to your YouTube channel on your behalf, using the
youtube.upload scope. - Playlist management and thumbnails: We use the
youtube.force-ssl scope to add uploaded videos to the YouTube playlist you select (playlistItems.insert) and, if you enable the thumbnail feature, to set a custom thumbnail on videos we have just uploaded (thumbnails.set). This scope is used only on videos we have just uploaded on your behalf - we do not modify any other videos on your channel. - Channel Information: We use the
youtube.readonly scope to read your channel name, ID, and thumbnail to display your account information in the dashboard. - Authentication: We use your Google account email address to identify your account. We do not use your Google data for advertising, market research, or any purpose unrelated to providing this service.
We do not use Google user data to serve advertisements, train AI models, sell to third parties, or for any purpose other than providing and improving the Longwave service.
For a full step-by-step explanation of how we access and process your YouTube videos, see our How We Use Your YouTube Data page.
Legal Basis for Processing (GDPR)
For users in the EEA, UK, or Switzerland, we process your personal data under the following legal bases:
| Data / Purpose | Legal Basis | Details |
|---|
| Account creation, authentication, session management | Contract performance (Art. 6(1)(b)) | Necessary to provide the Service you signed up for |
| YouTube and X OAuth tokens, upload automation | Contract performance (Art. 6(1)(b)) | Necessary to upload content on your behalf |
| Transactional emails (receipts, alerts) | Contract performance (Art. 6(1)(b)) | Necessary to fulfil billing and account obligations |
| Lifecycle and summary emails | Legitimate interests (Art. 6(1)(f)) | Keeping you informed about your account; opt-out available at any time |
| API call audit logs, usage data | Legitimate interests (Art. 6(1)(f)) | Quota reconciliation, fraud prevention, service integrity |
| Security logging, fraud prevention | Legitimate interests (Art. 6(1)(f)) | Protecting the Service and other users |
| Podcast audio extraction, RSS feed generation, directory distribution | Contract performance (Art. 6(1)(b)) | Necessary to provide the podcast distribution feature you enabled |
| Instagram OAuth tokens, content publishing via Meta API | Contract performance (Art. 6(1)(b)) | Necessary to publish content to your Instagram account on your behalf |
| Anonymous visitor analytics (demo page interactions) | Legitimate interests (Art. 6(1)(f)) | Improving the demo experience and measuring product-market fit; data is non-identifying and not shared |
How We Use Your Information
- To provide our video processing and automated distribution service
- To publish short-form video clips to your connected YouTube channel and X account on your behalf - automatically, at times you configure or that the Service schedules for optimal reach
- To authenticate your identity and manage your account session
- To send you transactional emails about your account (credit purchases, balance alerts, auto-recharge notifications)
- To send you optional lifecycle and summary emails (welcome, first Short ready, weekly summary, monthly report) - these can be disabled at any time from Settings or via the unsubscribe link in each email
- To ensure the security and integrity of our service
- To extract audio from your uploaded content and distribute it via RSS feeds to podcast directories on your behalf
- To publish content to your connected Instagram account on your behalf
Email Communications
We send two categories of email:
- Transactional - purchase receipts, credit balance alerts, auto-recharge confirmations. These are sent in direct response to account activity and cannot be opted out of while your account is active.
- Lifecycle & summary - welcome, first Short ready, weekly performance summary, monthly channel report. All default to enabled and can be disabled individually from Settings or via the one-click unsubscribe link in each email.
We log every email sent (recipient, subject, type, timestamp, success/fail) for operational purposes. These logs are retained for 90 days. We never share email addresses or send-history with third parties.
Cookies and Local Storage
We use minimal cookies and local storage:
- Session cookie: A 30-day httpOnly JWT to keep you signed in.
- OAuth cookies: Two short-lived cookies used during sign-in to prevent CSRF and secure the authorisation flow.
- Anonymous analytics identifier: A random UUID stored in your browser's localStorage (
anon_client_id) when you visit our demo page. This is not a cookie and can be cleared at any time by clearing your browser's local storage for our domain. It is used solely to group your anonymous interactions during a single browser session. We also set a corresponding httpOnly cookie (anon_client_id, 24-hour expiry) so that if you sign up during the same session, we can connect your pre-signup interactions to your account — this link is one-way and does not expose your identity. - Affiliate referral cookie: A first-party cookie (
ss_ref, 1-year duration) set when you arrive via an affiliate referral link, used solely to attribute sign-ups to the referring affiliate.
We do not use advertising, analytics, or tracking cookies from third parties. For full details see our Cookie Policy.
Data Storage and Security
We store your data using industry-standard security measures:
- OAuth token encryption: All OAuth access tokens and refresh tokens are encrypted with AES-256-CBC before being stored in our database. The encryption keys are never stored alongside the encrypted data.
- Database security: Your data is stored in Supabase (hosted on AWS in US West 2 - Oregon) with access restricted to authorized service accounts only.
- Session security: User sessions are managed via short-lived JWT tokens stored in httpOnly cookies, preventing client-side access.
- Video file handling: For Shorts generation, source video files are fetched and processed in memory on our worker servers and are never written to cloud storage. For episode uploads, your episode file is stored temporarily in Cloudflare R2 (US-based) during the upload and processing window, then permanently deleted once the YouTube upload completes. During upload to YouTube, video files are transiently routed through a US-based upload proxy (Fly.io) for geographic performance - they pass through in transit only and are not stored by Fly.io.
- Podcast audio storage: If you use the podcast feature, extracted audio files are stored permanently in Cloudflare R2 (US-based) to serve RSS feed downloads and directory distribution. Audio files are retained for as long as your podcast feed is active. If you disable the podcast feature, audio files are removed from the RSS feed but may remain in the R2 bucket until you delete the associated hub upload job.
Data Sharing and Third Parties
We integrate with the following third-party services to provide our service:
- Google/YouTube API: We transmit video files and metadata to YouTube on your behalf when you use our upload feature. Google's privacy policy applies to data handled by YouTube.
- Google Gemini API (production outputs): We send video transcripts, titles, and metadata to the Google Gemini API to generate AI-powered titles, descriptions, chapters, hashtags, and captions for your clips and episodes. We do not send raw video files to Gemini - only text derived from your content. This data is used solely to generate output returned to you and is not used to train or improve Gemini or any other AI model. Google's privacy policy and the Gemini API Additional Terms of Service apply.
- Google Gemini API (research tools): When you use AI-powered research features in the Insights section (such as content gap reports and transcript Q&A), excerpts from your video transcripts are sent to the Google Gemini API for processing. Only text excerpts are sent - no video files or personal information. Results are returned to you and not stored by Google for training purposes. These features are provided free of charge and are subject to daily usage limits to ensure fair access for all users. Google's privacy policy and Gemini API Terms of Service apply.
- X (Twitter) API: We transmit video files and post text to X on your behalf. X's privacy policy applies to data handled by X.
- Instagram / Meta API: If you connect your Instagram account, we transmit video files and metadata to your Instagram Business account on your behalf via Meta's Graph API. Meta's privacy policy applies to data handled by Meta.
- Supabase: We use Supabase for encrypted data storage and management. Supabase's privacy policy applies.
- Stripe: We use Stripe to process credit purchases. When you buy credits, your payment details are handled directly by Stripe - we never store card numbers. Stripe's privacy policy applies.
- Google Gmail API: We use Gmail OAuth to send transactional and lifecycle emails from dave@longwave.media. Email content is transmitted through Google's SMTP infrastructure. Google's privacy policy applies.
- Cloudflare R2: Episode files are temporarily stored in Cloudflare R2 (US-based object storage) during the upload and processing window. Files are permanently deleted as soon as the YouTube upload completes. Cloudflare's privacy policy applies.
- Fly.io (Upload Proxy): Video files are transiently routed through a Fly.io-hosted proxy in the United States during upload to YouTube. Video content is not stored by Fly.io. Fly.io's privacy policy applies to data in transit through their infrastructure.
- proxycheck.io: On first sign-in, we send your IP address to proxycheck.io to detect VPN or proxy usage. This is used solely for fraud prevention. proxycheck.io's privacy policy applies to data they process. The free tier requires no API key; you may contact us to opt out of this check.
- Podcast Directories (Apple Podcasts, Spotify, YouTube Music, Amazon Music, iHeartRadio, Pocket Casts, and others): If you enable the podcast feature, we transmit your podcast RSS feed (including episode audio files, titles, descriptions, cover art, and metadata) to these directories for distribution. Each directory's privacy policy applies to data handled by that directory. We are not responsible for how podcast directories handle your content or listener data.
We do not sell, rent, or share your personal data or Google user data with any third parties for marketing, advertising, or any other commercial purpose.
International transfers (GDPR):Your data is stored in the United States (Supabase on AWS us-west-2). Signal Group Limited is based in New Zealand, which is recognised by the European Commission as providing adequate protection for personal data under GDPR Article 45. Transfers to US-based sub-processors (Supabase, Stripe, Fly.io) are covered by Standard Contractual Clauses (SCCs) in those providers' data processing agreements, which you can request via privacy@longwave.media.
Your Rights
You have the right to:
- Access - request a copy of the personal data we hold about you
- Rectification - request correction of inaccurate or incomplete data
- Erasure - request deletion of your account and all associated personal data
- Restriction - request that we restrict processing of your data in certain circumstances (e.g. while a dispute is resolved)
- Portability - receive your personal data in a structured, machine-readable format
- Object - object to processing based on legitimate interests; we will stop unless we can demonstrate compelling legitimate grounds
- Withdraw consent - where processing is based on consent (e.g. lifecycle emails), withdraw it at any time without affecting prior processing. Use the unsubscribe link in any email or go to Settings
- Revoke platform access - disconnect YouTube at any time via Google Account Permissions or X via X account settings
- Lodge a complaint - if you are in the EEA or UK, you have the right to lodge a complaint with your national data protection authority. In New Zealand, complaints may be directed to the Office of the Privacy Commissioner
To exercise any of these rights, contact us at privacy@longwave.media. We will respond within 30 days. We may need to verify your identity before processing your request.
Data Retention
- Account data: Retained for as long as your account is active.
- OAuth tokens: Retained until you disconnect the platform or delete your account. When you disconnect, your OAuth credentials are permanently deleted from our systems. You can also independently revoke access at any time via Google Account Permissions.
- Channel snapshot data: Channel statistics (subscriber and view counts from the YouTube Data API) are cached for display purposes and refreshed when you open the dashboard.
- Email send logs: Records of emails sent (recipient address, subject, type, timestamp) are retained for 90 days for operational and compliance purposes, then deleted.
- Anonymous session data: Non-converted anonymous visitor sessions (including interaction events) are retained for 90 days, then permanently deleted. Converted sessions (where the visitor later signed up) are retained for the life of the associated account — the anonymous identifier is linked to the account and subject to the same deletion policy. The 90-day prune runs daily.
- Video processing data: Metadata about processed clips (titles, timestamps) is retained for your account history. Source video files are deleted from our worker machines immediately after processing completes. Episode files stored in Cloudflare R2 are permanently deleted as soon as the YouTube upload finishes.
- Podcast audio: Extracted audio files are retained in Cloudflare R2 for as long as your podcast feed is active. If you disable the podcast feature, audio files are no longer served via RSS but remain stored until you delete the associated hub upload job. Audio files are permanently deleted within 30 days of the associated hub upload job being deleted.
- Geolocation and VPN data: IP address, country, city, and VPN status are retained for the life of your account for fraud prevention and account security. All geolocation data is permanently deleted within 30 days of account deletion.
- Upon account deletion: All personal data, OAuth credentials, and account history are permanently deleted within 30 days of your request.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by applicable law. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, describing the nature of the breach, the likely consequences, and the measures we have taken or propose to take to address it.
To report a suspected security vulnerability or data breach, contact privacy@longwave.media immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date below. Your continued use of the service after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at: privacy@longwave.media
Last Updated: July 28, 2026