Before You Pull Studio
Privacy Policy
Effective October 6, 2026
Studio is local-first software for producing short-form content and understanding its performance. This policy explains the information it handles and the choices you have.
1. This website and the local application
This public website describes Before You Pull Studio. It does not provide accounts, a cloud Studio, or access to your local application. The site does not embed third-party trackers, advertising, analytics scripts, or social widgets.
Vercel hosts this website and may process standard request information, such as IP address, browser information, requested URL, and request time, to deliver, secure, and operate the site. See Vercel’s Privacy Policy.
2. Information you provide
Studio handles account authorization, product configuration, and information you voluntarily enter into its workflows. This can include ideas, Episode Briefs, scripts, production assets, review decisions, and publication records. Current project records and analytics history are stored locally.
If you email support, your sender address, message, and attachments are used to respond to your request. Support email is received through Resend, processed by a separate Vercel-hosted forwarding handler, and delivered to the owner’s Gmail inbox. These email services are separate from the local Studio. The forwarding handler does not intentionally retain message content or log email bodies or credentials. Do not send access tokens, passwords, or provider secrets.
3. Information from connected social accounts
You choose whether to connect an account and authorize access through its provider. Available information depends on granted permissions, account type, provider support, and reporting availability. A missing metric is not treated as zero.
Google / YouTube
Studio uses YouTube API Services. It may read channel identity; subscriber, video, and view counts; owned video metadata and statistics; and supported YouTube Analytics reports. Its configured permissions are read-only. See the Google Privacy Policy.
TikTok
Studio may read basic user and profile identity; follower, following, like, and video statistics; owned video metadata; and view, like, comment, and share counts. The normal configured TikTok integration does not provide Creator Rewards data or the complete Creator Center analytics dataset. See TikTok’s Privacy Policy.
Meta / Instagram
For authorized professional accounts, Studio may read account identity, follower and media information, owned media metadata, and supported media or account insights. These can include views, reach, likes, comments, shares, saves, and interactions where provided. Not every field is available for every account or media type. See the Instagram Privacy Policy.
4. How information is used
Connected-account information is used to provide account connection, analytics, performance tracking, comparable observations, historical comparisons, evidence-based Learnings, and troubleshooting of your integration. The public website does not receive your local analytics history.
The current version does not use connected social credentials to automatically publish content. Publication occurs externally and remains your responsibility.
5. Credentials and local protection
Access and refresh credentials are stored locally and encrypted using the operating system’s local protection mechanism. The current Windows implementation uses user-bound operating system protection. Credentials are not intentionally stored in browser local storage or normal application logs. Authorization codes are used for the authorization exchange and are not retained as application records.
Developer client secrets are supplied through local environment configuration rather than the browser. Encryption reduces exposure; it does not guarantee protection against a compromised device, operating system, or user account.
6. Sharing and third parties
Before You Pull does not sell personal information or connected-account information. Studio communicates with Google / YouTube, TikTok, and Meta / Instagram when you authorize a connection or collect supported analytics. Each provider handles information under its own policies.
Content production can use owner-configured services, including Codex-assisted production, visual generation providers, and ElevenLabs narration. Material sent to a configured service is processed under that service’s terms and privacy practices. These production services are separate from read-only social analytics; connected social credentials are not intended as production inputs.
Information may also be disclosed when required by applicable law or when necessary to address a support request you initiate. Send only the information needed for that request.
7. Retention, disconnection, and deletion
Analytics history may remain locally so historical comparisons and Learnings can use it. Disconnecting a provider stops local collection and removes the locally stored connection credentials. Historical analytics and publication records may remain until deleted separately.
Disconnecting locally does not necessarily revoke the provider’s authorization. Manage or revoke that authorization in the provider’s account settings. For Google, use Google’s third-party connections settings. TikTok and Instagram also provide account settings for connected applications.
To remove retained information, delete the corresponding local analytics records separately. Before You Pull does not host a central copy that support can erase remotely. Contact support@beforeyoupull.com for help identifying the local records to remove. Include the provider and the type of records, without sending credentials. Copies you create in backups or exports require separate deletion.
Support correspondence can remain in Resend and the owner’s Gmail mailbox while needed to handle your request or maintain support records, subject to those services’ retention and backup practices. You can contact support to request deletion of that correspondence. See Resend’s Privacy Policy and Google’s Privacy Policy.
8. Security and your choices
The application uses local credential encryption, authorization state checks, and bounded error reporting to reduce avoidable exposure. No system is completely secure. Keep your device, account, and backups protected, and review the permissions you grant.
You can decline to connect accounts, disconnect a provider, revoke provider-side access, remove local records, and choose which content-production services to configure. Features that depend on that information may then be unavailable.
9. Children
Studio is intended for people eligible to use the connected platforms and authorize their accounts. It is not directed at children under 13. Do not submit children’s personal information through support or production workflows.
10. Changes and contact
Changes to this policy will be published here with a revised effective date. Questions about privacy, account connections, or deletion: support@beforeyoupull.com.