Privacy policy
What this site collects, what it does not collect, and who sees what. Written to be understood by a reader rather than to protect its author.
Last updated: 2026-09-18
Who runs this site
Sbar Tube is a studio run by one person, acting as an individual. There is no registered company, no team, and no other legal entity behind this site, which is why this page names no company, no business address, and no appointed data protection officer. The person responsible for the site and for the studio tooling is its owner, reachable at the address given at the end of this page.
The project has three parts, and this policy keeps them apart: the public site at tube.sbarah.com, a private dashboard at tube-panel.sbarah.com that only the owner can sign in to, and a local tool on the owner's own machine that prepares episodes and, in future, uploads them to his own YouTube channel.
The public site: no account, no profile
The public site is static pages. They are built once before deployment and then served as files. There is no sign up, no comments, no form that sends your details to us, and no database running behind the pages.
- Your saved items and your light or dark theme choice are stored in your own browser using local storage. They never leave your device, and clearing your browser data deletes them.
- Search runs inside your browser: the page downloads a static index file and filters it locally. Your search words are not sent to any server of ours.
- The correction draft button and the transcript download button create a file on your own device. Neither sends anything to the studio.
The site shows no advertising, builds no visitor profile, sells no data, and shares nothing with advertising intermediaries. There is nothing to sell in the first place: there are no accounts and no visitor identities.
What loads from third parties
Saying that this site uses no third party would be untrue. This is the complete list of what actually loads:
- The site is hosted on the Cloudflare network. Like any web server, that network processes your IP address and browser type in order to deliver the page and protect the site. This is technical processing required to serve the site, and we build no profile from it.
- Aggregate visit measurement through Cloudflare Web Analytics on the production build. A small measurement script loads, and its purpose is page counts and page performance at the level of the site, not the level of a person. We do not use it to follow an individual visitor across other sites.
- The Buy Me a Coffee support button loads from that service, in the page footer, together with the typeface it uses. That is an explicit choice by the owner and not a self hosted component. If you open the support page or donate, you are then inside another service governed by its own policy, and we neither process nor see any payment data.
- The YouTube privacy enhanced player on youtube-nocookie.com, which appears only inside an episode page that has a published video. Playing the video means you are interacting with YouTube, and Google's privacy policy then applies.
The site's main typefaces are self hosted and are not fetched from an external provider. Google's privacy policy is available at https://policies.google.com/privacy.
The only personal data we keep
The private dashboard has exactly one user, the owner. It has no sign up and no password: signing in uses a one time code emailed to the owner, and the permitted account is fixed in advance in a single owner allowlist. Any other account that reaches the dashboard is refused and sees no data.
The personal data that actually exists in this project is therefore:
- The owner's email address and his authentication account identifier, because that is what makes the sign in code possible. They are stored in the project's Supabase database.
- The owner's own session cookies in his browser. They are HttpOnly, Secure and SameSite=Strict, so page scripts cannot read them.
- When the Telegram integration in the local build of the dashboard is used: the owner's Telegram identifier, and the linked channels' identifiers, titles and descriptions. These stay in a local database on the owner's own machine.
We collect no data about other people. The project has no end users, no audience generated content, and no mailing lists.
Use of YouTube API Services
This studio's publishing tool uses YouTube API Services. By using it you are agreeing to be bound by the YouTube Terms of Service at https://www.youtube.com/t/terms, and the Google Privacy Policy at https://policies.google.com/privacy also applies.
The tool is local, is not publicly available, and its only user is the channel owner. It asks no other person to sign in with a Google account, and it touches no channel other than the owner's own.
What Google user data it accesses, and how that data is used, stored and shared:
- What is read: the owner's own channel metadata and the metadata of videos he uploaded, such as video id, title and privacy status, in order to confirm that an upload landed as intended.
- What is written: the episode video file with its title, description, tags and the privacy status the owner chooses, with the altered or synthetic content declaration always set to true and the made for kids declaration always set to false.
- Where it is stored: the access token and refresh token stay on the owner's own machine and are uploaded to no server. We store no statistics or derived metrics from the YouTube API, and we create no metric the API does not itself provide.
- With whom it is shared: nobody. No YouTube API data is shared with any third party, and none of it is merged with any other data source.
The account holder can revoke the tool's access at any time from the Google Account permissions page at https://myaccount.google.com/permissions, which is the security settings page referenced by the YouTube developer policies at https://security.google.com/settings/security/permissions. Revoking access stops the tool immediately. Independently of that, any stored data originating from the YouTube API is deleted within 30 days of a deletion request sent to the contact address at the end of this page.
The AI services we use
Episode imagery is drawn locally on the owner's machine by an animation engine running in a headless browser, so the video itself passes through no external provider. Episode text is written with the help of language models through a single intermediary, OpenRouter, and narration audio is generated through the text to speech service fal.ai.
What is sent to those two services is the studio's own material: episode ideas and scripts. No visitor data is sent to them, because no visitor data exists, and no data originating from the YouTube API is sent to them either.
Children
This site addresses a general audience and is not directed at children. It asks nobody for any data, so it neither knowingly nor unknowingly collects data about a child.
Changes to this policy
If what is collected changes, or if a different third party starts loading, this page is updated and the date at the top of it is updated with it. Last updated: 2026-09-18.
Contact and deletion requests
For questions or complaints about privacy, or to request deletion of data, write to: m@muhmad.md. Deletion requests are answered and carried out within 30 days at the latest.