This Privacy Policy applies to the application named Content Factory by Gonzo Group ("the App"), operated by Gonzo Group. It describes how we collect, use, and store personal data when you use the App at https://gonzo.group.
Last updated: June 30, 2026
1. About the Service
Content Factory by Gonzo Group is a web platform that allows users to create, manage, and publish short-form video content, including publishing to social media platforms such as YouTube, TikTok, Instagram, and Telegram.
2. Information We Collect
We may collect:
- Account information (email, name, role)
- Integration data (such as Google/YouTube and TikTok authorization tokens)
- Usage data and technical logs
- Content data generated or uploaded by the user
3. Cookies and Information on Your Device
The App is a web application. We and, during certain integrations, third-party providers may store, access, or collect information on or from your device (including your browser) as described below.
Local storage and session storage (first party). When you use the App in a browser, we store data locally on your device using HTML5 localStorage and sessionStorage, including:
- Authentication tokens (cf_access, cf_refresh) so you remain signed in;
- Your last selected workspace (cf_last_group) and interface preferences (for example sidebar state and account-page settings);
- Short-lived UI state for the current browser tab in sessionStorage.
Administrator-only screens may also save filter presets in localStorage. These values are not used for advertising or cross-site tracking.
Cookies. The App itself does not set advertising or analytics cookies on https://gonzo.group. We do not sell data collected from cookies or local storage.
Third parties during sign-in. When you connect YouTube through Google, or TikTok through Login Kit, you are redirected to those providers' websites. Google and TikTok may place, access, or recognize cookies or similar technologies on your device or browser during that sign-in flow, according to their own policies. We do not control third-party cookies on accounts.google.com, google.com, tiktok.com, or similar domains.
Browser-connect integrations (optional). For some platforms (for example Instagram, TikTok, or VK browser sessions), if you choose to save a browser session, encrypted session data is stored on our servers after you explicitly confirm — not in cookies on your device for long-term use by us.
You can clear first-party local storage and session storage at any time through your browser settings; you will need to sign in again afterward.
4. How We Use Data
We use data to:
- Provide core platform functionality
- Enable content creation and publishing workflows
- Authenticate users and integrations (including Google/YouTube OAuth and TikTok Login Kit)
- Prevent abuse and ensure security
- Provide support
5. YouTube / Google Integration
When you connect your YouTube channel, we receive OAuth 2.0 tokens via Google Sign-In. We request the following scopes only:
- youtube.upload — to upload videos you create in the App to your own YouTube channel when you click Publish;
- youtube.readonly — to read basic channel information (channel ID, title) during connection and when you run an account health check.
We use the YouTube Data API solely to publish content that you create and explicitly choose to publish, and to verify that your connected channel is accessible. We do not download, resell, or aggregate YouTube data at scale, and we do not access your channel beyond what is required for publishing and connection checks initiated by you.
5.1 YouTube API Data we store
Subject to your use of the feature, we may store:
- Google OAuth refresh tokens (encrypted on our servers);
- YouTube channel title and a channel URL you provide (for display in the App);
- YouTube video identifiers returned after a successful upload (in your task publish history, visible to you and members of your workspace, limited to the most recent publish attempts per task).
We do not persist long-lived YouTube access tokens. Access tokens are obtained when needed and discarded after the API request completes.
5.2 Refresh and update of YouTube API Data
- Access tokens: refreshed on demand for each publish or account check (not cached long-term).
- Channel metadata (for example channel title from channels.list): refreshed when you connect YouTube or when you manually run «Check account» on a connected YouTube account. We do not refresh stored channel metadata on a background schedule without your action.
- Publish history: updated when you publish; older entries are trimmed automatically (we keep only a limited number of recent publish records per task).
5.3 Deletion of YouTube API Data
- Disconnecting or deleting a YouTube account in the App removes stored OAuth refresh tokens from our database promptly.
- You may revoke our access at any time via Google Account permissions.
- YouTube video IDs in task publish history remain until you delete the task, clear workspace data, or request deletion — they are shown only to you and your team for your own publishing records.
To delete stored tokens and related data from our systems, disconnect the YouTube account in the App or contact us at support@gonzo.group.
Google's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
For Google's privacy practices, see Google Privacy Policy.
6. TikTok Integration
When you connect your TikTok account, we receive authorization tokens via TikTok Login Kit. These tokens are used solely to upload and publish content on your behalf through the TikTok Content Posting API.
We do not access or modify your TikTok account beyond what is required for publishing content initiated by you.
7. Data Sharing
We do not sell personal data. Data may be shared only with:
- Infrastructure providers (hosting, storage)
- API providers required for functionality (including Google/YouTube and TikTok)
8. Data Retention and Deletion
We retain OAuth tokens and integration data only while your account connection is active and as needed for service operation, legal obligations, and security. When you disconnect a platform or delete your account, we delete or anonymize associated tokens and integration data within a reasonable period, unless retention is required by law.
To request deletion of your personal data or connected platform tokens, email support@gonzo.group from the address associated with your account.
9. Your Rights
You may request access, correction, or deletion of your data by contacting us.
10. Contact
For privacy requests contact: support@gonzo.group