Polityka prywatności
TeO Hub OtakOS (Katedra OtakOS) i strona otakos.wtf · obowiązuje od 3 października 2026
1. Kto odpowiada
Administratorem jest twórca projektu Katedra OtakOS, kontakt: teo@teo.center. Polityka dotyczy aplikacji TeO Hub OtakOS (oprogramowanie uruchamiane lokalnie na komputerze użytkownika) oraz strony otakos.wtf.
2. Zasada: dane zostają na Twoim komputerze
TeO Hub OtakOS działa na Twoim sprzęcie. Twoje pliki, projekty, rozmowy z lokalnymi modelami AI i ustawienia są zapisywane w katalogu Katedry na Twoim komputerze. Nie mamy do nich dostępu i nie wysyłamy ich na nasze serwery.
3. Dane Google / YouTube (YouTube API Services)
TeO Hub OtakOS korzysta z YouTube API Services. Korzystając z funkcji YouTube, akceptujesz Warunki korzystania z YouTube, a Twoje dane w Google podlegają Polityce prywatności Google.
Jakie dane i po co
- Token OAuth Google (token odświeżania) — po kliknięciu „Połącz z YouTube” i Twojej zgodzie. Służy wyłącznie do działań opisanych niżej.
- Wysyłanie filmów (
youtube.upload) — na Twój kanał trafia tylko film, który sam wskazałeś, z tytułem, opisem i tagami, które zatwierdziłeś. Domyślna widoczność: niepubliczny. - Odczyt kanału i statusu filmu (
youtube.readonly) — nazwa i adres Twojego kanału oraz status widoczności wysłanego filmu, żeby pokazać Ci, z którym kanałem jesteś połączony, i wstawić link do filmu na Twoją Wystawę dopiero, gdy da się go obejrzeć.
Gdzie są przechowywane
Token i informacje o wysłanych filmach zapisują się tylko lokalnie, w katalogu Twojej Katedry (plik skarbca poza jakimkolwiek repozytorium). Nie przesyłamy ich na serwery otakos.wtf, nie udostępniamy, nie sprzedajemy i nie używamy do reklam ani do trenowania modeli AI. Aplikacja łączy się bezpośrednio z serwerami Google.
Ograniczone wykorzystanie
Wykorzystanie i przekazywanie informacji otrzymanych z interfejsów API Google przez TeO Hub OtakOS jest zgodne z Zasadami dotyczącymi danych użytkownika w usługach interfejsu API Google, w tym z wymaganiami dotyczącymi ograniczonego wykorzystania (Limited Use).
Jak cofnąć dostęp i usunąć dane
- W aplikacji: Impresariat → „Rozłącz” — token zostaje usunięty z Twojego komputera.
- W Google: security.google.com/settings/security/permissions — cofnięcie dostępu aplikacji TeO Hub OtakOS.
- Usunięcie katalogu Katedry usuwa wszystkie dane aplikacji z Twojego komputera.
Dokładnie jakie dane Google przetwarzamy
- Odczytujemy z Google: identyfikator, nazwę i adres Twojego kanału YouTube (
channels.list,mine=true) oraz — wyłącznie dla filmów wysłanych przez aplikację — identyfikator filmu, jego widoczność (prywatny / niepubliczny / publiczny) i stan przetwarzania (videos.list,part=status). - Wysyłamy do Google: plik wideo, który wybrałeś, oraz zatwierdzone przez Ciebie tytuł, opis, tagi, kategorię i widoczność (
videos.insert). - Nie odczytujemy Twojego adresu e-mail, imienia, kontaktów, innych filmów, playlist, komentarzy, subskrypcji, statystyk ani przychodów.
Jak długo przechowujemy
- Token odświeżania — do chwili, gdy klikniesz „Rozłącz”, cofniesz dostęp w Google albo usuniesz Katedrę.
- Identyfikator i adres wysłanego filmu, jego tytuł, opis i tagi — w historii publikacji na Twoim komputerze, dopóki ich sam nie usuniesz.
- Nazwa kanału — w pamięci podręcznej aplikacji przez ok. 10 minut.
Udostępnianie i bezpieczeństwo
Nie przekazujemy danych użytkowników Google żadnym osobom trzecim — ani do analityki, ani do reklam, ani do brokerów danych. Nie mamy własnego serwera, który by je odbierał. Połączenia z Google idą szyfrowanym HTTPS; logowanie używa OAuth 2.0 z PKCE i jednorazowym parametrem state; token leży w pliku skarbca na Twoim komputerze, poza repozytorium kodu, a interfejsy zmieniające połączenie z YouTube są dostępne tylko z Twojego komputera (nie przez tunel ani z innych stron).
4. Kanał YouTube w wizytówce
Jeśli wpiszesz adres swojego kanału do wizytówki, Katedra pobiera z YouTube publiczne informacje (nazwę kanału i listę najnowszych filmów z publicznego kanału RSS) — bez logowania i bez tokenu.
5. Strona otakos.wtf
- Rejestr Katedr: gdy włączysz meldunek, Twoja Katedra wysyła do otakos.wtf swój nick, publiczny adres tunelu i podpis. Rejestr trzyma je w pamięci serwera (znikają po ok. 3 minutach ciszy) i pokazuje tylko nicki zatwierdzone przez zarządcę rejestru.
- Wizytówki są pobierane przez Twoją przeglądarkę bezpośrednio z Katedr ich właścicieli; ramki YouTube używają trybu youtube-nocookie i ładują się dopiero po kliknięciu.
- Strona nie używa ciasteczek reklamowych ani analitycznych. W pamięci przeglądarki (localStorage) zapisuje tylko Twoje ustawienia, np. język i „moją Katedrę”.
- Serwer hostingu (Google Cloud Run) zapisuje standardowe logi techniczne (adres IP, czas, adres żądania) na potrzeby działania i bezpieczeństwa.
6. Dzieci
Aplikacja nie jest skierowana do dzieci poniżej 13 lat.
7. Zmiany
O zmianach informujemy na tej stronie, z datą obowiązywania.
English
Privacy Policy
TeO Hub OtakOS (Katedra OtakOS) and otakos.wtf · effective October 3, 2026
1. Who is responsible
The controller is the creator of the Katedra OtakOS project, contact: teo@teo.center. This policy covers the TeO Hub OtakOS application (software that runs locally on the user's computer) and the otakos.wtf website.
2. Principle: your data stays on your computer
TeO Hub OtakOS runs on your hardware. Your files, projects, conversations with local AI models and settings are stored in the Cathedral folder on your computer. We have no access to them and do not send them to our servers.
3. Google / YouTube data (YouTube API Services)
TeO Hub OtakOS uses YouTube API Services. By using the YouTube features you agree to the YouTube Terms of Service, and your Google data is governed by the Google Privacy Policy.
What data and why
- Google OAuth token (refresh token) — obtained after you click “Connect YouTube” and consent. Used only for the actions below.
- Uploading videos (
youtube.upload) — only a video you selected is uploaded to your channel, with the title, description and tags you approved. Default visibility: unlisted. - Reading your channel and video status (
youtube.readonly) — your channel name and URL and the visibility status of the uploaded video, to show which channel is connected and to add the video link to your Exhibition only once it can be watched.
Where it is stored
The token and information about uploaded videos are stored only locally, in your Cathedral folder. We do not transfer them to otakos.wtf servers, share them, sell them, or use them for advertising or for training AI models. The app connects directly to Google's servers.
Limited Use
TeO Hub OtakOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access and deleting data
- In the app: Impresariat → “Disconnect” — the token is deleted from your computer.
- At Google: security.google.com/settings/security/permissions — revoke TeO Hub OtakOS's access.
- Deleting the Cathedral folder removes all app data from your computer.
Exactly which Google data we process
- We read from Google: the ID, title and URL of your YouTube channel (
channels.list,mine=true) and — only for videos uploaded by the app — the video ID, its privacy status (private / unlisted / public) and processing status (videos.list,part=status). - We send to Google: the video file you selected and the title, description, tags, category and privacy setting you approved (
videos.insert). - We do not read your email address, name, contacts, other videos, playlists, comments, subscriptions, analytics or revenue.
Retention
- Refresh token — until you click “Disconnect”, revoke access at Google, or delete the Cathedral.
- ID and URL of an uploaded video, its title, description and tags — in the publication history on your computer until you delete them.
- Channel name — cached in the app for about 10 minutes.
Sharing and security
We do not transfer Google user data to any third party — not for analytics, advertising or data brokers. We operate no server that receives it. Connections to Google use encrypted HTTPS; sign-in uses OAuth 2.0 with PKCE and a one-time state parameter; the token is kept in a vault file on your computer, outside any code repository, and the endpoints that change the YouTube connection are reachable only from your own computer (not through the tunnel or from other websites).
4. YouTube channel on the card
If you add your channel URL to your card, the Cathedral fetches public information from YouTube (channel name and latest videos from the public RSS feed) — without signing in and without a token.
5. The otakos.wtf website
- Cathedral registry: when you enable check-in, your Cathedral sends otakos.wtf its nick, public tunnel address and a signature. The registry keeps them in server memory (gone after ~3 minutes of silence) and shows only nicks approved by the registry steward.
- Cards are fetched by your browser directly from their owners' Cathedrals; YouTube frames use youtube-nocookie and load only after a click.
- The site uses no advertising or analytics cookies. Browser storage (localStorage) keeps only your settings, e.g. language and “my Cathedral”.
- The hosting server (Google Cloud Run) keeps standard technical logs (IP address, time, request URL) for operation and security.
6. Children
The app is not directed at children under 13.
7. Changes
Changes are announced on this page with an effective date.