Legal

Privacy policy

Last updated 22 August 2026

This document describes how the service actually behaves — each claim maps to a specific mechanism in the product, and we have tried to write it so you can check it against what you observe.

1. Who we are

PublishBench (“we”, “us”) is a product of Agent Marketing Essentials LLC, a limited liability company registered in Florida, United States. It provides a workspace for planning, researching, writing and preparing YouTube videos. That company is the controller of the personal data described here. Contact us through the contact page for any privacy request, including access, correction, deletion or portability.

2. What we collect

Information you give us

  • Account details — email address, an optional display name, your chosen password (stored only as a scrypt hash, never in readable form), preferred language and time zone.
  • Onboarding answers — your niche, audience, publishing goal and cadence. These pre-fill generation forms and nothing else.
  • Content you create — projects, ideas, scripts and their version history, transcripts, thumbnails, folders, notes and everything you generate.
  • Files you upload — images and audio, together with your attestation that you hold the rights to them.
  • Support messages — your name, email address and the content of any message you send us.

Information we receive on your instruction

  • Google account and YouTube data — only if you connect a channel. We request read-only YouTube access and your email address. We store your Google account id, email, and metadata about your channels and recent uploads. We cannot upload, edit or delete anything on your channel. See YouTube API Services below for what that access covers and how to withdraw it.

Information collected automatically

  • Session data — a session identifier, the IP address and user-agent recorded when a session is created, and the time it was last used.
  • Security and audit records — sign-ins, failed sign-in attempts, role and status changes, credit adjustments, channel connections and deletions. Values whose field names match token, password, secret, key or authorization are redacted before being written.
  • Usage records — which features you used, credits consumed, and the token counts and cost of each AI call. Used for billing accuracy and capacity planning.
  • Page views on our public pages — the page visited, the site that referred you, your country and browser type, on our marketing and sign-in pages and on shared report pages. This is recorded by analytics software we run ourselves, on our own servers. It sets no cookie, and no third party receives it. We do not run it inside the app itself.
  • How you first found us — if you arrive from a link carrying a campaign tag or an advertising click identifier, or from another website, we store that in the it_attr cookie described in section 8 and attach it to your account if you register. Arriving directly stores nothing.

We do not load third-party advertising trackers or product analytics scripts, and nothing on this site follows you to other websites. If you subscribe after arriving from one of our adverts, we do report that back to the advertising platform that sent you — an identifier that platform itself put in the link, and the amount — so we can tell which adverts are worth running. That report is sent from our servers, not from your browser. You can object to this under section 10.

The cookies we set are listed in full in section 8. The one third-party script we load is Cloudflare Turnstile on the registration page, described in section 6.

3. Why we process it

  • To provide the service (performance of a contract) — storing your work, running generations, enforcing plan limits.
  • To keep the service secure (legitimate interests) — rate limiting, audit logging, abuse prevention.
  • To take payment (performance of a contract) — subscriptions, top-ups and invoices.
  • To send product updates (consent) — only if you opt in, and you can withdraw it in Settings at any time.

4. Where your content goes

When you run a generation, the relevant input — your prompt, and any source text or transcript you attached — is sent to the AI provider configured for that capability (OpenAI and/or Anthropic). This is what makes the feature work; there is no local model. We send the minimum required for the request and never attach your email address, account id or unrelated content.

We do not use your content to train any model. Those providers process it under their respective API terms, which is a different thing from their consumer products: neither trains on API content by default, and each may retain a request for a limited period for abuse monitoring. We do not currently hold a zero-retention arrangement with either, so if that distinction matters to your work, treat anything you paste in as leaving our systems.

Research features send only the search terms you type to the YouTube Data API — see section 5. Article import fetches the URL you provide from our servers, subject to the safety checks in section 9.

5. YouTube API Services

PublishBench uses YouTube API Services. Research features send the search terms you type to the YouTube Data API and show you what it returns. If you connect a channel, we read that channel with your permission — read-only, never to write.

By using those features you are also agreeing to the YouTube Terms of Service. Google’s own handling of the data it receives is governed by the Google Privacy Policy, which is separate from this one and which we do not control.

You can withdraw our access to your channel at any time, in either of two places. Inside PublishBench, Settings → Channels → Disconnect revokes the grant at Google immediately. Independently of us, you can remove PublishBench from your Google account’s third-party access settings. Either route stops all further access. Data we retrieved under that grant is deleted within seven days of a revocation made here, and within thirty days of one made through Google’s settings, where Google notifies us rather than you telling us directly.

Public YouTube data we retrieve for research is refreshed or deleted within thirty days, except where an approved extension applies to statistics. Figures we display from the API are shown as the API returned them. Where a number is our own calculation rather than YouTube’s measurement — an opportunity score, an outlier factor — it is labelled as computed, and the formula is published in full on our methodology page.

Questions or complaints about how we handle YouTube data: support@publishbench.com.

6. Who else receives data

  • AI providers — OpenAI and Anthropic, for the content of generation requests as described above.
  • Google — for YouTube API requests, if you connect a channel or use research features.
  • Supadata — for transcripts of public videos you ask us to read. It receives the video’s public URL and nothing about you: not your email address, not your account id, and nothing you have written.
  • Stripe — for payments. Stripe receives your email address and payment details directly; we never see or store your card number.
  • Resend — our email provider, which receives the address and content of every email we send you: account mail (verification, password reset, security notices), the research digest, and any product email you have not unsubscribed from.
  • Railway — our hosting and database provider, as a processor storing your account and everything you create in the app.
  • Cloudflare — three separate roles. R2 stores the files you upload (audio and images) and the thumbnails you render. It is also the DNS for our domain, and it provides the Turnstile anti-abuse challenge on the registration form. Where that challenge is active it loads a script from challenges.cloudflare.com on the signup page and passes your IP address and browser signals to Cloudflare, which scores whether the signup is automated. It is the second of two locks on account farming, alongside a per-address rate limit. See Cloudflare’s privacy policy.

These are all the third parties that receive personal data. We do not sell personal data, and we do not share it for advertising.

7. How long we keep it

  • Account and content — until you delete your account, at which point it is removed from our live systems immediately (see section 10). Uploaded audio and images are deleted from object storage in the same pass.
  • Backups — our database is backed up on a rolling schedule and each backup expires automatically. A record you deleted can survive in an unexpired encrypted backup until that backup rotates out; it is not restored into the live service, and we do not use backups to reconstruct deleted accounts.
  • Support messages — the message, your name and your email address are kept for up to 24 months so we have a support history, then deleted.
  • Sessions — 30 days maximum, revoked after 14 days of inactivity, and purged 7 days after expiry.
  • Rate-limit counters — deleted after 24 hours.
  • Research cache — 3 to 12 hours depending on the tool. It holds public YouTube data only, not anything personal to you.
  • Audit and billing records — retained after account deletion where we have a legal obligation to keep them (tax and accounting records typically require several years). These retain the minimum needed: the event, the timestamp and an identifier, not your content.

8. Cookies

We set two cookies in ordinary use, both strictly necessary, plus two that are set only in particular circumstances:

  • it_session — your session token. HttpOnly, SameSite=Lax, Secure in production. Without it you cannot stay signed in.
  • it_csrf — a token your browser echoes back on write requests so we can verify they came from our own interface. Readable by our own scripts by design.
  • it_oauth_state — set only while you connect a YouTube channel, and only for ten minutes, to prevent an authorisation being completed into the wrong account.
  • it_attr — set only if you arrive from a link carrying a campaign tag or an advertising click identifier, or from another website, and only the first time. It holds what that link said about where it came from, and nothing about you. HttpOnly, SameSite=Lax, ninety days. If you register, its contents are attached to your account and it is not written again. Arriving directly sets no such cookie at all.

Where the Turnstile challenge described in section 6 is active on the registration page, Cloudflare may also set its own cookie or local-storage entry on that page under its own policy. We do not read it, and it plays no part in your session.

9. How we protect it

  • Passwords are hashed with scrypt and a per-user random salt.
  • Session and email tokens are stored only as keyed HMAC digests, so a database copy does not yield usable tokens.
  • Google refresh tokens are encrypted with AES-256-GCM before storage and decrypted only inside the module that calls Google.
  • Every query for your data is filtered by your user id at the database level, not merely checked afterwards.
  • Uploads are validated by declared type, file extension and magic bytes; markup files are refused outright, and stored files are served with a restrictive content policy so they cannot execute.
  • URLs you ask us to fetch are resolved and checked against private and link-local address ranges on every redirect hop.
  • Write requests require both a matching origin and a CSRF token; incoming payment webhooks are signature-verified and processed exactly once.

10. Your rights

  • Access and portability — Settings → Your data downloads a complete JSON export of everything you have created. It deliberately excludes credentials.
  • Correction — edit your profile and any content directly in the app.
  • Deletion — Settings → Delete account. This requires your password and a confirmation link sent to your email address. On confirmation we revoke any Google authorisation, delete your stored files, and delete your account row — every table holding your data cascades from it.
  • Objection and withdrawal of consent — turn off product updates in Settings; contact us for anything else.

Depending on where you live you may also have the right to complain to a data protection authority.

11. International transfers

Our processors (AI providers, Stripe, Google) may process data outside your country. Where required, transfers rely on the standard contractual clauses or equivalent safeguards those providers publish.

12. Children

PublishBench is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

13. Changes

If we make a material change we will notify signed-in users in the app before it takes effect. The date at the top of this page always reflects the current version.