Your choices are separate. Signing in, authorizing a connection, confirming an upload and requesting deletion each serve a different purpose.
Operator and scope
Cevan Agent is operated by Anshitong (Shanghai) Trading Co., Ltd. (安什通(上海)贸易有限公司), registered in China. Contact: help@cevanlabs.cn.
This policy covers the public Cevan website, accounts, company workspaces, creative assets, and the optional Google, mailbox and social connections you enable. Business content is processed under the company’s instructions and applicable service agreement. Our European business partner is rx consult srls; project-specific data sharing must have a defined purpose and lawful basis.
Google data and permissions
Cevan uses YouTube API Services for its YouTube connection and upload workflow. Google sign-in, a YouTube connection and a Gmail connection are separate choices. The consent screen identifies the permissions requested for that action.
| Feature | Data and permission | Purpose |
|---|---|---|
| Google sign-in | Google account identifier, email, verification status and name or profile image when supplied by the identity service. | Create or identify your Cevan account. Authentication is handled through the configured Supabase identity service. |
| YouTube connection | Channel ID and channel name; granted scopes, connection state, token expiry, access token and a refresh token when offline access is authorized. Scope: youtube.readonly. | Verify the destination channel and read back the status of uploads managed through Cevan. |
| YouTube upload | Your selected video bytes, title, description, visibility (public, private or unlisted), Made for Kids and synthetic media settings, subscriber notification choice; upload progress, video ID, returned metadata, processing status and receipts. Additional scope: youtube.upload. | Upload the content you confirm and show the result for the original publishing operation. |
| Optional Gmail | Mailbox identity, access/refresh tokens, authorized message headers, body and attachments. Scopes: gmail.readonly and, when sending is enabled, gmail.send. | Provide the enabled mail workflow, such as summaries, draft preparation, replies or authorized sending. |
The full YouTube scope names are https://www.googleapis.com/auth/youtube.readonly and https://www.googleapis.com/auth/youtube.upload. Gmail scope names use the same prefix with gmail.readonly or gmail.send. Google sign-in permissions are determined by the identity provider’s consent screen.
The current YouTube workflow verifies a single authorized channel. It does not provide a general channel selector, import your viewing history, download videos from YouTube, or request Drive, Calendar or Contacts access. Publishing receipt counts shown by Cevan describe its own operations; they are not YouTube views, reach or engagement analytics.
What happens during a YouTube upload
- You choose the saved work, video, destination account, title, description, visibility and other supported video options. You preview them and expressly confirm a publishing plan or schedule.
- Cevan reads the selected bytes from its private asset storage and sends the video and metadata to Google/YouTube through a resumable upload. A server-side worker handles the confirmed operation.
- Cevan saves the upload state and platform receipt, then checks the original operation’s status. An uploaded private or unlisted video is not reported as a public post. An uncertain result is checked rather than blindly resubmitted.
- Public videos and their metadata may be seen by anyone; unlisted videos may be accessible to people who have or receive the link. Private videos remain subject to YouTube’s visibility rules.
No upload is authorized merely by visiting this site, signing in or connecting a channel. Cevan does not receive your Google password. Uploaded content is then handled by Google/YouTube under their policies.
Other content you provide
Account registration involves an email, account name, password verification data and session information. Workspace use involves your company details, briefs, conversations, prompts, selected images, video, audio, attachments, permission records and saved results. We use these to perform your requested work, organize it and provide export.
Only submit content you have permission to use. Payroll, tax records, financial statements, payment credentials and third-party account passwords must not be submitted to the business workspace. Photographs, likenesses and voices require the permissions appropriate to the requested use. Separate notices and consent apply where required for sensitive information or new uses.
Purposes and AI processing
We use account information for identity and service access; selected content for your task; connected account data for the enabled connection; and necessary operation records for permissions, security and troubleshooting. Optional Google access relies on your authorization. Applicable legal bases may include performance of a contract, consent, legitimate security interests and legal obligations.
Google authorization tokens are credentials, not creative material, and are not sent to content-generation models. The YouTube publishing workflow uses channel and receipt data to perform and verify the confirmed upload, not as a prompt for generating marketing content. Content you separately submit for an AI task may be processed by the Cevan model gateway or the provider disclosed for that task.
Google user data must not be used to train general-purpose AI models. This policy does not authorize model training on Google data, advertising profiling, data brokerage or unrelated secondary use. Cevan’s use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements.
Storage, retention and protection
Social authorization credentials are encrypted on the server using a dedicated credential key. Database access is scoped by company and user permissions. Selected assets are held in private storage; the YouTube uploader transfers private bytes rather than exposing a public asset directory. Production access requires HTTPS. These controls do not mean that all workspace data is stored only on your device.
Access tokens are usable only within their validity and authorization; refresh tokens, if granted, support the authorized connection until it is disconnected or revoked. Completing a Cevan YouTube disconnect disables that local connection and removes its stored credential payload. Channel identity and past publishing records can remain until a separate deletion request is handled.
Account, creative and task records are retained only while needed for the stated service purpose, your instructions or a legal obligation. There is no single published fixed lifetime for all workspace records or backups; contact us for the arrangement applicable to your data. An asset you supplied and a receipt returned by YouTube are different records.
YouTube’s API rules require most cached API data to be refreshed or deleted within 30 calendar days. They also require deletion of stored user-related API data as soon as possible and within 7 calendar days when a user requests it or deletes the related application account. These are platform requirements, not a claim that disconnecting a connection automatically deletes every record. Please use the data deletion process to request removal. Backups must be handled consistently with applicable deletion requirements; legally required retention must be limited, explained and must not be used to continue the connection.
Revoke access and request deletion
Disconnect in Cevan: open Settings → Social accounts and disconnect the YouTube account. This stops further use through that local connection and clears its saved tokens. It does not revoke the Google-side grant, erase all workspace history or remove a video from YouTube.
Revoke at Google: open Google Account permissions, find Cevan or the relevant connected application and remove access. You can also use Google Account third-party connections. Separate sign-in, mail and social clients may appear as separate grants.
Delete Cevan-held records: email help@cevanlabs.cn with your account email, relevant company/channel and the data you want removed. We verify only the identity and authority necessary for the request. Never send a password, token or video file in a deletion email. Read the detailed instructions.
Delete a YouTube video: use YouTube Studio. Removing Cevan-held records or revoking authorization does not remove data already stored by YouTube. Disconnecting cannot undo a request that YouTube has already received.
Website and device information
This static public website uses local styles and a brand image. It has no Google sign-in form, tracking script, advertising, embedded YouTube player, third-party font request, cookie or browser-storage code. It follows your device’s color preference without saving a preference. Following an external link or opening your email app is your choice.
A hosting provider may receive normal connection information, including IP address, request path, time and browser headers, and may keep operational logs according to its configuration. In the Cevan application, necessary sessions, preferences, drafts and minimal request-recovery records may use browser storage. Clearing a browser does not delete server-held data.
Your rights and policy updates
Depending on applicable law, you may request access, correction, a copy, deletion, restriction, objection, withdrawal of consent or account closure, and may complain to the competent authority. Contact help@cevanlabs.cn. Where GDPR applies, rights requests are normally answered within one month, with any lawful extension explained; the shorter YouTube API deletion requirement remains applicable to that data.
Cevan is intended for business users and authorized organization members, not children. Material changes to purposes or permissions require an updated notice and any new consent required by law and platform rules. The date above identifies this website policy version.
Google and YouTube policies
Google and YouTube apply their own policies to their services. Please read the Google Privacy Policy, YouTube Terms of Service and YouTube API Services Developer Policies. For questions or complaints about Cevan’s handling of data, contact help@cevanlabs.cn.