Privacy Policy
Last updated 18 August 2026
Kat Hub is a private, invite-only tool operated by Nine Lives Development for scheduling and publishing short video content to social accounts its operators own. It is not a consumer product and there is no public sign-up — access is granted by an administrator.
Who this covers
Two kinds of people use Kat Hub: operators, who upload clips and approve posts, and reviewers, who are invited to watch clips and vote on them. Both are invited by an administrator. This policy covers both.
What we collect
- Your email address. Used to sign you in and to identify you to the administrator who invited you. Sign-in is a one-time emailed code; we never store a password.
- Access credentials for social accounts you connect. When an operator connects an X (Twitter) account, we store the OAuth access token, refresh token and expiry, plus the account handle and its numeric id, so the application can publish on that account's behalf and show which account is connected.
- Video and image files you upload, along with the metadata derived from them — duration, file type, generated captions, thumbnails and, where you supplied one, the source URL and creator attribution of the original clip.
- Engagement metrics for posts published through the tool — impressions, likes, reposts and replies, retrieved from the social platform's own API for the accounts you connected.
- Reviewer votes. If you are a reviewer, we record which clips you were shown and how you voted. Votes are advisory: a human operator makes every publishing decision, and nothing you vote on is published automatically.
What we do not collect
- No advertising identifiers, no third-party tracking pixels, and no analytics SDKs.
- No data about any social account other than the ones an operator explicitly connects. We request no permission that could read another account's followers, private messages or audience data.
- No payment information — Kat Hub does not take payments.
How your clips are processed
Uploaded clips are sent to third-party AI providers to generate captions and to screen for unsafe content. Today that means Google (Gemini), for analysing the video, and Anthropic (Claude), for writing caption variants — both reached through Vercel's AI Gateway. They receive the clip and a text prompt. They do not receive your email address, your credentials, or your engagement metrics.
If you connect a YouTube channel
Kat Hub does not currently connect to YouTube. Its Shorts feature prepares a file for you to upload by hand, and involves no Google account access at all.
If and when direct YouTube publishing is enabled, connecting a channel will store only the OAuth access token, the refresh token and its expiry, and the channel's id and title — the last so the interface can show you which channel you connected. Kat Hub will request no permission to read viewer data, analytics, comments or subscriber information, and will store none of it. Kat Hub's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Where it is stored
Account data is held in a PostgreSQL database hosted by Supabase, encrypted at rest. Video and image files are held in Cloudflare R2, and are served to the browser only through short-lived signed links. Access is restricted at the database level so that one workspace cannot read another's rows; credential columns are never sent to the browser and are never written to application logs.
Retention and deletion
- Disconnecting a social account erases its stored credentials immediately, in the same operation — the token values are overwritten, not flagged. Any post still waiting to go out on that account is cancelled at the same time.
- The account record itself is kept after disconnection, along with the posts already published through it and their engagement history. This is deliberate: deleting the record would erase that published history too. It holds no usable credentials once disconnected.
- Uploaded clips persist until deleted by an operator, and clips you delete are removed from storage.
- A removed reviewer's past votes are retained, because they contributed to decisions already made.
Revoking access yourself
You can revoke Kat Hub's access to a connected account at any time from that platform directly, independently of this application — for X at Connected apps, and for a Google account at Third-party apps with account access. Kat Hub treats a revoked credential as a disconnected account and asks an operator to reconnect; it does not attempt to work around the revocation.
Who we share it with
We do not sell your data and we do not share it for advertising. It is disclosed only to the infrastructure and AI providers named above, each acting on our instructions to run the service, and where we are required to by law.
Contact
Questions about this policy, or a request to delete your data, go to c.r.zambito@gmail.com.