Privacy Policy
Last updated: July 9, 2026
slp-pipeline ("the App", "we", "us") renders Super Smash Bros. Melee Slippi replays into videos and, at your direction, uploads them to your YouTube channel. This policy explains what data we access, how we use it, and your choices. Access to the App is limited to allowlisted accounts.
Information we access
- Google sign-in. When you sign in with Google we receive your email address and basic profile information. We use these only to authenticate you and to check you against our access allowlist.
- YouTube account. If you connect your channel, you grant
the App permission to upload videos to your YouTube account on your behalf
(the
youtube.uploadscope). We use this access solely to upload the videos you ask us to upload. - start.gg account (optional). If you choose to link uploaded videos to their bracket sets, you connect your start.gg account through start.gg's OAuth flow (or, alternatively, provide a start.gg personal access token). The OAuth grant covers your basic start.gg identity and tournament reporter/manager permissions; we use it only to call the start.gg API on your behalf to attach each uploaded video's URL to its set. Connecting start.gg is entirely optional; uploads work without it.
- Content you provide. The Slippi replay files you upload and the videos rendered from them.
How we use and store data
- Your email address and account settings (such as permissions and usage limits) are stored in the App's account database. While you are signed in, your email and account slug are also held in a signed session cookie that expires after 12 hours; signing out clears it.
- The credential that lets us upload to your YouTube channel (an OAuth refresh token) is stored encrypted in Google Cloud Secret Manager, isolated per account, and used only to perform uploads you initiate.
- Your start.gg credentials (OAuth access and refresh tokens, or a personal access token), if you connect start.gg, are stored encrypted in Google Cloud Secret Manager, isolated per account, and used only to link your uploaded videos to their start.gg sets.
- Replay files and rendered videos are stored in Google Cloud Storage so the pipeline can process and upload them.
- We do not sell your data, use it for advertising, or share it with third parties except the Google Cloud and YouTube services required to operate the App.
Data security
We take the protection of your data, including data we receive from Google APIs, seriously. Security procedures are in place to protect the confidentiality of your data against unauthorized access, alteration, or disclosure.
- We use encryption to protect your information. Data is encrypted in transit using HTTPS/TLS, and credentials such as your YouTube OAuth refresh token and start.gg tokens are stored encrypted at rest in Google Cloud Secret Manager, isolated per account.
- Access to stored credentials and content is restricted to the App's services that need it to operate; job status and error information may also be visible to the App's site operators for support and operations. The App itself is limited to allowlisted accounts.
- Replay files and rendered videos are stored in Google Cloud Storage, which encrypts data at rest by default.
- We retain Google user data only for as long as needed to provide the service and delete it on request or within a reasonable period after you revoke access.
Google API Services Limited Use
The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use YouTube API Services; by using the App you also agree to the YouTube Terms of Service and the Google Privacy Policy.
Retention and revocation
- You can revoke the App's access to your Google and YouTube account at any time at Google Account permissions. Revoking access stops all future uploads.
- You can disconnect or replace your start.gg connection at any time from the App's Settings page, and we delete stored start.gg credentials on request. If you connected by pasting a personal access token, you can also revoke the token itself from your start.gg developer settings.
- To have your stored credentials and content deleted, or for any privacy question, contact us at the address below. We delete stored YouTube credentials on request and within a reasonable period after access is revoked.
Contact
Questions about this policy: sasumt@gmail.com.