SudoFocus OS
Privacy information
Updated 10 September 2026 · Operator contact: sudofocus@gmail.com.
Purpose and operator
SudoFocus OS is operated by the creator of the SudoFocus channel to prepare, review and deliver music videos. It is not a public registration service. Support, privacy questions and deletion requests: sudofocus@gmail.com. Do not send passwords or tokens by email.
Information used
The application uses local media, titles, descriptions, tags, rights records and approval decisions to prepare and deliver the operator’s selected work. Local job and quality-check records support review and recovery from interrupted operations.
The app uses YouTube API Services. It requests youtube.upload to upload approved videos and thumbnails, and youtube.readonly to verify channel identity and check relevant video metadata, processing and privacy status. Information received includes channel names and identifiers, video identifiers, status information, permissions and dated verification results. It does not request Gmail, Drive, Contacts or YouTube Analytics access.
A separately connected TikTok account uses user.info.basic and video.upload for account verification and creator-inbox delivery. It does not use Direct Post. Captions and hashtags are prepared in the local handoff; the Upload API does not apply them or choose posting visibility. A separately connected Instagram account requests instagram_basic, instagram_content_publish, pages_show_list and pages_read_engagement to verify the selected Page and professional account and deliver approved Reels. It does not request inbox or message permissions. Google consent does not connect other destinations.
Authorization and storage
Provider sign-in and OAuth consent take place on the provider’s pages. The API client does not collect or store Google or YouTube login passwords. Optional, separate local-administration slots can hold owner-entered Meta, TikTok or Bilibili passwords in Windows Credential Manager; these are not used as a substitute for OAuth. Temporary local setup pages use short-lived security cookies and one-use checks to complete the connection.
The local app requires explicit acceptance of its versioned privacy notice and terms before YouTube authorization or API access. It records the notice version, digest and acceptance time in a local receipt. Missing or outdated acceptance holds YouTube access while preserving existing credentials and work. Accepting the notice does not approve a release or retry paused deliveries.
Access and refresh tokens, app client secrets and sensitive upload-session URLs are stored in the operating-system user’s native credential vault. An operator-supplied Google desktop-client file remains in its original local location and must be protected separately.
Ordinary local files store account identifiers and names, provider settings, dated permission checks and delivery receipts. Workspace files hold media, metadata, approval records and job state. These files are not all encrypted by the application; security also depends on the computer’s accounts, permissions, disk protection and backups.
The operator separately keeps selected login and app-credential records in Keeper. Those records and their history are governed by Keeper’s access and retention arrangements. SudoFocus OS does not automatically synchronize or remove Keeper records when a local account is disconnected.
Sharing
For Instagram URL-based delivery, the app temporarily uploads the selected video to a private Cloudflare R2 bucket. Bucket-scoped credentials remain in Windows Credential Manager. Instagram receives a signed HTTPS download URL, normally valid for 15 minutes; anyone holding that URL can download that object until it expires or the object is deleted. The bucket has no public browsing or public development URL, and signed URLs are not stored in delivery receipts.
The app attempts to delete the exact temporary object when it observes that Instagram ingestion has finished, failed or expired, and checks that the object is absent. A bucket lifecycle rule expires objects under the staging prefix after one day as a fallback; provider cleanup timing is not an immediate-deletion guarantee. Local originals, receipts and media already held by Instagram are separate and are not deleted by staging cleanup. Cloudflare processes storage and delivery requests under its own privacy arrangements.
Selected providers receive the authorization requests, media and metadata needed for the requested operation over HTTPS. The reviewed integration has no central SudoFocus cloud database or telemetry endpoint. It does not send Google API data to advertising services or generative-AI services. Optional remote review through Tailscale can transmit review media and job information to the permitted device.
Google’s processing is covered by the Google Privacy Policy. Other providers and separately selected backup or remote-access services have their own policies.
This informational site is prepared using OpenAI Sites, with hosted delivery through Cloudflare. Its application code has no SudoFocus contact form, analytics script, account-connection form or embedded media player. Hosting and access-control services may process technical request information and use cookies under their own policies; this is not a claim of log-free or cookie-free hosting.
Retention, disconnection and deletion
Removing authorization, removing local records and removing an uploaded video are separate actions. You can revoke Google access in Google Account third-party access settings. Local removal does not delete videos held by a platform.
The operator can inspect an inventory and explicitly disconnect YouTube through local command-line controls. Disconnect first holds local access, attempts to revoke the Google grant, and removes the known credentials and inventoried connection, upload and verification records covered by the reviewed plan. Unsuccessful revocation is reported as unconfirmed. Cleanup stops if records changed or storage checks fail.
This is partial cleanup, not complete erasure. Production job history, original and generated media, rights and approvals, diagnostic exports, other workspaces, the original Google client file, optional native password slots, unindexed vault entries and Keeper or other backup copies are not automatically removed. Local media hashes and safety state remain to prevent accidental duplicate uploads after reconnection. Copies containing account data require a separate reviewed deletion process.
The app flags API evidence older than 30 days as stale. Explicit maintenance can refresh supported channel and upload records. Apart from the temporary R2 staging cleanup described above, there is no automatic retention scheduler or blanket purge after revocation. The operator must arrange the remaining maintenance and copy review; this notice does not promise automatic deletion of all records within a fixed period.
Changes and contact
This notice must be updated when the actual data practices change. Additional providers, permissions or public multi-user features need their own disclosure and authorization. Privacy questions: sudofocus@gmail.com.