Privacy policy
Data controller
FouniStream is operated by founilh production, which acts as the controller of the personal data described below under the General Data Protection Regulation (GDPR).
Data collected
- Account: email address, name, language and sign-in identifiers;
- Content: imported videos, transcripts, clip metadata and brand kit (logo, colors and fonts);
- Usage: credit and operation history, and technical logs such as IP address and device;
- Support: messages exchanged with our support team.
- Partner program: partner code, attribution click, hashed browser identifier when available, attribution dates, commissions, payment status and information needed for fraud prevention.
Payment data such as card and billing details is collected and processed directly by our payment provider Stripe, which acts as Merchant of Record for eligible transactions: sale of the service, subscription management, payments, taxes and invoices. We do not store card numbers.
Google sign-in and Google data
FouniStream lets you create an account or sign in with Google. Authentication is handled through Google OAuth and Supabase Auth. FouniStream receives only the information needed to identify the account, including email address, name, profile picture when provided and a technical identifier linked to the Google account.
This information is used only to create, retrieve and secure your account, display profile information and enable sign-in. Signing in with Google alone does not give FouniStream access to Gmail, Google Contacts, Google Calendar or your entire Google Drive.
Google Drive
Some FouniStream storage features may use Google Drive. When an authorized administrator connects a Google Drive account, FouniStream requests the drive.file scope and the basic identity information needed to associate the account. This scope lets FouniStream create and manage files and folders created or opened by the application without requesting general access to all Drive content.
Drive access is used only for storage, import, processing, export and file deletion functions needed to operate FouniStream. Google tokens required for this connection are kept server-side in restricted-access data stores and are not returned to the browser. Ordinary users do not need to connect their own Google Drive when FouniStream uses its shared storage space.
FouniStream does not sell Google data, use it for personalized advertising or share it except with providers strictly necessary to deliver, secure and operate the service. When a file or its content must be analyzed by an AI feature requested by the user, only the data needed for that operation may be sent to the relevant technical providers.
FouniStream's use of information received from Google APIs is limited to the features described in this policy and complies with the Google API Services User Data Policy, including Limited Use requirements where applicable.
YouTube and YouTube Shorts
When you connect a YouTube channel, FouniStream uses Google OAuth to request youtube.upload, youtube.readonly and yt-analytics.readonly permissions together with basic profile information. One YouTube connection is used for video or Shorts publishing and channel analytics synchronization.
The youtube.upload scope is used only to publish videos that you choose to send from FouniStream to the selected channel. The youtube.readonly scope is used to identify the channel and read metadata and statistics needed by the service. The yt-analytics.readonly scope is used to retrieve YouTube Analytics data such as views, watch time, average view duration, average percentage viewed, subscribers gained and retention when available.
YouTube access and refresh tokens are stored server-side in restricted-access data stores and are never exposed to the browser. FouniStream uses these tokens only for user-requested actions, scheduled publishing and optional analytics synchronization.
FouniStream does not sell YouTube data, use it for personalized advertising or share it except with providers strictly necessary to deliver and secure the service. Use of YouTube data complies with the Google API Services User Data Policy, including applicable Limited Use requirements.
Control and deletion of Google data
You can stop using a Google connection by signing out of the service or, for Google Drive and YouTube connections available in your workspace, by using the disconnect option in FouniStream. You can also revoke authorization from your Google Account security settings. Deleting your FouniStream account deletes account data and associated content under the conditions described in the Retention section below.
Purposes and legal bases
- Account creation and management and provision of the service: performance of the contract;
- Security and prevention of fraud and abuse: legitimate interest;
- Optional measurement of site usage and the sign-up journey: consent, which can be changed or withdrawn in the cookie manager;
- Security, technical diagnostics and error prevention: legitimate interest;
- Customer support: performance of the contract;
- Accounting and tax obligations: legal obligation;
- Attribution, calculation and audit of the partner program and prevention of self-referrals and abuse: performance of the program and legitimate interest in preventing fraud;
- Any marketing communications: consent, withdrawable at any time.
Data sharing
Your data may be disclosed to the following categories of recipients:
- technical providers such as hosting, storage, analytics and support tools, subject to confidentiality obligations;
- Stripe, as payment provider and Merchant of Record for eligible transactions, for the sale of the service and management of subscriptions, payments, taxes and invoices;
- professional advisers such as legal or accounting advisers where applicable;
- public authorities where required by law.
Where data is transferred outside the European Union, those transfers are covered by appropriate safeguards such as standard contractual clauses or adequacy decisions.
Retention periods
Account data is kept while the account is active. After account deletion, it is deleted or anonymized within a maximum of 12 months, except where longer legal obligations apply, including accounting data kept for applicable statutory periods. Imported videos and content are deleted with the account. An unclaimed partner attribution expires after 30 days. Partner-program financial records and audit information may be kept for the statutory periods needed for accounting, proof of payment and dispute handling.
Security
We implement appropriate technical and organizational measures, including encrypted communications, role-based access controls within workspaces and access restricted to authorized people. Your videos remain private and are accessible only to authorized members of your workspace.
Your rights
You have rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent. You can export or delete your data from account settings. We respond to requests within one month. You may also lodge a complaint with the competent supervisory authority; in France, this is the CNIL.
Cookies
The service uses cookies essential to operation, such as session and preference cookies, and where applicable audience-measurement cookies. When a partner link is used, FouniStream may also keep a first-party attribution for 30 days limited to the partner code and click identifier. The server may store a hashed fingerprint of a random browser identifier to prevent double counting without keeping that raw identifier in the click log. You can manage preferences in your browser settings; see the Cookies page for details.