Legal
Privacy Policy
OAK Media Works ("OAK", "we") produces video deliverables for record labels and artists and runs a client portal to brief, review and approve that work. This policy explains what we collect, why, who processes it on our behalf, how long we keep it, and the choices you have.
1. Who is responsible
OAK Media Works LLC, a Massachusetts limited liability company (United States), is the data controller for the portal and this website. Contact for anything in this policy: tim@oakmediaworks.com.
2. What we collect
Account
- Name, email address, a password hash (never the password), an optional avatar, and your role and label (imprint) inside a workspace.
- Sign-in records: session and device tokens, IP address, browser/user agent, timestamps. Sign-in attempts are rate-limited per address.
- If you sign in with Google: your Google account email and profile name, as returned by Google. We never see your Google password.
Job briefs and project data
- Everything you enter to request work: job type, title, artist, specifications, due dates, platform targets, budgets and credit quotes, spreadsheet rows you import, and the original request snapshot we keep for audit.
- Review activity: timestamped notes, approvals, change requests, milestone states.
Media
- Source files you upload or link (video, audio, artwork, lyrics), the deliverables we produce, previews and thumbnails, and technical analysis data derived from your media (shot boundaries, beat grids, subject tracks, captions) that lets us re-render without re-processing.
- Per-delivery compute records (processing time, machine class, estimated cost). Clients see minutes, never internal cost figures.
Chat and notifications
- Messages in project and job threads, reactions, mentions, and the notification and email records that result. Message bodies are encrypted at rest with a per-workspace key.
- Feedback you send through the portal's feedback form.
Connected channels
- If you connect a YouTube channel for publishing, we store the channel id and title and an encrypted OAuth refresh token so we can upload on your instruction. See section 5.
Automatically
- Server logs (request path, status, timing, IP) for security and debugging; an audit log of significant actions (who approved, granted credits, changed a role) with the acting account and IP.
3. Why we process it (legal bases)
- Performing our contract with your label — producing, delivering and billing the work you request; operating the portal; support.
- Legitimate interests — securing the service (sign-in records, audit log, rate limiting), improving our tooling using aggregate quality metrics (for example how often an automatic crop needs correction), and keeping records for disputes.
- Consent — connecting a YouTube channel, and optional email notifications you can switch off in your profile.
- Legal obligations — tax and accounting records for credit purchases and statements.
4. Who processes data for us
We use a small number of service providers. Each processes data only on our instructions and under a written agreement.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Fly.io | Hosts the portal application and its database | All portal data | United States (Chicago region) |
| Cloudflare R2 | Object storage for uploaded media, deliverables and analysis bundles | Media files, previews, poster frames | Cloudflare network, no jurisdiction restriction (primarily United States) |
| Vercel | Hosts this website and review/preview pages | Site traffic logs | Global edge |
| Resend | Transactional email (magic links, invitations, job notifications) | Email address, notification text | United States |
| Anthropic (Claude API) | In the portal: import analysis (mapping spreadsheet columns to job fields). In the OAK editor applications: reading lyrics and briefs, aligning and checking lyric translations, describing scenes so a cut or a frame can be chosen | Spreadsheet headers and sample rows; lyric and brief text; individual video frames | United States |
| OpenAI and Google (Gemini) | In the OAK editor applications: an independent second check of lyric translations | Lyric text and its translation | United States |
| AtlasCloud | In the OAK editor applications: animating artwork and separating an image into layers for motion formats | Artwork and video frames for the job | United States |
| Google / YouTube | Sign-in with Google (if used); YouTube publishing when a channel is connected; reading public comments on the videos you point us to, for the fan-celebration format | Google account email, name and account id; channel id; uploaded video and its metadata; public comment text | Google infrastructure |
OAK editors — the people who do the work — access job data through OAK-issued accounts and device tokens that we can suspend or revoke immediately. Their identity is not shown to clients inside the portal. Editors are bound by an agreement covering confidentiality and deletion of local working copies on offboarding.
We do not sell personal data, share it with advertisers, or use client media to train machine-learning models. We may disclose data if required by law or to protect the rights and safety of OAK, our clients or others.
5. YouTube and Google API Services
The OAK Media Works portal uses YouTube API Services to publish approved deliverables to YouTube channels that a label administrator has chosen to connect. By connecting a channel you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
What we access and store when a channel is connected:
- Your channel's id and title, so you can pick the destination.
- An OAuth refresh token, stored encrypted, used only to upload videos and set their title, description, tags, privacy status and schedule as you specify in the portal.
- The id, status and (once published) URL of each video we upload, and our own quota usage counter.
We do not read your channel's analytics, subscribers or private data, and we do not touch any video you did not ask us to upload. For the fan-celebration format we read public comments on the videos you point us to, and only those. Tokens are not shared with any third party and are used only from our servers.
You can disconnect a channel at any time from the portal (Settings → YouTube), which deletes our copy of the token and revokes it with Google. You can also revoke OAK's access directly from your Google account at https://security.google.com/settings/security/permissions. Either action stops all future uploads immediately; videos already published stay on your channel under your control.
6. How long we keep data
The full schedule is on the Data retention page. In summary:
- Source media, analysis data and deliverables: for as long as your label is a client, so re-edits stay cheap and every version stays downloadable; deleted on request at any time, or within 30 days after your workspace closes.
- Job records, briefs, chat and review notes: for the life of the workspace, then deleted or anonymised within 30 days.
- Credit ledger, quotes and statements: 7 years from the transaction, as financial records.
- Server and audit logs: 90 days for request logs; audit log for the life of the workspace.
- Account data: until you or your label administrator deletes the account; then removed or anonymised within 30 days except where a record must be kept by law.
- YouTube tokens: until you disconnect the channel or the token is revoked.
7. Your rights
Depending on where you are, you may have the right to access, correct, export, restrict or delete your personal data, to object to processing based on legitimate interests, and to withdraw consent. Label administrators can manage most account data directly in the portal. For anything else — including a full export or deletion — email tim@oakmediaworks.com from the address on your account. We answer within 30 days. If you are in the EU/UK you may also complain to your supervisory authority.
Requests about media a label uploaded on behalf of an artist should go through the label, which controls that content.
8. Security
- All traffic is TLS. Passwords are hashed with Argon2; sessions are short-lived with refresh; device tokens are hashed at rest and revocable.
- Message bodies, asset titles and connected-channel tokens are encrypted at rest with per-workspace keys derived from a master key held outside the database.
- Access is role-based and label-scoped: a label's members only ever see their own label's jobs and media. Signed, expiring download URLs for media.
- Every consequential action is written to an audit log visible to the workspace owner.
No system is perfectly secure. If we learn of a breach affecting your data we will tell affected labels without undue delay.
9. Cookies
The portal sets strictly necessary cookies only: px_access and px_refresh (your session), and a short-lived px_oauth cookie while a Google sign-in is in progress. They are first-party and HttpOnly, and are not used for tracking or advertising. Display preferences (theme, thumbnail size, whether you have seen the welcome card) live in your browser's local storage, not in cookies. This website sets no cookies of its own. We do not use third-party analytics or advertising cookies anywhere.
10. Children
The portal is a business tool for labels and their teams and is not directed at anyone under 16. We do not knowingly collect data from children.
11. International transfers
Our providers are primarily in the United States. Where data about people in the EU/UK is transferred there we rely on the providers' standard contractual clauses and data-processing terms.
12. Changes to this policy
We will post any changes here and update the effective date. For material changes affecting connected channels or retention we will also email workspace owners.
