Crosspost Local
Privacy Policy
Last updated July 22, 2026
This policy describes how Karol Janowski, doing business as Narratwist ("we", "us", or "our"), handles information in Crosspost Local. Crosspost Local is a private, owner-operated utility, not a public or multi-user service.
Information Crosspost Local handles
When the operator connects YouTube, the app handles the OAuth access token and refresh token, granted scopes, the OAuth client identifier, the authorized YouTube channel ID and channel title, and the last successful authorization-verification time. When publishing, it handles the selected local long-form video and Short, the selected long-form custom-thumbnail file, each title, description, tags, category, audience selection, synthetic-media disclosure, subscriber-notification choice, visibility, upload progress, processing status, video ID, result URL, and sanitized errors.
The app also handles equivalent connection, publishing, and limited operator-directed engagement data for other platforms described in its interface. It does not sell personal information, serve advertising, build user profiles, or use platform data for unrelated purposes.
How YouTube API data is used
channels.listidentifies the exact channel selected during authorization and validates that authorization periodically while the app is running.videos.insertuploads each selected long-form video or Short only after the operator reviews and confirms the destination, metadata, audience, and visibility.thumbnails.setapplies the operator-selected custom thumbnail to the confirmed long-form upload.videos.listreads the processing and visibility result for videos uploaded in that publishing attempt.
Crosspost Local requests https://www.googleapis.com/auth/youtube.upload and https://www.googleapis.com/auth/youtube.readonly. The upload permission authorizes both videos.insert and thumbnails.set; custom-thumbnail support does not require a broader permission. It does not use these permissions to read subscriptions, playlists, comments, analytics, or unrelated videos.
The supported public YouTube Data API does not expose methods for adding or copying end screens or setting a Short's Related Video, so Crosspost Local does not perform those actions.
Storage and security
Crosspost Local stores application data on the operator's own machine. Provider credentials, including any credential temporarily retained solely to retry revocation, are encrypted at rest. Source video and YouTube custom-thumbnail files are removed after every dependent destination completes, is skipped, or is explicitly discarded. A thumbnail removed before publishing is deleted immediately; an otherwise unreferenced thumbnail is deleted when the local server next starts.
Retention and deletion
YouTube publishing attempts and their result metadata are automatically deleted after 30 days. The operator can delete all local YouTube publishing history immediately from the Connections screen; this cancels active YouTube work but does not delete videos already present on YouTube.
Disconnecting YouTube cancels active YouTube work and deletes the channel identity, active local credential, and all local YouTube publishing history. Deleting the entire local data directory removes the remaining local app database, but cannot by itself communicate a revocation request to Google.
Revocation and account control
On disconnect, Crosspost Local asks Google to revoke the token. Local access is disabled and local YouTube data is deleted immediately even if Google is unavailable. In that case, the encrypted credential is retained only in a revocation queue and retried automatically; it cannot be used to publish. The operator can also retry from the Connections screen or revoke access directly in Google account permissions.
Third parties and Google API policy
Confirmed video, the selected custom thumbnail, and metadata are sent to YouTube and handled under the YouTube Terms of Service and Google Privacy Policy. Crosspost Local's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Public website data
These public pages may use consent-managed analytics and cookies independently of the local app. See the Narratwist Cookie Policy and use Cookie preferences in the footer where available.
Contact
Questions or deletion requests can be sent to social@narratwist.com. The operator is Karol Janowski, doing business as Narratwist, Poland.