stepstube

Privacy Policy

Last updated: September 29, 2026

1. Data We Collect

  • Account data: Your email address, name and profile picture from Google sign-in, and the date you signed up.
  • Usage data: How many guides you have made today, so we can apply the daily limit. On Pro, which videos you made guides from in the last 30 days, so we can apply the fair-use limit. A record of each guide request with your account number, plan and time. If you accept analytics in the app, in-app events such as "shared a guide" or "reached the daily limit".
  • Subscription data: If you subscribe to Pro, we keep your Stripe customer ID and subscription ID, your plan, its status (for example active or cancelled) and the dates of your current billing period. We do not keep your card number.
  • YouTube links and transcripts: The links you submit. To build your guide we fetch the video's public transcript and some of its public YouTube comments. We keep a transcript for up to 30 days, filed under the video rather than under your account, so the next guide for that video is faster.
  • Guides: Each guide we make is saved with its video, not with your account, and is published on a public page on this site (/g/ followed by the video's ID). The page does not show who made the guide.
  • Invites and abuse prevention: A one-way hash of your IP address and of a random device ID set by the app, and when you made your first guide and how many you have made. We use these to credit invites and to stop people claiming invite bonuses with repeat accounts. We do not store the raw IP address or device ID. If you invite someone or join through an invite, we also record the link between the two accounts, its status, and the bonus guides earned and used.
  • Server logs: Our web server logs your IP address, your browser type and the pages you request. Our app's own logs record your account number and the IDs of the videos you request, but not your email or IP address.

2. Data We Do NOT Collect

  • BYOK API keys: Your Gemini API key is stored only in your browser's localStorage. On each request it is sent to our server and forwarded to Google on your behalf — we never write it to disk, never log it, and never retain it after the request completes.
  • Voice data: Voice mode uses your browser's built-in Web Speech API. Audio is processed locally by your browser and sent to your browser's speech service (typically Google). We never receive, store, or process voice audio.
  • Payment details: All payment processing is handled by Stripe. We never see or store your card number.

3. How We Use Your Data

  • Authenticate your account and enforce usage limits.
  • Process your extraction requests.
  • Manage your Pro subscription and answer support and refund requests.
  • Credit invites and stop invite abuse.
  • Understand how the service is used, so we can improve it.

We do not sell your data. We do not use third-party analytics trackers.

4. Cookies & Local Storage

  • Sign-in tokens: Stored in localStorage to keep you signed in.
  • Preferences: Dark mode, high contrast mode, voice mode settings, auto-saved URL input.
  • BYOK key: Stored in localStorage (encrypted when your browser supports it), never on our server.
  • My Collection: Up to 20 of your recent guides, saved in your browser.
  • Invites: The random device ID described above, and the invite code you arrived with, if any.

We do not set cookies and we do not use tracking pixels. The embedded YouTube player comes from YouTube and may set YouTube's own cookies (see below).

5. Data Retention

We keep your account data, subscription data, usage records and invite records while your account is active. Transcripts are kept for up to 30 days. The daily guide count resets at midnight UTC, and the Pro fair-use record only keeps the last 30 days. Web server logs are deleted after 15 days. Public guide pages are not linked to any account and stay up.

To delete your account, email hello@herakles.dev from your account email. We will delete your account and the data tied to it within 30 days and tell you when it is done. We keep billing records (your Stripe customer and subscription IDs and the history of your charges and refunds) for tax and accounting, and Stripe keeps its own records under its privacy policy. Logs that were already written are deleted on their normal schedule.

6. Third-Party Services

  • Google (sign-in, Gemini AI): Sign-in, and AI processing. To make your guide we send Google's Gemini API the video's transcript (or, when there is no transcript, the video's YouTube link) and some of the video's public YouTube comments. We do not send your name, email or account details. Google handles this data under its Gemini API terms. If you use your own API key, the request runs under your own agreement with Google. Our landing page also loads the Inter font from Google Fonts, so Google sees your IP address when you open that page. Subject to Google's Privacy Policy.
  • Stripe: Payment processing and subscription billing. Stripe collects and holds your payment details and billing email. We never see your card number. Cancellation happens in Stripe's billing portal. Subject to Stripe's Privacy Policy.
  • YouTube: Our server fetches transcripts and comments from YouTube. When you watch a video or view a guide, your browser loads the YouTube player and video thumbnails directly from YouTube, which sees your IP address and may set cookies. Subject to YouTube Terms of Service.

7. Contact

For privacy questions or to ask for deletion, email hello@herakles.dev. We reply within 2 business days. stepstube is provided by D. Michael Piscitelli (Herakles).