RollTape is a production studio for YouTube reaction creators: you record your reaction in your browser, and an AI producer handles setup, packaging, and publishing support. This policy describes what data we handle, what we deliberately do not, and the choices you have. It covers both the public site at rolltape.ai and the RollTape studio app. We wrote it to be readable; nothing here is meant to hide in the fine print.
Account basics (Google Sign-In). When you sign in with Google we receive your Google account identifier, name, email address, and profile picture. We use the identifier to key your channel brief, your first name to greet you, and your email/picture in the account menu. We do not receive your Google password.
Your channel brief. As you talk with the producer, it records what you tell it about your channel — channel name, what you react to, audience, voice and style preferences, layout and thumbnail choices, risk preferences, experience level, and free-form notes. If you share a link to your existing YouTube channel (or another public page), the producer also reads that page's public information — your channel's name, description, and public feed of recent uploads — to prefill the brief instead of interviewing you; everything it prefills is shown to you and editable by talking, like anything else in the brief. We persist this on our servers (Google Cloud Firestore, one document per user). You can see it in the app at any time — it is the channel preview — and change or remove any of it by telling the producer.
Your episode rack. The producer keeps a card per episode: the video you queued or reacted to (its YouTube link, title, and channel), the episode's status, the pick-time risk note, your drafted upload packet (title, description, chapters, tags, thumbnail concept), a link to the folder in your own Drive where the recording was saved, and the YouTube link once you publish. Metadata only — your recordings are never in it. You can remove any episode by telling the producer.
Conversations. Messages you exchange with the producer are sent to our server with each request and forwarded to our AI provider to generate the reply. They pass through our servers only to generate that reply and are not written to our operational logs; we do not persist chat transcripts in our database. Your conversation history is kept in your browser for the session (see "Data stored in your browser" below).
Recording session logs. During a recording session the app keeps a "moment log" — timestamps of when you started, paused, and stopped, audio level peaks, which camera/microphone was used, and window geometry. It contains no audio or video. At the end of a session it is sent to our server once so the producer can write your debrief and draft your title, description, and chapters; it is processed and not stored. A copy is saved with your recording files in your own storage.
Technical logs. Our hosting (Google Cloud Run) keeps standard request logs (timestamps, request paths, status codes, IP addresses) for operations and security.
To provide the product: keep your channel brief so the producer remembers your channel; generate replies, suggestions, and your upload packet; find videos you ask about; run and debrief recording sessions; operate and secure the service. That is the list. We do not sell personal data and do not use it for advertising.
The producer is powered by a third-party large-language-model provider (currently Anthropic, accessed under its commercial API terms). Your messages, your channel brief, your episode rack (including the drafted upload packet and the link to your own Drive folder), and session-log summaries are sent to that provider to generate responses. Separately, when you generate channel brand art (logo, banner, avatar), your channel name and niche — never any audio or video — are sent to Google's Vertex AI image model to create the art.
When you ask for captions on a recording, the audio of your own camera/voice track — never the source video's audio — is sent to Google Cloud Speech-to-Text to transcribe what you said. That audio is processed to produce the transcript and then discarded: it is not stored on our servers, and under the same commercial terms described below it is not used to train models. This is the only feature that sends any of your audio to a provider; the resulting transcript and caption file are saved to your own Google Drive, not to us.
The models RollTape uses are not trained on your data. As of July 6, 2026 we have confirmed that our current AI providers' commercial API terms do not permit them to use your content to train their models. A provider may briefly retain content to enforce its own safety policies; that is not model training. We verify this before adopting any new provider. The producer is an AI and can make mistakes; nothing it says is legal advice.
This no-training statement covers only what RollTape sends to its own AI providers (above). It is not a statement about what YouTube — or any other platform — may do with a video once you choose to upload it there; that is governed by those platforms' own separate terms and settings (for example, YouTube provides its own AI-training controls in YouTube Studio). RollTape never uploads on your behalf, so those choices stay with you.
RollTape uses YouTube API Services. By using the parts of RollTape that interact with YouTube you are also agreeing to the YouTube Terms of Service. The Google Privacy Policy describes how Google handles data on its side.
Permissions we may request from your Google account, always at the moment you first use the feature and never before:
We use the YouTube Data API on our servers to search for videos when you and the producer are choosing what to react to. Search results are shown in the conversation and are not stored — except that when you queue a video as an episode, that video's basic details (link, title, channel) are saved on its episode card in your rack, and removed when you remove the episode or delete your data. We keep that stored title/channel current with an automatic refresh that re-checks it at least every 30 days and clears it if the video has been made private or removed.
Revoking access: you can revoke RollTape's access to your Google account at any time at Google security settings, and you can stop sharing your camera, microphone, or screen at any time through your browser.
Two parts of the app load directly from Google in your browser: the Google Sign-In component, and — during a recording session — the official YouTube player that plays the video you are reacting to. Like any web request, these send standard technical data (such as your IP address and browser type) to Google, handled under the Google Privacy Policy. We add no advertising or analytics services on top of them. Our fonts are self-hosted (served from our own servers, not a Google CDN), so simply loading the app sends nothing to Google beyond what sign-in and the player already require.
The app keeps working data on your device: your sign-in token for the current session, your current conversation with the producer, recording chunks during a session (IndexedDB, so a long take doesn't need to fit in memory), and small preferences (for example, which microphone setup you confirmed). These stay on your device; clearing your browser's site data removes them.
We share data only with the service providers (subprocessors) needed to run the product, each processing it on our instructions. The full list:
| Provider | What they do for RollTape | What of yours they process |
|---|---|---|
| Google Cloud (Google LLC) | Hosting (Cloud Run) and database (Firestore), US region | Your channel brief, episode rack, and standard technical logs |
| Anthropic PBC | The AI model behind the producer | Your conversation messages, channel brief, session-log summaries, and episode rack (drafted upload packet and your Drive-folder link) — not used to train models (see AI processing above) |
| Google (Vertex AI image model) (Google LLC) | Generating your channel brand art (logo, banner, avatar) | Your channel name and niche only — no audio, video, or personal media |
| Google Cloud Speech-to-Text (Google LLC) | Transcribing your own voice track into captions, when you ask | The audio of your camera/voice track only (never the source video's audio) — processed to produce the transcript, then discarded; not stored by us, not used for training |
| YouTube Data API (Google LLC) | Video search, and reading your own channel's public page/feed when you share your channel link, to help pick and prefill | Your search queries and, when you share your own channel link, reads of your public channel page and uploads feed; results are shown and not stored except the episode-card title/channel (re-sourced from public oEmbed) |
If we add payment processing, payments will be handled by a payment processor (e.g., Stripe) and your card details will go to them, never to us; this list will be updated before that launches. We may disclose data if required by law. We do not sell personal data.
Your channel brief and episode rack are kept while you have an account so the producer remembers your channel. You can delete them yourself at any time: ask the producer, or use "Delete my data" in the account menu — after an on-screen confirmation, your brief and your entire rack are deleted immediately. You can also email privacy@rolltape.ai from your sign-in address and we will delete them within 30 days.
What that deletion reaches, stated plainly: it erases your channel brief and your entire episode rack from our database immediately. It does not reach the technical request logs described below (which age out on their own retention schedule), and messages already sent to our AI provider are subject to that provider's own retention, not ours. Your recordings are in your own Drive/YouTube/device and are yours to delete directly — we couldn't delete them if we wanted to, because we never had them.
Technical logs (timestamps, request paths, status codes, IP addresses) are retained for approximately 30 days and then deleted.
Traffic is encrypted in transit (HTTPS). Server-side secrets are held in Google Secret Manager. Sign-in is verified on every request via Google's token verification, and during our testing phase access is limited to an invited allow-list of verified accounts. The most privacy-critical design decision is architectural rather than procedural: your media never reaches us, so a breach of our systems cannot expose it.
If a breach happens. If we discover a breach that exposes your personal data, we will notify the affected users and any applicable authorities without unreasonable delay after confirming it, consistent with applicable law (including Utah's breach-notification statute and, where GDPR applies, notice to the relevant authority within 72 hours).
RollTape is for adults: you must be at least 18 to use it (Terms of Service §2). It is not directed to children, and we do not knowingly collect data from anyone under 18. Separately, the "made for kids" self-declaration you set before any upload is passed through to YouTube (a YouTube COPPA requirement) and is not used by us for anything else.
Where the service is offered. At launch, RollTape is offered only to users in the United States and is not made available to residents of the European Union or the United Kingdom. We do not knowingly sign up EU/UK users, and we do not intend the service to be directed to them. If you are in the EU or UK, please do not use RollTape until we announce availability in your region.
Depending on where you live (e.g., CCPA/CPRA in California), you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Contact privacy@rolltape.ai to exercise them. You also have the right to complain to your local data-protection authority.
If we change this policy we will update the effective date above and, for material changes, tell you in the app before they take effect.
Tarina Inc. · privacy@rolltape.ai · https://rolltape.ai