Authorised Google/YouTube data
- OAuth grant status and granted scopes
- Authenticated channel ID and channel title
- Channel upload eligibility information used for preflight checks
- Uploaded video ID, processing status, and visibility status
Public policy draft
This policy explains how KJW Video Publisher uses Google and YouTube data for the clinic's internal video-publishing workflow.
KJW Video Publisher is operated by 김진욱신경외과 (Kim Jinwook Neurosurgery Clinic), a medical clinic in the Republic of Korea. It is an internal tool for approved clinic personnel and is not offered to the general public.
The tool uses YouTube API Services only to identify the authenticated clinic-owned channel, upload a human-approved clinic-owned video with approved metadata, and verify the uploaded video's identifier, processing state, and visibility. Use of this tool is also subject to the YouTube Terms of Service. Google's handling of information is described in the Google Privacy Policy.
A refresh token is designed to be stored locally with restricted file permissions and used only for the approved publishing purpose. Access tokens are obtained for limited API operations and are intended to be held only temporarily. The tool does not collect or store the user's Google password or one-time verification code. OAuth client secrets and tokens are not provided to AI models.
The tool creates local evidence to prevent duplicate publication and support accountability. This may include source and approval digests, execution identity, target channel ID, approved metadata, timestamps, upload-attempt state, uploaded video ID, and verification outcome. This evidence is used only for clinic operations, security, troubleshooting, and compliance.
Data is used only to provide and protect the internal publishing workflow. The clinic does not sell YouTube API Data, share it with advertisers or data brokers, or use it for advertising. The public documentation pages use no analytics, tracking technology, cookies, advertising, or third-party scripts. Access is limited to authorised clinic personnel and service components required to perform the approved operation.
The design separates OAuth credentials from AI-model prompts and tool results, restricts credential-file permissions, binds publishing to the approved channel and media digest, prevents automatic resubmission after uncertainty, and records local evidence. These controls reduce risk but do not replace the missing revocation and deletion workflow described in section 10.
Authorisation tokens may be retained only while necessary for the active user's specific consent and the stated internal publishing purpose. Other stored YouTube API Data must be deleted or refreshed within 30 calendar days unless an applicable YouTube policy permits longer retention. Direct deletion requests and deletion following the client's own revocation mechanism must be completed as soon as possible and no later than 7 calendar days. Data associated with a grant revoked through Google's security settings must be removed as soon as possible and within the applicable policy deadline.
Users can revoke Google access through the Google security settings page required by YouTube policy or the current Google Account third-party access settings. To request deletion of locally stored OAuth/API-related data, email jjjbel@gmail.com. See the Data Deletion and Revocation page for the distinction between local data deletion and deleting a published video from YouTube.
The reviewed implementation does not evidence an in-product disconnect control, immediate programmatic token revocation, automated local credential deletion, API Data deletion workflow, or periodic 30-day refresh/delete job. These features must not be represented as automated. Until they are implemented and tested, requests require documented manual handling and audit submission remains on hold.
Privacy questions, complaints, revocation requests, and deletion requests may be sent to Jinwook Kim at jjjbel@gmail.com.
한국어 번역본
KJW Video Publisher는 대한민국 의료기관인 김진욱신경외과가 운영하는 내부 전용 도구입니다. 승인된 병원 직원만 사용하며 일반 대중에게 제공하지 않습니다.
인증된 병원 소유 채널 확인, 사람이 승인한 병원 소유 영상과 메타데이터 업로드, 업로드된 영상의 식별자·처리 상태·공개 상태 확인에만 YouTube API Services를 사용합니다. 본 도구 사용에는 YouTube 서비스 약관이 함께 적용되며 Google의 정보 처리 방식은 Google 개인정보처리방침에서 확인할 수 있습니다.
OAuth 권한 상태와 범위, 인증된 채널 ID·채널명·업로드 자격 정보, 업로드된 video ID·처리 상태·공개 상태를 처리합니다. 병원이 제공하는 최종 영상, SHA-256, 제목·설명·태그·카테고리·언어, 시청자층·합성 미디어 선언, 인간 승인과 대상 채널 결박도 처리합니다.
refresh token은 승인된 목적에 필요한 동안 제한된 파일 권한으로 로컬 저장하도록 설계되어 있습니다. access token은 제한된 API 작업에 일시적으로 사용합니다. Google 비밀번호와 OTP는 수집·저장하지 않으며 OAuth client secret과 token을 AI 모델에 전달하지 않습니다.
중복 게시 방지와 책임 추적을 위해 영상·승인 해시, 실행 식별자, 대상 채널, 승인 메타데이터, 시각, 업로드 시도 상태, video ID와 검증 결과를 로컬 증빙으로 남길 수 있습니다.
데이터는 내부 게시 흐름 제공과 보호에만 사용합니다. YouTube API Data를 판매하거나 광고주·데이터 브로커와 공유하지 않으며 광고에 이용하지 않습니다. 공개 문서 페이지에는 분석, 추적, 쿠키, 광고 또는 외부 스크립트를 사용하지 않습니다.
OAuth 자격증명과 AI 모델 경계를 분리하고, 자격증명 파일 권한을 제한하며, 승인 채널·영상 해시와 게시 실행을 결박하고, 불확실 응답 후 자동 재제출을 금지하며, 로컬 증빙을 기록하도록 설계했습니다.
인증 token은 활성 사용자의 동의와 명시된 목적에 필요한 동안만 보관합니다. 그 밖의 YouTube API Data는 공식 정책상 더 긴 보존이 허용되지 않는 한 30일 안에 삭제하거나 갱신합니다. 직접 삭제 요청과 제품 자체 철회 절차에 따른 삭제는 가능한 빨리, 늦어도 7일 안에 처리해야 합니다.
YouTube 정책이 지정한 Google 보안 설정 페이지 또는 현재의 Google 계정 제3자 앱 접근 설정에서 권한을 철회할 수 있습니다. 로컬 OAuth/API 관련 데이터 삭제는 jjjbel@gmail.com으로 요청하십시오. 자세한 구분은 데이터 삭제 및 권한 철회에서 확인할 수 있습니다.
검토된 구현에서는 제품 내 연결 해제, 즉시 programmatic token revocation, 로컬 인증정보 자동 삭제, API Data 삭제 흐름, 30일 주기 갱신·삭제 작업이 확인되지 않았습니다. 이를 자동 기능이라고 주장하지 않으며, 구현·검증 전에는 문서화된 수동 처리가 필요하고 감사 제출은 보류됩니다.
개인정보 문의·불만·철회·삭제 요청은 김진욱 담당자(jjjbel@gmail.com)에게 보내주십시오.