Privacy and data use
Privacy Policy
This Policy explains what Gutsav processes when creators request access, manage content synchronization, and monitor an assigned virtual phone.
- Effective
- 4 September 2026
- Last updated
- 4 September 2026
1. Scope and controller
This Policy applies to the Gutsav website, invite-request process, creator portal, content-transfer workflow, assigned virtual phones, support, and related operations. Gutsav is the controller of personal data processed for these purposes, except where applicable law assigns a different role.
YouTube, Instagram, TikTok, Bilibili, and other connected services process data under their own privacy policies. Gutsav does not control their independent processing.
2. Data we collect
Access and account data
Name, email address, creator handle, requested source and destination platforms, invite and account status, role, timezone, password hash, multi-factor authentication status, encrypted authenticator secret, hashed recovery codes, session records, and acceptance of legal terms. We do not store your Gutsav password in readable form.
Connected account and content data
Platform names, creator handles, public profile identifiers and URLs, connection status, source URLs, video files temporarily needed for transfer, thumbnails or cover frames, titles, descriptions, captions, tags, schedules, destination choices, publication URLs, content fingerprints, delivery results, and errors.
Virtual phone and usage data
Assigned-device identifiers and status, model and software information, account-connection status, battery and availability signals, commands needed to operate the service, remote-session start and end records, input needed during an active session, and the latest limited-retention screen image used to show device status or support a session.
Security and support data
Authentication events, IP-derived request information in operational logs, request identifiers, timestamps, audit events, rights confirmations, suspected misuse signals, complaints, support messages, evidence supplied to verify ownership or authorization, and actions taken by administrators.
Gutsav does not ask you to send destination-platform passwords through forms or support messages. You enter platform credentials directly during your private virtual-phone session, and the resulting platform session remains on the assigned device.
3. How we obtain data
We collect data directly from you; from actions taken through your Gutsav account; from the public source URLs and creator profiles you direct us to process; from destination platforms when confirming publication status; from your assigned virtual phone; and from administrators, rights holders, security reviews, or lawful requests.
4. Why we use data
- provide invitations, authentication, account security, content import, synchronization, scheduling, publishing, verification, and virtual-phone monitoring;
- carry out your instructions and maintain records of those instructions;
- confirm account relationships and detect content moved without authorization, virtual-phone misuse, fraud, abuse, security threats, and platform-policy violations;
- investigate complaints, require ownership evidence, suspend or terminate access, and establish, exercise, or defend legal claims;
- maintain service reliability, troubleshoot failures, audit administrative actions, and protect creators, rights holders, platforms, Gutsav, and the public;
- comply with law, court orders, valid legal process, sanctions, and regulatory duties; and
- review invite requests and communicate about access or support.
Depending on applicable law, these activities rely on performance of our contract with you, steps you request before entering that contract, compliance with legal obligations, legitimate interests in operating and protecting the service, consent where specifically requested, and establishment or defense of legal claims.
5. Ownership checks and monitoring
Gutsav may use automated and manual checks involving source and destination identifiers, account relationships, content metadata, public URLs, thumbnails or frames, file fingerprints, publication patterns, rights confirmations, complaints, and virtual-phone activity. We use this information to detect unauthorized content movement and misuse, request evidence, block transfers, restrict phone access, preserve relevant records, and suspend or terminate accounts.
These checks are safeguards, not a promise that every infringement will be detected. The user remains responsible for the content and its legality under the Terms & Conditions.
6. How we share data
We disclose data only as reasonably necessary:
- to YouTube, Instagram, TikTok, Bilibili, or another connected service when you direct a transfer, sign in, or request publication;
- to infrastructure, hosting, storage, security, backup, and support providers acting for Gutsav under appropriate obligations;
- to Gutsav administrators and authorized personnel who need access to operate, secure, support, or enforce the service;
- to rights holders, affected users, advisers, insurers, regulators, courts, or law enforcement when reasonably necessary to investigate a complaint, protect rights or safety, comply with law, or establish or defend a claim; and
- in connection with a financing, merger, acquisition, restructuring, insolvency, or transfer of the service, subject to lawful safeguards.
Gutsav does not sell personal data or use creator content for third-party behavioral advertising.
7. Retention
We keep data only for as long as reasonably necessary for the purpose collected, security, dispute resolution, enforcement, and legal obligations. Current operational periods are:
- Transferred video files: deleted once all related deliveries finish and, in all cases, targeted for deletion within 24 hours of storage.
- Virtual-phone screen images: only the latest status image is retained; it is replaced by the next image and expires no later than 26 hours after capture.
- Interactive screen relay data: kept in memory only while needed for an active or recently ended remote session.
- Authentication sessions: expire after seven days and may be invalidated earlier.
- Invitation links: expire after seven days; password-reset links expire after one hour. Expired link records are routinely removed.
- Audit and remote-session history: normally retained for 365 days, unless a different period is required for security, a dispute, or law.
- Access requests: retained for up to 24 months to review the request, prevent abuse, and document access decisions, unless continued retention is required for a dispute or law.
- Backups: normally rotate within 14 days.
Closing an account deletes the active account and associated content records and media, subject to de-identified audit records, rotating backups, legal holds, and records necessary to establish or defend claims.
8. International processing
Gutsav, its providers, connected platforms, and an assigned virtual phone may process data in countries other than yours. Where required, we use lawful transfer mechanisms and appropriate safeguards. Connected platforms determine their own processing locations under their policies.
9. Security
We use access controls, session security, encrypted or hashed authentication material, multi-factor authentication support, signed device communications, limited media retention, audit trails, and operational safeguards designed to protect data. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
You must protect your account, use unique credentials, keep recovery codes secure, close remote sessions after use, and promptly report suspected compromise through the contact form.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data; withdraw consent; or complain to a regulator. The portal’s Security page allows authenticated users to export account data and close their account.
For another privacy request, use the Gutsav contact form, begin the message with “PRIVACY REQUEST,” and state the request and account email. We may verify identity and authority before responding. Legal exceptions may apply.
The service uses an essential, secure session cookie to keep authenticated users signed in. Gutsav does not use advertising cookies on the public website.
11. Children
Gutsav is a professional creator service for adults and is not intended for anyone under 18. We do not knowingly permit minors to create accounts. If we learn that a minor provided personal data, we may close the account and delete the data as required by law.
12. Changes and contact
We may update this Policy to reflect service, security, or legal changes. The effective date above identifies the current version. Material changes will be presented through the service or website when required.
For privacy, security, rights, or legal questions, use the Gutsav contact form and clearly identify the nature of the request. This is the designated electronic contact channel for the service.