Publisher

Reinhardt Press Publisher Privacy Policy

Effective date: September 5, 2026.

Who operates the publisher

The Reinhardt Press maintainers operate Reinhardt Press Publisher to publish their own reviewed articles, videos, and posts. Questions and requests concerning this policy can be sent to press@reinhardt-web.dev. This policy covers the publisher and its article site.

Information accessed and its purpose

The publisher uses Google OAuth authorization and YouTube API Services to identify the connected channel, inspect its publication videos and their metadata and visibility, upload reviewed videos, captions, and thumbnails, and make approved videos public. Its Google permission can also permit deletion and comment operations; the current publishing workflow does not use those operations.

The publisher uses X OAuth authorization to check the connected account, upload reviewed media, publish approved posts, and inspect its own posts for verification and recovery from an interrupted operation. The current workflow does not request access to direct messages or account passwords.

The publisher processes the media, captions, titles, descriptions, post text, article URLs, and publication settings supplied by maintainers. It records content hashes, source revisions, platform identifiers, upload progress, and publication outcomes to support verification, recovery, and duplicate prevention.

Storage and access

Reviewed packages and media are staged in GitHub. GitHub Actions runs the publishing workflow and a repository branch stores publication receipts. Credentials are stored in GitHub environment Secrets and in local Terraform configuration and state used to administer the environment. Administrators with access to those systems can access the credentials or the associated data. Credentials must not be committed to the source repository.

Temporary execution files and platform responses may exist during a workflow run. Operational records may include publication URLs, identifiers, status information, and errors. We do not intentionally print OAuth tokens or API secrets in workflow logs. The repository's visibility and access controls determine who can read its packages and receipts.

The site uses Cloudflare hosting. Hosting requests can disclose IP addresses, requested URLs, browser information, and request timestamps to Cloudflare. The site's own templates do not add analytics scripts or tracking cookies. Following links to external sites subjects those visits to those services' practices.

Sharing and public publication

GitHub processes the staged files, credentials, and execution records needed to run the workflow. Google and YouTube receive the videos, captions, metadata, and credentials needed for YouTube operations. X receives the post text, short videos, and credentials needed for X operations. Cloudflare receives the built article site for hosting. Each service processes data under its own terms and policies.

Approved articles, videos, captions, thumbnails, and posts become public on their respective platforms. Revoking OAuth access does not remove content already published there. Contact us about removal, or use the platform's own content controls if you own the connected account.

We do not sell Google or X user data, use it for advertising profiles, or use it to train generalized AI models. Access is limited to operating and maintaining this publishing workflow, responding to the account owner's requests, and meeting applicable legal requirements. Human access is limited to authorized maintainers performing those tasks.

Reinhardt Press Publisher's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. See also the Google Privacy Policy, X Privacy Policy, GitHub Privacy Statement, and Cloudflare Privacy Policy.

Retention, revocation, and deletion

Credentials are retained while the connected account is configured for publication. Maintainer-supplied publication packages and locally generated publication records are retained to maintain publication history and prevent duplicates. Stored YouTube API data is refreshed or deleted within 30 calendar days; retained credentials are used only while authorization remains valid. Repository history, Terraform state backups, and service logs may contain earlier versions; deleting a current file alone does not erase those copies.

You can revoke the Google connection at Google Account permissions and revoke the X connection through X's connected-app settings. Revocation prevents further authorized API access; it does not by itself erase our stored copies.

Contact press@reinhardt-web.dev to request access to or deletion of data associated with your connected account. For a deletion or withdrawal request, we verify account ownership, stop using the connection, revoke its token when consent is withdrawn through us, and delete associated stored API data as soon as possible and within 7 calendar days of the request, including applicable retained copies. We periodically check Google authorization and remove associated API data within 30 calendar days of revocation through Google. This is an operator-managed process, not an automatic feature of the current workflow. Deleting our stored API data does not delete videos or other data held by YouTube; account owners must use YouTube's controls for that. Public copies already distributed to other people and independent third-party records are subject to their owners' controls and policies.

Changes

We will publish changes on this page and update its effective date. Material changes to the publisher's use of connected-account data will be disclosed before that use changes.