Statton Flow is a one-person automation business owned and operated by Issa Fard in Calgary, Alberta, Canada. This policy explains what information we handle, why, who it goes to, and how long it is kept. It covers this website, the Statton Flow client portal, and the automations we build and run for clients — including the Google-connected application named Statton Daud Engine.
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA).
Questions, requests, or complaints: issa@stattonflow.com. Issa Fard is the person accountable for personal information at Statton Flow.
Statton Daud Engine is a private automation. It is not a public product and there is no sign-up. It is used by Statton Flow and by clients who have explicitly connected their own Google account to it, so that short videos can be posted to that client's own YouTube channel on their behalf.
Statton Flow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Statton Daud Engine requests YouTube permissions only. Every scope it asks for is listed here:
| Scope | What we do with it |
|---|---|
openiduserinfo.emailuserinfo.profile |
Identify which Google account has been connected, so the automation posts to the right channel and you can see which account is linked. |
youtube.upload |
Upload video files to the connected channel. |
youtube |
Set each video's title, description, tags and privacy status, and manage the videos the app has uploaded. |
youtube.force-ssl |
Post a comment on videos that the app itself has uploaded. Nothing else on the channel is commented on or modified. |
yt-analytics.readonly |
Read view counts and audience retention for the connected channel, in order to produce the client's performance reports. Read only — nothing is written back. |
This app requests no other Google permissions. It does not request access to your Gmail, contacts, calendar, photos, Google Drive or Google Sheets. It does not access any Google account other than the one you have connected to it.
The automation does read video files from Drive folders you share with it, and does read and write a Google Sheet. That access does not come through Statton Daud Engine. It comes through Make.com's own Google connection, which you authorise separately and which appears as Make — not as Statton Daud Engine — in your Google account's connected apps.
Make's Google connection holds https://www.googleapis.com/auth/drive and https://www.googleapis.com/auth/drive.readonly. Those are Make's application and Make's permissions, granted by you to Make, and governed by Make's privacy notice. We use that connection to run your automation; we do not hold those permissions ourselves.
What we do through it is limited to the same two things described above: reading video files from the folders you have shared, and reading your configuration and writing the posting record in your Sheet. You can revoke Make's access at the same Google permissions page described below. Doing so stops the Drive and Sheets steps of your automation.
The app runs through a small number of service providers. Each one receives only what it needs to do its part:
| Provider | What it receives | Why |
|---|---|---|
| Make.com | The video file, its metadata, and the configuration and performance data read from the client's Sheet | Make.com is the automation platform the app is built on. Every step passes through it, and Make's own Google connection is what reaches Drive and Sheets. |
| Google Gemini API | The video content | To generate a suggested title and description for the video, through Make's built-in Gemini module. See "How the video content is used by Google" below, which you should read before connecting a channel. |
| Twilio | A short notification message, which may include the video's title and link | To send an SMS telling us and the client that a video has posted, or that something failed. |
We do not sell Google user data. We do not use it for advertising, and we do not transfer it to advertising platforms, data brokers or information resellers.
Statton Flow does not use Google user data to build, train or improve any AI or machine learning model of our own.
No person at Statton Flow reads a client's Google data except when the client asks us to, or where we are required to by law. In practice this means looking at a specific file or row when a client reports a problem with it.
This section matters, and we would rather state it plainly than bury it.
To write a suggested title and description, the automation sends the video content to Google's Gemini API, through Make's built-in Gemini module.
How Google may use that content depends on which Gemini API terms our key falls under. We have not confirmed that our key is on Google's paid terms, so you should assume the terms for unpaid services apply. Under Google's Gemini API Additional Terms of Service for unpaid services, Google states that:
In plain terms: the video content sent to Gemini may be used by Google to improve Google's own products, and may be read by Google's reviewers. That is Google's processing under Google's terms, not ours — but it happens because our automation sends the content there, so you should know before you connect a channel. If that changes, this page changes with it.
If you are a client and you do not want your video content processed this way, tell us at issa@stattonflow.com. We can run your automation without the title-and-description step, or generate it from a short topic you write yourself instead of from the video.
Nothing else in the automation works this way. Your YouTube analytics, your Drive file list and your Sheet contents are not sent to Gemini.
A client can disconnect the app from their Google account at any time, without asking us, at myaccount.google.com/permissions. Revoking access stops the automation immediately. Their files and their Sheet stay exactly where they are — they belong to the client, not to us.
If you fill in the audit or contact form, we collect what you type into it — typically your name, email, phone number, business type, and what you tell us about your situation. We use it to reply to you and to prepare the audit you asked for. It is not sold and not shared with anyone outside the providers listed in this policy.
Portal logins are created by Statton Flow. There is no self-registration. When a client signs in, we store their email address, the client account their login belongs to, and the score and comment they submit if they choose to rate our work. The portal shows each client only their own information.
Our hosting provider records standard server information such as IP address, browser type and the pages requested. This is generated automatically by the server and is used for security and to keep the site running.
Under PIPEDA and Alberta's PIPA you can:
Email issa@stattonflow.com with what you want deleted. We will confirm and action it within 30 days. For Google data, most of it is in the client's own Drive and Sheet and can be deleted by them directly and immediately; what we can delete on our side is the Make.com run history and any stored access tokens, and we will do so on request.
Statton Flow is based in Canada, but the providers above store and process data outside Canada, including in the United States and the European Union. Information held in another country can be accessed by the courts and law enforcement of that country. By using our services you are aware that your information may be processed outside Canada.
We keep access to client systems limited to the people who need it, use the providers named above rather than building our own storage, and connect to every service over an encrypted connection as those services provide. We make no claim beyond that: Statton Flow is a one-person business and holds no security certification.
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under 18.
If this policy changes, the "last updated" date above changes with it. If a change materially affects how we handle a client's data, we tell that client directly rather than relying on them to re-read this page.
Issa Fard — Statton Flow
Calgary, Alberta, Canada
issa@stattonflow.com