Privacy Policy

Statton Flow · Last updated 19 September 2026

Statton Flow is a one-person automation business owned and operated by Issa Fard in Calgary, Alberta, Canada. This policy explains what information we handle, why, who it goes to, and how long it is kept. It covers this website, the Statton Flow client portal, and the automations we build and run for clients — including the Google-connected application named Statton Daud Engine.

We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA).

Questions, requests, or complaints: issa@stattonflow.com. Issa Fard is the person accountable for personal information at Statton Flow.

1. Statton Daud Engine — the Google-connected app

Statton Daud Engine is a private automation. It is not a public product and there is no sign-up. It is used by Statton Flow and by clients who have explicitly connected their own Google account to it, so that short videos can be posted to that client's own YouTube channel on their behalf.

Google API Services User Data Policy

Statton Flow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What Google data the app accesses, and why

Statton Daud Engine requests YouTube permissions only. Every scope it asks for is listed here:

ScopeWhat we do with it
openid
userinfo.email
userinfo.profile
Identify which Google account has been connected, so the automation posts to the right channel and you can see which account is linked.
youtube.upload Upload video files to the connected channel.
youtube Set each video's title, description, tags and privacy status, and manage the videos the app has uploaded.
youtube.force-ssl Post a comment on videos that the app itself has uploaded. Nothing else on the channel is commented on or modified.
yt-analytics.readonly Read view counts and audience retention for the connected channel, in order to produce the client's performance reports. Read only — nothing is written back.

This app requests no other Google permissions. It does not request access to your Gmail, contacts, calendar, photos, Google Drive or Google Sheets. It does not access any Google account other than the one you have connected to it.

Google Drive and Google Sheets — a separate connection, not this app

The automation does read video files from Drive folders you share with it, and does read and write a Google Sheet. That access does not come through Statton Daud Engine. It comes through Make.com's own Google connection, which you authorise separately and which appears as Make — not as Statton Daud Engine — in your Google account's connected apps.

Make's Google connection holds https://www.googleapis.com/auth/drive and https://www.googleapis.com/auth/drive.readonly. Those are Make's application and Make's permissions, granted by you to Make, and governed by Make's privacy notice. We use that connection to run your automation; we do not hold those permissions ourselves.

What we do through it is limited to the same two things described above: reading video files from the folders you have shared, and reading your configuration and writing the posting record in your Sheet. You can revoke Make's access at the same Google permissions page described below. Doing so stops the Drive and Sheets steps of your automation.

Who the data is shared with

The app runs through a small number of service providers. Each one receives only what it needs to do its part:

ProviderWhat it receivesWhy
Make.comThe video file, its metadata, and the configuration and performance data read from the client's SheetMake.com is the automation platform the app is built on. Every step passes through it, and Make's own Google connection is what reaches Drive and Sheets.
Google Gemini APIThe video contentTo generate a suggested title and description for the video, through Make's built-in Gemini module. See "How the video content is used by Google" below, which you should read before connecting a channel.
TwilioA short notification message, which may include the video's title and linkTo send an SMS telling us and the client that a video has posted, or that something failed.

We do not sell Google user data. We do not use it for advertising, and we do not transfer it to advertising platforms, data brokers or information resellers.

Statton Flow does not use Google user data to build, train or improve any AI or machine learning model of our own.

No person at Statton Flow reads a client's Google data except when the client asks us to, or where we are required to by law. In practice this means looking at a specific file or row when a client reports a problem with it.

How the video content is used by Google

This section matters, and we would rather state it plainly than bury it.

To write a suggested title and description, the automation sends the video content to Google's Gemini API, through Make's built-in Gemini module.

How Google may use that content depends on which Gemini API terms our key falls under. We have not confirmed that our key is on Google's paid terms, so you should assume the terms for unpaid services apply. Under Google's Gemini API Additional Terms of Service for unpaid services, Google states that:

In plain terms: the video content sent to Gemini may be used by Google to improve Google's own products, and may be read by Google's reviewers. That is Google's processing under Google's terms, not ours — but it happens because our automation sends the content there, so you should know before you connect a channel. If that changes, this page changes with it.

If you are a client and you do not want your video content processed this way, tell us at issa@stattonflow.com. We can run your automation without the title-and-description step, or generate it from a short topic you write yourself instead of from the video.

Nothing else in the automation works this way. Your YouTube analytics, your Drive file list and your Sheet contents are not sent to Gemini.

How long it is kept

How to revoke access

A client can disconnect the app from their Google account at any time, without asking us, at myaccount.google.com/permissions. Revoking access stops the automation immediately. Their files and their Sheet stay exactly where they are — they belong to the client, not to us.

2. This website and the client portal

The audit form on this site

If you fill in the audit or contact form, we collect what you type into it — typically your name, email, phone number, business type, and what you tell us about your situation. We use it to reply to you and to prepare the audit you asked for. It is not sold and not shared with anyone outside the providers listed in this policy.

The client portal

Portal logins are created by Statton Flow. There is no self-registration. When a client signs in, we store their email address, the client account their login belongs to, and the score and comment they submit if they choose to rate our work. The portal shows each client only their own information.

Ordinary web data

Our hosting provider records standard server information such as IP address, browser type and the pages requested. This is generated automatically by the server and is used for security and to keep the site running.

3. Your rights

Under PIPEDA and Alberta's PIPA you can:

Requesting deletion

Email issa@stattonflow.com with what you want deleted. We will confirm and action it within 30 days. For Google data, most of it is in the client's own Drive and Sheet and can be deleted by them directly and immediately; what we can delete on our side is the Make.com run history and any stored access tokens, and we will do so on request.

4. Where data is stored

Statton Flow is based in Canada, but the providers above store and process data outside Canada, including in the United States and the European Union. Information held in another country can be accessed by the courts and law enforcement of that country. By using our services you are aware that your information may be processed outside Canada.

5. Security

We keep access to client systems limited to the people who need it, use the providers named above rather than building our own storage, and connect to every service over an encrypted connection as those services provide. We make no claim beyond that: Statton Flow is a one-person business and holds no security certification.

6. Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under 18.

7. Changes to this policy

If this policy changes, the "last updated" date above changes with it. If a change materially affects how we handle a client's data, we tell that client directly rather than relying on them to re-read this page.

8. Contact

Issa Fard — Statton Flow
Calgary, Alberta, Canada
issa@stattonflow.com

Terms of Use · Statton Flow