Paperwork · Legal
Privacy Policy
Last updated 31 August 2026
Paperwork is private podcast-production software built and operated by Cairnworks. This policy explains what information Paperwork handles, where that information goes, and how access to it can be withdrawn.
Paperwork is not currently a public service. It has no sign-up, no accounts for the public, and no visitors. It is used by its operator and by the host of the show it produces. This policy describes what Paperwork does today; if it is ever opened to other producers, this policy will be rewritten before that happens, not stretched to cover it. This policy is written for them, for the people who appear on the show, and for the platform providers whose APIs Paperwork uses.
1. Who is responsible
Cairnworks operates Paperwork and is responsible for the information it holds.
Contact: [email protected]
2. What Paperwork is
Paperwork turns finished podcast recordings into published episodes. It stores episode plans, ingests recorded media, drafts episode copy, renders artwork, and — once a person has approved an episode — publishes it to YouTube and to a website.
It runs on hardware Cairnworks controls. It is reachable only by its operators, behind authentication. There is no public interface.
3. Information Paperwork handles
Operator credentials. API credentials for the services Paperwork publishes to, including a Google OAuth refresh token for the YouTube channel it manages. Credentials are held in the server’s environment configuration, never in the database, and are never displayed in the application.
Episode records. Episode numbers, titles, recording and publication dates, planning notes, and the name of any guest appearing on an episode.
Recorded media. The video, audio and transcript files for each episode. These are stored on Cairnworks-controlled storage and mirrored to encrypted offsite backup.
Generated and edited copy. Draft titles, descriptions, chapter lists, show notes, blog posts and short-form captions, together with the edits the host makes to them.
Publication records. For each episode and destination: the identifier and URL of the published item, its status, when it was published, and the text of any error that occurred.
Operational logs. Records of which background jobs ran, when, and whether they succeeded — kept so that failures can be diagnosed.
Paperwork does not collect information from members of the public. It has no analytics, no cookies for visitors, no tracking pixels, and no contact forms.
4. People who appear on the show
Podcast episodes contain the voices and words of the host and of guests who have agreed to be recorded. Those recordings, and the transcripts made from them, are stored by Paperwork as part of producing the episode, and portions of them appear in published episodes and show notes.
Guests consent to being recorded and published as part of agreeing to appear. If you have appeared on an episode and want to discuss the material, contact us at the address above.
Paperwork is used to produce a show that discusses health topics in general, educational terms. It does not collect health information about listeners, and it holds no patient records of any kind.
5. Google user data and YouTube API Services
Paperwork uses YouTube API Services.
By authorizing Paperwork to act on a YouTube channel, the channel owner agrees to be bound by the YouTube Terms of Service.
Google’s own handling of information is described in the Google Privacy Policy.
The disclosures below describe how Paperwork accesses, uses, stores and shares Google user data.
What Google user data Paperwork accesses
Acting only on the single YouTube channel whose owner has authorized it, Paperwork accesses:
- the channel’s identity, to confirm which channel the authorization applies to
- the videos Paperwork itself has uploaded to that channel — their identifiers, titles, descriptions, chapter markers, caption tracks, thumbnails, privacy status and scheduled publication time
It accesses no other Google user data. It does not read viewer data, comments, subscriber lists, analytics, watch history, contacts, email, files, or the content of any other channel or account.
How Paperwork uses Google user data
Solely to publish episodes of the podcast it produces, on behalf of the channel owner, and only after a person has approved that episode. Specifically, it uploads a video file, attaches a caption track, sets a thumbnail, sets the title, description and chapter markers, sets a scheduled publication time, and reads the publication status of videos it has uploaded so that it can record when an episode went live.
Paperwork does not use Google user data to build profiles, to train machine learning models, for advertising, or for any purpose other than publishing the episode the data belongs to.
With whom Paperwork shares, transfers or discloses Google user data
No one. Google user data is not sold, shared, transferred or disclosed to any third party, and is not used by any third party for any purpose. It is not sent to the other services listed in §6 — those receive episode material such as transcripts and written copy, not data obtained from Google.
How Paperwork protects Google user data
The credential authorizing access is a Google OAuth refresh token, held in the server’s environment configuration on hardware Cairnworks controls. It is never written to the database, never displayed in the application, and never transmitted to any third party. The application itself is reachable only by its operators, behind authentication.
How long Paperwork retains Google user data, and how it is deleted
Paperwork stores the minimum needed to publish and to avoid publishing twice: for each published episode, the YouTube video identifier, the video’s URL, its publication status and time, and the text of any error returned while publishing. It stores no copies of video content, captions or thumbnails retrieved from YouTube.
These records are retained for as long as the episode remains published, so that an episode can be corrected, updated or archived rather than duplicated.
Deletion. Anyone may request deletion of the stored records for their channel by contacting the address in §1, and they will be deleted. Revoking Paperwork’s access, as described below, immediately ends all further access to Google user data; stored publication records are retained after revocation only as a record of what was published, and are deleted on request.
Revoking Paperwork’s access
Access granted to Paperwork can be revoked at any time through the Google security settings page at https://myaccount.google.com/permissions. Revoking access immediately and permanently ends Paperwork’s ability to act on the channel or to access any Google user data.
6. Other services Paperwork sends information to
Anthropic. Episode transcripts are sent to the Anthropic API to draft episode copy. Anthropic processes them under its own terms and does not use this data to train its models.
WordPress. The written version of an episode is filed to a WordPress site operated by the show, as an unpublished draft, using credentials scoped to that site.
Backblaze B2. Archived episode media is mirrored to encrypted offsite storage. The credentials used cannot delete existing files.
Cloudflare. Access to the application is protected by Cloudflare, which handles authentication for the operators.
Paperwork sends information to no other third party, and to no advertising, analytics or data-broker service of any kind.
7. Where information is stored and for how long
Episode records, generated copy and publication records are stored in a private database on Cairnworks-controlled hardware. Media files are stored on Cairnworks-controlled storage and mirrored to encrypted offsite backup.
Episode material is retained for as long as the episode remains published, so that it can be corrected, re-published or archived. Operational logs are retained for diagnosis. Nothing is retained for advertising or profiling, since neither occurs.
8. Security
Access to the application requires authentication and is limited to its operators. Credentials are held in server environment configuration rather than in the database, and are never shown in the interface. Offsite backup credentials are scoped so that they cannot delete existing archives. Media and database storage are on hardware under Cairnworks’ physical control.
No system is perfectly secure, and this one is small and privately operated rather than independently audited. It is described here accurately so that anyone relying on it can judge it for themselves.
9. Children
Paperwork is not directed to children, has no public users, and knowingly collects no information from anyone under 13.
10. Changes to this policy
If this policy changes, the revised version will be posted here with an updated date. Material changes affecting how information is handled will be reflected in the description above rather than added as an exception.
11. Contact
Questions about this policy, or requests concerning material held about you: