Privacy Policy
We collect very little, and this page says exactly what and why. It is short because the service is built to need little data.
What we collect
Very little, and the free tier does not require an account. We keep the replay file you submit, so your video can be re-produced if a delivery is lost or needs to be re-rendered. Alongside it we keep the minimum needed to run and support the render: your Discord user ID, so we can deliver your link and count your free renders; basic details of the request itself, such as the file name, its size, the time you sent it, and a fingerprint of the file used to recognize a re-upload of the same file; and a record of when you have rendered, so the weekly free limit can be applied. The temporary files created while a render runs are discarded once your video is delivered.
Delivered videos are uploaded to YouTube using YouTube API Services on
our own channel, public by default; the upload form has a box you can uncheck
to get an unlisted link instead, and either way we do not notify YouTube subscribers of the
upload. Free delivery to our own
channel never touches your Google account. If you have connected your own YouTube
channel and are in the group it is open to, your renders land there instead. See the section
below. That
upload is governed by the YouTube Terms of Service
and the Google Privacy Policy. If we ever hold
access to a Google account of yours, you can revoke it at any time from the
Google security settings page. Your finished
video is posted in our Discord. You are mentioned in the replay channel. For videos on our own
channel, the video, your in-game name, and your battle result are also added to our browsable
replay archive there, visible to members of the server. Each week we may feature that week’s
top-scoring renders that are public on our own channel
and credit the player in our Discord; by default your render is public and eligible for this,
but unchecking the public box when you submit (or sending /replay privacy:unlisted)
keeps it out of the showcase and off the videos we might feature, and you can always ask us to
switch a public video back to unlisted. Paid bundles are
not live yet. Only the free tier is. When paid checkout opens, this page will name the payment
processor before any card details are collected, and we will never see or store your card or
billing data ourselves.
You can ask us to delete the replay file and the other records we hold about you at any time. See “Deletion requests” below.
Cookies and tracking
We do not use tracking cookies or analytics scripts on this site. Because there is nothing to opt in or out of, there is no cookie banner.
Connecting your own YouTube channel
You can connect your own YouTube channel so a rendered replay is uploaded there instead of to ours. This is available to a small test group today, and we will open it more widely later.
What we access. When you connect your channel, we ask Google for one permission: the ability to upload a video to your YouTube channel. We do not receive your email address, your name, your profile, or a list of your channels, and connecting makes no request to read anything from your account. After we upload a video for you, YouTube’s response tells us the id of that video, from which we build its link, and the id and title of the channel it landed on. We store the channel id and channel title on your connection record, and the video URL, channel id and channel title on the record of that render. The connection record also holds when you connected, when it was last used, the permission granted, and whether it has been revoked.
How we use it. Only to upload your own rendered replay to your own connected channel, and to report the resulting video link back to you. Your video is uploaded with the visibility you choose, public by default, with our standard title and description plus a one-line credit naming WoT Replay 4K. We do not create a playlist on your channel. We only set that visibility once, when the video is uploaded, and can never change it afterward, because the permission you grant only allows uploading, not editing videos already there. We never include it in the weekly showcase, and we do not add it to our Discord replay archive. We do not use your data for anything else: no other use, no sale of your data, no ad targeting, and no human at WoT Replay 4K reads it beyond support you ask us for and consent to.
How long we keep it. Your connection record, including the encrypted refresh token, is kept until you disconnect the channel. If Google refuses the token, or we cannot reach Google when you disconnect, the record is marked revoked and no longer used, but the encrypted token stays on it until you ask us to delete your data. The channel id, channel title and video URL stored on a render record are kept with that render’s record until you ask us to delete your data, as described under “Deletion requests” below.
How to revoke access. Use the Disconnect button in Discord, or ask us. We revoke the refresh token at Google and delete our stored copy. If Google cannot be reached, we disable the connection on our side and stop uploading to your channel, and you can also remove our app’s access directly at myaccount.google.com/permissions. If Google refuses the token when we try to upload, we mark the connection revoked, stop using it, upload that video to our own channel with the visibility you chose instead, and tell you in the delivery post with a hint to reconnect.
Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who we share Google user data with
We share, transfer or disclose the Google user data described above only to the recipients listed here, and only to carry out the upload you asked for. Google and YouTube receive it to perform the upload itself. Amazon Web Services, our infrastructure provider, hosts the storage, the encryption keys, the compute and the operational logs, and if Google refuses your token that event is recorded in those logs together with your channel id. Our own render machine performs the upload. Discord, and the members of our Discord server who can see the channel your delivery is posted in, see your channel title and the video link, because the finished-render post mentions you and reads “Your 4K replay is ready on your channel <channel title>: <video link>”. Nobody else receives it.
We do not transfer or disclose your Google user data to third parties for purposes other than the ones described above. We do not sell it, and we do not give or sell it to data brokers or resellers. We do not use it for advertising, ad targeting or personalized ads, and we do not use it in credit-worthiness or lending decisions. We do not use it to train generalized artificial intelligence or machine learning models. No human at WoT Replay 4K reads it except for support you ask us for.
How we protect Google user data
Your connection record is stored in an AWS DynamoDB table in the AWS region us-west-2 (Oregon, USA). The refresh token is stored only as ciphertext, encrypted with a customer-managed AWS KMS key. The ciphertext is bound to your own member id, and that binding is asserted again when it is decrypted, so a token encrypted for you can never be decrypted as another member’s. The plaintext token is never written to disk, never written to a log, and never returned in any web response.
The token is decrypted in exactly two places. Our render machine decrypts it when it uploads your finished video to your channel, under an AWS identity whose permission to decrypt is fenced to that purpose alone. Our AWS Lambda function decrypts it when you click Disconnect, so the token can be revoked at Google. Traffic to Google, and traffic between our own components, runs over HTTPS/TLS. The connect flow uses a signed, single-use state token that expires after ten minutes, so a callback link cannot be replayed. Only the operator of the business has administrative access to the AWS account and to the render machine.
Your replay file is not Google user data. It is stored in Amazon S3 with server-side AES-256 encryption and all public access blocked, and it is kept until you ask us to delete it.
Deletion requests
To request deletion of any data we hold about you, contact us at contact@wotreplay4k.com. For a delivered render, this includes taking the video down from our YouTube channel, removing it from your playlist entry there, and deleting our stored link to it. If you have connected your own YouTube channel (see above), disconnecting revokes the refresh token at Google and deletes our stored copy. If Google cannot be reached, the encrypted copy is disabled and stays until you ask us to delete it.