Transparency

Trust center

Where Mecra keeps your data, which permissions it asks for and why, how to verify the file you downloaded, and the work we have not finished yet: all on one page.

Giving a desktop app access to your channel takes trust. On this page we write down what we keep, where, for how long, and what we have not done yet. The legal texts (Privacy Policy, Terms of Use, Cookie Policy) are authoritative; this page is a readable summary of them.

At a glance

WhatWhereFor how long
Your API keys (Gemini, Pexels)On your computer, in a local configuration fileUntil you delete them
Channel data, topic bank, produced videosOn your computerUntil you delete them
YouTube connection tokenOn your computer, in a local fileUntil you revoke access
License check: device hash, license key, version, IPOn our license serverMasked IP digest 30 days; event logs 90 days; device hash and trial counter indefinitely to prevent abuse
Your order keyOn our license server, encrypted365 days
“AI Included”: monthly usage (token) countOn our license serverFor the lifetime of the license record
“AI Included”: content of the text-generation request and replyNot stored; relayed to Gemini0 days on our server
Your visit to our websiteNo analytics, tracking cookies or third-party scriptsn/a

Your data stays on your computer

Mecra is a desktop app: your API keys, channel settings, topic bank and produced videos are kept in files on your own computer and are not sent to our servers. Those files live in your user folder; we recommend protecting your computer with disk encryption (such as BitLocker) and a strong Windows password. We are evaluating storing tokens with an additional layer of encryption.

What does the license server receive?

To verify your license the app sends our server: a device ID (a non-reversible digest derived from hardware), your license key, the app version and the IP address of the request. This is used only to check the license period, device limit and trial allowance. The IP address itself is never stored; only a keyed digest and a masked view are kept for abuse prevention. License documents are digitally signed, and the app verifies the signature locally.

License keys are masked in server logs; detailed retention periods are in the table above and in the Privacy Policy.

AI requests on “AI Included” plans

On “AI Included” plans you don't enter your own Gemini key; your text-generation request goes from the app to our server and is relayed with our key to Google Gemini (with a free OpenRouter model as a fallback). While this happens:

  • The request and reply are processed in memory; they are not stored and not written to logs.
  • Only the monthly usage (token) count per license is recorded, and a monthly cap applies.
  • The content is subject to the privacy policy of the provider (Google, OpenRouter).

If you don't want this relay at all, choose a “Bring your own keys” plan; requests then go straight from your computer to Google.

Google (YouTube) permissions

Mecra connects to YouTube with only three permissions, each with a clear purpose:

PermissionWhat for
youtube.uploadUploading the video, with its title, description and thumbnail, to your channel
youtube.force-sslManaging the uploaded video (privacy or scheduling fixes, playlists, comment and caption operations)
yt-analytics.readonlyRead-only access to your channel statistics (views, subscribers, watch time)

You can revoke access at any time on your Google account permissions page; after that Mecra cannot reach your channel.

A note on transparency: because Mecra's Google OAuth verification is not complete yet, Google may show a “Google hasn't verified this app” warning while you connect. This is a verification status notice, not a vulnerability; when verification completes the warning will disappear and we will update this page. Steps: install guide.

Verify your download

Only download the installer from this site. The SHA-256 hash of version 2.1.1 (137 MB) is:

22ba8028da4e5ede1604287cf88fb6f79ecad6c3774dbb5af727e95d301c4139

On Windows, open PowerShell in the folder where you saved the file and run:

Get-FileHash .\Mecra-Kurulum.exe -Algorithm SHA256

The value must match the one above exactly. If it doesn't, don't run the file and email us.

Windows and antivirus warnings: the installer is not yet signed with a code-signing certificate, so SmartScreen may show an “unrecognized publisher” warning, and because Node.js and ffmpeg are bundled some antivirus programs may flag the file. If the hash matches, it is the file we published. Steps: install guide.

Payment security

Your card details never reach us. Payments are taken through the payment provider that acts as the merchant of record (Lemon Squeezy) or directly by bank transfer; for transfers only the reference code in the description and the receipt details are used to match the payment. Cancellation and refund terms are on the Refunds page.

Our website

mecrastudio.com is static: it uses no analytics, tracking cookies or third-party scripts, and fonts are served from our own server. On the My account page your session is kept in the browser's session storage (sessionStorage), not in a cookie, and is deleted when you close the tab. Details: Cookie Policy.

Your rights

Under applicable data-protection law (in Turkey, KVKK) you can ask what data we hold, have it corrected and have it deleted. To delete your records on our license server write to destek@mecrastudio.com.

What we haven't done yet (open list)

Trust starts with not hiding the gaps. What is not finished today:

  • Google OAuth verification: in progress; until then you may see an “unverified app” warning.
  • Code signing: the installer is not signed yet; SHA-256 verification bridges the gap for now.
  • Instagram and TikTok: these two connections are beta; restrictions apply because the platforms' app approvals are not complete.
  • Independent security audit: not done yet.
  • Extra encryption of local tokens: under evaluation; today they are plain files in your user folder.
  • Card payments: coming soon; bank transfer is open today.

Reporting a vulnerability

If you notice a security problem, write to destek@mecrastudio.com with the subject “Security” and include details and steps to reproduce. We take reports seriously and reply as soon as we can. Please tell us before disclosing the issue publicly. Our contact details are also available in machine-readable form in security.txt.

Frequently asked questions

Does Mecra ask for my password?

No. The YouTube connection works through Google's OAuth permission screen; Mecra never sees your Google password. The same principle applies to Instagram and TikTok.

Does my data leave my computer?

Your API keys, channel data and produced videos stay on your computer. For license checks our server receives a hashed device ID, your license key and the app version. On “AI Included” plans your text-generation request is additionally relayed through our server to Gemini; the content is not stored, only a usage count is.

How do I verify the installer really came from you?

Download it only from this site and compare its SHA-256 hash with the value on this page (the command is below). If the values differ, do not run the file and contact us.

Why does Windows show a warning?

Because Mecra is a new app and the installer is not yet signed with a code-signing certificate, Windows SmartScreen may show an “unrecognized publisher” warning. The install guide explains the steps; code signing is on our list.

How do I report a security issue?

Email destek@mecrastudio.com with the subject “Security”. We take reports seriously, reply as soon as possible and, with your permission, credit you once a fix ships. Please tell us before disclosing an issue publicly.