Privacy Policy
What this app is
YT Channel Manager is a private, invitation-only web application used by one family to manage a single YouTube channel that the family owns. There is no public sign-up. It is not a commercial service and does not serve advertising.
Use of YouTube API Services
This app uses YouTube API Services to upload and manage videos, playlists, and related content on the owner's channel. By using the app you are also subject to the YouTube Terms of Service, and Google's handling of data is described in the Google Privacy Policy.
Information the app accesses, stores and uses
- Google authorization. The channel owner connects their Google account once. The app stores the resulting OAuth refresh token encrypted in AWS Secrets Manager. The token is used only by the app's server-side functions to act on that one channel, and it is never sent to a browser or shared.
- YouTube API data. The app reads channel, video, playlist, and (later) comment, caption, and analytics data for the owner's channel, and writes the changes the signed-in user requests, such as uploads, metadata edits, and playlist changes. Copies of API data kept for display are refreshed or deleted within 30 days, as required by the YouTube API Services Developer Policies.
- Uploaded files. Video and thumbnail files that users upload are staged temporarily in a private, encrypted storage bucket and deleted automatically after 7 days.
- App accounts. The app's own users (the channel owner and invited family members) sign in with app accounts managed by Amazon Cognito. The app stores their username, email address, and group membership.
- Audit log. Every change the app makes to the YouTube channel is recorded with who made it, what changed, and when, so the channel owner can review activity.
Sharing
The app does not sell, rent, or share any information with third parties, and does not use it for advertising. Data is processed only by Google (YouTube API Services) and by Amazon Web Services, which hosts the app.
Cookies and local storage
The app does not use advertising or tracking cookies. It stores sign-in session tokens in the browser only to keep users signed in to the app itself.
Revoking access
The channel owner can revoke this app's access to their Google account at any time from the Google security settings page at https://security.google.com/settings/security/permissions. Revocation takes effect immediately. After revocation, data obtained from YouTube API Services is deleted within 30 days.
Deletion requests
Users may ask for their app account and any associated stored data to be deleted by contacting the operator. Requests are completed within 7 days.
Contact
Privacy questions and deletion requests: contact the app operator at the support email address shown on the Google sign-in consent screen for this app.