Privacy Policy
Introduction
At YouTube AI Chat, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your personal information when you use our service.
Supported Creator Channel assistance
Supported Creator Channel assistance is a private Channel Hub for an adult Channel Steward who connects one public, account-owned YouTube Channel. It assesses observable interaction behavior, not people. Written YouTube clearance, Google OAuth verification, and the complete launch packet are required before real YouTube API Data is processed; this repository does not claim those external gates, live channels, creator consent, OAuth credentials, or production evidence.
Channel access and OAuth permissions
The connection is incremental and account-owned. The initial read permission is youtube.readonly and is used to verify the provider-returned public Channel identity. It does not permit publishing, editing, deleting, moderation, or access to held-for-review or likely-spam comments.
The broader youtube.force-ssl permission is requested only when the Steward first chooses a write action. Connecting a Channel, scanning, requesting a draft, or publishing a previous reply never implies consent for a later write.
- The read path is limited to published public comments and bounded same-thread context.
- A zero or ambiguous provider identity, missing authenticated account, invalid state, or unexpected scope blocks connection; a locally selected Channel cannot replace provider identity evidence.
Comment assessment and model-provider processing
A scan may create a private interaction assessment for the connected Channel Steward. Assessment and drafting are separate, structured server-side calls. The browser does not call the model provider, and a model cannot publish, dismiss, enforce, or select a Channel identity.
Only the minimum bounded context needed for the requested assessment or draft is sent through a disclosed provider under applicable no-training and data-processing terms. The provider name, endpoint, model, and current terms must be disclosed before real Channel data is processed; this repository does not invent or certify a provider contract.
- The bounded request can contain the current comment, distinct top-level comment, same-thread replies, Video title, thread relationship, supported-language indicator, and anonymous role markers.
- Author names, avatars, author Channel IDs, connected Channel IDs, Video/comment/reply IDs, OAuth tokens, API keys, account identity, cross-Video author history, and engagement history are not sent to the provider.
- Potential addresses, phone numbers, email addresses, schools, identity documents, and similar sensitive Safety Flag evidence are masked and excluded by default.
Private AI drafts and final review
An AI-generated Reply Draft is private assistance. It is editable, is never public merely because it was generated, and is available only after the Steward confirms a non-severe Actionable Abuse assessment and separately requests a draft.
Publication always requires per-item final review and deliberate confirmation of the exact final text. The product does not autonomously, silently, or in bulk publish replies, and the final text must pass the product validators before the one external write attempt.
- Safety Flags and Allowed Criticism never receive a reply draft; Reviewable Interaction requires a human decision before it can become draft-eligible.
- The product does not edit a published reply in-app. External edits remain on YouTube.
Retention, refresh, and deletion
YouTube API Data used for Channel assistance is kept only for the bounded review lifecycle and no longer than 30 calendar days. Retained comment or reply text is refreshed or deleted within that window; a changed source creates a new assessment, and a deleted source removes local review text.
Allowed Criticism raw text is not retained or shown in the Review Queue. Drafts, corrections, private review decisions, and audit provenance are also bounded by the same policy window. Durable analytics contain only non-identifying aggregates; logs do not contain comment text, draft text, author identity, or sensitive evidence.
- Active reply-control provenance survives only while needed and while it is refreshed within each 30-day window.
- A public reply on YouTube remains public until the Steward separately deletes it; local retention expiry never silently deletes a public reply.
Revocation, disconnect, and account deletion
A registered owner can disconnect the Channel and revoke authorization regardless of subscription tier. New scans, drafts, and writes stop immediately when entitlement, identity, or grant state is unavailable. Local deletion starts even if Google's revocation endpoint is temporarily unavailable; the work remains visible and retryable and is not reported complete before the known provider and local outcomes are verified.
Disconnect and account deletion remove tokens, Channel data, review text, drafts, and reply-control provenance under the applicable cleanup deadline. Once authorization or provenance is removed, product-assisted deletion cannot be promised without retaining data that should be deleted.
- The Steward may use Google's account permissions page to review or revoke the grant when the provider surface is needed.
- A failed provider operation never becomes an unverified success and never authorizes a retry that could duplicate a reply.
Downgrade grace and the YouTube fallback
After paid access ends, new scans, assessments, drafts, and publications stop immediately. Existing Channel data remains available for export, local deletion, product-assisted public-reply deletion, or resubscription during a seven-day read-only grace period. At grace-period expiry, the grant is revoked and local Channel data is deleted.
In-app public-reply deletion is available only while the original grant and refreshed provenance remain available, including during the grace period. After the grant or provenance is removed, the Steward must use YouTube's native tools, such as YouTube Studio, to delete a remaining public reply; YouTubeAI does not retain data to preserve an in-app deletion promise.
- Changing the Active Connected Channel never transfers work or makes another Channel's draft publishable.
- There is no scheduled monitoring, bulk publication, or background reply action in this flow.
Information We Collect
- Account information (email address when you sign up)
- Usage data (how you interact with our service)
- YouTube video URLs you submit for summarization
- Generated summaries and analysis
- Technical information (IP address, browser type, device information)
How We Use Your Information
- To provide and improve our video summarization service
- To personalize your experience
- To communicate with you about your account or our service
- To analyze usage patterns and improve our website
- To protect our legal rights and comply with applicable laws
Data Storage and Security
We implement appropriate technical and organizational measures to protect your personal information. However, no method of transmission over the Internet or electronic storage is 100% secure.
Third-Party Services
We use third-party services for:
- Authentication (Supabase)
- Analytics (Google Analytics)
- Video data (YouTube API Services)
Each of these services has their own privacy policies and handling practices.
Your Rights
You have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your information
- Object to processing of your information
- Withdraw consent
Contact Us
If you have any questions about this Privacy Policy, please contact us at privacy@youtubeai.chat.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “last updated” date.