Our Commitment to Transparency
YouTool.io is a creator-supported YouTube tool built to be useful without being mysterious about data. This page explains, in plain English, what YouTube information is accessed, why it is accessed, how it is processed, what may be stored, and how you can revoke access.
Key Principle: We collect the minimum data necessary to provide our service and never sell your personal information to third parties.
Data Collection Overview
What We Collect
| Data Type | Source | Purpose | Retention |
|---|
| YouTube URLs/IDs | User Input | Tool Functionality | Processed for requested tools; some history may be stored locally in your browser |
| Search Queries | User Input | Service Provision | Local Storage Only |
| Usage Analytics | Automatic Collection | Service Improvement | Aggregated Only |
| Device Information | Browser | Compatibility | Anonymous |
| Public YouTube Data | YouTube API | Analysis | Returned for requested analyses; not used to build a permanent analytics-history database |
| Account Profile | Google Sign-In / Supabase | Account and Extension Authentication | While account is active or until deletion is requested |
| Extension Session Records | Chrome Extension / Supabase | Keep the extension linked to your account | Until revoked, expired, or no longer needed |
| Connected Channel Records | Google OAuth / YouTube APIs | Connected-channel stats and creator tools | Until you disconnect your YouTube channel or request deletion |
| Extension Settings and Cache | Chrome Storage | Remember settings and load stats faster | Local to your browser until cleared or extension is removed |
What We Don't Collect
- YouTube Passwords: We never ask for or collect your YouTube password
- Payment Details: We do not store credit card or banking details on YouTool.io servers. If support contributions or payments are processed through a third-party provider in the future, that provider handles payment details directly
- Unrequested Private Content: Public website tools analyze public YouTube data. Connected-channel features can access read-only analytics for your own channel only after you authorize that access through Google
- Connected-Channel Comment Text: The account dashboard does not store comment text or reply snapshots as connected-channel private analytics history
- Personal Communications: No emails, messages, or private data
- Credit Decisions: We do not use data to determine creditworthiness or for lending purposes
- Location Tracking: No precise geolocation data
Data Flow Process
How Your Data Moves Through Our System
1
Input: You provide a YouTube URL/search query, or the extension reads the current YouTube page when you use an enabled feature
2
Processing: We extract the video/channel ID and validate the input
3
API Request: We query YouTube's public API for public content or, for connected-channel features, use your read-only authorization to request your channel analytics
4
Analysis: Our tools process the requested public data or authorized connected-channel data to generate insights
5
Display: Results are shown to you in real-time
6
Storage: Public tool inputs are generally handled for the requested result. Account profiles, extension session records, YouTube connection records, connected-channel analytics history, local preferences, and local extension stats cache may be stored as described in this disclosure.
Account and Extension Data
Some newer YouTool.io features are account-based and use server-side infrastructure. These features are optional, but they require account and connection records to function.
- Google Sign-In: Supabase authentication receives basic Google profile information such as your name, email address, avatar, and account identifier
- Profiles: We store basic account profile fields so your account page and extension connection can identify your account
- Extension Sessions: We store hashed extension tokens, expiration dates, revocation status, extension ID, user agent, and last-used timestamps so the extension can stay linked without asking you to sign in every time
- Chrome Storage: The extension stores feature toggles, theme settings, selected stats range, authentication state, and a once-daily local stats cache on your device
Google OAuth Scopes
YouTool.io requests Google access only for the feature you choose to use.
- openid, email, profile: Used for Google sign-in and account sessions
- youtube.readonly: Used for connected-channel features that need read-only YouTube channel and video metadata
- yt-analytics.readonly: Used for connected-channel features that need read-only YouTube Analytics reports for your own channel
These YouTube scopes are read-only. YouTool.io cannot upload videos, edit videos, delete content, post comments, or make channel changes through these permissions.
Connected YouTube Channel Data
If you choose to connect your YouTube channel, YouTool.io uses Google OAuth with read-only YouTube and YouTube Analytics scopes. We store the connection record so you do not need to reconnect on every visit.
- Stored Connection Fields: Google subject ID, YouTube channel ID, channel title, channel thumbnail URL, authorized scopes, access token, refresh token, token expiration time, update time, and disconnect status
- Stats Requests: When the extension popup loads connected-channel stats, our API requests channel subscriber count plus YouTube Analytics metrics such as views, subscribers gained, and subscribers lost for the selected 1D, 7D, or 30D range
- Analytics History: While your channel remains connected, YouTool.io may store connected-channel snapshots, video metadata, daily channel/video analytics, traffic sources, search terms where returned by YouTube Analytics, audience/device/geography breakdowns, playlist add/remove metrics, comment counts, and generated insight reports to support historical comparisons and full channel analysis. We may review these connected-channel patterns internally to improve tools and build future aggregate benchmark or experiment features, but we do not publish individual channel analytics or creator-specific case studies without permission
- Analysis Requests: Video and channel analyzer features request public YouTube metadata and statistics for the video or channel you ask to analyze
- Disconnection: You can disconnect your YouTube channel from the Account page. After disconnection, the connection is marked inactive, stored OAuth tokens are cleared where supported by the connection record, the connection is not used for new stats requests, and stored private connected-channel analytics history tied to your account is deleted
YouTube API Data Usage
Compliance with YouTube Terms
Our use of YouTube data is strictly governed by the YouTube API Services Terms of Service:
- Public website tools access publicly available information
- Connected-channel features access read-only data you authorize through Google OAuth
- Data is used solely for analytics and insights
- Connected-channel history may be used internally to improve creator benchmarks, experiment ideas, and tool quality
- We comply with all YouTube API quotas and rate limits
- Extension stats may be cached locally in Chrome storage once per day for faster loading
- We do not sell YouTube API data or use it for personalized advertising
Types of YouTube Data Accessed
- Video Metadata: Titles, descriptions, thumbnails, publish dates
- Public Statistics: View counts, like counts, comment counts
- Channel Information: Names, subscriber counts, creation dates
- Public Comments: Text content of publicly visible comments only when a public tool specifically requests comments
- Playlist Data: Public playlist contents and metadata
- Connected Channel Analytics: Views, impressions, thumbnail click-through rate, watch time, average view duration, average percentage viewed, subscriber gain/loss metrics, engagement metrics, traffic sources, search terms where returned, audience/device/geography breakdowns, and content type breakdowns for your own connected channel when you authorize that access
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this data only to provide and improve YouTool.io creator tools, do not sell it, do not use it for personalized advertising, and do not use it to determine creditworthiness or for lending purposes.
Analytics and Tracking
Google Analytics
We use Google Analytics to understand how users interact with our service:
- Page Views: Which tools are most popular
- User Journey: How users navigate through our site
- Performance Metrics: Loading times and error rates
- Demographics: General geographic and device information
- Anonymization: IP addresses are anonymized
Vercel Analytics
Our hosting provider collects performance data:
- Page load speeds and performance metrics
- Error rates and availability monitoring
- General usage patterns for optimization
- No personal identification data is collected
Local Storage Usage
Browser Storage
We use your browser's local storage and Chrome extension storage for:
- Search History: Your recent searches for quick access
- Tool Preferences: Filter settings and display options
- Session Data: Temporary data during your visit
- Performance Cache: Improved loading times
- Extension Settings: Enabled tools, custom theme, playback settings, hide controls, selected stats range, and local daily stats cache
Control Over Local Data
- You can clear your search history at any time
- Browser settings allow you to disable local storage
- Private/incognito browsing prevents data storage
- Data is specific to your device and browser
Third-Party Services
No Advertising
YouTool.io does not currently run display ads, sell ad inventory, or use Google API data for advertising. The project is supported through optional user contributions while the public tools remain free to use.
External Fonts and Assets
- Google Fonts: Typography assets loaded from Google's CDN
- Boxicons: Icon library from external CDN
- Image Hosting: Some images served from Tumblr CDN
Data Security Measures
Technical Safeguards
- HTTPS Encryption: All data transmission is encrypted
- Secure Hosting: Infrastructure provided by Vercel with enterprise security
- Database Provider: Account, extension session, and YouTube connection records are stored in Supabase
- Token Handling: Extension session tokens are stored server-side as hashes; YouTube OAuth tokens are used only to provide connected-channel features
- API Security: YouTube API keys and service credentials are stored server-side
Access Controls
- Limited access to production systems
- Regular security updates and monitoring
- Principle of least privilege for all services
- Automated security scanning and alerts
Your Rights and Controls
Data Access Rights
- Transparency: This disclosure provides complete visibility
- Local Access: You can view all locally stored data through browser tools
- Limited Collection: We minimize data collection to essential functions
- Disconnect Controls: You can disconnect your YouTube channel from your Account page and sign out of the extension from the extension popup
Control Options
- Browser Settings: Control cookies and local storage
- Analytics Opt-out: Use browser extensions to block tracking
- Google Revocation: Revoke YouTool.io access from your Google Account permissions page
- Service Discontinuation: Stop using our service at any time
- Deletion Requests: Contact support to request deletion of account data stored server-side
Data Retention Policies
What We Keep
- Analytics Data: Aggregated usage statistics for service improvement
- Error Logs: Technical logs for debugging and performance monitoring
- Security Logs: Access logs for security monitoring
- Account Records: Basic profile records for signed-in users
- Extension Session Records: Session hashes, expiration, revocation, and last-used timestamps
- YouTube Connection Records: Connected-channel metadata and OAuth tokens while your channel remains connected
- Connected Channel Analytics History: Read-only channel/video snapshots, daily metrics, analytics breakdowns, and generated insight runs while your channel remains connected
What We Delete
- Individual Public Tool Results: Generally returned in real time and not used to build a permanent history of every analysis result
- Disconnected Channel Use: Once disconnected, the stored connection is marked inactive, stored OAuth tokens are cleared where supported by the connection record, the connection is not used for new YouTube API requests, and stored private connected-channel analytics history tied to your account is deleted
- Local Extension Cache: Can be cleared by clearing extension storage or removing the extension
International Data Transfers
Our service operates globally with appropriate safeguards:
- Hosting: Vercel provides global CDN with data protection compliance
- Google Services: Subject to Google's international data transfer policies
- Legal Compliance: We comply with applicable data protection laws
Changes and Updates
We may update our data practices to improve our service or comply with legal requirements:
- Material changes will be communicated through this page
- We'll update the "Last Updated" date for any modifications
- Significant changes may be announced on our website
- Continued use constitutes acceptance of updated practices
Contact and Questions
For specific questions about our data usage or to exercise your rights:
Regulatory Compliance
Our data practices are designed to comply with:
- GDPR: European General Data Protection Regulation
- CCPA: California Consumer Privacy Act
- COPPA: Children's Online Privacy Protection Act
- YouTube API Policies: Google's developer terms and policies