Privacy Policy
Last updated: 15 August 2026
1. Who we are
YTCMS Creator Center ("YTCMS", "we", "us") is an independent YouTube creator operations platform. We are not affiliated with, endorsed by, or an official product of Google LLC or YouTube. Contact us any time at support@ytcms.app.
2. Data we collect
- Account data: your email address, display name and authentication identifiers used to sign in to your workspace.
- Workspace data: workspaces, teams, roles, projects, notes, cases and any content you create inside the product.
- Google / YouTube data: when you authorize a channel, we receive your Google account identity (email, profile name) and the YouTube data covered by the scopes you approve — channel profile, channel and video metadata, statistics and analytics.
- Operational data: logs, audit records, sync history and error diagnostics needed to run the service securely.
3. Google OAuth and YouTube API Services
YTCMS Creator Center uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service and the Google Privacy Policy.
- We request the minimum OAuth scopes required for the features you use.
- We use YouTube data only to display and manage your own channels inside your workspace — analytics, publishing, metadata management and rights/recovery workflows you initiate.
- We never sell YouTube data, never use it for advertising or profiling, and never transfer it to third parties except infrastructure providers acting on our instructions.
- We do not use YouTube data to train generative AI or machine-learning models.
You can revoke our access at any time from your Google security settings or by disconnecting the channel inside YTCMS. Revoking access stops all future syncing and triggers deletion of the stored tokens for that connection.
4. How we store and protect data
- OAuth access and refresh tokens are encrypted (AES-256-GCM) before storage and are never exposed to the browser.
- Row-level security isolates every workspace; staff access is least-privilege and audit-logged.
- All traffic is served over TLS.
5. Retention and deletion
Cached YouTube data is retained no longer than 30 days unless you keep the channel connected, in which case it is refreshed from the API. Disconnecting a channel deletes its tokens immediately and its cached data within 30 days. Deleting your account removes your workspace data within 30 days, except records we must keep for legal, billing or security reasons. Request deletion at support@ytcms.app.
6. Sub-processors
We rely on infrastructure providers for hosting, database, email delivery and optional AI features. They process data only on our instructions and under contractual confidentiality obligations.
7. Your rights
You may request access, correction, export or deletion of your personal data, and you may object to certain processing. We respond to verified requests within 30 days.
8. Children
The service is not intended for anyone under 18 years of age.
9. Changes
We will update this page when our practices change and revise the "last updated" date above. Material changes are announced inside the product.