LEGAL · PRIVACY
Privacy Policy
Last updated 3 September 2026 · applies to ytmate.in and the connected app
We run free tools and a paid studio for YouTube creators. This page lists exactly what we collect, why, how long we keep it, and how to make us delete it.
1. Who we are
ytmate.in and the connected creator app are operated by Sanjeev Sharma, an individual based in India. Contact: privacy@ytmate.in. We are not affiliated with YouTube or Google.
2. YouTube API Services
This application uses YouTube API Services. By using it you also agree to the YouTube Terms of Service and the Google Privacy Policy.
You can revoke our access at any time from Google's security settings at security.google.com/settings/security/permissions, or from Settings → Channels in the app.
3. What we collect from YouTube, and why
- Free tools: nothing about you. We fetch public data for the video or channel you paste (title, tags, public counts, thumbnails) and cache it for up to 24 hours.
- Connected channel: with your permission we read your videos and channel details (
youtube.readonly) and your YouTube Analytics (yt-analytics.readonly). This powers the dashboard, reports and alerts. - Optional, asked separately: manage your videos (
youtube.force-ssl) so you can push a thumbnail or title after confirming it, and read revenue (yt-analytics-monetary.readonly) if you turn on earnings in reports.
4. How long we keep it
- Titles, descriptions, tags and comment text: refreshed or deleted within 30 days, as YouTube's Developer Policies require.
- Statistics and analytics: up to 36 months while your channel stays connected. We re-confirm your authorization every 30 days; if it fails, syncing stops and you are emailed.
- Refresh token: encrypted at rest (libsodium) and deleted the moment you disconnect.
- Disconnect in the app deletes all channel data within 7 days. Revoking from Google's page deletes it within 30 days.
5. What we collect from you
Email address, name (if you use Google sign-in), time zone and language. Payment records come from Razorpay or our merchant of record; we never see your card or UPI details. Alert addresses (phone number for WhatsApp, Telegram chat id) only if you add them.
6. Your AI keys
If you add your own OpenAI, Google, Anthropic or other API key, it is stored encrypted, shown to you only as its last 4 characters, and used only for the actions you trigger. Your provider bills you directly. We never log the content of requests, only provider, model, token counts and latency. Remove a key and it is deleted immediately.
7. Labels and what we compute
Every number that comes from YouTube is shown as YouTube returned it. Anything we compute, such as velocity against your baseline, thumbnail scores, predicted CTR bands or audit findings, carries a "Not from YouTube" label. We never profile viewers by protected attributes and never show audience data below channel level.
8. Cookies and analytics
A session cookie keeps you signed in and an anonymous cookie enforces free-tool limits. Free tool pages show advertising through Google AdSense, which uses its own cookies under Google's policy. We use a privacy-friendly page counter with no cross-site tracking.
9. Your rights
Export everything from Settings → Profile. Delete your account there too; it completes within 7 days. For anything else write to privacy@ytmate.in. If you are in the EU or UK you have GDPR rights; if you are in India, the DPDP Act applies and the same controls satisfy it.