1. Scope and controller
This Privacy Policy applies to Shorts Dashboard, operated as Shorts Auto HQ. Questions and privacy requests may be sent to ferreyromonii@gmail.com.
2. Google and YouTube data we access
After an authorized Google Account grants consent, the application may access:
- YouTube channel identifiers, names and public channel or video metadata.
- Read-only channel statistics, including video, view and subscriber information made available by the YouTube APIs.
- Read-only YouTube Analytics reports for channels the user is authorized to manage.
- OAuth access and refresh tokens required to maintain the authorized connection.
The requested scopes are youtube.readonly and yt-analytics.readonly. They do not permit the application to create, modify or delete YouTube content.
3. How we use the data
We use this data to identify the connected channel, display operational and performance reports, monitor connection health and provide the features requested by authorized users. The optional Learning module links explicitly confirmed production records to published videos and reads official metrics for comparable 3, 7 and 28 calendar-day periods. Channel and language scopes remain separate.
Measurement starts only after the operator accepts this policy version and enables it for the selected channel. Advanced derived analysis, experiments and application of learned changes have separate controls and remain unavailable without the applicable documented provider permissions. A connection or an approval by the app operator does not substitute for an approval required from YouTube.
4. Storage and service providers
The production processes, authenticated dashboard and Learning storage run on the private OVH server. OAuth credentials use restricted filesystem permissions and are not displayed in the browser. Google provides OAuth, the YouTube Data API and the YouTube Analytics API. An optional, separately configured Google Analytics connection can read campaign measurements for the operator's websites.
5. Sharing and sale
We do not sell Google user data, send it to advertising platforms, or use it to target advertisements. Access is limited to authorized operators and service providers necessary for the disclosed feature, subject to the applicable Google policies and consent.
Google or YouTube API data and conclusions derived from it are excluded from external AI prompts by default. Any future transfer for an approved Learning feature requires a documented review of the specific provider, purpose, applicable permissions and informed user consent. The existing use of an AI service to generate the operator's own scripts does not itself authorize transfer of YouTube metrics. The Learning module does not train a general-purpose AI model.
6. Retention and deletion
The Learning module limits API evidence to a maximum of 30 days since retrieval or verification unless refreshed. It expires dependent evidence and disables learned changes when their required evidence is no longer valid. Original scripts, audio, montage and production records are kept separately from API evidence; deleting API data does not delete those originals or change a publication on YouTube.
Users can delete the selected channel's Learning API data from the Learning panel. This stops its Learning features and removes their API evidence; it does not revoke the shared Google connection or erase every legacy module. Requests covering the entire application, OAuth credentials, legacy reports or managed backups must use the Data Deletion page so the operator can check all affected stores.
Requested deletion of Google or YouTube data must be completed as soon as possible and within seven calendar days. Following external Google revocation, applicable stored data must be removed as soon as possible and within 30 calendar days. Backups are included in the deletion process; restoration must not reactivate revoked access or reintroduce deleted data.
7. Security
We use authenticated administrative access, HTTPS transport, restricted secret storage, limited-scope OAuth permissions and operational logging designed to avoid exposing credentials. No system can guarantee absolute security, but access is limited to what is needed to operate the service.
8. Google API Services User Data Policy
Shorts Dashboard's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
The application uses YouTube API Services. Google's handling of data is described in the Google Privacy Policy. Access may be revoked through Google Account permissions.
9. Changes
Material changes will be published with an updated effective date. A new purpose or transfer requiring additional consent will remain disabled until that consent and any required provider approval are recorded.