1. Scope and controller
This Privacy Policy applies to Shorts Dashboard, operated as Shorts Auto HQ. Questions and privacy requests may be sent to [email protected].
2. Google and YouTube data we access
After an authorized Google Account grants consent, the application may access:
- YouTube channel identifiers, names and public channel or video metadata.
- Read-only channel statistics, including video, view and subscriber information made available by the YouTube APIs.
- Read-only YouTube Analytics reports for channels the user is authorized to manage.
- OAuth access and refresh tokens required to maintain the authorized connection.
The requested scopes are youtube.readonly and yt-analytics.readonly. They do not permit the application to create, modify or delete YouTube content.
3. How we use the data
We use this data only to identify the connected channel, display operational and performance reports, monitor connection health, support channel planning and provide the features requested by authorized users.
4. Storage and service providers
Long-lived OAuth credentials are stored on a private OVH production server with restricted filesystem permissions and are not displayed in the browser. Railway provides the authenticated control interface and relays time-limited authorization commands to the production server. Google provides the OAuth, YouTube Data API and YouTube Analytics API services.
5. Sharing and sale
We do not sell Google user data. We do not use it for advertising. Data is shared only with infrastructure providers needed to operate the service, with the authorized channel operators, when required by law, or when the user explicitly directs us to do so.
6. Retention and deletion
Connection data is retained while the channel remains connected or while needed for the authorized operational purpose. Users may revoke access in their Google Account and request deletion using the instructions on the Data Deletion page. After a verified request, OAuth tokens and the related connection record are deleted from active storage, subject to limited security backups and legal obligations.
7. Security
We use authenticated administrative access, HTTPS transport, restricted secret storage, limited-scope OAuth permissions and operational logging designed to avoid exposing credentials. No system can guarantee absolute security, but access is limited to what is needed to operate the service.
8. Google API Services User Data Policy
Shorts Dashboard's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
9. Changes
Material changes will be published on this page with an updated effective date. Continued use after a change is subject to the updated policy.