Policy document
Privacy Policy
API Client: ELYT Media Publisher · Effective date: September 29, 2026
This application uses YouTube API Services. Use of this application is subject to the YouTube Terms of Service, and the handling of your Google Account data is additionally governed by the Google Privacy Policy.
1. What this application is
ELYT Media Publisher is an internally operated tool that publishes video content to one YouTube channel on behalf of its owner. It is not offered to the public, has no external user accounts, and is not a multi-user or multi-channel service.
2. Google Account authorization
Access to YouTube data is obtained through Google's standard OAuth 2.0 installed-application flow. When the owner authorizes this application, Google presents its own consent screen naming the exact permission requested; the owner selects the Google Account to connect and can decline at that screen at any time.
Scope requested
This application requests exactly one OAuth scope:
https://www.googleapis.com/auth/youtube.force-ssl
This is the minimum scope covering every action the application performs (see §3). No broader Google scope — Gmail, Drive, Contacts, Calendar, or any other product — is ever requested.
3. YouTube API Data accessed, and why
No other YouTube Data API resource — playlists, comments, subscriptions, channel membership, analytics, or search — is read or written by this application.
4. What is stored
- The OAuth client ID and client secret issued to this application, and the long-lived refresh token obtained when the owner authorizes access.
- Locally-generated production records referencing already-public information about the owner's own uploaded video: its YouTube video ID, title, and current privacy status.
These are stored only on the operator's own local machine, inside Windows Credential Manager (an operating-system-level, encrypted credential store) for the OAuth values, and in local project files for the video-reference records. Nothing is transmitted to, or stored on, any third-party server operated by this application — there is none; the application has no backend service and no database beyond the operator's own computer.
5. What is not stored
- The Google Account password is never seen, requested, or stored — authorization happens entirely through Google's own consent screen.
- Short-lived OAuth access tokens are not persisted: each is obtained fresh from the stored refresh token immediately before use and is held only in process memory for the duration of that operation.
- No viewer, subscriber, comment, or analytics data is collected, stored, or retained — this application never requests analytics or audience-data scopes.
6. No sale or third-party sharing
No data accessed through YouTube API Services is sold, rented, or shared with advertisers, data brokers, or any other third party. It is used solely to operate this application for its single owner.
7. Data retention
The refresh token and client credentials are retained until the owner revokes them (see §9) or replaces them by re-authorizing. Local video-reference records are retained as part of the owner's own production history for as long as that production project is kept.
8. Data deletion
The owner can delete all locally stored credentials at any time by removing the corresponding entries from Windows Credential Manager on the machine running this application. Local production records can be deleted directly as ordinary files. Because this application has no external server or database, deleting these local items removes all data this application holds.
9. Revoking access
The owner can revoke this application's access to their Google Account at any time, independently of this application, at Google Account → Security → Third-party apps & services. Revocation immediately invalidates the stored refresh token for future use.
10. Contact
Questions about this policy: elyonchayil@gmail.com