Legal
Effective date: 1 June 2025. Last updated: 21 July 2026.
TubeSignalHQ is a software-as-a-service platform for YouTube creators, operated by DM Visibility LLC ("DM Visibility LLC", "we", "us", "our"). TubeSignalHQ is a product of DM Visibility LLC. For all privacy-related questions, data requests, or complaints, contact us at support@tubesignalhq.com.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, DM Visibility LLC acts as the data controller for your personal data under the General Data Protection Regulation (GDPR) and equivalent national laws. If you are located in California, USA, additional rights apply under the California Consumer Privacy Act (CCPA) — see Section 8.
Account data — your email address, display name, and optionally a profile picture from Google sign-in. Legal basis: contract performance.
YouTube channel data (Channel Health & Viewer Fatigue Risk) — when you connect a YouTube channel via Google OAuth, we request read-only access using four scopes: `openid` and `email` (identify which Google account is granting access and associate it with your TubeSignalHQ account — not YouTube-specific, and do not grant access to Gmail, Drive, contacts, or other Google services), `youtube.readonly` (channel and video metadata), and `yt-analytics.readonly` (performance analytics: views, watch time, CTR, impressions, traffic sources, audience retention). If you separately, explicitly enable transcript-based Viewer Fatigue Risk analysis, we request one additional permission, `youtube.force-ssl`, at that later point — not as part of the initial connection. Google classifies `youtube.force-ssl` as a broad permission (it can also support editing or deleting YouTube content), even though we use it exclusively to download your existing caption/subtitle files and never call any endpoint capable of publishing, editing, or deleting content. We do not request monetization/revenue data. See Section 3 ("Google and YouTube API Data") for full detail. Legal basis: contract performance.
Video transcripts — for Viewer Fatigue Risk analysis, we process and store video transcripts to detect topic repetition, authenticity signals, and audience fatigue patterns. Transcripts are only available for channels you've connected via Google OAuth, downloaded directly from YouTube's Captions API using your authorized connection. We do not obtain transcripts for channels you haven't connected. Transcripts are stored in our database linked to your account and deleted when you disconnect the channel or delete your account. Legal basis: contract performance.
Audit inputs — video titles, thumbnail images, opening hook text, and transcript excerpts you submit for packaging analysis. Thumbnails are stored in a private storage bucket accessible only to your account. Opening hook text and transcript excerpts are stored in our database linked to your account. All audit input data is deleted when you delete your account. Legal basis: contract performance.
Publish Planner data — content you create in the Publish Planner, including video titles, script outlines, thumbnail concepts, hook text, tags, scheduled publish dates, niche categories, notes, and workflow status (draft through published). This data is scoped to your workspace — visible to other members of that workspace, not to unrelated users or other workspaces. See Section 3a ("Workspaces and collaboration") for exactly which roles can see what. Legal basis: contract performance.
Competitive intelligence data — YouTube channel and video metadata for competitor channels you add to Competitor Intel rooms. This data is sourced entirely from the public YouTube Data API and does not include any personal data of our users. Legal basis: contract performance.
Automated analysis outputs — scores, risk assessments, and diagnostic results produced by our analysis pipeline from the data you provide. Legal basis: contract performance.
Billing data — subscription plan, billing interval (monthly or annual), billing period dates, and subscription status. We store Stripe customer and subscription identifiers to manage your subscription. We never see, receive, or store your card number or bank details — payment processing is handled entirely by Stripe. Legal basis: contract performance and legal obligation.
Registration and waitlist data — if you join our waitlist or request early access, we collect your name, email address, YouTube channel name and URL, and content niche. This information is used solely to process your access request and notify you when access is available. Legal basis: consent. You may withdraw at any time by emailing support@tubesignalhq.com.
Analytics and behaviour data — page views, feature interactions, and in-product events (e.g. audit submitted, plan upgraded) collected via Google Analytics 4, PostHog, and our own internal product analytics. None of these load, initialise, or record anything until you accept analytics cookies — see Section 7. Used to understand how the Service is used and to improve it. Legal basis: consent, where consent is required (see Section 7); we separately rely on legitimate interests only for essential server logs, fraud prevention, security monitoring, and strictly necessary operational measurements that do not depend on any of the optional tracking technologies described here.
Technical data — standard server logs (IP address, browser type, referring URL) retained for security and debugging. Error reports are processed through Sentry (see Section 5). Legal basis: legitimate interests.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
TubeSignalHQ uses Google OAuth to access YouTube information only after you grant permission. This section explains exactly what we access, why, and what happens to it.
What we access and why. Connecting your channel requests four permissions, granted together at connection time:
The `openid` and `email` scopes are identity-verification scopes, not YouTube-specific — they exist to correctly attribute the authorization to your account and prevent duplicate or mismatched connections. They do not give TubeSignalHQ access to Gmail, Google Drive, contacts, or any other Google service, and are separate from (not a substitute for, and not shared token storage with) the Google Sign-In authorization described later in this section. Together with the two YouTube scopes above, these four are the only permissions requested at connection time — genuinely read-only, with no scope in this set permitting any write, edit, publish, or delete operation.
A third, separately-requested permission for caption download. If you choose to enable Viewer Fatigue Risk transcript analysis, we ask for one additional permission at that point — a distinct step, with its own explanation, not part of the initial connection:
We do not request `yt-analytics-monetary.readonly` or any other revenue/monetization scope. No feature in TubeSignalHQ reads or uses monetary YouTube data.
How this data is used. Only to provide the specific, visible features you've enabled by connecting a channel — your Channel Health dashboard, Viewer Fatigue Risk analysis, and the recommendations and reports built from that analysis. We do not use it for any purpose you haven't asked for.
Where and how it's stored. OAuth access and refresh tokens are encrypted at rest (AES-256-GCM) in our Supabase database and are never exposed in API responses, client-side code, or logs. Channel metadata, analytics, transcripts, and related reports are stored in our database and scoped to the applicable workspace through row-level security. They may be accessed only by authorized members of that workspace according to their assigned roles, as described in Section 3a. Unrelated users and other workspaces cannot access them.
Who can process it. Only infrastructure providers necessary to host, secure, and operate the Service (see Section 4): Supabase, which hosts our database and stores this data at rest, and Vercel, which hosts the application code and executes the server functions that receive the OAuth callback from Google, make the YouTube API calls, and pass the responses through to Supabase for storage — Vercel processes this data in transit as part of running the Service, even though it is not where the data is durably stored. We do not share Google or YouTube data with any provider beyond what's needed to run the Service itself. Authorized DM Visibility LLC personnel may access your specific, identifiable Google or YouTube data only: (a) after you expressly authorize access to that data for a support request you've raised; (b) to investigate suspected security incidents, abuse, or fraud; (c) to comply with a legal obligation; or (d) for internal operations, and only where the data has first been properly aggregated or de-identified. We do not grant general-purpose debugging access to identifiable Google or YouTube data outside these cases.
What we don't do with it. We do not sell Google or YouTube data, use it for advertising or targeted ads, provide it to data brokers, use it to determine creditworthiness, or use it to train generalized artificial-intelligence or machine-learning models.
Limited Use. TubeSignalHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. For how Google itself handles data on its end, see Google's Privacy Policy.
Disconnecting. You may disconnect a YouTube channel at any time from the Channel Health or Viewer Fatigue Risk section of your dashboard. Disconnecting deletes the channel's Authorized Data (metadata, analytics, downloaded transcripts, and derived reports) from our systems immediately, and attempts to revoke our access token with Google — including the caption-download permission, if you had granted it; Google does not support revoking a single permission from a connection while keeping the rest. We report exactly what happened: if Google confirms the revocation, we tell you so; if Google can't be reached, we keep retrying automatically and tell you a retry is pending; if Google rejects the request outright, we tell you to remove access directly through your Google Account instead, with a link to do so. We do not claim a Google-side revocation succeeded unless Google's response actually confirms it. If you granted caption-download access and later decide you no longer want it, disconnecting and reconnecting the channel (declining the separate caption-import step) removes it while keeping the rest of your connection.
You may also revoke TubeSignalHQ's access directly through your Google Account's third-party access page, independent of anything in our dashboard — this is also the definitive way to remove access if our own revocation attempt could not be confirmed. If you revoke access this way, we detect it the next time we attempt to sync your data, stop all further API calls immediately, and delete the associated Authorized Data within 7 days if the connection isn't restored in the meantime. A later reconnection creates a new authorization — it does not "undo" or retroactively excuse the period during which access was revoked; it simply means a fresh grant now exists, so scheduled deletion tied to the earlier revocation no longer applies.
Google Sign-In is separate from YouTube authorization. Signing in with Google and connecting a YouTube channel are two independent authorizations, and may use different Google Cloud projects. Deleting your TubeSignalHQ account attempts to revoke the YouTube authorization as described above, and separately attempts a best-effort revocation of the Google Sign-In consent via Google's own client-side revocation mechanism while you're still signed in. Neither this app nor Supabase (our authentication provider) retains a server-side copy of the Google Sign-In token, so we cannot revoke it server-side the way we can for YouTube access — if the best-effort attempt doesn't succeed, removing it requires the same manual step through your Google Account's third-party access page linked above.
Disconnecting does not affect YouTube itself. Deleting your TubeSignalHQ data — whether by disconnecting a channel, revoking access through Google, or deleting your account — does not delete, modify, or otherwise affect anything stored by YouTube or your YouTube channel itself.
Cached data retention. Authorized data (channel metadata, analytics, transcripts) is retained only while a channel remains connected, and is deleted per the disconnection rules above. Public, non-authorized YouTube API data used by Competitor Intel (Section 2, "Competitive intelligence data") is refreshed or deleted within 30 days. If we cannot refresh it within that period, it is no longer displayed and is removed from user-facing access; see Section 5 for full retention detail.
TubeSignalHQ supports shared workspaces with multiple people. This section explains, plainly, what that means for your data.
Personal vs. workspace data. Your authentication credentials and private profile information remain personal to you. Limited account-identification information — specifically your display name, email address, profile picture, workspace role, and invitation status — may be visible to authorized members of workspaces you join, where necessary for collaboration and workspace administration (for example, the Team settings roster, or attribution showing who created a shared item). Everything else described in Section 2 — connected-channel data, video transcripts, audit inputs, Publish Planner content, competitive intelligence data, and automated analysis outputs — is workspace data: scoped to the workspace it was created in, not to you individually, and visible to other members of that same workspace according to their role.
Roles and what they can see or do. Every workspace has one Owner, and may have any number of Admins and Members:
Leaving a workspace. Any member — Owner, Admin, or Member — may leave a workspace they belong to, except a sole Owner (see below). Leaving removes your access to that workspace's data immediately; it does not delete the workspace or its data for the remaining members.
What happens when the workspace Owner deletes their account. If the Owner is the workspace's only member, deleting their account permanently deletes the entire workspace and all of its data — connected channels, OAuth grants (revoked with Google), reports, audits, and Publish Planner content — along with the account itself; see Section 5 for exact timing. If the workspace has other members, TubeSignalHQ blocks account deletion until the Owner resolves that first — by removing the other members from Settings → Team, or otherwise handing off the workspace — specifically so that deleting one person's account never silently deletes shared data other people are still using, or leaves it orphaned with no owner. See our Terms of Service Section 15 for the corresponding contractual statement of this restriction.
We share data only with processors that support the operation of the Service:
We use PostHog for product analytics where you've provided the required consent. Processing locations depend on the configured PostHog service instance and provider infrastructure.
Provider data processing terms apply automatically where incorporated into our agreement with each processor. Where a bespoke data processing agreement has been separately negotiated and executed, we'll update this list to reflect it.
Sentry is conditionally disclosed, not currently active. Sentry error monitoring is not enabled in production today, because no production Sentry DSN is configured — Sentry receives no production error reports at this time. Where Sentry error monitoring is enabled, it may receive error messages, stack traces, and limited request context necessary to diagnose application failures. Before any report is sent, TubeSignalHQ is configured to remove authorization headers, cookies, OAuth tokens, JWTs, encrypted-token patterns, and other known sensitive values, and this scrubbing is already in place in our client- and server-side code regardless of whether Sentry is currently receiving data. Sentry Session Replay is disabled and is not enabled by turning Sentry on — enabling error monitoring does not automatically enable Session Replay, and we do not record page interactions, DOM structure, or visual playback of your sessions under any current configuration. If Sentry is enabled in production, this policy will be updated to accurately state the configured retention period, processing region, and confirm these scrubbing and Session Replay controls remain in place, before or at the time it is enabled.
Transfers to processors outside the EEA are governed by the EU Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism.
Retention depends on the category of data — the table below replaces a single blanket "we delete everything immediately" claim with what's actually true for each category:
Account data (email, display name, profile picture) — retained while your account is active, deleted immediately when you delete your account from Settings.
Google and YouTube Authorized Data (channel metadata, analytics, transcripts) — deleted immediately when you disconnect the channel in-app or delete your account. If access is instead revoked through your Google Account directly, we detect it on our next sync attempt, stop all API calls immediately, and delete the associated data within 7 days if the channel isn't reconnected in the meantime.
OAuth access and refresh tokens — encrypted at rest. Purged as soon as Google confirms revocation, which is normally immediate on disconnect/account deletion. If Google can't be reached right away, the encrypted token is kept only long enough to retry the revocation (up to 7 days), with no application access to it in the meantime — it is purged the moment revocation succeeds or that retry window ends. Within 7 days of a detected Google-side revocation (you revoked access directly through your Google Account), the associated tokens are purged the same way.
User-submitted content (audit inputs, Publish Planner entries, script outlines, thumbnails) — retained while your account is active, deleted immediately when you delete your account.
Public YouTube API data (competitor channel/video metadata in Competitor Intel) — refreshed or deleted within 30 days. If we cannot refresh it within that period, it is no longer displayed and is removed from user-facing access, independent of whether the room or workspace it's referenced by still exists.
Analytics events (Google Analytics 4, PostHog) — anonymised or deleted within 90 days, per each platform's own configured retention window.
Application logs (server logs — IP address, browser type, referring URL) — deleted within 90 days.
Error reports (Sentry) — Sentry is not currently active in production (Section 4), so no production error reports exist to retain today. Where and when Sentry is enabled: retained per Sentry's own project-level retention window, not automatically purged on a per-account basis when you delete your account; Sentry currently has no mechanism in this codebase for us to trigger a targeted per-user purge on request. Reports are scrubbed of tokens and credentials before they're sent (Section 4) and are not designed to contain your Google/YouTube data or submitted content.
Backups — we do not currently maintain a separate managed backup system. If that changes, we will update this section to describe it, including how long backup copies persist after you delete data.
Billing and tax records — Stripe retains billing records as required by financial regulations (typically 7 years) — this is outside our control and unaffected by deleting your TubeSignalHQ account.
De-identified data — data that has been aggregated or stripped of anything identifying you (e.g. anonymised analytics) may be retained indefinitely, since it no longer constitutes your personal data.
If you are located in the EEA, UK, or Switzerland, you have the following rights:
Right of access (Art. 15) — request a copy of all personal data we hold about you. Email support@tubesignalhq.com.
Right to erasure (Art. 17) — request deletion of your account and all associated data. Use the "Delete account" option in Settings, or email support@tubesignalhq.com. If you are the sole Owner of a workspace with other members, the shared-workspace condition in Section 3a may need to be resolved first (removing those members or handing off the workspace) before deletion can proceed. Once that condition, if applicable, is resolved, deletion via Settings is initiated immediately; requests by email are completed within 30 days regardless. As with any deletion method, certain billing, tax, security, fraud-prevention, or legally required records may be retained for the periods stated in Section 5, and this does not imply every record held by every processor is erased instantaneously.
Right to data portability (Art. 20) — receive your personal data in a machine-readable format. Email support@tubesignalhq.com.
Right to rectification (Art. 16) — correct inaccurate personal data. Update your profile in Settings or email support@tubesignalhq.com.
Right to object (Art. 21) — object to processing based on legitimate interests, including analytics tracking. Email support@tubesignalhq.com.
Right to restrict processing (Art. 18) — request that we suspend processing in certain circumstances. Email support@tubesignalhq.com.
Right to withdraw consent — where processing is based on consent (e.g. waitlist registration), you may withdraw at any time without affecting the lawfulness of prior processing.
Right to lodge a complaint — you have the right to complain to your local supervisory authority (e.g. the ICO in the UK, or your national DPA in the EU) if you believe we have mishandled your data.
We will respond to all rights requests within 30 days.
We use a strictly-necessary session authentication cookie (required to stay logged in) and, with your consent, optional analytics cookies from Google Analytics 4 and PostHog to understand feature usage and improve the product. Google Analytics 4 and PostHog do not load or set cookies until you accept analytics cookies. We do not use advertising cookies or cross-site behavioural tracking cookies.
For the full list of cookies, what each one does, and to change your analytics preference at any time, see our Cookie Policy.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to know — you may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the third parties with whom we share it.
Right to delete — you may request deletion of personal information we have collected from you, subject to certain legal exceptions.
Right to correct — you may request correction of inaccurate personal information we hold about you.
Right to opt out of sale or sharing — we do not sell your personal information and do not share it for cross-context behavioural advertising.
Right to limit use of sensitive personal information — we do not use sensitive personal information beyond what is necessary to provide the Service.
Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA rights.
To exercise your California rights, email support@tubesignalhq.com with "California Privacy Request" in the subject line. We will respond within 45 days, with a possible 45-day extension where permitted by law.
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you become aware that a child has provided us with personal data, please contact support@tubesignalhq.com and we will delete it promptly.
Data is stored in Supabase (PostgreSQL) with row-level security policies enforced at the database level. File storage uses private buckets inaccessible to other users. All data in transit is encrypted via TLS 1.2+. OAuth access and refresh tokens are additionally encrypted at rest (AES-256-GCM) before being stored. Access to production systems is restricted to authorised personnel under the principle of least privilege.
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect. The effective date at the top of this page will always reflect the most recent version.
For all privacy questions, data requests, or complaints:
Legal operator: DM Visibility LLC (operator of TubeSignalHQ)
Email: support@tubesignalhq.com
We aim to respond within 5 business days and will always complete substantive requests within 30 days.