Security & control
The four principles
- Voluntary connection. Your own channel is connected via Google sign-in (OAuth) only at your explicit request; TubeMakers never asks for or stores your Google password.
- Read-only access. The analytics features request read-only permissions only. Write actions such as uploading a video – where enabled – are performed only after the target channel, visibility and consequences are shown and you explicitly confirm.
- Separated data. Private channel data is visible only to the channel owner and the team members they explicitly authorise. Data of different channel owners is never analysed together.
- Revocable at any time. The connection can be removed in TubeMakers or in your Google security settings; stored data is deleted on request within seven calendar days.
Which data TubeMakers uses
| Data type | Examples | Who sees it | How long |
|---|---|---|---|
| Public channel and video data | title, description, thumbnail, views, likes, subscribers | users of the respective workspace | refreshed or deleted within 30 days |
| Your own channel analytics (after Google connection) | audience retention, traffic sources, impressions, click-through rate | channel owner and authorised team members only | while the connection exists; authorisation re-verified every 30 days |
| TubeMakers analyses | views per hour, outlier scores, patterns, recommendations | per feature and workspace | clearly labelled as TubeMakers analysis; at most 36 months where approved by YouTube |
| Access tokens | Google OAuth tokens | nobody – encrypted in the server vault only | while consent is active; immediate revocation possible |
Which permissions are requested
For research and analytics TubeMakers requests exactly two read-only permissions from Google: read channel and video information (youtube.readonly) and read your own channel’s statistics (yt-analytics.readonly). The Google consent screen shows you these permissions before connecting. Write permissions are not requested in advance; publishing through TubeMakers – where enabled – is a separate step with its own request and its own confirmation.
What TubeMakers does not do
- No actions on your channel without your explicit confirmation in each case – no uploading, no commenting, no playlist changes.
- No sale and no advertising use of Google or YouTube data; no third-party advertising in the application.
- No inference of sensitive attributes of viewers or creators (health, age, origin, religion, political opinion, sexual orientation).
- No mixing of private data of different channel owners.
- No cookies, no trackers and no external scripts on this website.
Technology in brief
Encrypted transport (HTTPS), encrypted access tokens that never leave the server, tenant and role checks on every access, logging of security-relevant events, regular backups and tested restore and deletion procedures.
Disconnecting
In TubeMakers under Settings → YouTube connection → Revoke access and delete data, or directly in your Google security settings. The full procedure is described on Delete your data.
Note: TubeMakers uses YouTube API Services. The YouTube Terms of Service and the Google Privacy Policy apply in addition.