Privacy Policy
Last updated: 27 August 2026
YT Accounts ("the application") is a private, invitation-only workspace used to manage YouTube channels that belong to its users. This policy explains what the application collects, why, how long it keeps it, and how you remove it. You must agree to this policy before you can use the application.
Who is responsible
The application is operated privately by its administrator, who can be reached at privacy@yt.wholelayer.com. There is no company, no advertising network and no analytics vendor behind it.
What the application collects
Your account in the application
A username, an email address and a password hash. The password itself is never stored. Accounts are created by the administrator; there is no public registration.
Data obtained through Google APIs
When you connect a YouTube channel, you are sent to Google to sign in and to approve access. The application never sees your Google password. Google returns access and refresh tokens, which are stored encrypted at rest. With them the application accesses:
- Your channel and its videos — identifiers, titles, descriptions, tags, thumbnails, privacy status and publication dates, so the workspace can show and edit them.
- Video uploads — the permission to upload the video files you choose to the channel you choose.
- Your channel's analytics — daily views, impressions, click-through rate, watch time, average view duration, subscriber changes and audience retention. This access is read-only and covers only the channels you connected.
Content you upload
Video files, thumbnails, banners, avatars and the text you write for them, stored so you can reuse them across uploads.
Technical records
Server logs with request paths, timestamps and IP addresses, kept for operating and debugging the service. A session cookie and browser local storage hold your sign-in session and interface preferences, such as language and theme. No advertising or tracking cookies are used, and no third-party analytics scripts run on this site.
How the data is used
Solely to provide the features you asked for: showing your channels and videos, publishing and editing them on your instruction, and displaying your own analytics. The application does not use your data to build advertising profiles, and it does not sell, rent or trade it.
Limited Use of Google user data
The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, this means:
- Google user data is used only to provide and improve the features described above, which are visible to you in the interface.
- Google user data is not transferred to others except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition, and never for advertising.
- Google user data is not used for serving advertisements of any kind.
- No human reads your Google user data, except with your explicit permission, for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymised.
- Google user data is not used to develop, improve or train generalised artificial intelligence or machine learning models.
Third parties
The application runs on infrastructure controlled by its administrator. It has no advertising partners and no data brokers.
Some optional features generate text or images with third-party AI providers. When you use them, the material you supply for that generation — such as your own prompt, a reference image, and the publicly visible name and description of the channel you are generating for — is sent to the provider for the sole purpose of producing the result you requested. Your OAuth tokens and your channel's analytics are never sent to these providers, and nothing sent to them is used to train models on your behalf.
How long data is kept
- OAuth tokens — until you disconnect the channel, revoke access in your Google Account, or your account is deleted. Disconnecting revokes the token with Google and removes it from the database.
- Channel, video and analytics records — until you delete the channel from the workspace or your account is deleted.
- Uploaded media — until you delete it.
- Server logs — rotated and discarded on a rolling basis, and not used to build any profile of you.
Removing access and deleting your data
You can disconnect any channel from inside the application at any time, which revokes the token and deletes the stored analytics for that channel. You can also revoke the application's access directly in your Google Account at myaccount.google.com/permissions.
To have your account and everything associated with it deleted, write to privacy@yt.wholelayer.com. Deletion is permanent.
Security
Traffic is served over HTTPS. OAuth tokens and other secrets are encrypted at rest. The workspace itself sits behind an additional gateway password, and each user signs in with their own account and sees only their own channels. No system is perfectly secure, and no absolute guarantee is offered.
Children
The application is not directed at children and is not made available to them. Accounts are issued individually by the administrator.
Changes to this policy
If this policy changes, the date at the top of the page is updated. If a change materially affects how your data is handled, users are notified before it takes effect.
Related terms
Use of the application is also governed by the terms of use, the YouTube Terms of Service and the Google Privacy Policy.