YT Accounts

Privacy Policy

Last updated: 27 August 2026

YT Accounts ("the application") is a private, invitation-only workspace used to manage YouTube channels that belong to its users. This policy explains what the application collects, why, how long it keeps it, and how you remove it. You must agree to this policy before you can use the application.

Who is responsible

The application is operated privately by its administrator, who can be reached at privacy@yt.wholelayer.com. There is no company, no advertising network and no analytics vendor behind it.

What the application collects

Your account in the application

A username, an email address and a password hash. The password itself is never stored. Accounts are created by the administrator; there is no public registration.

Data obtained through Google APIs

When you connect a YouTube channel, you are sent to Google to sign in and to approve access. The application never sees your Google password. Google returns access and refresh tokens, which are stored encrypted at rest. With them the application accesses:

Content you upload

Video files, thumbnails, banners, avatars and the text you write for them, stored so you can reuse them across uploads.

Technical records

Server logs with request paths, timestamps and IP addresses, kept for operating and debugging the service. A session cookie and browser local storage hold your sign-in session and interface preferences, such as language and theme. No advertising or tracking cookies are used, and no third-party analytics scripts run on this site.

How the data is used

Solely to provide the features you asked for: showing your channels and videos, publishing and editing them on your instruction, and displaying your own analytics. The application does not use your data to build advertising profiles, and it does not sell, rent or trade it.

Limited Use of Google user data

The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, this means:

Third parties

The application runs on infrastructure controlled by its administrator. It has no advertising partners and no data brokers.

Some optional features generate text or images with third-party AI providers. When you use them, the material you supply for that generation — such as your own prompt, a reference image, and the publicly visible name and description of the channel you are generating for — is sent to the provider for the sole purpose of producing the result you requested. Your OAuth tokens and your channel's analytics are never sent to these providers, and nothing sent to them is used to train models on your behalf.

How long data is kept

Removing access and deleting your data

You can disconnect any channel from inside the application at any time, which revokes the token and deletes the stored analytics for that channel. You can also revoke the application's access directly in your Google Account at myaccount.google.com/permissions.

To have your account and everything associated with it deleted, write to privacy@yt.wholelayer.com. Deletion is permanent.

Security

Traffic is served over HTTPS. OAuth tokens and other secrets are encrypted at rest. The workspace itself sits behind an additional gateway password, and each user signs in with their own account and sees only their own channels. No system is perfectly secure, and no absolute guarantee is offered.

Children

The application is not directed at children and is not made available to them. Accounts are issued individually by the administrator.

Changes to this policy

If this policy changes, the date at the top of the page is updated. If a change materially affects how your data is handled, users are notified before it takes effect.

Related terms

Use of the application is also governed by the terms of use, the YouTube Terms of Service and the Google Privacy Policy.

Contact

privacy@yt.wholelayer.com