Privacy Policy
This policy explains how the operator of ytapi.dev (“YTAPI”, “we”) processes personal data on the website and dashboard at ytapi.dev, the documentation at docs.ytapi.dev, the public demo, and the API at api.ytapi.dev. Contact [email protected]. The registered name and postal address of the operator will be published on this page when it is available. Until then, the controller is the operator of those hostnames.
We are the controller for account, billing, and service-operation data. When a customer uses the API to retrieve public YouTube content that contains personal data, the customer decides why that content is retrieved. Business customers can request a data processing agreement at the same address. We do not sell personal data.
1. What we process and why
| Data | Why | Legal basis (GDPR) | How long |
|---|---|---|---|
| Name, email, avatar, sign-in provider id, session token, session IP address and user agent | Create and secure your account, send transactional email | Contract, Art. 6(1)(b) | Until you delete the account |
| One-time sign-in codes, stored as a hash | Sign you in by email | Contract, Art. 6(1)(b) | Until used, or 10 minutes |
| Sign-in code requests and agent sign-ups: a keyed hash of the email address and of the IP address, and the time | Limit how often codes are requested and stop automated signups | Legitimate interest, Art. 6(1)(f) | Deleted after about two days |
| Normalized email address (lowercase, without a +tag, and for Gmail without dots), the signup credits given, the account id, and how the account signed up | Give signup credits once per mailbox | Legitimate interest, Art. 6(1)(f) | Kept after the account is deleted, for as long as we give signup credits, so the same mailbox does not receive them again |
| OAuth access tokens from Google or GitHub, if you use those providers | Sign you in | Contract, Art. 6(1)(b) | Until you disconnect the provider or delete the account |
| API key hash, prefix, last four characters, scopes, expiry, rate-limit settings, last-used time | Authenticate requests and apply the limit your pack paid for | Contract, Art. 6(1)(b) | Until you delete the key or the account. The full key is shown once and is not stored |
| Credit balance and credit ledger (purchases, playground use, API consumption, refunds) | Meter the Service and explain a charge | Contract, Art. 6(1)(b); legal obligation for tax records, Art. 6(1)(c) | Ledger entries for payments are kept for the tax retention period that applies to the operator. Other ledger entries follow the account |
| API request log: time, endpoint, method, status, latency, credits, cache status, IP address, video id, error code | Operate the API, show usage, investigate abuse and billing disputes | Contract, Art. 6(1)(b); legitimate interest, Art. 6(1)(f) | 31 to 62 days. Logs are deleted a calendar month at a time, once the newest entry of that month is 31 days old. The credit ledger keeps the credits used |
| Connected apps: the app's registration (name and return URLs), your approval, access and refresh tokens stored only as SHA-256 hashes, and a key record that requests from the app are logged and billed under | Let an app you approve, such as Claude, call the API for you without an API key | Contract, Art. 6(1)(b) | Access tokens expire after 1 hour and refresh tokens after 90 days. Your approval and the tokens are deleted when you disconnect the app or delete the account |
| Batch job status and results, which can include transcript text and metadata you asked for | Run the job and let you poll it | Contract, Art. 6(1)(b) | Until you delete the account or ask us to delete the job |
| Cached API responses, including transcript text, in a shared server cache | Answer a repeated request quickly | Legitimate interest, Art. 6(1)(f) | Up to 30 days |
| Stripe customer id, Checkout Session id, price id, payment status, dispute and refund identifiers. Card numbers stay at Stripe | Take payment, credit your balance, handle a refund or dispute | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) | Payment records for the tax retention period that applies to the operator |
| Messages you send through the contact form or to [email protected] | Answer you | Contract or legitimate interest, Art. 6(1)(b) or (f) | Until the request is resolved, then up to 24 months |
| Public-demo request: video id, IP address, Turnstile result | Run the demo and stop automated abuse | Legitimate interest, Art. 6(1)(f) | The IP limiter is kept in memory on the web process and is not a long-term profile |
| Server and security logs | Keep the sites available and investigate incidents | Legitimate interest, Art. 6(1)(f) | About 30 days, unless we need a specific log for a security incident |
Signup credits and pack purchases are tied to the user account, not to a separate organization balance.
We measure how the website and dashboard are used with Umami Cloud, a cookieless analytics service, using its EU region. It records the pages viewed, the referring site, the country (derived from the IP address, which Umami does not store), browser and device type, and a few interactions we choose to count, such as which credit pack is selected or whether the demo returned a transcript. It sets no cookies, does not identify you, and does not follow you across other sites. Legal basis: our legitimate interest in understanding and improving the site, Art. 6(1)(f) GDPR. We do not use Google Analytics, advertising pixels, or session replay.
Transactional email (sign-in codes and account mail) is part of the Service. We do not send a marketing newsletter from the product as it runs today. The contact form is only the message you submit.
2. Cookies and similar storage
The dashboard uses a sign-in session cookie. It is required to keep you logged in. The public demo and the sign-in page use Cloudflare Turnstile, which may store a bot-detection cookie under Cloudflare’s terms. We do not ask you to accept an advertising cookie because we do not set one.
3. Processors and places
We use processors who act on our instructions:
| Processor | Role | Where processing can occur |
|---|---|---|
| Hetzner | Servers for the API, database, dashboard, and cache | Germany (Nuremberg) and the EU |
| Cloudflare | DNS, documentation hosting, Turnstile, and the egress network that fetches public YouTube data | Global, including the United States |
| Stripe | Payments, receipts, disputes | United States and other Stripe locations |
| Optional sign-in | United States and Google locations | |
| GitHub | Optional sign-in | United States and GitHub locations |
| Resend | Transactional email | United States |
| Umami | Cookieless website analytics | European Union (Umami Cloud EU region) |
YouTube receives the traffic required to fetch a public page or player response. That fetch is how the API works. We send the video, channel, or playlist identifier, not your account email, to YouTube.
Where a processor is outside your country, we rely on that processor’s Standard Contractual Clauses or an equivalent safeguard the processor offers, such as the EU-US Data Privacy Framework where the processor is certified. We disclose data when the law requires it, and to enforce the Terms.
4. API content
Customers use the API to fetch publicly available YouTube transcripts and metadata. A response can contain personal data that a speaker or channel put in a public video. The customer is responsible for having a legal basis for what they do with that response.
We cache successful responses for performance, for up to 30 days, in a shared cache that is not encrypted as a separate per-customer vault. Batch results are stored against the account so you can poll them. To ask for a video’s cached copy or a batch result to be deleted, email [email protected] with the video id or job id. Deletion from our cache does not remove the video from YouTube.
5. Your rights
If the GDPR or a similar law applies, you can ask to access, correct, or delete your personal data, to restrict or object to processing, to receive a portable copy, and to withdraw consent where processing is based on consent. You can delete the account in the dashboard settings. Deletion removes the account, keys, and the data that is stored only for that account. We keep records we are legally required to keep, including payment records, and we may keep a specific log while a fraud, chargeback, or security investigation is open.
Email [email protected]. We respond within one month. If a request is complex, we may extend that by up to two months and will tell you within the first month. We may ask you to prove you control the account. You can also complain to the data protection authority where you live or where the operator is established.
6. Security
The API is served over HTTPS. API keys and the tokens of connected apps are stored as a SHA-256 hash. A connected app gets the YouTube data its requests return; we do not give it your email address, billing details or other account data. Stripe stores card data; we store the customer and session identifiers. Staff access to production is limited to the people who operate the servers.
No method of transmission or storage is perfectly secure. Tell us at [email protected] if you believe a key or account has been exposed, and revoke the key in the dashboard.
7. Children
The Service is for developers and businesses. We do not knowingly create accounts for anyone under 16. If you believe we have, write to us and we will delete the account.
8. Changes
We will update this policy when the Service or the law changes. The date below is the current version. Continued use after the new date means you have the updated policy. A change that starts a new kind of processing will be described here before it starts.
Version 2.2 · 8 October 2026