Youtio
Privacy Policy
Last updated: July 24, 2026
Youtio (“Youtio”, “we”, “us”) is a web application and Chrome extension that helps YouTube creators optimize video titles, descriptions, tags, and related metadata using artificial intelligence.
This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to our website, dashboard, APIs, and the Youtio Chrome extension.
Service website: https://youtio.com
1. Information We Collect
We collect information that you provide directly, information created when you use the Service, information read from YouTube Studio or YouTube APIs when you ask us to, and limited technical data needed to operate and secure the Service.
2. Information You Provide
- Account details: name, email address, and a password hash (for email registration) or a Google sign-in marker (for Google login).
- Profile data you choose to add, such as an avatar image and optional brand or channel style notes.
- Optional image-generation API keys that you paste in your profile (stored encrypted). You may remove them at any time.
- Content you submit for optimization: video URL, title, description, tags, transcript text, target audience, tone, video type, competitor titles, and similar inputs.
- Messages you send through the contact or feedback form (email and message body).
- Plan and credit-related preferences shown in your account (plan type, monthly limits, usage counters).
3. Information Collected Through the Chrome Extension
When you use the Chrome extension on YouTube Studio, the extension can read fields from the open Studio page (such as title, description, tags, page URL, and video ID) and send them to our servers when you run an analysis or apply results.
The extension stores your session token, UI language, and theme preferences in Chrome extension storage so you stay signed in. It may also read our session cookie on youtio.com to sync login after Google sign-in.
The extension does not scrape unrelated browsing history. It operates on YouTube Studio pages you open and calls our API and YouTube transcript endpoints as needed for the features you trigger.
4. Google and YouTube Data
Google Sign-In uses OAuth scopes limited to openid, email, and profile. We receive your Google account email, name, and subject identifier as provided by Google’s userinfo endpoint to create or sign you into a Youtio account.
Separately, when you connect a YouTube channel (“Connect channel”), we request YouTube read-only access (youtube.readonly) plus basic profile scope. We store channel identifiers and metadata such as channel name, channel URL, thumbnail URL, subscriber count, and video count, together with OAuth access and refresh tokens.
Access and refresh tokens for connected channels are encrypted at rest (AES-256-GCM) before storage in our database. Login session JWTs are stored in an HttpOnly cookie on the website and, for the extension, also in Chrome storage after cookie sync.
Video title, description, tags, transcript, and Studio field values are processed when you request generation or automation. They are used only to provide the features you request (optimization, applying metadata, usage accounting).
We do not sell Google or YouTube user data. We do not use Google user data for advertising. We do not use Google user data for unrelated purposes.
We design the product so Google/YouTube data is processed by automated systems. Authorized operators may access account or log records when needed for support, security, abuse prevention, or legal compliance—not for advertising.
You can remove a connected YouTube channel from Youtio (channel delete in the product). That deletes the stored channel row and encrypted tokens, and we attempt to revoke the OAuth token with Google. You can also revoke Youtio’s access in your Google Account permissions at https://myaccount.google.com/permissions.
Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements, for the scopes we request.
5. How We Use Information
- Provide accounts, authentication, and plan/credit enforcement.
- Generate and return AI suggestions and apply them when you ask.
- Sync and display connected YouTube channels you authorize.
- Operate rate limits, prevent abuse, and diagnose failures.
- Respond to contact/feedback messages.
- Improve reliability and user experience of the Service (without selling personal data).
6. Artificial Intelligence Processing
When you run a generation, we send relevant inputs (for example title, description, transcript excerpts, tags, tone, language, and channel style notes) to third-party AI providers so they can return suggestions.
Text generation currently uses OpenAI and/or Google Gemini, selected by our server configuration. Thumbnail image generation may use OpenAI, Google Gemini, and/or fal.ai—either via Youtio’s configured server keys or via an encrypted API key you supply.
We do not operate our own foundation model trained on your private video content. Whether a third-party provider uses API inputs to improve their models is governed by that provider’s terms and settings; we do not independently verify each provider’s training practices for every request.
Generated outputs (titles, descriptions, tags, keywords, hashtags, thumbnail ideas/prompts/images, scores where enabled) may be stored in your account history so you can review them later.
7. Third-Party Service Providers
We use infrastructure and AI vendors to run the Service. The table lists providers wired into this product. Payment checkout endpoints exist in code but are not completed for live card processing at the time of this policy; paid plans may be activated manually by an administrator.
| Service Provider | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|
| Vercel | Host the website and API | HTTP requests, logs typical of hosting platforms | Link |
| Supabase (PostgreSQL) | Primary application database | Account, channel, generation, usage, and related records | Link |
| Google OAuth / YouTube Data API | Sign-in and optional channel connect | Profile/email for login; channel metadata and OAuth tokens when connected | Link |
| OpenAI | AI text and optional image generation | Prompts and content you submit for generation | Link |
| Google Gemini (Google AI) | AI text and optional image generation | Prompts and content you submit for generation | Link |
| fal.ai | Optional image generation (if selected) | Image prompts / references when that provider is used | Link |
| TranscriptAPI | Optional server-side transcript fetch (when configured) | Video ID / public caption data needed to retrieve a transcript | Link |
9. Data Retention
- Account profile data is retained while your account remains open.
- Connected YouTube channel records and encrypted tokens are retained until you disconnect the channel or delete your account.
- Generation history, usage logs, templates, favorites, and similar product records are retained while your account is active so features work (history, limits, support).
- After you delete your account through the in-product Delete Account flow, we permanently delete your user profile, connected channels and tokens, generations, and related account-owned records from the application database as part of that request.
- Limited server or security logs held by our hosting provider may persist for a short operational period according to that provider’s systems and are not used to rebuild your account.
- If we are legally required to keep a record (for example a billing dispute or abuse investigation), we retain only what is necessary for that purpose.
10. Data Security
We use HTTPS in production, HttpOnly session cookies for web login, password hashing for email accounts, encryption for stored YouTube OAuth tokens and optional user image API keys, and server-side authorization for paid features and credits.
No method of transmission or storage is 100% secure. Please protect your account credentials and revoke Google access if you suspect misuse.
12. Chrome Extension Permissions
The store build of the extension requests only the permissions required for its features:
- storage — save login session and extension preferences.
- cookies — sync the Youtio web session cookie after Google login.
- activeTab & scripting — inject/communicate with YouTube Studio on the active tab to read and apply metadata.
- sidePanel — show the Youtio panel beside Studio.
- Host access to studio.youtube.com — content script and Studio automation.
- Host access to youtube.com — fetch public timedtext/transcript data when you analyze a video.
- Host access to ytimg / ggpht thumbnail hosts — display or handle thumbnail images shown in Studio.
- Host access to youtio.com — call Youtio APIs for auth, generation, and account data.
13. User Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. You can update profile information in the dashboard, disconnect YouTube channels, remove optional API keys, and delete your account.
You may also email support@youtio.ai to request access or deletion. We may need to verify that the request comes from the account owner.
14. Account and Data Deletion
You can delete your account from Dashboard → Profile → Delete Account, or from the Chrome extension Account tab. Deletion asks for explicit confirmation, removes connected YouTube channels and stored tokens, deletes your profile and related product data as described above, signs you out, and cannot be undone.
You can also request deletion by emailing support@youtio.ai from the address on your account. See also https://youtio.com/data-deletion.
15. International Data Transfers
Our application is hosted on Vercel and stores data in a Supabase-hosted PostgreSQL database. AI providers process prompts on their infrastructure. This may involve processing outside your country. By using the Service you understand that such transfers are necessary to operate Youtio.
16. Children’s Privacy
Youtio is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child created an account, contact us and we will delete it.
17. Changes to This Privacy Policy
We may update this Policy when the product or legal requirements change. The “Last Updated” date at the top will change. Continued use after an update means you accept the revised Policy for future use of the Service.
18. Contact Information
Privacy and data requests: support@youtio.ai
Website: https://youtio.com
Contact form: https://youtio.com/contact