Privacy Policy
Last updated: 13 September 2026
This Privacy Policy explains what data Shorts Otopilotu (the "Application") collects, how it is used, stored and deleted. The Application is an internal tool operated by Muhammet Umut Aksoy (the "Operator") to manage YouTube channels owned by the Operator. It has no third-party users.
1. Use of YouTube API Services
The Application uses YouTube API Services (the YouTube Data API and the YouTube Analytics API). By using the Application, the user (the Operator) agrees to be bound by the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy.
2. Data the Application accesses
- Public YouTube data (no user authorization required): titles, descriptions, thumbnails, publication dates and public view/like/comment counts of videos on publicly listed channels in the same content niche, and public channel metadata. This data is used only to measure which story topics perform well.
- Authorized data (OAuth 2.0, granted by the Operator for each owned channel): permission to upload videos and set their metadata on the Operator's own channels (
youtube.upload, youtube), and read-only access to the Operator's own channel analytics (yt-analytics.readonly). The Application never accesses any other Google account and never acts on channels not owned by the Operator.
- OAuth tokens: refresh and access tokens issued by Google for the Operator's channels.
3. How data is used
- Public statistics are used to compute internal, clearly labeled derived metrics (for example, how a video's view count compares with its channel's typical view count). These metrics are generated by the Application and are not sourced directly from YouTube.
- Authorized data is used solely to upload and schedule the Operator's own videos and to read the Operator's own channel performance.
- No data is sold, shared with third parties, or used for advertising. No data is used to train machine-learning models.
4. Storage and retention
- Data is stored in a private database on a server controlled by the Operator (hosted in the European Union).
- Public statistical data (view, like and comment counts) and derived metrics may be retained for up to 36 calendar months. Other public metadata (video titles, descriptions, channel names) is refreshed or deleted within 30 days.
- Authorized data (the Operator's own channel analytics) is retained only as long as needed for reporting and is deleted when the related channel is removed from the Application.
- OAuth tokens are stored on the Operator's access-controlled server with restricted file permissions (readable only by the Application's service account) and are never transmitted to anyone other than Google.
5. Cookies and third parties
The Application has no web interface for end users and sets no cookies. Besides YouTube API Services, the Application sends the text of its own video scripts to third-party AI text services to draft on-screen captions; no YouTube user data or authorized data is included in those requests.
6. Revoking access and deleting data
- You can revoke the Application's access to your Google account at any time from the Google security settings page (myaccount.google.com/permissions). Revocation immediately stops all uploads and analytics reads for that channel.
- To request deletion of any stored data, email muhammetumutaksoy@gmail.com. Requests are fulfilled within 7 days.
7. Google API Services User Data Policy
The Application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Changes and contact
Changes to this policy are posted on this page with a new "last updated" date. Questions: muhammetumutaksoy@gmail.com.