Privacy Policy
Effective date: 4 October 2026 · Version 2
1. Scope and contact
This policy covers YouTube Portfolio Automation, a private Google Apps Script application for one configured owner. The operator is QaaS — private channel project; it does not identify a registered legal entity. Privacy contact: eldar.aslanbeily@gmail.com.
The app uses YouTube API Services. Google's handling of information is described in the Google Privacy Policy. These information pages do not grant access to the private app.
2. Current deployment and consent
The currently deployed app supports authorization setup and channel-ID verification only. At this review checkpoint no channel grant is connected. It cannot upload, publish or collect analytics, and the policy-v2 publisher and daily privacy-maintenance process are not installed.
The app checks the signed-in and execution account email against its configured owner. Private configuration holds the allowed channels. A consent attempt uses a temporary request value, a Google user identifier and a timestamp to validate the callback. A completed grant would store OAuth access and refresh tokens, granted permissions, the verified channel ID, connection state, check time and configuration fingerprint. Google handles account sign-in; the app does not collect Google passwords.
The new candidate requires configured public policy links, a policy version and explicit policy agreement before its feature or consent operations. Acceptance of this policy alone does not install the candidate or grant Google access.
3. Permissions
Offline integrated candidate: channel authorization requests only youtube.force-ssl. It supports channel verification, private upload, video-processing checks and authorized visibility or scheduling changes. The permission also permits broader YouTube changes than the candidate implements, so access is limited by the app's owner, channel and release checks. No analytics permission is requested.
The candidate's controller requests permission for external service requests, the owner's email and drive.file for its app-created private video files and queue spreadsheet, including storage-quota checks. It does not request account-wide Drive access. See Google's Drive permission documentation.
script.scriptapp is needed only for a separately approved installation of the optional daily privacy-maintenance trigger. That trigger refreshes or erases cached API data and retries revocation; it does not upload or publish.
The older authorization-only deployment predates this scope reduction. Its configuration includes youtube.readonly, youtube.force-ssl and unused yt-analytics.readonly. It must be replaced or reduced before channel authorization; future features do not justify an unused permission.
4. Candidate data flow and storage
- Original media: the owner selects a local MP4. The candidate transfers it through Apps Script to an app-created private Drive file, checking file integrity, ownership and sharing. These files are owner-created media.
- Original release plans: a private Google Sheet holds owner-supplied channel and media selections, title, description, tags, language/category information, audience and synthetic-media choices, release authority, integrity bindings and local pre-dispatch checkpoints that help avoid duplicate submissions. It is not a history of API-returned upload receipts.
- API data: returned video IDs, processing/privacy observations, transfer offsets, resumable-session addresses and scheduling/upload receipts and video-ID-bound scheduling approvals are held in bounded private Apps Script User Properties. They are kept out of the Sheet's original plans and history. Channel identity-verification records also have expiry checks.
- Transfer to YouTube: after authorization and release checks, the candidate sends video bytes and metadata to YouTube as a private upload. Any later public, unlisted or scheduled publication requires the applicable release authority and platform/audit gates. Public publication exposes the video and relevant metadata to its YouTube audience.
Client configuration is stored in Script Properties. Tokens and operational records are in User Properties, with the official OAuth2 library also using the owner's user cache. Token values and resumable transfer addresses are not returned to the browser interface.
The intended boundary is an unshared script and an owner-only deployment. A script editor could change owner-executed code to access data; these stores are not a separate secret vault. API traffic uses HTTPS. There is no separate app-managed encryption layer or independently verified at-rest security claim. Apps Script may retain platform execution/error records outside the app's retention controls; reviewed code does not intentionally log tokens, raw provider responses or media.
5. Who receives information
App data is sent to Google's authorization, Apps Script and YouTube services; the publisher candidate also uses Google Drive and Sheets. The reviewed app does not send Google API data to an advertising service, data broker, external analytics service or AI-model service. Its private API cache and video files are not hosted by this information website.
If you email the privacy contact, the operator receives your email address and the message you send, through the email service. Include only what is needed to identify and resolve your request. Do not email passwords, tokens or authorization links.
6. This website and hosting
These static pages are hosted with OpenAI's ChatGPT Sites on Cloudflare infrastructure. Their source has no forms, advertising pixels, analytics scripts or embedded videos, and sets no cookies itself. That does not mean the hosting or sign-in layer is cookie-free.
OpenAI and Cloudflare may process request and security information such as IP addresses, browser/device details, request times and traffic information to serve and protect the website. OpenAI sign-in and hosting/security services may use cookies or similar technologies. Exact cookies depend on the services and settings involved; the operator has not independently audited all host-level logs or cookies and cannot set their retention through this static page.
See OpenAI's Privacy Policy, OpenAI's Cookie Policy, Cloudflare's Privacy Policy and Cloudflare's cookie documentation. Google sign-in and the private Apps Script interface are separate services and may use Google's platform cookies.
7. Limited Use commitment
YouTube Portfolio Automation's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.
Google API data will be used only for disclosed, authorized app features. It will not be sold, used for advertising or credit decisions, or used to train general-purpose AI models. Additional human access or transfers will be limited to the purposes and permissions allowed by that policy, including legally required disclosures where applicable. An additional recipient or use requires review before it begins.
8. Stop access and delete app-held API data
You can revoke access in Google Account security permissions. Review both the Apps Script controller and channel OAuth connections where applicable. Google explains connection management here.
Candidate control, not yet installed: the app-wide disconnect action immediately blocks further app work and clears its API cache and channel-verification records. It prepares durable revocation work before resetting local tokens, then attempts Google's revocation endpoint. Revocation can affect all OAuth clients and scopes in the same Google project, not just a selected channel.
If Google cannot confirm revocation, the candidate reports an unresolved issue rather than success. A token may be retained privately only to retry revocation. The candidate's maintenance code removes retry tokens after an internal five-day cutoff when it runs; unresolved provider or token-reset failures still require the operator to finish cleanup and check Google Account permissions.
Revoking Google's access does not itself erase all app-stored records. If the dashboard is unavailable, email the privacy contact so the operator can stop work, remove app-held Google API data and tokens, and verify completion. The deployed older authorization-only version does not have the candidate's app-wide deletion control.
9. Original files, plans and YouTube videos
Disconnecting does not silently delete original MP4s, owner-written release plans or videos already held by YouTube. Original media and plans can remain in the owner's Drive/Sheet until the owner explicitly requests their deletion. A request to delete those originals must be handled separately and coordinated with any in-progress upload. API-derived receipts are treated separately from these originals.
Deleting app-held records does not delete YouTube content or data retained by Google under its own policies. Manage existing videos directly in YouTube Studio, including videos published outside this app.
10. Retention commitments
The operator is responsible for these deadlines:
- Remove app-held Google API data promptly and within seven calendar days after an explicit deletion request or in-app revocation.
- After revocation through Google, remove associated app-held API data promptly and within thirty calendar days; regularly check authorization so revocation is detected.
- Refresh or delete stored non-statistical YouTube API data within thirty calendar days. Retain authorization tokens only as needed for authorized active use or the bounded revocation process.
These commitments reflect the YouTube developer policies. They cover the app's stored API data, not deletion from Google's systems or automatic destruction of original creative files.
11. Maintenance limits and operator fallback
The offline candidate expires API caches and identity bindings at twenty-eight days when its code runs. It can separately install a daily privacy-maintenance trigger, with explicit approval and an additional permission. Maintenance refreshes actual API observations, checks the original channel/grant binding, removes missing or revoked data and clears orphaned sessions. Missing or stale maintenance setup blocks candidate publishing operations.
This is not an autonomous storage expiry guarantee. If the controller's permission is revoked, the trigger is missing, or execution fails, code may not run to perform cleanup. The operator must monitor execution and unresolved revocations and manually complete deletion or refresh within the approved deadlines. No external failure-alert delivery is implemented. Trigger, revocation, deletion and private-upload checks must be validated on the real deployment before unattended operation.
The candidate has been tested offline only. No live retention performance, uninterrupted operation, six-month reliability or unattended production-to-publication pipeline is claimed.
12. Changes and questions
Before new data uses or permissions begin, the operator will update this policy and obtain required consent. Contact eldar.aslanbeily@gmail.com with questions, complaints or requests. This policy does not claim Google verification, a completed YouTube API audit or legal compliance certification.