← Back to TubePush

Privacy Policy

Last updated: July 24, 2026

This policy explains what Aadit Shah ("we") collects when you use TubePush, where it's processed, how long we keep it, and the choices you have. Plain-language summary: we collect your email and the data needed to generate and push YouTube metadata; your video transcripts are sent to a third-party AI provider (OpenAI) to generate the output; we don't sell your data.

1. What we collect

Account data: your email address, and — if you sign in with Google — your name and profile picture from Google OAuth.

YouTube channel data: if you connect a channel (or paste a public channel link), we store your channel ID, name, avatar, and subscriber count, and fetch up to your last 30 videos' titles, descriptions, tags, and view counts to build an AI profile of your channel. If you connect via OAuth, we store your OAuth tokens encrypted (AES-256-GCM).

Video transcripts & generation data: to generate metadata we fetch the transcript of the video you submit and store a history of your generations (the input, the generated title/description/tags, the AI model used, token counts, and latency).

Prompt profiles: the tone, keywords, writing style, and examples you save.

Billing data: your DodoPayments customer ID and subscription/credit status. We never receive or store your full card details — DodoPayments handles those.

Product analytics: with your consent, pages viewed and in-app actions plus basic device/browser info are collected via PostHog (see §6). We also record a limited set of server-side transactional events, such as signup, generation, and purchase completion, to operate and troubleshoot the Service; these do not use an analytics cookie or include transcript content. Aggregate, cookieless traffic metrics are collected via Vercel Analytics.

2. How we use it

  • authenticate you and keep you signed in;
  • generate SEO-optimized titles, descriptions, and tags;
  • build a channel fingerprint to personalize the output;
  • push metadata to YouTube only when you ask us to;
  • track your generation usage against your plan;
  • process payments and prevent abuse of free generations;
  • understand product usage and fix problems.

We do not sell your personal data, and we do not use it for advertising.

3. Sending transcripts to an AI provider

To generate metadata, the transcript and relevant channel data for the video you submit are sent to OpenAI, a third-party AI provider, for processing. This is core to how the Service works. OpenAI processes this data to return the generated output; its handling of that data is governed by OpenAI's own terms and privacy policy. Transcripts are retrieved through a third-party transcript provider (transcriptapi.com). Please don't submit videos whose transcripts contain sensitive personal information you don't want processed this way.

4. Where your data is processed

TubePush is operated by a solo founder based in India and serves users globally, so your data may be processed in countries other than your own, including the United States and India. Our main processors and their roles:

  • Neon (PostgreSQL) — primary database, hosted in the US (AWS us-east-1).
  • Vercel — application hosting and cookieless traffic analytics.
  • OpenAI (US) — generates metadata from transcripts and channel data.
  • transcriptapi.com — retrieves YouTube transcripts.
  • DodoPayments — Merchant of Record; processes payments and taxes.
  • PostHog (US) — product analytics (see §6).
  • Upstash (Redis) — rate limiting; no personal profile data stored.
  • Resend — sends sign-in and transactional emails.
  • Sentry — error monitoring in production.

Where required, transfers rely on appropriate safeguards (such as standard contractual clauses offered by these providers).

5. YouTube API data

TubePush uses YouTube Data API Services. Data we obtain from YouTube is used solely to provide the Service and is not shared with third parties except the AI processing pipeline described above. TubePush's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke our access anytime via Google Account Permissions.

6. Cookies & analytics

Essential cookies keep you signed in (session) and protect OAuth flows (CSRF). These are always on and required for the Service to work.

Analytics cookies come from PostHog, which we use to understand product usage. PostHog stores an identifier and may set a cookie. We only initialize browser-side PostHog analytics after you accept via the cookie banner; if you decline, browser behavior and page-view events are not sent to PostHog. A small number of cookie-free, server-side transactional events (for example signup, generation, and purchase completion) may still be recorded for service reliability and fraud prevention. Vercel Analytics is cookieless and used for aggregate traffic only. We do not use advertising or cross-site tracking cookies.

7. Data retention

We keep your account and related data while your account is active. Ingested channel videos are stored to maintain your AI profile and refreshed over time. If you delete your account, your profiles, generation history, channel data, and OAuth tokens are permanently deleted, within 30 days at the latest. Some records DodoPayments holds as Merchant of Record (e.g. transaction/tax records) may be retained by them to meet their legal obligations.

8. Your rights

Depending on where you live (for example under the EU/UK GDPR or India's DPDP Act), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can delete your account and all associated data anytime from the Settings page. For any other request, email info@tubepush.io and we'll respond within a reasonable time. You can also revoke YouTube access at Google Account Permissions.

9. How we protect your data

We apply the following safeguards to sensitive data, including the YouTube account data and OAuth tokens described in §1 and §5:

  • Encryption in transit: all connections to TubePush and to our processors (Google/YouTube, OpenAI, Neon, DodoPayments) use TLS/HTTPS.
  • Encryption at rest: your YouTube OAuth access and refresh tokens are encrypted with AES-256-GCM before being stored in our database; the decryption key is held only in server-side environment configuration and is never exposed to the client or logged.
  • Access controls: production database and infrastructure access is limited to the founder; no third party has standing access to raw user data. Application code only decrypts YouTube tokens at request time, server-side, to make the specific API call needed (e.g. fetching or updating your video metadata).
  • Scope limitation: we request only the YouTube API scopes needed to analyze your channel and push metadata updates that you initiate; we never take actions on your channel you haven't explicitly requested.
  • Data minimization & deletion: tokens and channel data are deleted when you disconnect your channel or delete your account (see §7), and revoking access via Google Account Permissions immediately invalidates our stored tokens.
  • Monitoring: production errors are tracked via Sentry to detect and respond to issues; Sentry is configured not to receive transcript content or OAuth tokens.

10. Children

TubePush is not intended for anyone under 18, and we don't knowingly collect data from children.

11. Changes & contact

We may update this policy; we'll change the date above and, for material changes, notify you where appropriate. Questions or requests: info@tubepush.io. TubePush is operated from Mumbai, Maharashtra, India, by a solo founder acting as data controller.