Privacy Policy
Last updated: August 24, 2026
WhatToUpload ("we") is an AI planning tool for YouTube creators at whattoupload.com. This policy explains what we collect, why, and the controls you have. The short version: your creative data exists to personalize your own workspace, you can see and delete everything we learn about you, and we never sell your data.
What we collect
Account information: your name, email address and password hash (or your Google account identity if you sign in with Google).
Content you create in the product: ideas, packaging directions, scripts, research notes, calendar entries and your creator profile (what you make, who for, tone).
Creative decisions: when you save, select, edit or reject AI-generated options, we record those decisions to personalize future suggestions. This is the product's core feature ("Creator Brain").
Usage analytics: we use Vercel Analytics (page views), Google Analytics (traffic sources and page views) and Microsoft Clarity (anonymized session interactions such as clicks and scrolls, to find usability problems). These help us improve the product; we do not sell this data or use it to build advertising profiles.
YouTube data
WhatToUpload uses the YouTube API Services. By connecting your YouTube channel you agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms). Google's Privacy Policy applies at https://policies.google.com/privacy.
If you choose to connect your YouTube channel, we request read-only access and import: your channel name, avatar, subscriber count, your uploaded videos' titles, descriptions, thumbnails, publish dates and public statistics (views, likes, comments). We never gain the ability to upload, edit, delete or comment on your behalf.
This data is used solely to personalize your own workspace, for example by learning your title patterns and suggesting follow-up ideas. It is never shared with other users or third parties, and is not used for advertising.
You can disconnect at any time from the Channel page, which revokes our access with Google and stops all further syncing. You can also revoke access from your Google security settings at https://myaccount.google.com/permissions. Upon disconnection you may request deletion of previously imported YouTube data (see Your rights below); stored API data is refreshed or deleted in line with the YouTube API Services policies.
How we use your data
- To provide the product: generating ideas, titles, packaging, scripts and research personalized to you.
- To power your Creator Brain: your decisions inside the app are converted into preferences with confidence scores, visible and editable by you.
- AI processing: content you submit (ideas, briefs, profile context) is sent to our AI model providers to generate results. Providers process it as data processors and it is not used to train their public models per their API terms.
- We do not sell your data. We do not share it with advertisers.
Your rights and controls
- Inspect and correct: every learned preference is visible on your Creator Brain page, with controls to correct, delete or confirm it.
- Disable learning: you can pause decision recording entirely at any time.
- Delete: you can request deletion of your account and all associated data (including imported YouTube data) by emailing us; deletion completes within 30 days.
- Export: you can request an export of your data.
How we protect your data
We treat your YouTube data and your account credentials as sensitive data, and protect them with the following mechanisms.
- Encryption in transit: every connection to whattoupload.com is served over HTTPS using TLS 1.2 or higher. The application's connection to its database also requires TLS (sslmode=require); unencrypted database connections are refused.
- Encryption at rest: all data, including imported YouTube data and OAuth tokens, is stored in managed PostgreSQL (Neon, AWS us-east-1) which encrypts data at rest using AES-256. Backups and snapshots are encrypted with the same mechanism.
- Credential handling: account passwords are never stored in plaintext. They are salted and hashed with scrypt, and the hash is all we retain. We cannot recover or read your password.
- OAuth token handling: Google OAuth access and refresh tokens are held server-side only. They are never sent to the browser, never written to logs, never exposed through any API response, and never shared with third parties.
- Access control: production database access is restricted to the single operator of the service, authenticated separately from the application. Administrative access to the app requires Google sign-in from an explicit email allowlist; a password session is not sufficient to reach any administrative view. Passwords, sessions, verification tokens and OAuth tokens are never rendered in any administrative interface.
- Revocation: disconnecting your channel calls Google's token revocation endpoint, so our access is withdrawn at Google rather than merely forgotten locally, and syncing stops immediately.
- Retention and deletion: imported YouTube data is retained only while your channel is connected and your account is active. On disconnection you may request its deletion, and account deletion removes all associated data, including imported YouTube data, within 30 days. Stored YouTube API data is refreshed or deleted in line with the YouTube API Services policies.
- Minimization: we request read-only YouTube scopes only. We never hold write, upload, edit, delete or comment permissions on your channel, so a compromise of our systems cannot be used to alter your channel.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, email polostudio.brand@gmail.com and we will respond.
Limited Use of Google user data
WhatToUpload's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Concretely, this means we use Google user data only to provide and improve the user-facing features described in this policy; we do not transfer it to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with your consent; we do not use it for advertising, and we do not sell it; and no human reads it except with your explicit consent, to comply with applicable law, or where it has been aggregated and anonymized for security or abuse investigation.
Google user data is never used to train any AI model, ours or a third party's.
Contact
Data controller: WhatToUpload. For privacy requests, deletion or questions: polostudio.brand@gmail.com.