Privacy Policy
Effective date: 6 October 2026
This Privacy Policy explains how Zypalo ("we", "us", the "Service", at https://zypalo.com) collects, uses, stores, and protects your information, including data obtained through Google APIs and the YouTube Data API.
1. Information we collect
- Account information: your name, email address, and a securely hashed password.
- Google/YouTube authorization data: OAuth access and refresh tokens, your authorized YouTube channel ID and title — obtained only after you explicitly grant permission via Google OAuth 2.0.
- Content metadata you provide: video titles, descriptions, tags, categories, thumbnails, schedule times, templates, and upload job status.
- Operational data: activity/audit logs, in-app notifications, and per-day API usage counters.
We do not store your video files. Video content is uploaded directly from your browser to YouTube/Google via YouTube's resumable upload protocol; the bytes never pass through or reside on our servers.
2. How we use information
- To authenticate you and operate your account.
- To perform the YouTube actions you explicitly request: verifying your channel, creating uploads, setting metadata/thumbnails, and scheduling publishing.
- To display your upload history, status, and activity to you.
- To maintain security, prevent abuse, and keep audit logs.
3. Google user data — Limited Use
Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the user-facing features described on our home page.
- We do not transfer or sell Google user data for advertising, marketing, or other unrelated purposes.
- We do not allow humans to read Google user data unless (a) you give explicit consent, (b) it is necessary for security or to comply with law, or (c) the data is aggregated and anonymized for internal operations.
4. Scopes we request and why
https://www.googleapis.com/auth/youtube.upload— to upload videos to your channel.https://www.googleapis.com/auth/youtube— to set video metadata, thumbnails, and scheduled publishing.https://www.googleapis.com/auth/youtube.readonly— to read your channel identity to verify the correct channel and show channel status.
We request the minimum scopes necessary for the features you use.
5. How we store and protect data
- Data is stored in Cloudflare D1 (a managed SQL database) with access restricted to the Service.
- OAuth tokens and any client secrets are encrypted at rest using AES-GCM; passwords are hashed with PBKDF2.
- All traffic is served over HTTPS. Sessions use secure, HttpOnly cookies with CSRF protection.
- Each user's data is logically isolated (multi-tenant); users cannot access other users' data.
6. Data sharing
We do not sell your data. We share data only with Google/YouTube as required to perform the actions you request, and with infrastructure providers (Cloudflare) strictly to operate the Service.
7. Data retention and deletion
We retain your data while your account is active. You may disconnect a channel at any time (which deletes its stored OAuth tokens), and you may request deletion of your account and associated data by contacting us at mirafzalali132@gmail.com.
8. Revoking access
You can revoke this application's access to your Google account at any time via Google Account → Security → Third-party access. You can also disconnect channels from within the app.
9. Children's privacy
The Service is not directed to children under 13 (or the age required by your jurisdiction), and we do not knowingly collect their data.
10. Changes to this policy
We may update this Privacy Policy. Material changes will be reflected by updating the effective date above.
11. Contact
Questions about this policy: mirafzalali132@gmail.com.
← Back to home
Zypalo