Privacy policy
Last updated 26 September 2026
ChannelOS is a private tool its operator uses to plan, produce and schedule YouTube Shorts for YouTube channels they own or manage. Only accounts created by the operator can sign in. This policy explains what data ChannelOS handles, why, and how you can remove it.
YouTube API Services
ChannelOS uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google handles your data under the Google Privacy Policy.
Data we access and store
- Sign-in: the email address of each operator account, and a session cookie.
- Connected YouTube channels (Google OAuth, scopes
youtube.upload,youtube.readonly,yt-analytics.readonly, and optionallyyt-analytics-monetary.readonly): channel ID, name and handle; an OAuth refresh token; titles and metadata of the channel's recent uploads; and per-video analytics such as views, watch time, retention and, if granted, estimated revenue. - Content ChannelOS creates: ideas, scripts, voice-overs, video files, review notes and production costs.
ChannelOS does not access comments, subscribers' personal data, private messages or any channel it was not explicitly connected to.
How we use it
- Upload videos that a person has approved in ChannelOS, with the metadata and publish time reviewed there. Nothing is uploaded without approval.
- Show performance dashboards and learn which topics and formats work for each channel, to rank future ideas.
- Alert the operator when something needs attention (for example a failed video or a disconnected channel).
ChannelOS never likes, comments, subscribes, or otherwise engages on YouTube, and never generates artificial views or engagement. Data is not sold, not used for advertising; ChannelOS does not use it to train AI models.
Who processes it
Data is shared only with the services needed to run ChannelOS:
- AI providers via OpenRouter: channel profile, idea and script text, and aggregated video analytics, to write scripts, voice-overs and videos and to analyse performance. OAuth tokens are never sent.
- Hosting: the operator's server (database, queue, search index) and a private S3-compatible bucket for media files.
- Telegram: short operational alerts to the operator's own chat, if enabled.
Storage and security
OAuth refresh tokens are encrypted (AES-256-GCM) before they are stored. All connections use HTTPS; media files are private and shared only through links that expire after 15 minutes. Access is limited to the operator's accounts.
Retention and deletion
Data is kept while a channel is connected to ChannelOS. Analytics are refreshed for videos from the last 90 days. You can revoke ChannelOS's access to your Google account at any time at Google security settings; after that ChannelOS can no longer read or upload anything. To have stored data deleted, contact us below; we delete it within 30 days, including tokens, analytics and media.
Cookies
ChannelOS sets only functional cookies: the sign-in session, the selected channel, and the sidebar state. The colour theme is kept in your browser. There are no analytics or advertising cookies.
Google API data
ChannelOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions or deletion requests: hello@mdhk.ltd. We will post changes to this policy on this page and update the date above.