Privacy Policy
Last updated: February 11, 2026
1. Introduction
OneTube ("we", "our", or "us") operates the onetube.io website and service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws. Our legal basis for processing your data is the performance of a contract (providing the service you signed up for) and our legitimate interests (security, fraud prevention, and service improvement).
2. Information We Collect
2.1 Account Data
When you sign in via Google OAuth, we receive and store:
- Your name, email address, and profile picture
- Your Google account ID (used as a unique identifier)
2.2 Authentication Tokens
We store Google OAuth access and refresh tokens to access the YouTube Data API on your behalf. These tokens allow us to fetch your channel statistics, video metrics, and comments. Tokens are stored in our database and are used solely for YouTube API requests.
2.3 Server-Side Usage Data
When you interact with the service, our server automatically logs the following information with each action you perform:
- IP Address: Logged for security monitoring and abuse prevention
- User Agent: Your browser and device information, logged for compatibility and security
- Action Logs: Records of actions you perform within the service (e.g., adding channels, viewing analytics, triggering syncs) for audit and troubleshooting purposes
This data is collected server-side and is not stored in cookies. It is stored in our database in audit logs and usage event tables.
2.4 YouTube Data
When you connect your YouTube channels, we collect and store data through the YouTube Data API and public channel pages, including:
- Channel statistics (subscribers, total views, video count)
- Video metadata (titles, publish dates, view counts, likes, comments count, durations)
- Video comments (fetched via YouTube Data API for AI analysis)
- Historical snapshots of channel and video metrics for trend analysis
This data is used solely to provide you with analytics within our service. You may also add third-party channels for competitive analysis; public data for those channels is collected without requiring their OAuth consent.
2.5 Payment Data
Payments are processed by Stripe. We store your Stripe customer ID and subscription ID in our database to manage your plan. We do not store credit card numbers, CVVs, or other payment card details — these are handled entirely by Stripe. See Stripe's Privacy Policy.
2.6 Preferences
We store your timezone preference (for scheduling data syncs) and other UI settings such as sidebar state. These are used to personalize your experience.
3. How We Use Your Information
- To provide, maintain, and improve our service
- To fetch and display your YouTube analytics and competitor data
- To perform AI-powered analysis of video comments
- To process payments and manage subscriptions
- To send important service updates and notifications
- To detect and prevent fraud, abuse, and unauthorized access
- To troubleshoot issues and improve service reliability
- To comply with legal obligations
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your data with:
- Google: Authentication (OAuth) and YouTube Data API access
- Stripe: Payment processing
- DeepSeek: AI analysis of video comments (only comment text is sent, no personal data)
- Infrastructure Providers: Server hosting and database services
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
5. Data Security
We implement security measures to protect your data:
- All data transmitted via HTTPS/TLS encryption
- Access controls and authentication requirements for all endpoints
- Server-side audit logging for security monitoring
- Database access restricted to authenticated services only
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.
6. Data Retention
We retain different types of data for different periods:
- Account data: Retained for as long as your account is active. Deleted upon account deletion request.
- OAuth tokens: Retained while your account is active; revoked and deleted upon account deletion.
- Audit logs: Retained indefinitely for security and compliance purposes.
- Usage events: Retained indefinitely for service improvement and analytics.
- YouTube data (snapshots): Retention depends on your subscription plan — ranging from 30 days (Free) to unlimited (Business).
- Feed events: Retained according to your plan: 30 days (Free), 90 days (Pro), unlimited (Business).
You may request deletion of your data at any time by contacting us at privacy@onetube.io.
7. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Request transfer of your data in a machine-readable format
- Restriction: Request limitation of processing
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for optional cookies at any time via our Cookie Policy page
To exercise these rights, contact us at privacy@onetube.io. We will respond within 30 days as required by GDPR.
8. Cookies
We use a minimal number of cookies. We do not use any third-party analytics or advertising cookies. The cookies we use are:
- auth_token (Essential): HttpOnly session cookie for authentication
- cookie_consent (Essential): Stores your cookie preferences for 1 year
- sidebar_state (Functional): Remembers your sidebar preference for 7 days — only set with your consent
Essential cookies are required for the service to function and cannot be disabled. Functional cookies are optional and require your consent before being set.
For full details, including how to manage your preferences, see our Cookie Policy.
9. Third-Party Services
Our service integrates with:
- Google: Authentication and YouTube API access. See Google's Privacy Policy.
- Stripe: Payment processing. See Stripe's Privacy Policy.
- DeepSeek: AI comment analysis. Only anonymized comment text is sent for processing.
10. Children's Privacy
Our service is not intended for users under 16 years of age. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the service. We will update the "Last updated" date at the top of this page when we make changes. Your continued use after changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related inquiries or to exercise your rights:
Email: privacy@onetube.io