Privacy Policy

Effective and last updated: June 7, 2026

Developed with YouTube

1. Scope and operator

This Privacy Policy explains how InTubeMedia processes information through the InTubeMedia channel management service at cms.intubemedia.com. It covers local CMS accounts, Google Sign-In for CMS authentication, and separately authorized YouTube channel access. Privacy questions, complaints, and deletion requests can be sent to shivlalbainslaofficial@gmail.com.

2. Information we process

  • CMS account information, such as name, email, phone number, role, channel assignments, approval status, and support messages.
  • Local CMS account passwords in the CMS user data store are retained as one-way hashes. Separately configured administrative login secrets remain in server-side environment configuration. A CMS password is separate from a Google or YouTube password.
  • Google Sign-In profile information when a user chooses Google Sign-In for CMS authentication.
  • YouTube channel and video metadata, including channel ID, channel title, thumbnails, subscriber/view/video counts, video titles, descriptions, privacy status, and monetization-related metadata.
  • YouTube Analytics metrics, including views, watch time, traffic and audience metrics, CPM, RPM, estimated revenue, and other monetary analytics available to the authorized channel.
  • OAuth authorization records, including one-time authorization state, consent version and time, access token, refresh token, token expiry, granted scopes, and the verified Google channel ID.
  • Operational records such as essential session cookies, request timestamps, sync status, audit events, exports, payment/reporting records, and security logs. OAuth token values and Google authorization codes are not intentionally written to application logs.

3. Google and YouTube APIs and scopes

InTubeMedia uses Google-hosted OAuth 2.0, the YouTube Data API, and the YouTube Analytics API. A channel owner or authorized manager must review the disclosure for the exact assigned channel and approve these scopes on Google's consent page:

  • youtube: read channel/video data and perform video updates or deletes only after an authorized user explicitly requests that action in the CMS.
  • yt-analytics.readonly: read channel analytics for dashboards, statistics, and reports.
  • yt-analytics-monetary.readonly: read estimated revenue and monetary analytics for revenue dashboards, monthly reports, and authorized exports.
InTubeMedia never asks for, receives, or stores your Google or YouTube password. Google sign-in and YouTube permission approval occur only on Google-controlled domains. Google returns authorization tokens to our server after approval; it does not provide us with your Google password.

4. How authorization works

  1. An authenticated CMS user generates a random, one-time link bound to an exact assigned channel. The link expires after 15 minutes.
  2. The channel owner or authorized manager reviews the requested data and purposes, confirms channel authority, and accepts this Policy and the Terms.
  3. The user continues to Google, where Google authenticates the user and displays the requested permissions.
  4. Google returns an authorization code. InTubeMedia exchanges it on the server; access and refresh tokens are not returned to browser JavaScript.
  5. InTubeMedia calls channels.list(mine=true) and stores authorization only if Google returns the exact channel ID assigned in the CMS. Rejected or mismatched authorization is revoked and not stored.

5. How we use data

  • Authenticate and administer CMS accounts and authorized roles.
  • Display channel dashboards, statistics, videos, health information, and analytics.
  • Generate monthly analytics, revenue reports, payment calculations, and authorized exports.
  • Refresh channel data and detect invalid, expired, or externally revoked authorization.
  • Perform video metadata updates, privacy changes, or video deletion only when an authorized user deliberately initiates the specific action.
  • Secure, troubleshoot, audit, and improve the service and respond to support or compliance requests.

Google API data is used only to provide or improve user-facing features that are prominent in InTubeMedia. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

6. Storage and security

  • HTTPS protects information in transit.
  • OAuth access and refresh tokens are encrypted at rest using AES-256-GCM authenticated server-side encryption before storage in Redis/server infrastructure.
  • Local CMS account passwords in the CMS user data store are one-way hashed before storage, and administrative login secrets are restricted to server-side environment configuration.
  • Tokens remain server-side and are available only to service components that need them to call Google APIs.
  • Role and channel-assignment checks limit which CMS users can access channel data or request channel actions.

No internet service is risk-free. We use reasonable administrative and technical safeguards, investigate suspected misuse, and restrict authorized access to people and processors who need it for the purposes described here.

7. Sharing and disclosures

We do not sell YouTube API data, use it for targeted advertising, or disclose it for unrelated purposes. We may disclose limited information only to:

  • the account's authorized client, company, administrator, or agent according to configured roles and channel assignments;
  • Google APIs, as necessary to perform the user-authorized request;
  • hosting, database/Redis, email, security, and infrastructure providers acting for InTubeMedia under appropriate confidentiality and security obligations;
  • authorities or other parties when required by law, necessary to protect rights and safety, or involved in a properly structured business transfer subject to applicable safeguards.

8. Retention, refresh, and deletion

  • OAuth tokens are retained only while the channel remains authorized and connected. Access tokens are refreshed and authorization is revalidated through scheduled sync and API use.
  • Current, backup, snapshot, video, statistics, dashboard, date-range, monthly analytics, and monthly revenue-export caches may be retained to provide consistent historical dashboards and exports while authorization remains valid. Stored API statistics are refreshed or revalidated at least every 30 days.
  • When a user chooses Revoke Access or delinks/removes a channel in the CMS, InTubeMedia requests immediate revocation at Google and deletes the local token and authorized channel caches as part of that operation. The interface does not report success if this cleanup fails.
  • If Google authorization is revoked externally, InTubeMedia detects invalid authorization during scheduled token refresh or API revalidation, then deletes the unusable token and related authorized data. This detection and cleanup is designed to occur within 30 calendar days.
  • After a verified account/data-deletion request, we delete the account and related authorized Google/YouTube data within seven calendar days unless limited retention is legally required. Separate invoices, payment evidence, fraud/security records, or legal records may be retained only as required and are not used to recreate revoked YouTube API data.

9. Your controls

  • Revoke a channel in InTubeMedia through Channels → Revoke Access / delink / remove.
  • Revoke InTubeMedia externally through Google Account permissions.
  • Request access, correction, account deletion, or deletion of authorized data by emailing shivlalbainslaofficial@gmail.com or using the Contact page. Include the CMS email and relevant channel ID so we can verify the request.

10. Cookies

InTubeMedia uses essential authentication and session cookies to sign users in, protect requests, and maintain account security. We do not use YouTube API data for advertising profiles. Browser controls may block cookies, but essential CMS functions may then stop working.

11. Google and YouTube terms

Use of connected YouTube features is also subject to the YouTube Terms of Service and the Google Privacy Policy.

12. Changes and contact

We may update this Policy when our services or legal obligations change. We will post the revised effective date here. For privacy questions, complaints, or deletion requests, email shivlalbainslaofficial@gmail.com.