Privacy Policy
Last updated: September 15, 2026
Overview
Your Slayo account
openid, email and profile scopes. It gives Slayo no access to your YouTube channel, and no YouTube API Data is collected during sign-in.- What we collect at sign-in. Your Google account identifier (the stable
subclaim), your email address, your display name, and the URL of your Google profile picture. - Why. To identify you across sessions, to keep each user’s connected accounts and data separate from every other user’s, to show who is signed in, and to contact you about your account.
- What else the account record holds. The date you joined, the invite code you signed up with, and your plan. Slayo does not take payments today; the billing fields on the account record are unused and empty.
- If you ask for access before being invited. Slayo is invite-only. If you request access, we store the email address and name you submit on a waitlist until we invite you or you ask us to remove it.
Platform data we access
- TikTok: your basic profile and public profile info (display name, username, avatar, verification status and aggregate follower/following/like/video counts), your list of videos and their public metrics, and the ability to upload and post videos on your behalf (TikTok Login Kit, Display API, and Content Posting API).
- YouTube (Google): your channel info, the ability to upload videos on your behalf, and read-only channel/video analytics (YouTube Data API and YouTube Analytics API).
- Instagram (Meta): your professional account info, media, and insights, and the ability to publish content (Instagram Graph API).
YouTube API Services
We access only the single channel you authorize, and only through the scopes you approve. We never access any other channel, never read another user’s data, and never download or store the video files already on your channel.
Authorized scopes
youtube.upload (publish videos you create in Slayo), youtube.readonly (read your own channel and videos), yt-analytics.readonly (read your own performance metrics).
Accessed via the YouTube Data API v3
Your channel ID and uploads-playlist ID. For each of your own videos: the video ID, title, description, tags, thumbnail URL, publish date and duration, together with its public statistics — view count, like count and comment count.
Accessed via the YouTube Analytics API
Day-by-day metrics for your own channel only: views, estimatedMinutesWatched, likes and comments. We do not request demographic, geographic, traffic-source or revenue data.
Sent to YouTube when you publish
The video file you upload or generate, plus the title, description, tags, privacy setting, category and made-for-kids flag you enter in Slayo.
How we use it
Solely to render your dashboard and analytics inside Slayo, to publish what you ask us to publish, and to produce the content insights you explicitly request. We do not sell it, use it for advertising, use it for any form of ad targeting, or use it to train machine-learning models.
What we store, and for how long
Dashboard analytics is fetched live from the YouTube API on each page load and is not cached or stored. The only YouTube API Data we store is inside saved insight reports, which contain your video titles (truncated to 120 characters), view, like and comment counts, publish dates and hashtags. Those reports are automatically deleted 30 days after generation, in line with the YouTube API Services Developer Policies’ requirement that stored API Data be refreshed or deleted within 30 days. Your OAuth tokens are stored until you disconnect or revoke.
Third-party processing of YouTube API Data
When — and only when — you press “Generate” on the Insights page, the summarised video titles and metrics listed above are sent to Anthropic’s Claude API to produce the written recommendations. Anthropic acts as our processor, does not use data submitted through its API to train its models, and retains it only transiently for that request. This is the only third party that receives YouTube API Data from Slayo, and it never happens in the background or without your action.
How to revoke access
Disconnect YouTube in Slayo Settings, or remove Slayo’s access at Google Account → Third-party apps & services. Either action stops all further API access; disconnecting in Slayo also deletes the stored token immediately. Saved insight reports can be deleted on request at any time, and expire on their own within 30 days.
What we store
- Your account record: Google account identifier, email, display name, profile picture URL, join date, the invite code used, and plan.
- OAuth access/refresh tokens issued by YouTube, TikTok, and Instagram when you connect each platform. These let Slayo call the respective APIs as you.
- Your saved hashtag library, per-platform publish preferences, and any additional profiles you create.
- Upload job status (per-platform progress + result) for a short period after each publish.
- Saved insight reports, which embed the video titles and metrics described above, for 30 days.
- Monthly usage counters (how many publishes, insight runs, renders and searches you have made) used to enforce plan limits.
- Invite codes we issue, and waitlist entries (email and name) submitted by people requesting access.
- Searches you run on the Trending page and their results, so you can revisit them.
What we don't store
- Your YouTube / TikTok / Instagram passwords (auth uses OAuth, so we never see them).
- Your video file long-term. It lives in object storage only while the publish is running and is deleted afterward.
- Any cross-site tracking identifiers or third-party advertising cookies.
How we use your data
- To publish the videos you choose to the platforms you select.
- To display your analytics and generate the content insights you request.
- To keep you signed in to connected platforms and refresh access as needed.
- To operate, secure, and troubleshoot the service.
Where data is stored
Who we share with
- YouTube (Google): we call the YouTube Data and Analytics APIs using your token.
- TikTok: we call the TikTok Login Kit, Display, and Content Posting APIs using your token.
- Meta / Instagram: we call the Instagram Graph API using your token.
- Anthropic (Claude API): only when you press “Generate” on the Insights page, and only the summarised video titles and metrics described in the YouTube API Services section above. Anthropic does not train its models on data submitted through its API.
- Mailgun: your email address, used solely to deliver an invite to Slayo. No marketing email is sent.
- Vercel and Upstash, as infrastructure providers, may process this data on our behalf under their respective terms.
Data retention
- OAuth tokens: kept until you disconnect the platform in Settings or revoke access, after which they are deleted.
- Uploaded video files: deleted immediately after the publish completes.
- Upload job status: retained for roughly one hour after a publish, then discarded.
- Hashtag library and preferences: kept until you change or delete them, or request account deletion.
- Saved insight reports (which summarise your video titles and view counts): automatically deleted 30 days after generation.
- Your account record: kept until you ask us to delete your account, after which it and all data linked to it are removed.
- Waitlist entries: kept until you are invited or you ask us to remove the entry.
- Monthly usage counters: retained for roughly 70 days so plan limits can be applied across a billing month, then discarded.
Your rights and choices
- Disconnect a platform in Settings, and Slayo deletes the stored OAuth token for that platform.
- Revoke Slayo’s access directly from each platform: TikTok → Profile → Settings and privacy → Security & permissions → Manage app permissions; Google Account → Third-party apps & services; Meta → Business Settings / Apps and websites.
- Request access to, correction of, or deletion of any data we hold about you by emailing us.
Data deletion requests
Children's privacy
Cookies
slayo_session— identifies your signed-in account. Lasts 30 days, or until you log out.oauthstate_*— a random value used to verify the OAuth callback came from the flow you started (CSRF protection). Expires after 10 minutes.slayo_invite— carries an invite code across the sign-in redirect. Expires after 10 minutes.slayo_profile— remembers which of your profiles is selected.
