Privacy Policy

Last updated: September 15, 2026

Overview

Slayo (“Slayo”, “we”, “us”), operated by The Leo Apps, helps you publish a single video to YouTube, TikTok, and Instagram in one step and view your performance analytics in one place. To do that, we hold the minimum data needed to call those platforms’ APIs on your behalf. We do not sell your data and do not share it beyond what’s required to perform the actions you ask for. This policy explains what we collect, how we use it, how long we keep it, and the choices you have.

Your Slayo account

You create a Slayo account by signing in with Google. That sign-in uses a separate Google OAuth client from the one used for YouTube, and it requests only the openid, email and profile scopes. It gives Slayo no access to your YouTube channel, and no YouTube API Data is collected during sign-in.
  • What we collect at sign-in. Your Google account identifier (the stable sub claim), your email address, your display name, and the URL of your Google profile picture.
  • Why. To identify you across sessions, to keep each user’s connected accounts and data separate from every other user’s, to show who is signed in, and to contact you about your account.
  • What else the account record holds. The date you joined, the invite code you signed up with, and your plan. Slayo does not take payments today; the billing fields on the account record are unused and empty.
  • If you ask for access before being invited. Slayo is invite-only. If you request access, we store the email address and name you submit on a waitlist until we invite you or you ask us to remove it.

Platform data we access

When you connect a platform, you authorize Slayo through that platform’s official OAuth flow. The data we may access is limited to the scopes you approve:
  • TikTok: your basic profile and public profile info (display name, username, avatar, verification status and aggregate follower/following/like/video counts), your list of videos and their public metrics, and the ability to upload and post videos on your behalf (TikTok Login Kit, Display API, and Content Posting API).
  • YouTube (Google): your channel info, the ability to upload videos on your behalf, and read-only channel/video analytics (YouTube Data API and YouTube Analytics API).
  • Instagram (Meta): your professional account info, media, and insights, and the ability to publish content (Instagram Graph API).
Slayo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Our use of TikTok data complies with the TikTok Developer Terms of Service and TikTok’s platform policies.

YouTube API Services

Slayo uses YouTube API Services. By connecting your YouTube channel you agree to be bound by the YouTube Terms of Service, and information Google collects is handled in accordance with the Google Privacy Policy.

We access only the single channel you authorize, and only through the scopes you approve. We never access any other channel, never read another user’s data, and never download or store the video files already on your channel.

Authorized scopes

youtube.upload (publish videos you create in Slayo), youtube.readonly (read your own channel and videos), yt-analytics.readonly (read your own performance metrics).

Accessed via the YouTube Data API v3

Your channel ID and uploads-playlist ID. For each of your own videos: the video ID, title, description, tags, thumbnail URL, publish date and duration, together with its public statistics — view count, like count and comment count.

Accessed via the YouTube Analytics API

Day-by-day metrics for your own channel only: views, estimatedMinutesWatched, likes and comments. We do not request demographic, geographic, traffic-source or revenue data.

Sent to YouTube when you publish

The video file you upload or generate, plus the title, description, tags, privacy setting, category and made-for-kids flag you enter in Slayo.

How we use it

Solely to render your dashboard and analytics inside Slayo, to publish what you ask us to publish, and to produce the content insights you explicitly request. We do not sell it, use it for advertising, use it for any form of ad targeting, or use it to train machine-learning models.

What we store, and for how long

Dashboard analytics is fetched live from the YouTube API on each page load and is not cached or stored. The only YouTube API Data we store is inside saved insight reports, which contain your video titles (truncated to 120 characters), view, like and comment counts, publish dates and hashtags. Those reports are automatically deleted 30 days after generation, in line with the YouTube API Services Developer Policies’ requirement that stored API Data be refreshed or deleted within 30 days. Your OAuth tokens are stored until you disconnect or revoke.

Third-party processing of YouTube API Data

When — and only when — you press “Generate” on the Insights page, the summarised video titles and metrics listed above are sent to Anthropic’s Claude API to produce the written recommendations. Anthropic acts as our processor, does not use data submitted through its API to train its models, and retains it only transiently for that request. This is the only third party that receives YouTube API Data from Slayo, and it never happens in the background or without your action.

How to revoke access

Disconnect YouTube in Slayo Settings, or remove Slayo’s access at Google Account → Third-party apps & services. Either action stops all further API access; disconnecting in Slayo also deletes the stored token immediately. Saved insight reports can be deleted on request at any time, and expire on their own within 30 days.

What we store

  • Your account record: Google account identifier, email, display name, profile picture URL, join date, the invite code used, and plan.
  • OAuth access/refresh tokens issued by YouTube, TikTok, and Instagram when you connect each platform. These let Slayo call the respective APIs as you.
  • Your saved hashtag library, per-platform publish preferences, and any additional profiles you create.
  • Upload job status (per-platform progress + result) for a short period after each publish.
  • Saved insight reports, which embed the video titles and metrics described above, for 30 days.
  • Monthly usage counters (how many publishes, insight runs, renders and searches you have made) used to enforce plan limits.
  • Invite codes we issue, and waitlist entries (email and name) submitted by people requesting access.
  • Searches you run on the Trending page and their results, so you can revisit them.
Everything above is namespaced per account: one user’s tokens, analytics and preferences are never readable by another user.

What we don't store

  • Your YouTube / TikTok / Instagram passwords (auth uses OAuth, so we never see them).
  • Your video file long-term. It lives in object storage only while the publish is running and is deleted afterward.
  • Any cross-site tracking identifiers or third-party advertising cookies.

How we use your data

  • To publish the videos you choose to the platforms you select.
  • To display your analytics and generate the content insights you request.
  • To keep you signed in to connected platforms and refresh access as needed.
  • To operate, secure, and troubleshoot the service.
We do not use your content or platform data for advertising, and we do not sell it or share it with data brokers.

Where data is stored

OAuth tokens, hashtag library, publish preferences, and job state live in Upstash Redis (managed via Vercel). The video itself is uploaded from your browser to Vercel Blob (public URL with an unguessable token in the path), passed to the platforms, then deleted.

Who we share with

  • YouTube (Google): we call the YouTube Data and Analytics APIs using your token.
  • TikTok: we call the TikTok Login Kit, Display, and Content Posting APIs using your token.
  • Meta / Instagram: we call the Instagram Graph API using your token.
  • Anthropic (Claude API): only when you press “Generate” on the Insights page, and only the summarised video titles and metrics described in the YouTube API Services section above. Anthropic does not train its models on data submitted through its API.
  • Mailgun: your email address, used solely to deliver an invite to Slayo. No marketing email is sent.
  • Vercel and Upstash, as infrastructure providers, may process this data on our behalf under their respective terms.
Each platform handles your content under its own privacy policy once Slayo hands it off. We do not otherwise share your personal data with third parties.

Data retention

  • OAuth tokens: kept until you disconnect the platform in Settings or revoke access, after which they are deleted.
  • Uploaded video files: deleted immediately after the publish completes.
  • Upload job status: retained for roughly one hour after a publish, then discarded.
  • Hashtag library and preferences: kept until you change or delete them, or request account deletion.
  • Saved insight reports (which summarise your video titles and view counts): automatically deleted 30 days after generation.
  • Your account record: kept until you ask us to delete your account, after which it and all data linked to it are removed.
  • Waitlist entries: kept until you are invited or you ask us to remove the entry.
  • Monthly usage counters: retained for roughly 70 days so plan limits can be applied across a billing month, then discarded.

Your rights and choices

  • Disconnect a platform in Settings, and Slayo deletes the stored OAuth token for that platform.
  • Revoke Slayo’s access directly from each platform: TikTok → Profile → Settings and privacy → Security & permissions → Manage app permissions; Google Account → Third-party apps & services; Meta → Business Settings / Apps and websites.
  • Request access to, correction of, or deletion of any data we hold about you by emailing us.
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. To exercise any of them, contact us at the address below.

Data deletion requests

To delete the data Slayo holds about you, disconnect your platforms in Settings (which removes the stored tokens) and email admin@theleoapps.com with the subject “Data deletion”. We will delete the associated data we control within 30 days and confirm once complete.

Children's privacy

Slayo is not directed to children. The service is intended for users who are at least 18 years old (or the age of majority in their jurisdiction), and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

Cookies

Slayo sets only http-only, signed, strictly-necessary cookies. There are no analytics, advertising or cross-site tracking cookies, and no third-party cookies.
  • slayo_session — identifies your signed-in account. Lasts 30 days, or until you log out.
  • oauthstate_* — a random value used to verify the OAuth callback came from the flow you started (CSRF protection). Expires after 10 minutes.
  • slayo_invite — carries an invite code across the sign-in redirect. Expires after 10 minutes.
  • slayo_profile — remembers which of your profiles is selected.

Security

Tokens are stored in managed Redis with TLS in transit and encryption at rest. Connections between your browser and Slayo use HTTPS. We follow standard OAuth best practices for token handling. No method of transmission or storage is 100% secure, but we work to protect your data using reasonable safeguards.

International users and governing law

Slayo is operated from, and your data may be processed in, the United States and other countries where our infrastructure providers operate. This policy is governed by the laws applicable to The Leo Apps’ place of operation, without regard to conflict-of-laws rules.

Changes

We may update this policy as the service evolves. The “Last updated” date at the top reflects the most recent change; material changes will be reflected here.

Contact

Questions or data requests? Reach out at admin@theleoapps.com.