LAST UPDATED 20 SEPTEMBER 2026
Privacy Policy
This policy covers the Purr Detour public information website and YT_FACTORY, the channel owner's locally operated production application. The application is currently for the owner's channel, not a service that accepts other users' Google accounts.
Data accessed
- Google OAuth authorization credentials, including access and refresh tokens, to maintain the owner's authorized connection.
- YouTube channel identifiers, video identifiers, titles, descriptions, tags, visibility, processing status and upload records.
- Public reference-video metadata and available public statistics for content research.
- Authorized channel performance reports: available views, engaged views, watch time, viewing duration, percentage viewed, likes, shares, subscriber gains, traffic sources and country/region breakdowns. Unavailable information is marked UNKNOWN. These are reports, not individual viewers' identities.
- Locally created production files, prompts, quality assessments, costs and operational records. Contact messages are received only if you choose to email the operator.
Purposes and limits
Data is used to operate the owner's channel, upload and manage original videos, prevent duplicate uploads, diagnose failures, review performance and inform future production. The application does not use Google user data for advertising targeting, sale, credit assessment or training generalized AI models. It does not request Gmail, Drive, contacts or browsing-history access.
Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. The application uses YouTube API Services; see the Google Privacy Policy.
Storage and security
OAuth credentials and the Gemini key are encrypted with Windows user-bound DPAPI on the owner's computer. Channel records, analytics, reference metadata and production reports are stored in local files and SQLite. Access to the credential directory is restricted to the Windows account and SYSTEM. Credentials are not published to this website or source repository. Local database and media files are not represented as independently encrypted by this application; their protection also depends on Windows account and device security.
Providers and disclosure
Google receives authorized API requests, uploaded videos and metadata. Higgsfield receives generation inputs needed to produce original visuals. Gemini may receive public reference URLs, original production media and non-secret production instructions for analysis and QC. Private Google-authorized Analytics reports and OAuth credentials are not sent to Gemini or Higgsfield in the current integration. Any future semantic analysis of authorized Google user data requires a separate policy and provider-compliance review before enabling it.
This static website has no application login, contact form, advertising, custom tracking scripts or connection to the local factory database. Its hosting provider may process ordinary request information such as IP address and browser details to deliver and secure the site; the operator does not claim that the provider keeps no logs. Email is processed by the operator's email provider. Data may be processed in providers' operating countries.
Retention and deletion
Local data is retained only while needed for the stated functions and subject to applicable YouTube API storage rules. Public API statistics must be refreshed or deleted within the applicable 30-day period. Authorized analytics retained longer require continued authorization checks under YouTube policy. Automated retention enforcement is still being implemented; the operator remains responsible for these checks and deletions, and unattended operation is not represented as ready.
You can revoke Google access through Google Account permissions. Revocation stops future authorized access but does not itself erase local copies. To request removal, email the operator at formasa666@gmail.com with the affected channel or video URL. Never send passwords, API keys or OAuth tokens. The operator will verify the request as needed and remove applicable stored Google user data as soon as possible and within seven calendar days of a valid deletion request. Applicable local copies, reports and operator-controlled backups must be included.
Deleting local YT_FACTORY records does not delete videos or data held by YouTube. Manage those separately in YouTube Studio or your Google account. Original production assets not containing Google API data may be retained for channel operations and rights records unless separately removed.
Questions and changes
Contact the operator for access, correction, deletion or privacy questions. Material changes will be reflected on this page with an updated date. This policy does not state or imply Google verification, approval or endorsement.