How we use YouTube data
Last updated 18 August 2026 · HOI Social Media Hub by High On Innovation
HOI Social Media Hub uses YouTube API Services to let you manage your own channel from the Service. This page lists every permission we ask for, exactly what it is used for, what we store, and how to take it back. It complements our Privacy policy; the YouTube Terms of Service and the Google Privacy Policy also apply.
1. What happens when you click Connect YouTube
- You are sent to Google's own sign-in page and choose the Google account that owns the channel. We never see the password.
- Google shows the permissions below; you approve them.
- Google gives the Service tokens for that channel. We encrypt and store them and read the channel's name, picture, subscriber count and video list.
- From then on the Service works only on that channel, only for the actions described here.
2. Each permission and what it is for
| Permission (as Google shows it) | Technical scope | Used for | Never used for |
|---|---|---|---|
| View your YouTube account | youtube.readonly | Reading your channel, your videos and their statistics (views, likes, comments) so reports, weekly summaries and expected-vs-got comparisons are real. | Reading other people's private data. Only your own channel. |
| Manage your YouTube videos | youtube.upload | Uploading the Shorts your team approves, on the schedule you set, with the title and description you wrote. | Uploading anything not approved by a person in your workspace. Deleting videos. |
| See, edit, and permanently delete your YouTube videos, ratings, comments and captions | youtube.force-ssl | Reading comments on your videos into your inbox, and posting the replies you approve. (Google bundles reading and writing comments into this one broadly-worded permission.) | Deleting videos, changing ratings, editing captions, replying without a human action. |
| View your YouTube Analytics reports | yt-analytics.readonly | Showing your viewers' age group, gender and country breakdown (last 90 days) on the Audience page. | Building profiles of individual viewers — the data is aggregate only. |
We ask for all four at connection time so the channel works across the whole product (publish, inbox, reports, audience). If Google ever lets you grant only some, features that need a missing permission simply say so instead of failing silently.
3. What we store, and where it appears
| Data | Shown in | Kept |
|---|---|---|
| Channel identity (name, handle, picture, subscriber and video counts) and encrypted tokens | Connect Accounts | Until you disconnect — then deleted immediately |
| Your videos: title, description, thumbnail, publish date, statistics | Growth & ROI (YouTube tab), weekly digest | Refreshed while connected; imported videos deleted on disconnect |
| Comments on your videos and replies sent through the Service | Inbox | Refreshed while connected; deleted on disconnect |
| Aggregate viewer demographics | Audience | Refreshed daily; deleted on disconnect |
| Videos you published through the Service (your own content and its record) | Growth & ROI | Your content — stays in your workspace until you delete it |
Data is visible only to users of the workspace the channel belongs to. Tokens are AES-encrypted at rest and never shown to anyone.
4. AI features and YouTube data
When you ask the AI to draft a Short's title/description, suggest a reply to a comment, or explain a video's result, the specific text or numbers involved are sent to an AI model provider for that request only (see sub-processors in the Privacy policy). We do not use YouTube data to train models, and no AI action reaches YouTube without a person approving it first.
5. Taking access back
- In the Service: Connect Accounts → the channel card → Disconnect. Tokens and imported YouTube data are deleted at once.
- At Google: myaccount.google.com/permissions → HOI SMA → Remove access. This works even if you cannot sign in to the Service.
- To have every remaining trace removed, follow Data deletion.
6. Our commitments
- We comply with the Google API Services User Data Policy, including its Limited Use requirements, and with the YouTube API Services Terms of Service and Developer Policies.
- We refresh or delete stored YouTube data within 30 days, and delete it immediately on disconnect.
- We do not sell YouTube data, use it for advertising, or transfer it to third parties except the sub-processors that run the Service.
- We respect YouTube's API quota; when the daily budget is nearly used, the Service delays non-urgent work rather than exceeding it.
Questions about this page? Email info@highoninnovation.com or highoninnovation.india@gmail.com.

