Privacy policy
Version 2026-09-09. A recorded acceptance applies to this version, and to this version only: changing this text asks for acceptance again.
1. Use of the YouTube API Services
GameInflux uses the YouTube API Services to obtain public information about channels and videos.
2. Data accessed and collected
Only public data, obtained by API key on public endpoints. No YouTube user authentication is requested, and no private account data is accessible. What follows is the complete list — not a summary.
From a YouTube channel
- identifier, title, description, custom URL, avatar image URL;
- subscriber, video and view counts;
- the creation date, the country and the language that the channel itself declares — never a location or a language we observe or infer;
- the identifier of the channel’s uploads playlist. It is collected but never displayed: it serves only to list that channel’s videos;
- the three dates of our own cycle — when a value was collected, when it is due to be refreshed, when it expires. These three are shown on the channel page;
- two markers recording when our own jobs last enriched the channel and last listed its uploads. They are ours, not YouTube’s, and they are never displayed.
From a video
- identifier, and the identifier of the channel that published it;
- title, and description — the description is collected and stored, but never displayed;
- publication date, and thumbnail image URL;
- the language and the original audio language that the video itself declares;
- view, like and comment counts. A count a channel chooses to hide stays absent; it is never replaced by a zero.
How we found a channel
We run our own search queries, written by hand. For each result we keep the query and the strategy used, the page and the position of the result, and the identifiers YouTube returned. This provenance is kept for at most 29 days, is never refreshed, and is never shown to anyone: not as an affinity, not as a filter, not as any way of browsing the site.
What we collect from you
- two first-party cookies, each valid for one year: one holds a random token standing for your acceptance of this policy, the other holds your language choice;
- a server-side record of that acceptance: a fingerprint of the token, the policy version, and two dates. The token itself never reaches our database, which therefore cannot tell who accepted;
- nothing else. No IP address, no user agent, no referrer, no account, no browser fingerprint, no audience measurement, no third-party tracker. Your searches, filters and sort orders travel in the address bar and are never recorded.
No audiovisual content is downloaded. Images are displayed from the URLs provided by YouTube, without copy or rehosting: your browser requests them directly from YouTube’s own image hosts, and is told not to send the address of the page you are on.
Some fields are requested only so that we can validate YouTube’s answer, and are then discarded — the hidden-subscriber flag is one. From the step that lists a channel’s uploads we keep nothing at all: no playlist entry, no title, no thumbnail, no position. No pagination token is stored.
3. Storage, retention and deletion
Every value keeps its collection date, its refresh deadline and its expiry deadline. The durations actually applied are the following:
- refresh due: 21 days after collection;
- expiry and removal from display: 29 days after collection, before the 30-day refresh-or-delete limit of the YouTube API Services;
- physical deletion by an automatic process run every hour in the database.
An expired value is never presented as current: it is removed from display before its physical deletion. No history beyond this window is kept, and a channel or a video YouTube stops returning expires at once, without waiting for its deadline.
Three things are deliberately kept longer, and we would rather name them than let a reassuring sentence stand in their place:
- the removal register — a channel identifier, the date, and an opaque case reference — is kept with no time limit. Erasing it would let the channel be discovered and indexed again, which would undo the very removal it records;
- the record of a privacy-policy acceptance is kept beyond the year during which it is valid;
- our operational records — the log of API calls, quota counters, job and deletion runs — are kept with no time limit. They hold no data obtained from the YouTube API Services: an endpoint name, a cost, a status, a normalised error code.
4. Use and processing
Values are rendered as received, for consultation. No score, ranking, categorisation or derived metric is computed from this data.
5. Sharing and processors
No data obtained from the YouTube API Services is sold, redistributed, or shared with a third party for that party’s own use. No export, no download and no replication interface are offered.
Two providers process this data on our behalf, on our instructions, and for no purpose of their own:
- Vercel hosts the application, runs its server code, and triggers the scheduled jobs that collect and refresh the data;
- Supabase hosts the PostgreSQL database in which the data is stored, and runs the hourly deletion job inside it.
We name them rather than describe them vaguely: an application that runs on hosted infrastructure has processors, and claiming otherwise would be inaccurate. This policy states what our own repository establishes about their role, and nothing beyond it.
6. Authorized Data
GameInflux handles no Authorized Data: no OAuth authorisation is requested, and no data specific to a YouTube account is accessible.
You can review and revoke access granted to third-party apps on your Google Account connections page. GameInflux currently requests no such access, so there is no GameInflux YouTube authorisation to revoke.
7. Your rights
A user of the service may request deletion of the data concerning them; it happens within seven days. A creator whose public channel appears in our index may request its removal: we honour any verified request where retention is not legally required.
For deletion or removal requests, or questions or complaints about our privacy practices, contact us at privacy@gameinflux.com. Writing to us necessarily discloses your own address: we use it to answer you and to handle your request, and for nothing else. Once the matter is settled, the removal register keeps only what section 3 names — a channel identifier, a date, and an opaque case reference — never the address you wrote from.
Deleting data held by GameInflux does not delete or change data held by YouTube. To delete data on YouTube, use YouTube’s own tools.
8. Security and internal access
Access to data is restricted by distinct database roles. Deletion of data obtained from the YouTube API Services has a single technical path, reserved to a dedicated identity. Administration operations are logged without creating a historical copy of this data.