Privacy Policy
Last updated · September 2026
The short version
Tubient accesses your YouTube Analytics data to display in your dashboard. We store an authentication token and your pipeline sessions so you don't lose your work between visits. We do not sell your data or use it for advertising, and we share it with no one beyond the two processors that make the product work: Google Gemini for AI answers, and Sentry for crash reports — which are stripped of personally identifiable information and user-generated content before they are sent.
Privacy by Design
Tubient is built with a "Privacy by Design" architecture. We ensure that you have full control over your data and that non-essential tracking is restricted until you explicitly allow it.
Unlike many platforms that track first and ask later, Tubient blocks all non-essential storage (such as API response caching) by default. This data is only stored in your browser after you click "Accept All" on our privacy banner.
One category is treated as essential rather than optional: error diagnostics. When the dashboard crashes, or a request fails on our servers, we receive a scrubbed crash report so the fault can be fixed, because an application that breaks silently cannot be kept secure or reliable. It is not analytics and never used to profile you — it stores nothing in your browser and records no address or location, and every report has personally identifiable information and user-generated content removed before it is sent. Reports are labelled with your account identifier so we can tell which account a fault affected — never your name or email address. See Error Monitoring below.
Data Classification
Essential
Required for the app to function
- Authentication Tokens
- UI Settings (Theme, Size)
- Consent Preference
- Session History
- Error Diagnostics
Non-Essential
Optional performance optimizations
- YouTube API Cache
- Transient Support Query Drafts (LocalStorage)
- Future Analytics (Placeholder)
Information Access, Collection, and Storage
Tubient provides AI-powered YouTube analytics. To provide these services, our API Client accesses, collects, and stores specific user information and API Data:
- YouTube API Data (Access): When you authenticate, our application accesses your YouTube channel information (including channel name, handle, and thumbnail) and your YouTube Analytics data (including views, watch time, subscriber counts, and engagement metrics).
- Authentication Information (Storage): We store a long-lived Refresh Token, encrypted, in our secure server-side database to maintain your connection. A short-lived session credential is held by your browser while you are signed in to perform authorized requests on your behalf.
- YouTube Metadata (Collection): Your channel ID, display name, and thumbnail URL are collected and stored in our database. We also collect and store basic video metadata (titles, durations, and thumbnails) to facilitate instant loading and visual recognition.
- Pipeline Sessions (Storage): The analytics pipelines you build (your dashboard layout and chart configurations) and your AI conversation history are stored in our remote database to allow you to persist and resume your work across different devices. This includes cached video identifiers so the AI assistant can reference your videos without repeatedly re-fetching data from YouTube.
- Ephemeral Cache (Storage): If you provide consent, specific YouTube API responses are cached in your browser's storage for a limited time (up to 24 hours) to improve performance and minimize API quota usage. Our servers also maintain a short-lived cache of video metadata.
- Usage Metrics: We track total API usage volumes (quotas) at an aggregate level to manage service health and limits.
How We Use Your Information
The information and API Data we access and collect is used exclusively for the following purposes:
- Visualization: To generate interactive charts, graphs, and tables based on your channel's performance.
- AI Insights: To provide the Google Gemini AI model with the necessary context to answer your natural language questions about your YouTube data.
- Instant Context: To provide metadata context to the AI assistant without requiring redundant external API calls.
- Session Persistence: To save your progress, configurations, and history so you can access them in future sessions.
- Optimization: To reduce the number of redundant network requests made to YouTube's servers.
We do not sell your data, use it for advertising, or share it with any third parties except for two processors described below: Google Gemini, which powers the AI assistant, and Sentry, which receives scrubbed crash reports so faults in the dashboard and on our servers can be diagnosed and fixed.
Use of YouTube API Services
Tubient uses YouTube API Services as an API Client to fetch real-time analytics data and channel metadata. All metrics are provided directly by YouTube API. By using our application, you agree to be bound by the:
The API Data fetched is processed to provide the visualizations and AI-driven analysis features of the app. As noted above, this data is only stored permanently if it relates to your account identity or saved session configurations. Raw analytics metrics are only stored ephemerally in your browser's cache.
Tubient's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI Processing (Google Gemini)
Tubient includes an AI assistant powered by Google Gemini. When you interact with the assistant:
- Your natural language queries and recent conversation context are sent to our backend and forwarded to the Gemini API.
- We share anonymized metrics and the structure of your dashboard to help the AI construct visualizations.
- Sensitive credentials or personal profile data are never shared with the AI model.
- We do not use your data or queries to train AI models.
Error Monitoring
When something breaks, Tubient sends an automatic crash report to Sentry, our error monitoring provider, so the fault can be found and fixed. This happens in two places: in your dashboard when the page itself fails, and on our servers when a request you made fails there. This is classified as essential to keeping the service secure and reliable, so it is not covered by the privacy banner — it is not analytics, is never used to profile you or measure your behaviour, and is never used for advertising.
What a crash report contains
- The error type and message, and the stack trace showing which code failed.
- For a fault in the dashboard, your browser and operating system version and the page path where it happened. For a fault on our servers, which part of our own code failed.
- A short trail of preceding actions (for example "a network request failed") to reproduce the fault.
- Identifiers for the account, YouTube channel and pipeline session in use, so we can tell which account a fault affected and check whether your saved data was involved. These are opaque reference numbers — they carry no name, email address or contact details.
What is removed before it is sent
Crash reports are stripped of personally identifiable information and user-generated content before they leave — in your browser for a dashboard fault, and before the report leaves our server for a server fault. Specifically, we remove:
- Authentication tokens and authorization codes, including any present in the page address.
- Email addresses, your display name and your profile picture.
- Your user-generated content: the questions you ask the AI assistant, your video titles, and your YouTube Analytics values. Query strings, request bodies and console output — the places this content travels — are dropped in full rather than filtered.
We also do not collect your IP address, your location, your cookies, or the contents of any request or response. Server-side reports are configured to discard the incoming request entirely — its address, headers and body are never attached — so what reaches Sentry is the fault and the opaque identifiers above, nothing else. Error monitoring writes nothing to your browser's storage, and reports are never used to measure or profile how you use the product.
Scope and retention
- It covers the signed-in dashboard and the servers behind it. Our marketing, documentation and blog pages are not monitored.
- Reports are processed and stored by Sentry on servers in the United States, and are retained for 90 days before automatic deletion.
- Sentry acts as a processor on our behalf and does not sell your data. Their handling is governed by the Sentry Privacy Policy.
Security & Retention
Your data is protected by industry-standard security measures:
- Encryption: All data is encrypted in transit (HTTPS/TLS) and at rest within our Firestore database.
- Access Control: All database operations are authenticated through our backend server; there is no direct client-side database access.
- Retention: We retain your saved pipelines and tokens as long as your account is active. YouTube API data stored on our servers is refreshed or deleted at least every 30 calendar days, except for identifiers and authorization tokens retained while your authorization remains active. When you remove a channel or request account deletion, we permanently wipe all associated data.
Your Rights and Revocation
You have full control over your data usage:
- Revocation: You can revoke Tubient's access to your YouTube account at any time via the Google Security Permissions page.
- Data Deletion: You can permanently delete all your stored pipeline sessions, tokens, and account data at any time via the "Delete My Account" option on the Account Page.
- Access: You have the right to request a copy of the data stored in our database.
Browser Storage Policy
Tubient stores data locally in your browser (using local storage and IndexedDB) to provide a high-performance experience. We do not use cookies. We follow a "Privacy by Design" architecture: non-essential storage is blocked by default until you provide explicit consent.
Essential Storage
Required for the application to function.
Signed-in profile information (name, avatar, plan)
UI preferences (Theme, Font Size)
Stores your privacy preferences
AI Chat history
Non-Essential Storage
Used for optimization and performance.
Caches YouTube API responses to reduce quota usage
Stores partial support request drafts to prevent progress loss
Withdrawal of Consent
You can withdraw your consent at any time by clearing your browser's site data for Tubient, or by clicking the "Reject Non-Essential" button on the privacy banner or using the toggle in your Settings page. We also respect Global Privacy Control (GPC) signals sent by your browser.
Contact
For privacy questions, data requests, or to exercise your rights under GDPR/CCPA, please visit our Contact Page.
Official Address
Tubient
2/4 Carden Ave, Wahroonga, NSW, 2076, Australia