YouDarkyoudark.com
Back

Privacy Policy

Last updated: May 12, 2026 (LGPD section added)

1. Introduction

YouDark ("we", "us", or "our") operates the website youdark.com and provides an operating system for faceless YouTube channels β€” analytics, topic intelligence, SEO tooling, copyright scanning, and AI video generation (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using YouDark, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and display name through our authentication provider (Supabase Auth). If you sign in via Google OAuth, we receive your name, email, and profile picture from Google.

2.2 YouTube Data

If you connect your YouTube channel, we request the minimum scopes needed for the features you use:

  • youtube.upload β€” to upload videos to your channel when you click Publish
  • youtube β€” to add an uploaded video to a playlist you select
  • youtube.readonly β€” to display your channel name, avatar and basic statistics on the Dashboard
  • yt-analytics.readonly β€” to display your last-30-day CTR and retention on the Dashboard

We store your YouTube OAuth tokens (access token and refresh token) securely in our database. These tokens are only used for the user-initiated actions described above. We never access your YouTube data without your direct action.

2.3 Generated Content

We temporarily store scripts, images, audio, and videos generated through our Service to enable rendering and delivery. Rendered videos are stored on our servers for download and optional YouTube publishing.

2.4 Usage Data

We collect anonymized usage data such as pages visited, features used, render counts, and error logs to improve our Service. We do not use third-party tracking or advertising cookies.

2.5 Payment Information

Payments are processed by Stripe. We do not store your credit card number or banking details. Stripe handles all payment information in accordance with PCI-DSS standards.

3. How We Use Your Information

  • Provide, operate, and maintain the Service
  • Process your video renders and deliver generated content
  • Publish videos to YouTube when you explicitly request it
  • Process payments and manage subscriptions via Stripe
  • Send transactional emails (account verification, password reset)
  • Monitor and improve Service performance and reliability
  • Detect and prevent fraud or abuse

4. Data Sharing

We do not sell your personal data. We share information only with:

  • Supabase β€” authentication and database hosting
  • Google/YouTube API β€” only when you use the YouTube Publisher feature
  • Stripe β€” payment processing
  • Google Gemini API β€” AI script and content generation (no personal data is sent)
  • Railway / Vercel β€” infrastructure hosting

5. Google API Services User Data Policy

YouDark's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use the YouTube Data API and YouTube Analytics API solely to provide the user-facing features described in this policy: channel analytics, video upload, and playlist management.
  • We do not use Google user data for serving advertisements.
  • We do not allow humans to read Google user data unless we have the user's specific consent to read specific records, it is necessary for security purposes (e.g. investigating abuse), or it is necessary to comply with applicable law.
  • We do not transfer Google user data to third parties unless necessary to provide our services, comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to users.

Data we store from Google APIs:

  • OAuth refresh and access tokens (encrypted at rest in Supabase)
  • YouTube channel ID, display name, avatar URL
  • Channel statistics (subscriber, view, video counts) β€” refreshed up to once per hour
  • Channel CTR and average retention over the last 30 days β€” refreshed up to once per hour

You can revoke YouDark's access to your YouTube account at any time through your Google Account permissions page or by disconnecting your channel in the YouDark dashboard.

6. Data Retention

  • Account data β€” retained until you delete your account
  • Rendered videos β€” stored for 30 days after creation, then automatically deleted
  • YouTube tokens β€” deleted when you disconnect your channel or delete your account
  • Usage logs β€” retained for up to 90 days for debugging purposes

7. Data Security

We implement industry-standard security measures including encrypted data transmission (TLS/SSL), encrypted database storage, and secure token management. However, no method of electronic transmission or storage is 100% secure.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Revoke YouTube access at any time
  • Export your generated content before account deletion

To exercise any of these rights, contact us at support@youdark.com.

9. Children's Privacy

Our Service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date.

11. Contact Us

If you have questions about this Privacy Policy, please contact us at: support@youdark.com

12. LGPD β€” Brazilian users

If you are located in Brazil or YouDark processes your personal data in Brazil, the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) applies. This section makes our LGPD obligations explicit. The rest of this policy continues to apply alongside.

12.1 Legal basis for processing (LGPD Art. 7)

We process your personal data on the following legal bases:

  • Contract execution (Art. 7 V) β€” to provide the Service you signed up for: account, channel scoring, weekly plans, billing.
  • Consent (Art. 7 I) β€” for non-essential cookies (first-party analytics), marketing emails, and any feature you explicitly opt into.
  • Legitimate interest (Art. 7 IX) β€” for fraud prevention, security logging, abuse detection, product improvement based on aggregate metrics. We weigh this against your reasonable expectations and never use legitimate interest to override an explicit refusal.
  • Legal obligation (Art. 7 II) β€” to retain billing records for the period required by Brazilian tax law (typically 5 years).

12.2 First-party analytics cookie

We set one first-party cookie, yd_sid (random UUID, 1-year expiry, SameSite=Lax), to measure how the signup funnel performs in aggregate. No third-party trackers, no advertising cookies, no cross-site tracking. The cookie is gated by a consent banner β€” declining keeps the rest of the site working; only funnel analytics are skipped.

12.3 International transfers (LGPD Art. 33)

Some of our processors are located outside Brazil. We rely on these for service operation under LGPD Art. 33 II (transfer necessary for contract execution) and the contractual safeguards each processor provides:

  • Supabase (United States) β€” authentication + database. Standard contractual clauses + SOC 2.
  • Stripe (United States, Ireland) β€” payment processing. PCI-DSS + GDPR DPA.
  • Resend (United States) β€” transactional email delivery.
  • Google / Gemini API (United States) β€” AI inference for scripts, scoring, and the free tools. No personal data is included in prompts.
  • Vercel (United States) β€” application hosting.

12.4 Your rights under LGPD Art. 18

You have nine specific rights under Brazilian law. They are listed and actionable at our dedicated page: youdark.com/data-rights. We respond to requests within 15 business days as required by LGPD Art. 19.

12.5 Data Protection Officer (Encarregado, LGPD Art. 41)

You can contact our Encarregado pelo Tratamento de Dados Pessoais (DPO) at privacy@youdark.com for any privacy-related question. The DPO is responsible for handling LGPD requests, communicating with the ANPD, and orienting staff on data-protection practices.

12.6 Data breach notification (LGPD Art. 48)

In the event of a security incident that may pose risk or relevant harm to data subjects, we will notify the ANPD and affected users within a reasonable timeframe β€” generally within 72 hours of becoming aware β€” including the nature of the affected data, mitigation measures taken, and recommended actions for affected users.

12.7 Children and adolescents (LGPD Art. 14)

YouDark is not directed at children under 18. Processing of personal data of children under 12 requires specific, highlighted, and given by at least one parent or legal guardian β€” we do not knowingly collect such data. For users between 12 and 18, processing must serve the best interest of the data subject. If you believe we have collected data from a minor in non-compliance with LGPD, please contact us immediately.

12.8 ANPD (Brazilian Data Protection Authority)

If you believe we have not adequately addressed your concern, you may file a complaint with the Autoridade Nacional de ProteΓ§Γ£o de Dados (ANPD) at gov.br/anpd.