Privacy Policy
Last updated: June 23, 2026
1. Who We Are
playlist.al ("we", "our", "us") is a content management platform that helps creators manage, schedule, publish, and analyze media content across platforms including YouTube and Facebook.
2. Data We Collect
When you connect a third-party account (such as a Facebook Page or YouTube channel) to playlist.al, we collect and store:
- Your account identifier and display name on that platform
- The names and IDs of pages or channels you manage
- OAuth access and refresh tokens required to act on your behalf
- Content you choose to upload, schedule, or edit through our platform (videos, images, titles, descriptions, tags, captions, thumbnails)
- Per-video metadata and metrics returned by the platform's API (e.g., view counts, engagement, revenue) for display in your dashboard
We do not collect your platform password, personal messages, or any data beyond what is necessary to provide the service.
3. How We Use Your Data
We use your data exclusively to:
- Publish, schedule, and edit content on your connected accounts on your behalf
- Display your connected pages, channels, videos, and history within the platform
- Surface engagement, audience, and revenue analytics to you (the account owner)
We do not sell, rent, or share your data with third parties for advertising or any other purpose. We do not use YouTube API data to train machine-learning models. We do not surface YouTube API data to anyone other than the authenticated owner of the underlying channel.
4. Facebook Permissions
We request the following Facebook permissions:
- pages_show_list — to list the Pages you manage
- pages_manage_posts — to create and schedule posts on your Pages
- pages_read_engagement — to display your existing posts and engagement data
You can revoke these permissions at any time through your Facebook App Settings.
5. YouTube API Services
playlist.al uses YouTube API Services to provide creator tooling for YouTube channels you own and operate. By using the YouTube features of playlist.al, you agree to be bound by the YouTube Terms of Service. Information handled through YouTube API Services is governed by the Google Privacy Policy.
When you connect a YouTube channel, we request the following OAuth scopes:
- youtube and youtube.force-ssl — read and write the videos, playlists, and channel settings you own
- youtube.upload — upload new videos to your channel
- youtubepartner and youtubepartner-channel-audit — manage and audit content for CMS / Content-Owner users (optional)
- youtube.channel-memberships.creator — surface membership data on the memberships dashboard (optional)
- yt-analytics.readonly and yt-analytics-monetary.readonly — display engagement and revenue analytics for your videos
How we handle YouTube API data:
- Use: Solely to provide the creator-tooling features described above to you, the channel owner.
- Storage: Video metadata snapshots and analytics rollups are cached in our database for 30–90 days to power your dashboard without re-fetching on every page load. Older records are pruned automatically by a scheduled job.
- OAuth tokens: Encrypted at rest, scoped per user and channel, and deleted server-side when you disconnect the channel.
- Sharing: We do not sell, license, syndicate, or share YouTube API data with any third party. YouTube API data is never used for advertising and is never used to train AI/ML models.
- Revocation: You may revoke our access at any time through the Google Security page at https://myaccount.google.com/permissions. You may also disconnect a channel from your account settings inside playlist.al, which immediately deletes the associated tokens and cached data from our systems.
6. playlist.al Chrome Extension
The optional playlist.al browser extension brings playlist.al features directly into YouTube and YouTube Studio. This section describes exactly what the extension collects, how it handles that information, where it is stored, and with whom (if anyone) it is shared. No category is omitted.
6.1 What the extension collects and handles
- YouTube video identifiers and URLs — when you choose to send a video to your playlist.al server, the extension reads the current video's ID/URL from the page and sends it to playlist.al so the server can fetch that video.
- Video frames and screenshots — when you use the frame-capture or thumbnail features, the extension captures still images from the video you are viewing and sends them to playlist.al for processing.
- Video metadata you choose to generate — when you use the AI title, description, tag, or thumbnail features in YouTube Studio, the extension reads the relevant fields (e.g. existing title/description and the video frame) and sends them to playlist.al to produce suggestions, which are written back only into the Studio input fields you control.
- YouTube Studio page data — to render its in-page tools and the publishing checklist, the extension reads content from the YouTube and YouTube Studio pages you have open, including observing YouTube's own internal ("Innertube") API responses already loaded by those pages. This data is read locally in the page to drive the UI; it is not collected into a separate profile.
- Account credentials and session — to act on your behalf, the extension authenticates you to your playlist.al account. When you sign in through the extension popup, your email and password are sent over HTTPS directly to playlist.al, which returns a session cookie. The extension does not store your password.
- Local preferences and flags — your download format/quality preferences, feature toggles, onboarding state, per-video checklist progress, and short-lived cached AI suggestions.
The extension does not collect browsing history, keystrokes outside its own controls, data from sites other than YouTube, YouTube Studio, and playlist.al, or any data unrelated to the features above.
6.2 How the data is handled and used
- Data is used solely to provide the feature you invoked — sending a video to your server, capturing a frame, generating metadata/thumbnails, or maintaining the publishing checklist.
- Network requests are made only to
playlist.al (your account and processing backend) and to YouTube/YouTube Studio (the sites you are already using). The extension does not transmit your data to any other destination.
- The extension is not used for advertising, profiling, or any purpose unrelated to its stated functionality.
6.3 How the data is stored
- On your device: preferences, feature flags, onboarding/checklist state, and cached AI suggestions are stored locally in the browser via
chrome.storage.local. Cached AI suggestions are short-lived (about one hour). You can clear all of it at any time by removing the extension or clearing its storage.
- Authentication: your playlist.al session is held as a standard, HTTPS-only session cookie; your password is never stored by the extension.
- On our servers: any video, frame, or metadata you send for processing is handled under the same terms as the rest of this policy (see sections 2, 3, 5, and 7), including encryption in transit and the retention limits described in section 7.
6.4 How the data is shared
We do not sell, rent, trade, or share extension data with third parties. Data leaves your browser only to (a) your own playlist.al account backend to perform the action you requested, and (b) YouTube/YouTube Studio, which you are already signed in to and operating. We do not use this data for advertising and do not use it to train AI/ML models.
6.5 Permissions and why they are needed
- storage — to save your preferences and feature flags locally on your device (section 6.3).
- downloads — to save videos and images you request to your computer.
- Host access to
youtube.com and studio.youtube.com — to read the current video and render the in-page tools on the pages you are using.
- Host access to
playlist.al — to authenticate you and send the data you choose to process to your account backend.
6.6 Removing the extension
Uninstalling the extension removes all locally stored extension data. To revoke its access to your account, sign out from the extension popup or your playlist.al account settings.
7. Data Retention
Your access tokens and connected-account data are stored securely and retained for as long as your account is active. You can disconnect any connected account at any time from your account settings, which will immediately delete all associated tokens and cached data from our systems.
8. Data Security
All data is transmitted over HTTPS. Access tokens are stored securely and are only accessible to your account. We do not log or expose your page tokens in any application output.
9. Your Rights
You have the right to:
- Access the data we hold about you
- Request deletion of your data at any time
- Disconnect any connected account, which removes all associated data immediately
- Revoke OAuth permissions directly through the issuing platform (e.g., Google account permissions for YouTube, Facebook App Settings for Facebook)
To request data deletion, contact us at client@onair.al or use the disconnect option in your account settings.
10. Contact
For any privacy-related questions, contact us at:
client@onair.al