Privacy Policy
Last updated: 1 August 2026
Klyf provides YouTube channel diagnostics. You connect your YouTube channel and we analyze your own Studio data to tell you which of your videos to fix first and why. This policy explains what we access, why, how long we keep it, and how to remove it.
Google / YouTube data we access
When you connect your channel, you grant us access through Google’s OAuth consent screen. By default we request two read-only scopes:
- youtube.readonly: to list your videos and read their public metadata (titles, publish dates, durations).
- yt-analytics.readonly: to read your channel’s analytics, including impressions, click-through rate, audience retention, watch time, views, and subscribers gained.
We access only your own channel’s data, and we never access other people’s channels. Unless you explicitly turn on auto-reply (see below), Klyf holds read-only access and never posts, edits, or deletes anything on your channel.
Posting replies (optional, Pro only)
If you are on Klyf Pro, you can grant one additional Google scope, youtube.force-ssl, through a separate Google consent screen. This is entirely opt-in and powers Klyf's advanced features: posting the comment replies you have explicitly approved (auto-reply), and reading the captions and transcripts of your own videos so a script Klyf drafts can match your voice and so Klyf can show you what is said where viewers drop off. We never edit or delete anything, we never post without showing you the exact text first, and we use this access only for those features. You can revoke it at any time from your Google Account permissions page, which turns the advanced features off while leaving your read-only diagnostics working.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. YouTube analytics you authorize are handled in accordance with the YouTube Terms of Service and the Google Privacy Policy.
Public comments
To tell you what your audience keeps asking for, Klyf also reads the public comments on your recent videos using a YouTube Data API key. These are comments already visible to anyone on YouTube; reading them does not use your account’s authorization. We summarize the themes for you and do not sell or share this data. Posting replies is a separate, opt-in step described above under “Posting replies”, and only ever posts text you have approved.
How we use it
We use your channel data solely to generate your diagnostics: a ranked list of your videos, the funnel stage where each is underperforming (distribution, click-through, retention, or subscriber conversion), and the estimated cost of each gap. We do not use your data to train machine-learning models, and we do not sell it or share it with advertisers or data brokers.
Access tokens
Your Google refresh token is stored encrypted at rest and is used only to retrieve your analytics on your behalf. You can revoke our access at any time from your Google Account permissions page, or by disconnecting Klyf. On revocation we stop all access immediately.
How we protect your data
We treat the Google and YouTube data you authorize as sensitive, and protect it with the following technical and organizational measures:
- Encryption in transit. All data moving between your browser, Klyf, Google’s APIs, and our infrastructure travels over encrypted HTTPS/TLS connections. We do not transmit your data over unencrypted channels.
- Encryption at rest. Your Google refresh token is encrypted with authenticated encryption (AES-256-GCM) before it is written to storage, using a secret key held in our server environment and never in the database. Our database and hosting layer additionally encrypt stored data at rest.
- Least privilege. Klyf requests the narrowest scopes needed to work: read-only access by default, and one optional advanced scope only if you turn on a Pro feature that needs it (posting approved replies, or reading your own transcripts to match your voice in a script and to see what is said where viewers drop off). We never request the ability to edit or delete your videos, and we never access channels other than your own.
- Restricted access. Access to production systems and to stored user data is limited to authorized personnel, protected by strong authentication, and used only to operate, secure, and support the service.
- Trusted infrastructure. We run on established hosting and database providers that maintain their own security programs, and who process your data only under contract, on our instructions, and never for their own purposes.
- Secure deletion. When you disconnect or request deletion, we permanently remove your stored data and destroy your encrypted tokens, and our access to your channel ends immediately.
No online service can promise perfect security, but these safeguards are designed to protect your data against unauthorized access, disclosure, alteration, and loss. If we ever become aware of a breach affecting your data, we will notify affected users and the relevant authorities as required by law.
Data retention and deletion
- Raw YouTube data (daily metrics, impressions, click-through rate) is retained for a maximum of 30 days, consistent with the YouTube API Services Terms of Service, then deleted.
- Derived statistics (medians, funnel diagnoses, retention summaries) that we compute from your data may be retained longer to show you trends over time.
When you disconnect your channel, or on request to privacy@klyf.ai, we delete your stored data, both raw and derived, and revoke and destroy your stored tokens. Deletion is complete and permanent.
Sharing
We do not share your channel data with third parties except infrastructure providers strictly necessary to operate the service (our database and hosting providers), who process it under contract on our behalf. We disclose data if required by law.
Analytics
We use PostHog for first-party product analytics, to see how people find Klyf and reach key milestones (like connecting a channel or subscribing). It stores a first-party analytics identifier on your device to measure this. We use no third-party or advertising trackers, never sell your data, and never send your YouTube channel data to analytics.
Changes
We’ll update this page and the “last updated” date when this policy changes.