What we read from your channel, and how we look after it.

Creatorscope never posts, edits or deletes anything on your channel. Below is every permission it asks Google for, and why, so you can check.

Last updated · 23 September 2026

What we read from YouTube

When you connect a channel, Google asks you to approve these permissions. Here's each one, and why:

  • openid, email, profile: your name, email address and profile picture, to sign you in.
  • youtube.readonly: read your videos, titles, descriptions, thumbnails, comments and channel details.
  • yt-analytics.readonly: read your channel analytics, including views, watch time, retention curves and impressions.
  • yt-analytics-monetary.readonly: read the revenue figures in those analytics, so each video's earnings sit next to its views.
  • youtube.force-ssl: download the captions of your own videos when you ask for them. The writer works from them. Google has no narrower permission that allows caption downloads.

The analytics and readonly permissions only let us read. The caption permission is broader than we'd like, because Google puts caption downloads behind it. We use it for one thing: downloading captions. Nothing in Creatorscope's code writes to YouTube. You can remove our access in your Google account at any time. The full detail is in the privacy policy.

What we store

A copy of the YouTube data we pulled, meaning your videos and their details, thumbnails, retention curves and analytics, so the app doesn't call YouTube on every page load.

What you make in the app: pipeline cards, research, scripts, ideas, voice samples and settings.

Every row belongs to your account. Your videos, scripts and voice samples are tied to your user ID in the database. Other accounts can't see them, and nothing is pooled with anyone else's.

How we protect it

Every request checks ownership. Before a request touches a video, a channel, a comment reply, a script or a voice document, the server checks it's yours (ownsVideo, ownsChannel, ownsCommentReply and the rest). If it isn't, you get a 404, the same answer as if it didn't exist.

Raw errors stay on our side. Database messages and stack traces go to our error log in Sentry. They're never sent to your browser.

Crash replays are masked. When something crashes inside the app, Sentry records a replay of the moments before it. Replays run with maskAllText and blockAllMedia, so text and media are masked before they leave your browser. Cookie and Authorization headers are removed from every event. We can see that a button broke. We can't read your script.

Payment events count once. Every Stripe event ID is recorded in a stripe_events table before it's handled, so a repeated event can't grant a plan twice.

Rate limits survive deploys. The free title check and the front-page demo count requests per IP address in our database, so the limits don't reset when we ship an update.

Data deletion

Delete your account in Settings and everything goes at once. The same step cancels your subscription and revokes our Google access.

When a paid plan ends, or you remove our access in your Google account, a daily job deletes the data we pulled from YouTube 30 days later. Your account, scripts and research stay, so you can come back to them.

Rather we did it? Email hello@creatorscope.studio. No forms, and nobody will try to talk you out of it.

Where data lives

The app runs on Vercel in Dublin. The database is Turso, also in Dublin (AWS eu-west-1). Everything travels over TLS. Your sign-in cookie is HttpOnly and Secure and holds a random token, nothing else. Signing in on a new device signs you out of the old one.

We follow GDPR practices: your data is kept to your account, analytics cookies wait for your consent, and deletion happens when you ask. We don't hold a SOC 2 or ISO 27001 certification, and we'd rather say so than show a badge we haven't earned.

What we don't do

  • We never write to your channel. No posting, no edits, no deletions, no scheduled uploads. The one broad permission we hold, youtube.force-ssl, is only used to download captions. We never call a write endpoint with it.
  • We never sell or share your data. Not with advertisers, not with data brokers. The only outside services that see your content are the AI providers that make things for you: Anthropic (Claude) for the writing and analysis, Google (Gemini) for web research, voice matching and one of the two thumbnail models, and Higgsfield for the other thumbnail model.
  • Your scripts and voice samples stay in your account. Only your account uses them, and nobody else can see them.
  • We don't train anything on your data. The writer looks up excerpts from your own captions each time it writes, for your account only. Your channel won't become someone else's head start.

Questions or disclosure

Found a security problem? Email hello@creatorscope.studio with the details. That's Alex, the founder, and he replies himself, usually within a day. There's a machine-readable version at /.well-known/security.txt. Retention, third parties and your rights are covered in the privacy policy.

Creatorscope

Reinholdsson Media House B.V. · Zwolle, The Netherlands

KVK 96166959 · BTW NL867496265B01

Made by Alex Reinholdsson · reinholdssons.com

Not affiliated with YouTube or Google. Creatorscope reads your channel through their official API.