Privacy policy
Content Lab is a private application that Tom Plumpton (“the owner”) runs on his own computer for his YouTube channel, Loop Mechanics. This policy explains what the application accesses, how it uses and stores that information, who else receives it, and how to remove it. It also covers this information website, separately, at the end.
Content Lab uses the YouTube API Services. By using it, you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
Who uses Content Lab
Only the owner signs in to Content Lab, with the Google account that manages the Loop Mechanics channel. The application runs on the owner's computer and is not available to anyone else. It does not access other people's Google accounts or channels.
Two connections to YouTube
Content Lab reaches YouTube in two separate ways. They handle different information and are described separately below.
- The Google sign-in, which reads the channel's identity and analytics through Google's APIs.
- Zernio, a third-party publishing service, which publishes the owner's approved videos to the channel.
1. The Google sign-in
Permissions requested
- View your YouTube account (
youtube.readonly) - Used to identify the connected channel and, when the owner asks, to read details of the channel's own videos, such as the title, description and privacy status, to confirm that a publication appeared as approved.
- View YouTube Analytics reports for your YouTube content (
yt-analytics.readonly) - Used to read channel analytics when the owner asks Content Lab to sync them.
Content Lab does not request permission to upload or manage videos: it does not upload through the Google sign-in, and publication goes through Zernio, described below. It does not request access to revenue reports, Gmail, Google Drive, contacts or any other Google service.
Information accessed and stored
- Sign-in credentials: the access token and refresh token Google issues, when the access token expires, and the permissions granted.
- Channel identity: the channel ID, channel title and handle, when the connection was last checked, and whether the owner confirmed it is the right channel.
- Channel analytics: daily channel totals for the 28 days ending the previous day, covering views, engaged views, estimated minutes watched, average view duration, likes, comments, shares and subscribers gained, together with the date range requested and when it was collected. These are totals for the whole channel. Content Lab does not receive information about individual viewers, or the text of comments.
- Sign-in in progress: while the owner is signing in, a random state value and a verification code used to complete the sign-in securely. They expire after ten minutes and are deleted once used.
How it is used
This information is used only to show the owner which channel is connected, to check a publication, and to show how the channel is performing in the owner's local dashboard. Analytics are fetched only when the owner requests a sync. Content Lab does not use this information for advertising, sell it, or use it to train artificial intelligence models.
2. Publishing through Zernio
The Loop Mechanics channel is connected to Zernio within the owner's Zernio account. That connection is authorised by the owner on Zernio's own terms, not through Content Lab's Google sign-in. Content Lab uses Zernio's API, with the owner's Zernio key, to publish videos the owner has approved.
For each approved video, Content Lab sends Zernio:
- the video file;
- its title, and its description, including hashtags and any music credit;
- the scheduled time, and its YouTube settings: visibility, whether it is made for children, whether it contains altered or synthetic content, and its category.
Zernio then publishes the video to YouTube. Content Lab keeps a local record of each publication: which video it was, a checksum of the file, when it was attempted, its status, and the identifiers and links Zernio returns. Content Lab does not send Zernio any information it receives through the Google sign-in. Zernio's handling of this information is described in Zernio's privacy policy.
Where information is stored
Everything above is stored in files and a local database on the owner's computer, in a private data folder that is excluded from version control. Files holding the Google sign-in and analytics can be read only by the owner's user account on that computer. Content Lab does not encrypt these files itself, and there is no Content Lab server or cloud database.
Who else receives information
- Google and YouTube receive the requests Content Lab makes to their APIs.
- Zernio receives approved videos and their text, as described above.
- AI assistants. The owner operates Content Lab with the help of AI coding assistants (Anthropic's Claude and OpenAI's Codex) running on his computer. When the owner asks one to carry out a Content Lab task, such as syncing analytics or checking a publication, what it reads while doing so, which can include channel identity and analytics figures, is sent to that assistant's provider to process the request, under that provider's terms.
Content Lab does not sell information, share it with advertisers, or allow third parties to serve content or advertisements through it.
Limited Use
Content Lab's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies and device storage
While the owner signs in with Google, Content Lab places a single cookie in the owner's browser to tie the sign-in to that browser. It cannot be read by scripts, lasts at most ten minutes and is cleared when the sign-in finishes. Content Lab uses no advertising or analytics cookies. The information described above is stored on the owner's computer as explained under “Where information is stored”.
How long information is kept
- Sign-in credentials and channel identity are kept until the owner disconnects, or until Google stops accepting them.
- Analytics: each sync replaces the previous report. The latest report is kept until the owner deletes it; disconnecting does not delete it.
- Publishing records are kept until the owner deletes them. They are what stop the same video being published twice, so disconnecting does not delete them.
Disconnecting, revoking access and deleting information
- Disconnect in Content Lab. Disconnecting on the application's YouTube page deletes the saved sign-in credentials, channel identity and any sign-in in progress. It keeps analytics and publishing records, and does not revoke the permission granted to Content Lab at Google.
- Revoke access at Google. You can revoke Content Lab's access to your data at any time via the Google security settings page at https://security.google.com/settings/security/permissions. After that, Content Lab can no longer read the channel or its analytics.
- Delete retained analytics by deleting the analytics file in Content Lab's private YouTube data folder.
- Delete publishing records only after checking that no publication is still in progress or unresolved. Content Lab uses these records to confirm whether an attempt reached YouTube; deleting an unresolved one could lead to the same video being published twice.
- Zernio and YouTube keep their own copies. Disconnect the channel or delete posts in Zernio, and delete videos in YouTube Studio, under those services' own policies.
This information website
This website, content.tomplumpton.me, is separate from the application. It has no sign-in, forms, cookies, analytics or scripts of its own, and loads no third-party fonts or embedded content. It is hosted by GitHub Pages, and its domain name is served by Cloudflare's DNS. GitHub processes information about visits, such as IP addresses, to deliver and protect the site, as described in the GitHub General Privacy Statement. The owner does not receive visitor logs from GitHub.
Changes
If Content Lab's use of information changes, this policy will be updated before the change takes effect, and the date at the top will change.
Contact
For questions or complaints about Content Lab or this policy, email tomplum.content@gmail.com.