Menu
THE CLEAR VERSION

Your data.
Your business.

Privacy policy · 2 October 2026

What YTProof does

YTProof creates video cards from sample earnings or estimated YouTube revenue retrieved with your permission. An account and claimed username are required to create a card. Every export publishes its video and earnings record on the account’s public creator profile. The editor explains this before export. We do not sell your data or use advertising or analytics trackers.

Google sign-in and YouTube access

Username/password sign-up uses a private email for confirmation and recovery. Passwords are hashed by the authentication service. Google sign-in uses your Google account identifier and email to maintain your account and session. Your email never appears in a card or public profile. Connecting YouTube is a separate read-only consent flow. The permissions allow channel information and broader analytics, including monetary reports. We fetch only each separately authorised channel’s identity and daily estimated revenue needed for your selected period and currency.

YTProof uses YouTube API Services. Google’s handling of data is explained in the Google Privacy Policy. You can revoke access in Google account permissions.

Your public profile and cards

You choose a unique handle, public display name and optional bio. Handles remain assigned to the account until account deletion. Profiles show published cards. A proof page includes the original video, amount, currency, reporting dates, publication time, expiry and file fingerprint; connected cards also show when earnings were fetched. Channel names are hidden unless explicitly enabled. Anonymous mode hides identity on the video, but signed-in exports remain linked to their public profile.

Published videos, posters and earnings records expire within 30 days. Connected records expire no later than 30 days after the underlying API data was fetched. Sample cards are clearly unverified. File comparison happens locally using the original’s SHA-256 fingerprint; files selected for this check are not uploaded. A mismatch can result from editing or ordinary re-encoding and is not itself proof of fraud.

Where data lives and for how long

Media previews stay in the browser. Exports upload selected backgrounds and audio to private storage, which renders the original card from the account’s authorised earnings snapshot. Uploaded inputs are deleted after rendering or cancellation; cleanup removes expired and abandoned jobs. The resulting video and poster are public until removed or expired. Downloaded copies remain under the downloader’s control.

No earnings or tokens are saved to browser local storage. Only an explicitly chosen display name may be saved locally. Account and profile records remain until deletion. Hosted account sessions use Supabase authentication and session refresh; the self-hosted local backend uses sessions of up to eight hours. YouTube tokens are encrypted, scoped to the session and expire within Google’s supplied lifetime. We do not request offline YouTube access or retain YouTube refresh tokens. Supabase account session refresh tokens are retained in HTTP-only cookies to maintain sign-in; they do not grant YouTube access. Private revenue snapshots last at most fifteen minutes. Scheduled cleanup removes expired data, media, consent state and rate-limit entries. This installation must run that cleanup as described in its setup guide.

Your controls

Account settings lets you edit your profile, remove published cards, disconnect channels, sign out or delete your account. Signing out clears private session connections and reports; published cards remain until expiry or removal. Disconnecting YouTube removes published connected earnings cards, stored connections and reports and requests Google revocation. Detected revocation also removes connected proofs. If Google is temporarily unavailable, an encrypted token is queued for revocation retry until it expires.

Account deletion removes the identity, profile, sessions, published cards and stored API data. These controls do not delete data held by Google, your YouTube channel, downloaded copies or copies independently shared by other people.

Security and service providers

Session cookies are HTTP-only and use secure transport over HTTPS. The app uses ownership checks, OAuth state and PKCE, encrypted short-lived tokens and request validation. Connected exports use server-owned reports; arbitrary finished uploads cannot acquire a connected verification label. Downloaded videos can still be edited. The hosting operator, Google, Supabase (authentication, private database and media storage), and Vercel (hosting and temporary rendering) process data needed for the service. Operator backups and logs must avoid retaining API data past expiry and recording OAuth codes, private earnings or uploaded inputs.

Contact

The operator must configure a public contact route before launching this installation.