PRIVACY POLICY

Privacy policy

How data is collected, used, stored and deleted when using YouTube API Services and Google OAuth 2.0.

Operator
David Liu (individual operator)
Last updated
September 7, 2026

This policy explains how the local desktop tool “Tennis Coaching Publisher” (the “Tool”) handles data when using YouTube API Services and Google OAuth 2.0. The Tool is a private personal tool, not offered for sale, for uploading the operator’s selected tennis practice videos, metadata, thumbnails and captions to the YouTube channel managed by the operator.

1. Information collected and used

The Tool uses the following information within the permissions explicitly granted by the operator on Google’s consent screen.

  • YouTube channel ID and channel name
  • IDs, titles, descriptions, tags, languages, categories, recording dates, visibility and processing status of videos uploaded or managed through the Tool
  • IDs, languages, names and processing status of caption tracks set through the Tool
  • Search results within the operator’s own channel to prevent duplicate uploads
  • Video, caption, thumbnail and metadata files selected locally by the operator
  • OAuth access tokens and refresh tokens

The Tool does not collect or store Google Account passwords or two-step verification codes.

2. Purposes of use

Information is used only for the following purposes.

  • Verify the operator’s own YouTube channel
  • Upload selected videos as private first
  • Set and verify titles, descriptions, tags, recording dates, thumbnails and captions
  • Check processing results and publish only when the operator explicitly instructs publication
  • Prevent duplicate uploads using SHA-256 and deterministic markers, and resume safely after interruptions
  • Keep OAuth/YouTube API audit test videos private in an explicit audit-test mode

The Tool is not used for advertising, behavioural tracking, profiling, selling data or creating independent statistical metrics from YouTube API data.

3. OAuth permissions

The Tool requests the following permissions required for its functions.

  • https://www.googleapis.com/auth/youtube.upload
  • https://www.googleapis.com/auth/youtube.force-ssl

The first permission is used for uploading and managing videos; the second is used to verify and update videos, captions and related settings. Authorisation uses Google’s official flow in the system browser with a localhost redirect.

4. Storage and security

OAuth refresh credentials are stored in the macOS Keychain service TennisYouTubeUploader when available. Only when Keychain is unavailable are they saved in the following user-only folder as a file with 0600 permissions.

~/Library/Application Support/TennisYouTubeUploader/oauth/

The local upload ledger stores file paths, SHA-256 hashes, YouTube video IDs, caption IDs, processing status and verification times. OAuth client JSON, OAuth credentials and ledgers are not committed to Git. Original videos and other files selected by the operator remain in the operator’s local environment.

5. Sharing with third parties

The Tool sends Google LLC/YouTube the information necessary for the specified upload operations. It does not sell, rent or provide personal information or YouTube API data to other third parties. Videos published on YouTube are subject to YouTube’s and Google’s terms and privacy policies.

6. Retention and deletion

OAuth credentials are retained until the operator revokes the connection. Upload ledgers are kept only as long as necessary for duplicate prevention and audit records. Following a deletion or disconnection request, relevant OAuth credentials and local data derived from the YouTube API are deleted promptly, and no later than seven days, unless an applicable obligation requires retention.

For steps, see How to delete user data. Revoking access in the Google Account, deleting local credentials, deleting ledgers and deleting videos on YouTube are separate operations.

7. Information about people in tennis videos

Videos, audio, player names and coaching content are not collected from the YouTube API. They are content the operator supplies to the Tool after confirming lawful rights and necessary consent. Before publication, the operator checks participant consent, image, voice and copyright rights, and the intended visibility.

8. Not a service directed at children

The Tool is not a service directed at children. Current upload manifests explicitly set madeForKids=false for verified adult practice recordings. If a video is made for kids, do not use the Tool for it; assess it separately under YouTube’s requirements.

9. User choices and external terms

The operator can revoke access at any time through Third-party connections in the Google Account. The Tool’s use of YouTube API Services is subject to the YouTube API Services Terms of Service and Google Privacy Policy.

10. Changes and contact

If this policy changes, the date on this page is updated. The operator reviews significant changes before using the Tool again. The public contact address is below.

david.liu.492@gmail.com

11. This website’s language preference

On a first visit, the website uses your browser’s language preferences to choose Japanese, English or Simplified Chinese. Your own selection takes priority and is saved in this browser’s localStorage where available, or sessionStorage if localStorage is unavailable. Only the language preference is stored; it is not used for advertising or behavioural analytics. You can change it from the language menu at any time, or reset it by clearing this website’s data in your browser.