SOCIALSTATS

SocialStats Privacy Policy

MediaCrew — overarching policy

MediaCrew builds custom web tooling for content creators. We minimize data collection across every product we build. Simply: if the data isn't needed for functionality, we don't store it.

What we collect across all products

How we use it

Sharing

We do not sell user data. We do not share personal data with third parties. We make use of anonymous analytics tools (like Google Analytics and Cloudflare Analytics) to improve our products and services.

How we protect your data

We take the security of your data seriously and have security procedures in place to protect the confidentiality, integrity, and availability of the information we hold, including sensitive data such as authentication tokens. These safeguards include:

No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices and to promptly address any vulnerabilities we become aware of.

Retention

Platform logs are retained for 14 days. Bug reports are kept only as long as needed to resolve the issue. Per-product retention specifics live in each product's section below.

Your rights

You may request a copy of the data we hold about you, or request its deletion, at any time. Account deletion in a given product removes that product's user-level data in accordance with the retention policy described in that product's section.

Contact

For any privacy-related question or request, email privacy@mediacrew.dev.

SocialStats

SocialStats provides analytics for streamers across social media platforms. This section describes data collection specific to SocialStats.

What we collect

Platform OAuth tokens

When you connect a social account, we store the OAuth access and refresh tokens issued by that platform, encrypted at rest. We do not request scopes beyond those required to read the metrics shown in your dashboard.

Social media metrics

Views, likes, comments, and other metrics for your social media posts. This includes both private and public posts.

Account identifiers

Your platform user IDs and display names, so we can render your dashboards and reconnect tokens after refresh.

External parties

SocialStats integrates with third-party platform APIs to retrieve the metrics shown in your dashboards. Your use of each connection is also governed by the developer terms and privacy policy of the relevant platform:

You may revoke any of these connections at any time from SocialStats or directly from the third-party platform.

YouTube user data

Because SocialStats accesses your YouTube account through the YouTube API Services, this subsection describes specifically how we handle YouTube user data, in line with the Google API Services User Data Policy, including the Limited Use requirements.

APIs and scopes

SocialStats accesses YouTube data through the YouTube Data API v3 and the YouTube Analytics API. When you connect a YouTube account, we request only the following read-only OAuth scopes:

We do not request write scopes, monetary-reporting scopes, or any other Google scopes.

What YouTube data we access

We access and store time-series stats for the videos on each connected channel. This includes views, likes, impressions (which is a distinct metric from views), and other engagement and performance metrics surfaced by the YouTube Data API and YouTube Analytics API. We read these metrics for every video on the connected channel, including videos marked unlisted or private, so that your dashboard reflects your full activity. We also store your channel ID and channel display name so we can render dashboards and reconnect tokens after refresh. We do not access your email, contacts, Drive, or any other Google service outside of YouTube.

How we use YouTube data

YouTube user data is used solely to render the analytics dashboards and time-series comparisons that you have asked SocialStats to produce, including comparing performance against the other platforms you have connected. Our use of information received from YouTube API Services complies with the Limited Use requirements. In particular, we do not use YouTube user data:

How we share YouTube data

We do not sell YouTube user data, and we do not share it with third parties for their own purposes. The only third party that processes YouTube user data on our behalf is Amazon Web Services (AWS), which hosts our encrypted databases. AWS acts as a subprocessor under its own published security and privacy commitments and has no right to use your data for any other purpose. We do not transfer YouTube user data to advertising networks, data brokers, or AI/ML training providers.

How we store and protect YouTube data

YouTube user data, including OAuth access and refresh tokens and the metric data we retrieve, is stored in Amazon DynamoDB and encrypted at rest by AWS. OAuth tokens receive an additional layer of application-level encryption (with salting) before being written, so that even with database access an attacker cannot read raw tokens. Data is transmitted exclusively over TLS. Access to our production environment is restricted to a small number of authorized operators using individually authenticated credentials. Our engineers may review raw YouTube API response data when investigating a specific bug or support request, but they cannot read your raw OAuth tokens or other authentication secrets.

How long we keep YouTube data & how to delete it

YouTube user data is retained on the schedule described in the “Retention” section below: the first 15 days of stats for any video are retained permanently, and the most recent 180 days of activity are retained on a rolling basis. You can delete your YouTube data from SocialStats at any time by clicking the “Unlink” button on your YouTube connection. Unlinking immediately invalidates your stored OAuth tokens and marks your YouTube data for deletion, which is completed within 30 days. You may also revoke SocialStats's access directly from your Google Account at myaccount.google.com/permissions. For an expedited purge, email privacy@mediacrew.dev with the subject “SocialStats YouTube data deletion”.

Retention

The first 15 days of any social media post are retained permanently. Statistics on the last 180 days of activity are retained on a rolling basis. If you delete your SocialStats account, or delete your team, we immediately purge all retained OAuth tokens and connected account data. Your metrics are retained in a soft-deleted state for 30 days, after which they are permanently deleted. Account audit logs are retained for 90 days, after which they are permanently deleted. Deleting your SocialStats account or team does not purge audit logs at the 30-day mark.

Your rights

Revoke any platform connection from SocialStats at any time. Doing so will immediately invalidate the stored OAuth tokens. Use privacy@mediacrew.dev with the subject “SocialStats data request” for export or expedited deletion.