SocialStats Privacy Policy
At MediaCrew, we believe in minimizing data collection and retention. We only collect what's necessary to operate SocialStats and assist with troubleshooting. Our overarching practices are below, followed by SocialStats-specific details.
MediaCrew — overarching policy
MediaCrew builds custom web tooling for content creators. We minimize data collection across every product we build. Simply: if the data isn't needed for functionality, we don't store it.
What we collect across all products
- The minimum identifiers needed to operate the product (e.g. an account ID or OAuth subject).
- Operational logs — request paths, status codes, and error traces — retained for a short window for debugging.
- Bug-report payloads you explicitly submit, which may include a device UUID and system logs.
How we use it
- Operating and troubleshooting the products you use.
- Identifying patterns in errors and bug reports.
- Improving the products over time.
Sharing
We do not sell user data. We do not share personal data with third parties. We make use of anonymous analytics tools (like Google Analytics and Cloudflare Analytics) to improve our products and services.
How we protect your data
We take the security of your data seriously and have security procedures in place to protect the confidentiality, integrity, and availability of the information we hold, including sensitive data such as authentication tokens. These safeguards include:
- We use encryption to protect your information. All data is encrypted in transit using TLS, and data at rest is encrypted in our databases and storage.
- Sensitive credentials, such as platform OAuth access and refresh tokens, receive an additional layer of application-level encryption before being stored.
- Access to production systems and user data is restricted to a small number of authorized personnel using individually authenticated credentials, and is granted on a least-privilege basis.
- We rely on established infrastructure providers (such as Amazon Web Services) whose platforms are independently certified against recognized security standards.
- We monitor our systems and apply security updates to help protect against unauthorized access, disclosure, alteration, or destruction of data.
No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices and to promptly address any vulnerabilities we become aware of.
Retention
Platform logs are retained for 14 days. Bug reports are kept only as long as needed to resolve the issue. Per-product retention specifics live in each product's section below.
Your rights
You may request a copy of the data we hold about you, or request its deletion, at any time. Account deletion in a given product removes that product's user-level data in accordance with the retention policy described in that product's section.
Contact
For any privacy-related question or request, email privacy@mediacrew.dev.
SocialStats
SocialStats provides analytics for streamers across social media platforms. This section describes data collection specific to SocialStats.
What we collect
Platform OAuth tokens
When you connect a social account, we store the OAuth access and refresh tokens issued by that platform, encrypted at rest. We do not request scopes beyond those required to read the metrics shown in your dashboard.
Social media metrics
Views, likes, comments, and other metrics for your social media posts. This includes both private and public posts.
Account identifiers
Your platform user IDs and display names, so we can render your dashboards and reconnect tokens after refresh.
External parties
SocialStats integrates with third-party platform APIs to retrieve the metrics shown in your dashboards. Your use of each connection is also governed by the developer terms and privacy policy of the relevant platform:
- YouTube: data is retrieved through the YouTube API Services, and your use is subject to the YouTube API Services Terms of Service and the Google Privacy Policy.
- TikTok: data is retrieved through TikTok's developer APIs under the TikTok Developer Terms of Service and is also subject to the TikTok Privacy Policy.
- Instagram: data is retrieved through the Instagram Platform APIs under the Meta Platform Terms, and is also subject to the Instagram Privacy Policy.
You may revoke any of these connections at any time from SocialStats or directly from the third-party platform.
YouTube user data
Because SocialStats accesses your YouTube account through the YouTube API Services, this subsection describes specifically how we handle YouTube user data, in line with the Google API Services User Data Policy, including the Limited Use requirements.
APIs and scopes
SocialStats accesses YouTube data through the YouTube Data API v3 and the YouTube Analytics API. When you connect a YouTube account, we request only the following read-only OAuth scopes:
https://www.googleapis.com/auth/youtube.readonly— to read your channel and video metadata.https://www.googleapis.com/auth/yt-analytics.readonly— to read aggregated analytics for your channel.
We do not request write scopes, monetary-reporting scopes, or any other Google scopes.
What YouTube data we access
We access and store time-series stats for the videos on each connected channel. This includes views, likes, impressions (which is a distinct metric from views), and other engagement and performance metrics surfaced by the YouTube Data API and YouTube Analytics API. We read these metrics for every video on the connected channel, including videos marked unlisted or private, so that your dashboard reflects your full activity. We also store your channel ID and channel display name so we can render dashboards and reconnect tokens after refresh. We do not access your email, contacts, Drive, or any other Google service outside of YouTube.
How we use YouTube data
YouTube user data is used solely to render the analytics dashboards and time-series comparisons that you have asked SocialStats to produce, including comparing performance against the other platforms you have connected. Our use of information received from YouTube API Services complies with the Limited Use requirements. In particular, we do not use YouTube user data:
- to serve, target, or measure advertising;
- to train or improve generalized AI or machine-learning models;
- to build user profiles for personalization outside of your own SocialStats dashboard; or
- for any purpose other than providing you the analytics features described above.
How we share YouTube data
We do not sell YouTube user data, and we do not share it with third parties for their own purposes. The only third party that processes YouTube user data on our behalf is Amazon Web Services (AWS), which hosts our encrypted databases. AWS acts as a subprocessor under its own published security and privacy commitments and has no right to use your data for any other purpose. We do not transfer YouTube user data to advertising networks, data brokers, or AI/ML training providers.
How we store and protect YouTube data
YouTube user data, including OAuth access and refresh tokens and the metric data we retrieve, is stored in Amazon DynamoDB and encrypted at rest by AWS. OAuth tokens receive an additional layer of application-level encryption (with salting) before being written, so that even with database access an attacker cannot read raw tokens. Data is transmitted exclusively over TLS. Access to our production environment is restricted to a small number of authorized operators using individually authenticated credentials. Our engineers may review raw YouTube API response data when investigating a specific bug or support request, but they cannot read your raw OAuth tokens or other authentication secrets.
How long we keep YouTube data & how to delete it
YouTube user data is retained on the schedule described in the “Retention” section below: the first 15 days of stats for any video are retained permanently, and the most recent 180 days of activity are retained on a rolling basis. You can delete your YouTube data from SocialStats at any time by clicking the “Unlink” button on your YouTube connection. Unlinking immediately invalidates your stored OAuth tokens and marks your YouTube data for deletion, which is completed within 30 days. You may also revoke SocialStats's access directly from your Google Account at myaccount.google.com/permissions. For an expedited purge, email privacy@mediacrew.dev with the subject “SocialStats YouTube data deletion”.
Retention
The first 15 days of any social media post are retained permanently. Statistics on the last 180 days of activity are retained on a rolling basis. If you delete your SocialStats account, or delete your team, we immediately purge all retained OAuth tokens and connected account data. Your metrics are retained in a soft-deleted state for 30 days, after which they are permanently deleted. Account audit logs are retained for 90 days, after which they are permanently deleted. Deleting your SocialStats account or team does not purge audit logs at the 30-day mark.
Your rights
Revoke any platform connection from SocialStats at any time. Doing so will immediately invalidate the stored OAuth tokens. Use privacy@mediacrew.dev with the subject “SocialStats data request” for export or expedited deletion.
Last updated: June 23, 2026