Privacy Policy
Last updated July 31, 2026
This policy explains what the service processes when you submit a public YouTube video and what is retained to operate, secure, and improve the summarizer.
Operator and contact
Summarize YouTube Videos is operated by an individual merchant based in Hong Kong SAR under the public business name “Summarize YouTube Videos.” Reach the operator through the contact page or at hello@summarizeyoutubevideos.com. Do not submit personal, confidential, or access-controlled video material.
Information we process
- The YouTube URL or video ID you submit.
- Public video metadata, captions or transcripts, and the summary generated from them.
- A salted one-way hash of the requesting IP address, used to prevent repeated requests from inflating a video's demand count. The raw address is not stored in the application database.
- An email address if you unlock an export, request a Magic Link, create an account, or purchase a plan. Login-link and browser session bearer tokens are stored only as one-way hashes.
- If you choose Google sign-in: the verified email address returned by Google. The service requests only OpenID, email, and basic profile scopes; it does not retain Google access or refresh tokens or access files, contacts, YouTube data, or other Google services.
- Stripe customer, subscription, plan, renewal and cancellation identifiers for paid access. Card details are entered on Stripe's hosted pages and are not stored by this service.
- If you connect Notion: workspace identifiers and encrypted OAuth access and refresh tokens. The tokens are used only for the exports you request and are deleted when you disconnect Notion.
- Operational information such as provider, model, token usage, generation cost, timestamps, and error logs.
- For public API customers: a one-way API-key hash, key name and scopes, normalized resource ID, endpoint, status, latency, cache/provider indicators, credit usage, and request ID. API request and response bodies are not retained in the activity log.
- Usage information such as pages viewed, approximate location, device and browser type, referral source, clicks, scrolling, product events, and session-replay data collected by Google Analytics and Microsoft Clarity. Input fields and account email addresses are masked from Clarity recordings. YouTube URLs, payment session IDs, email addresses, and summary content are not sent as custom analytics event properties. Public page and summary content can appear in a Clarity recording, which is another reason not to submit confidential material.
How the information is used
Submitted content is used to fetch the transcript, generate the requested notes, return the result, cache completed work, prevent abuse, diagnose failures, and decide which useful summaries qualify for public index pages.
Service providers
Requests may be processed by Cloudflare for bot protection, TranscriptAPI or Supadata for transcripts, DeepSeek for summary generation, Resend for login email, Google for optional account authentication, Stripe for billing, Notion for a direct export you request, Google Analytics for aggregate traffic and product-event measurement, Microsoft Clarity for heatmaps and session replay, Feishu for operational and billing incident alerts, and the infrastructure providers that host the application, database, and encrypted off-site backups. Only the information needed for each task is sent to that provider.
Storage and retention
- Public-video transcripts and summaries are cached so the same material does not need to be purchased and generated again. They and hashed demand records do not currently have a fixed automatic deletion date; they are removed when no longer needed to operate the service or after a valid removal request.
- Magic Links expire after 15 minutes, work once, and expired link records are removed after a short operational grace period. Account sessions expire after 30 days; signing out deletes the current session.
- Device-bound export and purchase cookies expire after at most one year. Removing cookies in your browser removes that device's local proof, but does not cancel a Stripe subscription.
- Stripe subscription and transaction identifiers are retained while needed to provide paid access, handle refunds and chargebacks, keep financial records, and meet applicable legal obligations.
- Notion credentials are retained only while the connection remains active and are deleted from the application database when you disconnect it.
- API request metadata is retained for 90 days. Durable job records, including requested transcript output and webhook URLs, are retained for 30 days. Revoking a key prevents future use but does not erase records before those operational windows expire.
- Encrypted off-site database backups are retained on a rolling 14-day schedule. A deletion can remain in an encrypted backup until that backup ages out and is not restored except for disaster recovery.
Cookies and accounts
The service does not use advertising storage or behavioural advertising cookies. Google Analytics and Microsoft Clarity load with analytics storage denied by default. In that state they may receive limited, cookieless measurements, but do not write their analytics cookies. If you choose “Allow analytics cookies,” Google may write Analytics cookies and Clarity may write _clck and _clskso page views can be connected into a visit. Your choice is stored in this browser's local storage and can be changed at any time using “Privacy choices” in the footer.
Summarising a video needs no account. A signed cookie can remember an address entered at the export gate on one device. A completed Stripe Checkout can also issue a device-bound purchase cookie. Separately, a Magic Link proves control of your email and creates a 30-day passwordless session, which lets an active subscription follow you across devices. The database stores salted account hashes to enforce paid quota and associate your private saved library without repeating your email on every usage row. Signing out deletes the current login session.
Cloudflare Turnstile may process browser and network signals needed to distinguish people from automated abuse, under Cloudflare's own privacy terms.
Your choices
Do not submit private, confidential, or access-controlled material. For removal of a summary, deletion of a stored email address, or any other privacy request, use the address on the contact page.
You can disconnect Notion from the account page and cancel a subscription from Stripe's billing portal. A Magic Link is optional unless you want cross-device access or a connected export.
Use “Privacy choices” in the footer to allow or withdraw analytics cookie consent. Browser privacy controls, content blockers, and Global Privacy Control may provide additional choices. Withholding analytics cookie consent does not limit the summarizer.
Privacy checklist
- The service does not sell personal information, run behavioural advertising, or share personal information for cross-site advertising.
- Payment-card data stays on Stripe's hosted pages. Google access tokens are not stored. Notion tokens, when that optional connection is enabled, are encrypted before storage.
- HTTPS is used in transit; login and session bearer tokens are stored as one-way hashes. No online system is completely secure, so private or confidential video material should not be submitted.
- Providers may process data in countries other than your own. The service limits each transfer to the information needed for the requested feature.
- The service is not directed to children under 13 and does not knowingly collect their personal information. A parent or guardian can request deletion using the contact address below.
- Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information, and to complain to a privacy regulator. Requests are handled without requiring a paid account.
Privacy requests
Email hello@summarizeyoutubevideos.com from the address connected to the account or purchase when possible. Describe the account, summary URL, or information involved and the action requested. Identity may be verified before disclosing or deleting account information. The service will respond within the period required by applicable law.
Changes
This policy will be updated when the service adds advertising or materially different data processing. The date at the top identifies the current version.