Privacy Policy
Contents
01
Information We Collect
- Account information. When you create a SIGNAL account we collect your email address and, if you sign up with Google, the name associated with your Google account.
- YouTube channel information. When you connect a YouTube channel via Google OAuth we receive your channel name, channel ID, and channel thumbnail, along with OAuth access and refresh tokens that are stored securely so SIGNAL can upload clips you have authorized.
- TikTok account information. When you connect a TikTok account via TikTok OAuth we receive your display name, avatar, and open ID, along with OAuth access and refresh tokens that are stored securely so SIGNAL can post clips you have authorized through the TikTok Content Posting API.
- Twitch channel information. The public Twitch channels you choose to monitor, together with publicly available stream and clip metadata retrieved from the Twitch API.
- Clip and publishing history. The clips SIGNAL detects, the approval decisions you make, and records of clips published to your connected channels.
- Usage data and platform analytics. Basic operational data such as login timestamps, feature usage, and diagnostic logs used to keep the platform reliable.
02
How We Use YouTube API Services
SIGNAL uses YouTube API Services to publish approved highlight clips to YouTube channels on behalf of authenticated users. We access YouTube Data API v3 to: (1) verify connected YouTube channels via channels.list, (2) upload approved video clips to user-connected channels via videos.insert using the channel owner's own OAuth authorization. We do not access, store, or use any YouTube user data beyond what is necessary to perform these specific authorized actions.
By connecting a YouTube channel to SIGNAL you also agree to the YouTube Terms of Service.
03
YouTube API Data Usage and Deletion
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In compliance with YouTube API Services Terms of Service:
- We store YouTube OAuth tokens (access tokens and refresh tokens) securely encrypted in our database solely to perform authorized upload operations on behalf of the channel owner.
- Users may revoke SIGNAL's access to their YouTube channel at any time by: (1) clicking Disconnect in the SIGNAL settings, or (2) visiting Google Account permissions at myaccount.google.com/permissions and removing SIGNAL from authorized apps.
- Upon disconnection or account deletion, all stored YouTube OAuth tokens are immediately deleted from our systems.
- We do not sell, trade, or share YouTube user data with third parties.
- YouTube-related data stored by SIGNAL is used exclusively to provide the clip publishing service the user has explicitly authorized.
04
Google Privacy Policy
Our use of Google and YouTube services is also governed by Google's Privacy Policy, available at https://policies.google.com/privacy.
05
How We Use TikTok API Services
SIGNAL uses the TikTok Content Posting API to publish approved highlight clips to TikTok accounts on behalf of authenticated users. When you connect a TikTok account via TikTok's OAuth flow, we: (1) retrieve your basic profile (display name, avatar, open ID) to confirm the connected account, and (2) upload or post the video clips you have explicitly approved, using your own OAuth authorization. We do not read your private messages, followers, analytics, or any TikTok data beyond what is necessary to perform these specific authorized actions.
- TikTok OAuth tokens (access and refresh tokens) are stored securely encrypted in our database and used solely to perform the posting operations you authorize.
- You may revoke SIGNAL's access to your TikTok account at any time by: (1) disconnecting TikTok in the SIGNAL settings, or (2) removing SIGNAL from your authorized apps in the TikTok app under Settings & Privacy → Security & Permissions → Apps and services.
- Upon disconnection or account deletion, all stored TikTok OAuth tokens are immediately deleted from our systems.
- We do not sell, trade, or share TikTok user data with third parties.
Your use of TikTok through SIGNAL is also governed by the TikTok Terms of Service and the TikTok Privacy Policy.
06
Data Storage and Security
- Where your data lives. SIGNAL stores data on US-based cloud servers.
- Encryption. Data is encrypted in transit using TLS and encrypted at rest by our database and storage providers.
- Token security. OAuth access and refresh tokens are stored server-side only, are never exposed to the browser, and are transmitted exclusively over encrypted connections to Google's APIs.
- No plaintext credentials. Account passwords are hashed with bcrypt before storage. We never store or log plaintext passwords or credentials.
07
Data Retention and Deletion
We retain account information, clip history, and publishing records for as long as your account remains active, so the platform can keep learning from your decisions and maintain an accurate publishing history. Operational logs are retained for a limited period for reliability and security purposes.
You can request deletion of your account and all associated data at any time by emailing privacy@signalclips.app. We will complete verified deletion requests within 30 days. Disconnecting your YouTube channel or TikTok account deletes the stored OAuth tokens for that service immediately, independent of any broader deletion request.
08
Third Party Services
- YouTube (Google) — publishing approved clips to your connected channel via the YouTube Data API.
- TikTok — posting approved clips to your connected TikTok account via the TikTok Content Posting API.
- Twitch — monitoring the public streams and clips of channels you choose, via Twitch's public API.
- Gemini (Google) — analyzing clip video and audio to generate titles, descriptions, and tags.
- Cloud infrastructure providers — hosting, database, and object storage services used to operate the platform.
Each of these services processes data under its own terms and privacy policy. We share with them only what is necessary to provide the SIGNAL service.
09
Cookies and Analytics
- Session cookies. We use a single httpOnly session cookie to keep you signed in. It contains an opaque identifier — no personal information.
- No advertising cookies.
- No cross-site tracking.
Any analytics we collect are first-party, operational, and used only to understand how the platform is performing.
10
Changes to This Policy
If we make material changes to this policy, we will notify users by email or by a prominent notice in the SIGNAL dashboard before the changes take effect. Your continued use of signalclips.app after changes take effect constitutes acceptance of the updated policy.
11
Contact Us
SIGNAL Inc. / Execution Labs LLC154 North Broadway
White Plains, NY 10603
privacy@signalclips.app