Privacy policy
ChannelText keeps as little personal data as it can to run your account and your jobs. Last updated 2026-09-26. Contact: business@aitorsm.com.
What we store and why
- Account: your email address and a salted hash of your password (never the password itself), to sign you in and to link your payments to your balance.
- Sign-in and API keys: a hash of each session token (valid 30 days) and of each API key, with the key's name, its first characters and when it was created, last used and revoked.
- Balance: a ledger of top-ups, reservations and charges (amounts, dates, and the payment's order id at Polar).
- Jobs: the links you submitted and your choices (language, files, limits, dates), each job's progress, and the transcripts and files it produced, so you can download them again.
- Your browser: one session cookie (
ytw_session, needed to stay signed in) and, in your browser's local storage, the form you typed and a signed-in flag. No advertising or analytics cookies and no tracking scripts. - Visit counts, without cookies: when you open one of our landing or documentation pages, we add one to a counter for that page and that day. If you came from another website, we also add one to a counter for that website's name only (for example
www.google.com, never the full address or what you searched). We count, per day, how many cost estimates, sign-ups, top-ups started, top-ups paid and jobs started there were, and whether a job came from the website, the API or the MCP server. Only these totals are stored: no IP address, no browser or device details (user agent), no account, no cookie and no other identifier is stored with them, and no third-party analytics service or script is used. Your browser's user agent is read while the page is served, only to leave automated crawlers out of the count, and is then discarded. - Short-lived: your IP address is used in memory to limit sign-ups and failed sign-ins and is not written to our database. Our server logs record errors, job ids, random account ids and payment order ids, not your email; the web server in front of it may keep standard access logs (IP address, time, page requested) for a short time for security.
Who else receives data
- Polar (payments, merchant of record): your email address and your account id when you open a checkout, and the payment details you enter on Polar's page. We never see your card number.
- Our processing provider, a cloud platform that runs the extraction: the links you submit, your choices and a random id for your account (never your email). It keeps a run's results for a limited time under its own retention rules and, for "Update this channel", the ids of the videos already delivered for each set of links you used. We delete those records, and the results of your runs that it still holds, when we delete your account.
- YouTube receives the requests for the videos' captions, not your identity.
We do not sell personal data or use it for advertising.
How long
Account, jobs and files are kept while your account exists. When you ask us to delete your account, within 30 days we delete your email address, password hash, sessions, API keys, jobs and files, and the processing provider's records for your account described above. Balance ledger entries (amounts, dates, job ids and Polar order ids) are kept for accounting under a random account id that no longer leads to your email; Polar keeps its own payment records as the seller.
Your rights
Write to business@aitorsm.com from your account's email to get a copy of your data, correct it or delete your account. If you are in the EU or UK you can also complain to your data protection authority.