Respondu

Privacy Policy

Effective DATE · Last updated DATE

Respondu reads the comments on your own channels so it can draft replies for you to approve. This page says exactly what that means for data — what is collected, where it goes, how long it stays, and how to get rid of it.

This policy covers the Respondu service operated by LEGAL ENTITY NAME (“we”, “us”), reachable at CONTACT EMAIL. It applies to the people who sign in and connect a channel — our customers — and to the people who leave comments on their content.

The short version

What we collect

If you ask for early access

If you put your email address into the form on this site, we store that address, the page you submitted it from, and the time you did. We use it for one thing: to email you when there is a place. We do not add you to a newsletter, we do not pass it to anyone else, and there is nothing else in the message. Ask us at CONTACT EMAIL and we will delete it, whether or not you have signed up since.

When you sign in

We use Sign in with Google. From it we receive your email address, your name, your profile picture and your Google account identifier. We ask for no other identity information, and we never receive your password.

When you connect a channel

Connecting a channel grants us an OAuth access token and refresh token. We request one of two permission levels, and you choose which:

youtube.readonly Read your channel, its videos and their comments. Respondu can draft a reply but cannot post one.
youtube.force-ssl The above, plus posting and deleting replies. Requested only if you choose to let Respondu post.

Tokens are encrypted before they are stored, using AES-256-GCM with a key held outside the database. Each token is cryptographically bound to the connection it belongs to, so a token record cannot be moved to another account and used there.

From your connected channels

Channel Identifier, title, handle, avatar image URL
Videos and posts Identifier, title, publication date, kind
Comments Text, publication and edit timestamps, identifiers, and the commenter's public display name and public channel identifier

If you leave comments on somebody's channel: when a creator connects that channel to Respondu, your public comments and your public display name are processed as described here. We collect only what is already publicly visible on the platform, we never contact you, and we build no profile of you across creators. Each creator's data is isolated from every other creator's.

What you create in Respondu

The answers you write to questions Respondu raises, the reply drafts it produces, and your decisions on those drafts — approved, edited, or discarded. Your edits are measured, because how much you change a draft is how Respondu decides how much to trust itself. We record the size of the change, not a record of your writing for any other purpose.

Google user data, and the Limited Use requirements

Respondu's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Who else sees this data

We do not sell data. We share it only with the services needed to run Respondu:

AI provider Comment text, the content title it appeared under, and your own saved answers are sent to OpenRouter and the model it routes to, so a comment can be classified and a reply drafted. CONFIRM your OpenRouter account has prompt logging and training disabled, and name the specific models here.
Hosting HOSTING PROVIDER AND REGION. Data is stored on servers we control.
Google / YouTube Where the data came from, and where approved replies are sent.

How long we keep it

Comment text 30 days, then deleted automatically. If the comment is still on the platform when we next check, the copy is refreshed and the 30 days start again. This follows YouTube's requirement that stored API data be refreshed or deleted on roughly a 30-day cycle.
What we derived from a comment Kept after the text is deleted: the category, the sentiment, the safety flags, and whether a reply was sent. This is what lets a creator see the history of their channel without us holding the text.
Your answers, drafts and decisions Kept until you delete them or close your account. A superseded answer is retained so that “why did my reply say that?” has an answer.
OAuth tokens Deleted immediately when you disconnect a channel.
Sign-in sessions 30 days after they are revoked or expire.

Withdrawing access

Two things, and it is worth knowing that they are separate:

  1. Disconnect the channel in Respondu, on the Channels screen. This deletes our copy of your tokens immediately and stops all reading and posting.
  2. Remove Respondu at Google, at myaccount.google.com/permissions. Disconnecting in Respondu does not do this for you, so the grant remains listed in your Google account until you remove it there.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to receive a copy in a portable format, to object to or restrict our processing of it, and to complain to a data protection authority. Write to CONTACT EMAIL and we will respond within 30 days.

CONFIRM the legal bases you rely on (likely: contract, for customers; legitimate interests, for processing commenters' public comments), your UK/EU representative if you have one, and your lead supervisory authority.

Security

OAuth tokens are encrypted at rest. Each customer's data is isolated at the database level rather than by application code remembering to filter, so one customer's query cannot return another's rows. Sessions are HttpOnly, Secure and SameSite cookies. All traffic is over HTTPS.

No system is perfectly secure. If we discover a breach affecting your personal data, we will tell you and the relevant authority as the law requires.

International transfers

CONFIRM: the AI provider and possibly the hosting provider may process data outside the UK/EEA. Name the safeguard relied on — usually Standard Contractual Clauses.

Children

Respondu is for people running a channel or a business account. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 as a customer.

Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.

Contact

LEGAL ENTITY NAME, REGISTERED ADDRESS, CONTACT EMAIL