Privacy Policy
Last updated: March 8, 2026
1. Information We Collect
Account information: Email address and display name when you register. If you sign in with Google, we receive your name and email from Google OAuth.
YouTube API key: Your personal YouTube Data API key, which you provide during onboarding. This key is stored in our database to make API calls on your behalf.
Usage data: Search queries, search history, and feature usage to improve the Service.
Technical data: Browser type, IP address, and device information collected automatically for security and analytics purposes.
2. How We Use Your Information
- To provide and operate the Service
- To make YouTube Data API calls using your provided API key
- To maintain your search history and preferences
- To process payments and manage subscriptions
- To communicate service updates and respond to support requests
- To detect and prevent abuse or unauthorized access
3. YouTube API Data
Gleam accesses YouTube data through the official YouTube Data API v3 using your personal API key. We do not store raw YouTube video data beyond temporary caching (up to 30 days) to reduce API usage and improve performance. Video data displayed in the Service is public information available through the YouTube API.
Our use of the YouTube Data API is subject to Google’s Privacy Policy.
4. Data Storage & Security
Your data is stored securely using Supabase (hosted on AWS). We implement industry-standard security measures including encrypted connections (HTTPS), row-level security policies, and secure authentication.
5. Data Sharing
We do not sell your personal information. We share data only with:
- Service providers: Supabase (database), payment processors, and hosting providers — only as necessary to operate the Service
- Legal requirements: When required by law or to protect our rights
6. Data Retention
Account data is retained while your account is active. Search history is stored for up to 90 days. Cached YouTube data expires after 30 days. When you delete your account, we remove your personal data within 30 days.
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your data
- Withdraw consent at any time
To exercise these rights, contact us at help@gleam.fit or use the account settings in the app.
8. Cookies
We use essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies.
9. Children’s Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy from time to time. We will notify users of material changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance.
11. Contact
For privacy-related questions or concerns, contact us at help@gleam.fit.