Last updated: November 30, 2025
1. Introduction
ForSubs ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information when you use our service.
2. Information We Collect
For Creators:
- Google account information (name, email, profile picture)
- YouTube channel information (channel ID, name, subscriber count)
- OAuth tokens for YouTube API access (stored encrypted)
- Campaign and perk configuration data
- Billing information (processed by Stripe)
For Subscribers:
- Verification status (subscribed/not subscribed) - stored as anonymous hash
- Email address (only if voluntarily provided)
- We do NOT store your YouTube subscription list
3. How We Use Information
- To verify YouTube subscription status
- To deliver perks to verified subscribers
- To provide analytics to creators (aggregate, anonymized data)
- To process payments and manage subscriptions
- To communicate important service updates
4. YouTube API Services
ForSubs uses YouTube API Services. By using our service, you also agree to be bound by the YouTube Terms of Service and Google Privacy Policy.
We only request read-only access to your YouTube data. We never post, modify, or delete anything on your YouTube account.
5. Data Sharing
We do not sell your personal information. We may share data with:
- Service providers (Supabase for database, Stripe for payments, Vercel for hosting)
- Creators (only aggregate analytics and voluntarily provided emails)
- Legal authorities when required by law
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. You can request deletion of your data at any time.
7. Your Rights (GDPR)
If you are in the European Union, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data
- Object to data processing
- Data portability
To exercise these rights, contact us at privacy@forsubs.com
8. Security
We implement industry-standard security measures including encryption of sensitive data, secure HTTPS connections, and regular security audits.