Privacy Policy
Last updated: 2 August 2026
This policy explains how Decode (“Decode”, “we”, “us”), operated by Nicholas Ayers, sole proprietor, doing business as Decode, accesses, uses, stores, shares, and deletes your information — including data we obtain from Google and YouTube on your behalf.
Decode is a forensic analytics tool for YouTube creators. It reads your own channel and analytics data and uses it to predict how your unpublished videos are likely to perform. If you do not agree with this policy, do not connect your Google account to Decode.
1. Who we are
Nicholas Ayers, sole proprietor, doing business as Decode, Arizona, United States. Contact: support@decodevideo.com. We are the controller of the personal data described here.
2. Information we collect
2.1 Account information
You create a Decode account with your email address. We do not use Google to sign you in, and connecting a YouTube channel is a separate, later step. We use your email address to authenticate you and to contact you about the service.
2.2 YouTube data (Google user data)
When you choose to connect a YouTube channel, Decode requests your explicit consent for the following permissions and reads the following data. You can use a Decode account without connecting a channel; the product simply has nothing to analyze until you do.
- youtube.readonly — your channel details and your uploaded videos, including titles, descriptions, tags, thumbnails, durations, and publish dates.
- yt-analytics.readonly — your YouTube Analytics reports for your own channel, including views, watch time, average view duration, audience retention, impressions, and click-through rate.
- yt-analytics-monetary.readonly — your YouTube earnings reports for your own channel: estimated revenue per video, and the revenue-per-thousand-views (RPM) derived from it. Decode displays these on each video's detail page, alongside that video's other performance figures. We do not read payment details, AdSense account information, or payout data. This is financial information about your channel: it is never shared, never used for advertising, never aggregated with other creators' figures in any form that could identify you or your channel, and never shown to anyone but you.
- youtube.force-ssl — the caption tracks on your published videos. This permission is defined by Google as read and write. Decode uses it only to read captions. Decode has no feature that uploads, edits, or deletes anything on your channel, and never exercises the write capability this permission grants. We request it because YouTube provides no read-only alternative for caption access.
Decode does not upload, publish, edit, or delete anything on your YouTube channel, and does not access the data of channels you do not own. Where a permission grants more access than Decode uses — as with youtube.force-ssl above — we use only the narrower capability described.
2.3 Content you submit
Content you upload for analysis: scripts, candidate titles, thumbnail images, and optional narration audio. Narration audio is transcribed for pacing analysis and the audio file is deleted immediately after processing; we do not retain the audio.
2.4 Account and usage information
Authentication records, subscription and billing status, log data, IP address, browser and device information, and records of your activity inside Decode. If you delete your account, a minimal record of that deletion is retained — see section 6.2.
3. How we use your information
- To build a model of your individual channel and identify what distinguishes your higher-performing videos from your lower-performing ones.
- To generate predictions, grades, and recommendations for videos you have not yet published.
- To compare locked predictions against actual results and report the accuracy of those predictions back to you.
- To display your own earnings figures for each video alongside that video's other performance data.
- To operate, secure, support, and bill for the service.
We use your Google user data only for the purposes described above. We do not use it for advertising, and we do not sell it. We do not use your Google user data, or content derived from it, to train generalized artificial intelligence or machine learning models. Analysis is performed for your account and its outputs are shown to you.
4. Who has access to your data
We do not sell your data and we do not share it with advertisers or data brokers.
4.1 Service providers
We share limited data with service providers who process it on our behalf, under contract, solely to run Decode:
- Railway — backend application hosting and database storage.
- Vercel — frontend hosting.
- Clerk — authentication and session management.
- Anthropic — analysis of the scripts, titles, thumbnails, and transcripts you submit.
- OpenAI — transcription of narration audio you submit. The audio is deleted immediately after transcription.
- Google Workspace — email. If you write to our support address, that correspondence is stored there.
Content sent to Anthropic and OpenAI for processing is not used by those providers to train their models. When Decode begins offering paid plans we will use a payment processor for billing, will not store your card details, and will update this policy before that processing begins.
4.2 Decode personnel
Authorized Decode personnel and contractors may access customer data — including Google user data accessed via YouTube APIs — for the purposes of technical support, debugging, security investigation, and abuse prevention. This includes the ability to view a customer's account as that customer would see it, in order to reproduce and resolve a reported problem. This access is logged, restricted to those with a legitimate business need, and governed by confidentiality obligations. Personnel do not access customer data for personal reasons or competitive research.
4.3 Other disclosures
We may also disclose information where required by law, to enforce our Terms of Service, or in connection with a merger or acquisition. If Decode is acquired, this policy continues to apply to data collected under it until you are notified otherwise.
5. How long we keep it, and how it is protected
We keep different categories of data for different periods:
- YouTube API Data (video and channel metadata, caption text, analytics and earnings figures) is refreshed from the YouTube API or deleted within 30 calendar days, in line with the YouTube API Services Developer Policies. We do not retain stale copies of your YouTube data.
- YouTube identifiers (your channel ID and video IDs) are retained while your account is active, so that refreshed data can be matched to the right video.
- Content you submit (scripts, candidate titles, thumbnails) and the predictions generated from it are retained while your account is active, so that Decode can compare predictions against outcomes over time. Narration audio is deleted immediately after transcription.
- Account and billing records are retained while your account is active and afterwards only where law requires it.
Data is transmitted over HTTPS and stored on access-controlled infrastructure. OAuth tokens are stored encrypted and are never exposed to other users. No system is perfectly secure, and we cannot guarantee absolute security.
6. Your choices and rights
6.1 Revoking Decode's access to your Google data
You can revoke Decode's access to your Google and YouTube data at any time via the Google security settings page at https://myaccount.google.com/permissions (also reachable at https://security.google.com/settings/security/permissions), or from your account settings inside Decode. Revoking access stops all further data retrieval.
6.2 Deleting your data
You can delete your account and all data Decode stores about you from your Decode account settings, or request deletion by emailing support@decodevideo.com. Deletion is immediate, except for billing records we are legally required to keep.
When you delete your account, we retain a minimal record of the deletion, solely to demonstrate that we honored your request. That record holds two things and nothing else: a one-way hash of an internal Decode identifier, and the deletion timestamp. It contains no YouTube data, no email address, no IP address, and no identifier that can be read back to you. It is retained for as long as necessary to evidence compliance.
Deleting the data stored by Decode does not in any way affect data stored by YouTube. To delete data held on YouTube itself, use YouTube directly or another authorized application that supports deleting that data.
6.3 Access, correction, and portability
You may request a copy of the personal data we hold about you, ask us to correct it, or object to or restrict certain processing. Depending on where you live, you may have additional rights under the GDPR, UK GDPR, or the CCPA/CPRA, including the right not to be discriminated against for exercising them. You may also withdraw your consent at any time by disconnecting your channel or deleting your account. Email support@decodevideo.com and we will respond within the period required by applicable law. If you are in the UK, EU, or EEA and believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection supervisory authority.
7. Cookies
Decode uses cookies and similar storage that are strictly necessary to keep you signed in and to keep the service secure. We do not use advertising cookies.
8. Children
Decode is not directed to children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
9. International transfers
Decode is operated from the United States. If you use Decode from outside the United States, your information will be transferred to and processed in the United States under appropriate safeguards.
10. Decode's own analysis vs. YouTube's data
Decode produces its own figures — predicted retention ranges, element grades, pacing notes, and recommendations — by analyzing your channel data together with content you submit. These are Decode's outputs, not YouTube metrics, and they are labeled as such wherever they appear. Where Decode displays actual YouTube Analytics figures, they are shown as YouTube reports them and are not modified or replaced.
11. YouTube and Google
Decode uses YouTube API Services. By using Decode you also agree to be bound by the YouTube Terms of Service. Google's own handling of your information is described in the Google Privacy Policy. You can review and revoke third-party access to your Google account, including Decode's, at https://myaccount.google.com/permissions.
Decode is not affiliated with, endorsed by, or sponsored by YouTube or Google.
12. Changes to this policy
If we change how we access, use, store, or share your Google user data, we will update this policy and ask you to re-accept it before the new processing begins. Material changes will be announced in the product and, where we hold a working address for you, by email.
13. Contact
Questions about this policy or about your data: support@decodevideo.com.