Vysta Creative UploaderPrivacy Policy
Vysta Creative Uploader · Last updated: 12 August 2026
This Privacy Policy explains how Vysta Paid Media Group handles data in connection with the Vysta Creative Uploader application, which uploads video content to YouTube channels that authorize our access.
Google/YouTube data we access
This application uses YouTube API Services. With your explicit authorization, we request exactly two permissions (scopes) and no others:
https://www.googleapis.com/auth/youtube.upload— permission to upload video files to the YouTube channel you authorize.https://www.googleapis.com/auth/youtube.readonly— used for a single read-only request immediately after you authorize, to confirm which YouTube channel was authorized (its channel ID, title and handle). Many of our clients manage several channels under one Google account, so this confirmation ensures videos are never uploaded to the wrong channel.
These are the only scopes our application requests, and each is the
narrowest permission available for its purpose. Uploading a video through the YouTube Data
API (videos.insert) is not possible with any narrower permission, and
youtube.readonly is the narrowest scope that allows us to read the channel's
own identity (channels.list). We do not request broader scopes
such as youtube, youtube.force-ssl, or
youtubepartner.
Accordingly, the only Google user data we access is the video content you provide for upload, the identity of the channel you authorized (channel ID, title and handle), and the title, link and ID that YouTube returns for each uploaded video. Although the read-only permission would technically permit broader reading, we use it solely for that one channel-identity request. We do not read, modify, or delete any existing content on your channel, and we do not access your videos, playlists, subscriber data, analytics, comments, watch history, email address, contacts, or any other account information.
How we use the data
Access is used solely to upload the video files you provide to your designated YouTube channel on your behalf, and to record the resulting video title, link, and ID for reporting. We do not use this data for advertising or profiling, and we do not sell it.
Data sharing
We do not share your Google/YouTube data with third parties, except as necessary to operate the service on Google Cloud infrastructure, or where required by law.
How we protect your data
Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information, and we apply the following safeguards to all Google user data handled by this application:
- Encryption in transit: all communication between the application, Google APIs, and our servers is encrypted using HTTPS/TLS.
- Encryption at rest: all stored data, including OAuth authorization tokens, is encrypted at rest on Google Cloud Platform infrastructure.
- Secure credential storage: OAuth credentials and authorization tokens are stored in Google Secret Manager and access-controlled storage, and are never exposed publicly or committed to source code.
- Restricted access: access to Google user data is limited to authorized Vysta personnel who require it to operate the service, and is protected by account-level authentication and access controls.
- Secure infrastructure: the application runs on Google Cloud Run within Google Cloud Platform, benefiting from Google's underlying infrastructure security.
- Minimum access: we request only the two permissions described above
(
youtube.uploadandyoutube.readonly), each the narrowest available for its purpose, and we use the read-only permission for a single channel-identity request.
Data storage, retention and deletion
We store your personal information only for a period of time that is consistent with the business purpose described in this policy. Specifically:
- The OAuth authorization token required to upload on your behalf is retained only for as long as your authorization remains active. If you revoke access, the token becomes invalid and is deleted from our systems.
- Video files are processed transiently for the sole purpose of performing the upload and are deleted immediately after the upload completes. They are not archived or retained.
- We retain only the resulting video title, link, and ID for campaign reporting purposes.
- When the data retention period expires for a given type of data, we delete or destroy it. You may also request deletion of your data at any time by contacting us at the address below, and we will delete it promptly.
Limited Use disclosure
Vysta's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Artificial intelligence and machine learning
We do not use Google user data obtained through this application to develop, improve, or train generalized artificial intelligence or machine learning models. Google user data is used only to provide the upload functionality described above.
Revoking access
You can revoke this application's access at any time from your Google Account permissions at myaccount.google.com/permissions, or by removing our access in your YouTube Studio channel settings.
Related terms
Contact
For any questions about this policy, contact us at bhargav.t@vystapmg.com.