Privacy Policy
Privacy Policy
Last updated: 2026-09-07
Uses YouTube API ServicesThis policy covers this website (operated by Enrique Rubio) and Traffic OS, a private internal application also operated by Enrique Rubio, Spain. Traffic OS is not a public product; this policy exists because Traffic OS uses YouTube API Services and Google OAuth 2.0, and because this website is that application's public disclosure surface.
1. Use of YouTube API Services
Traffic OS uses YouTube API Services. By authorizing Traffic OS to access a YouTube channel, the channel owner (the operator, Enrique Rubio) agrees to be bound by the YouTube Terms of Service and the YouTube API Services Terms of Service.
2. Google OAuth 2.0
Traffic OS authenticates against channels using Google's OAuth 2.0 authorization flow. Access is requested only for channels owned by, or explicitly authorized by, the operator. Traffic OS does not request access to any Google Account other than those the operator controls.
3. API data accessed
Through YouTube API Services, Traffic OS accesses:
- Channel identity data (via
channels.list) needed to verify which channel is being acted on. - Video metadata and status for videos uploaded through Traffic OS (via
videos.insertandvideos.list). - OAuth tokens required to authenticate these requests.
Traffic OS does not access private messages, other users' data, analytics beyond what is needed to confirm publish status, or any YouTube data unrelated to channels the operator controls.
4. Purposes
API data is used exclusively to:
- Verify the identity of a channel before any action is taken on it.
- Upload video content that has already been reviewed and explicitly approved by the channel owner.
- Confirm that an upload finished processing and published successfully.
- Maintain an append-only internal audit history of publications.
API data is never used for advertising, for training generalized machine-learning or AI models, or for any purpose unrelated to operating the channels the operator controls.
5. Storage
OAuth credentials and API data used by Traffic OS are stored on infrastructure controlled by the operator, outside of any source control system, with filesystem permissions restricted to the operator. No API data or credentials are stored in this website's codebase or deployed alongside it. This policy does not publish internal hostnames, file paths, or infrastructure details, since doing so would itself be a security risk.
6. Retention, update, and deletion
Traffic OS follows the retention limits in the YouTube API Services Developer Policies:
- Data obtained through YouTube API Services that is not explicitly permitted for longer retention is kept for no more than 30 calendar days, after which it is deleted or refreshed by re-fetching it from the API.
- If channel authorization is revoked, associated API data is deleted within 30 calendar days of revocation.
- Deletion requests are honored as soon as possible and within 7 calendar days, consistent with those same policies.
7. Sharing
API data is not shared with any third party. Traffic OS has no external customers, tenants, or partner integrations that receive YouTube API data.
8. No sale of YouTube API data
YouTube API data is never sold, rented, or sublicensed to any third party, for any purpose, in accordance with the YouTube API Services Developer Policies.
9. Security approach
Access to Traffic OS and its stored credentials is restricted to the operator. Credentials are kept outside of source control and outside of any file served by this website, with filesystem permissions restricted to the operator's own account. This description is accurate as implemented; this policy does not claim encryption, compliance certifications, or security controls that have not actually been put in place.
10. Google Privacy Policy
Google's use of information received from Traffic OS's use of YouTube API Services is additionally governed by the Google Privacy Policy.
11. YouTube Terms of Service
Channel access authorized to Traffic OS is subject to the YouTube Terms of Service in addition to this policy.
12. Revoking access
Any Google Account that has authorized Traffic OS can review and revoke that access at any time at myaccount.google.com/permissions. Revoking access there stops Traffic OS from making further API calls for that channel; associated API data is then deleted per the retention terms above.
13. Data deletion requests
To request deletion of data associated with a specific channel, contact hello@enriquerubio.dev. Include the channel identifier so the request can be matched to the correct data.
14. Operator / contact information
Operator: Enrique Rubio, an individual (Spain). Contact: hello@enriquerubio.dev. See also the contact page.
This policy may be updated to reflect changes to Traffic OS or to YouTube API Services requirements. Material changes will update the "Last updated" date above.