Privacy policy

What we hold, and why

Last updated 27 September 2026.

This describes the platform as built. It has not yet been through legal review, and should be checked before it is relied on in an agreement.

Who this is for

Zipr operates a YouTube multi-channel network. This policy covers two groups: the people who use the platform (our own staff and our partners’ staff), and the owners of channels managed through it.

YouTube data, and what we do with it

Zipr uses YouTube API Services. By authorising a channel you are also agreeing to the YouTube Terms of Service, and Google’s own handling is covered by the Google Privacy Policy.

  • Reporting data. Views, watch time, revenue, subscribers, claims and catalogue metadata, delivered by YouTube as a daily export. We use it to report on performance and to calculate what each partner is owed.
  • Authorisation. When a channel owner grants access, Google gives us a token. We store it encrypted and use it only to publish to that channel and read its own data. We never receive, store or have access to your Google password.
  • What we do not ask for. Nothing outside YouTube — not your email, not Drive, not photos, not contacts, and no ability to sign in anywhere as you.

Withdrawing access

A channel owner can revoke Zipr at any time at myaccount.google.com/permissions, without telling us first and without needing our agreement. Publishing stops immediately. Videos already on the channel are unaffected — they belong to the channel.

On revocation we delete the stored token. Reporting data already delivered by YouTube is retained where we need it to settle amounts already earned; that obligation is the only reason we keep it.

Platform accounts

We hold a name, work email address, role, and the channels or partner an account is scoped to. Passwords are stored only as a scrypt hash and cannot be recovered by anyone, ourselves included. Sign-in attempts are logged with time and IP address so an account can be defended if it is questioned.

Where it is held, and for how long

Reporting data is held in Google BigQuery and commercial records in Google Cloud SQL, both in the Mumbai region. Reporting and settlement records are kept for as long as the commercial relationship and the tax records arising from it require. Sign-in logs are kept for twelve months.

Who else sees it

Nobody it is not needed by. Partners see their own channels and their own commercial terms, never another partner’s. We do not sell data and we do not share it for advertising.

It is processed by Google Cloud (hosting and data), Vercel (application hosting), and SAP for payment processing. We disclose data to a government or regulator only where the law requires it.

Your rights

You can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted where we are not required to keep it. Write to privacy@zipr.tv and we will answer within thirty days.