Privacy Policy
Last updated 13 September 2026
YT Memory is a private tool operated by an individual for personal use. Access is restricted to a small allowlist of accounts. It has no public sign-up, no advertising, and no analytics.
What is collected when you sign in
Signing in with Google returns an identity token containing your email address, name and profile picture. The application uses the email address for a single purpose: to check it against the allowlist and decide whether to grant access. Your name and picture may be displayed in the interface to show who is signed in.
The application requests only the basic openid,
email and profile scopes. It does not request and
cannot obtain access to Gmail, Drive, Calendar, Contacts, or your YouTube
account or viewing history.
What is stored
- A session cookie in your browser or app, so you are not asked to sign in on every request. It expires after 30 days.
- Your email address, in server session records and request logs, to identify who made a request.
- Job records — the videos submitted, the transcripts fetched, the summaries generated, and token usage. Workflow history is kept for 7 days.
What is sent elsewhere
- Anthropic (Claude) receives video transcripts and the prompts used to summarize them, in order to generate the summaries.
- GitHub receives the finished summaries, which are committed to a repository owned by the operator. Where that repository is public, the summaries are public; your identity is not included in them.
- YouTube is contacted to retrieve publicly available captions and video metadata.
- Cloudflare routes requests to the server and may log request metadata as part of providing that service.
Nothing is sold, rented, or shared with advertisers or data brokers. There is no third-party analytics or tracking on this site or in the application.
Where data is held
The application runs on hardware operated privately by the operator, not on rented cloud infrastructure. Credentials are stored with file permissions restricted to the service account, and job payloads containing access tokens are encrypted at rest.
Retention and deletion
Sessions expire after 30 days. Workflow history is discarded after 7 days. Published summaries remain in the blog repository until removed by the operator. If you have used this application and want your session and logged email removed, write to support@zengarden.space and it will be deleted.
Your Google data
The application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google sign-in data is used only to authenticate access and is never used for advertising, sold, or transferred to others except as required by law.
Contact
Questions about this policy or about data held by this application go to support@zengarden.space.
Changes
If this policy changes, the date at the top of this page changes with it.