Read-only access
OAuth scopes are limited to youtube.readonly and yt-analytics.readonly. SponsorsMetrics cannot upload, edit, delete, or publish anything on your channel.
Read security detailsOne page summarising every guarantee SponsorsMetrics makes about read-only access, sponsor isolation, encryption, and your GDPR rights. Each section links to the canonical detail page so the policy stays authoritative.
Every guarantee on this page is sourced from a detail document that legal and security own outright. The hub stays summary-only so the canonical pages can't drift out of sync.
OAuth scopes are limited to youtube.readonly and yt-analytics.readonly. SponsorsMetrics cannot upload, edit, delete, or publish anything on your channel.
Read security detailsOAuth tokens are encrypted at rest with AES-256-GCM. Per-secret HMAC signing protects sponsor links, CSRF tokens, and webhook payloads.
Read security detailsSponsors only ever see the public report link you choose to share. They never receive your YouTube account, OAuth tokens, dashboard, or other campaigns.
Read sponsor boundariesAccess, rectification, erasure, portability, and objection rights are documented and actionable from your account or by emailing privacy@sponsorsmetrics.com.
Read privacy policySponsorsMetrics uses two read-only OAuth scopes from Google. Every other YouTube capability — uploads, edits, comments, livestreams, AdSense — stays out of reach by design.
Read channel and video metadata so SponsorsMetrics can identify the videos and segments your campaigns reference.
Can read
Cannot do
Read the YouTube Analytics data that powers each Day 7 / 14 / 30 report — views, retention, watch time, demographics.
Can read
Cannot do
You can review and revoke these scopes at any time from your Google Account permissions page. Revocation is honoured immediately on the SponsorsMetrics side.
Every third party that handles SponsorsMetrics data, what they do, and why they're in the chain.
Postgres database, authentication and row-level security.
Payment processing for paid plans and Agency seat add-ons.
Transactional email delivery (sponsor reports, milestone notifications).
Hosting, edge runtime, and analytics for the web application.
OAuth provider and source of YouTube Analytics data via the YouTube Analytics API.
AI model provider for optional report-generation features.
Yes. From your Google Account permissions you can revoke SponsorsMetrics at any time. We also expose revoke controls inside the SponsorsMetrics Settings → Channels page.
Account data is kept while the account is active. Reports remain stored so historical campaigns survive plan changes. Account deletion is destructive — see Privacy section 5 for details.
No. Sponsors only see the public report link you share. There is no sponsor-side OAuth, no SSO into your YouTube account, and no path from the sponsor view back into your dashboard.
Primary database hosted on Supabase (EU region). OAuth tokens encrypted with AES-256-GCM. See the subprocessor list above for every third party that touches data.
Each topic has a dedicated mailbox so requests land where they can be answered fastest.