Privacy Policy
Last updated: 3 October 2026
This is the human version. The legalese version is the same content, just dressed up. We don't run accounts, we don't sell data, and we don't track you around the internet. Below is exactly what happens when you use AuraWizard.
1. Who we are
AuraWizard is a one-shot YouTube channel analysis tool. You paste a channel URL, you get a one-time report. There is no account to create, no email to give us, no password to remember.
Operator: AuraWizard
Contact: wizard@aurawizard.com
If you have a question about your data, deletion, or anything in this policy, the contact email above is the way to reach us.
2. What we collect
When you submit a channel for analysis
- The YouTube channel URL you paste. This is the input to the tool.
- Any tags you add (optional). Used as analysis hints.
- Your content focus and region selection. Used to shape the report and pick YouTube’s popular-themes chart.
- Your IP address, temporarily. Held in memory for a few minutes only, used to rate-limit abusive request patterns. It is not written to our database.
When you pay
- A Stripe Checkout session ID. We store this in our database to make sure each paid session can only be redeemed once. It does not contain your card details or your name.
- Stripe itself collects your payment details. We never see your full card number, CVC, or billing address. Stripe is the payment processor and has its own privacy policy at stripe.com/privacy.
- If you choose BYOK (Bring Your Own Key) at the discount price, the YouTube API key you enter is held in memory only for the duration of your single analysis. It is not stored, not logged, and not reused for anyone else.
What we fetch from YouTube about the channel you analyze
When you submit a URL, we fetch publicly available information about that channel from the YouTube Data API: channel name, description, subscriber count, view counts, recent video titles, tags, durations, and similar public metadata. This is the same information visible to anyone who visits that YouTube channel.
What we send to Google Gemini
To generate the AI insights section of your report, we send the channel's public metadata (channel name, recent video titles, public tags, basic stats) and any optional niche tags you typed into the form to Google Gemini for analysis. We do not send your IP, your Stripe session ID, or any custom API key you provided. Google's handling of this data is governed by their API Terms.
What we store long-term in our database
For the trajectory feature (the "Your Trajectory" card that lets returning customers see how the channel has progressed over time), we store a minimal snapshot per analysis:
- The YouTube channel ID (a public identifier like
UCxxxxxx) - A timestamp
- Subscriber count, total video count, and average likes per video
Those trajectory rows do not include video titles or tags. We do not store: your IP address, your name, your email, your card details, or your custom API key. The history is keyed only by the public YouTube channel ID.
The saved report
We keep one copy of the finished report, keyed by the Stripe checkout id or the invite code, so a closed tab or a restart does not throw away a report that was already generated. That copy includes the public channel stats, recent video titles, tags, and the AI tips. It does not include a YouTube API key. Reopening it requires the unguessable session id from that run. Email us and we will delete it.
What stays on your device
While you're paying through Stripe and being redirected back, your browser's localStorage temporarily holds the channel URL, tags, category, region, and content focus you submitted — not your YouTube API key. This is so we can resume your analysis after you return from Stripe. It's cleared automatically once the analysis completes. If you used the BYOK discount, we will ask you to paste your key again after checkout (it is never written to disk on our servers or in localStorage).
An invite run keeps the code, channel URL, and tags in sessionStorage only until the report page opens. The YouTube API key is not included. After a report finishes, the browser remembers that session id in sessionStorage so a refresh can reopen the saved copy.
We do not set any tracking cookies, analytics cookies, or advertising cookies of our own. Your browser may receive cookies from Stripe during checkout — that is governed by Stripe's policy, not ours.
What we do not collect
- We do not have user accounts.
- We do not collect your name or email address (Stripe collects an email at checkout for receipts; we don't read it from our side).
- We do not track you across other websites.
- We do not run analytics services like Google Analytics or Facebook Pixel.
- We do not run advertising trackers.
- We do not fingerprint your device.
3. How we use the data
We use what we collect for exactly these purposes and nothing else:
- To generate your one-time analysis report.
- To make sure each paid Stripe session can only be redeemed once (the session ID).
- To prevent abuse (the temporary IP-based rate limit).
- To enable the trajectory feature on returning visits (the channel-keyed history).
- To cache YouTube API responses so we don't burn quota answering the same question twice and so reports load faster (cached entries don't contain anything user-specific — just YouTube's public data).
We do not:
- Sell your data to anyone.
- Share it with advertisers.
- Use it to train AI models of our own.
- Use it for marketing.
4. Third parties we share data with
There are exactly three:
| Service | What they receive | Why | Their policy |
|---|---|---|---|
| Stripe | Your payment details (directly from your browser to them, never via us), email at checkout | To process the payment | stripe.com/privacy |
| YouTube Data API (Google) | The channel URL/ID you submit | To fetch the public channel data | policies.google.com/privacy |
| Google Gemini API | Public channel metadata (name, video titles, tags, stats) | To generate AI insights | policies.google.com/privacy |
We don't use any other third-party processor. No analytics, no error monitoring with PII, no email service, no CRM.
5. How long we keep things
| What | Retention |
|---|---|
| Channel analysis history (channel ID, public metrics) | Indefinitely, so the trajectory feature works long-term. You can request deletion at any time — see Section 6. |
| Finished report (stats, titles, tags, AI tips) | Kept so you can reopen it. You can request deletion at any time. |
| Stripe session IDs (used-sessions table) | Kept for as long as needed so a paid checkout cannot be redeemed twice. Not your card or name. |
| YouTube API cache | Up to 30 days for handle→channel ID maps, 7 days for tag/topic/competitor lookups, 24 hours for deep channel analysis, then automatically expired |
| Daily quota counters | 90 days, then automatically deleted |
| IP addresses (rate limit) | A few minutes in memory only — never written to disk |
| BYOK custom API keys | The duration of a single request — never stored |
localStorage analysis params on your device | Cleared as soon as your report is generated |
6. Your rights
Depending on where you live, you may have rights under GDPR (EU/UK), CCPA/CPRA (California), the Privacy Act 1988 (Australia), or similar laws. The practical version:
- Right to know what we hold about you. Email us with the channel URL you analyzed; we will tell you exactly what's stored under that channel ID. Because we don't tie analyses to a person, we can only answer at the channel level.
- Right to delete. Email us with the channel URL or the payment session id and we will remove that channel's history and the saved report within 30 days.
- Right to a copy of your data (portability). Same — email us with the channel URL.
- Right to object / opt out. Don't use the service. There is nothing else to opt out of (no marketing, no profiling, no sale of data).
- Right to correct. If a stat looks wrong, the source is YouTube; reach out to YouTube to correct it. We just store what their API returns at the moment of the scan.
To exercise any of these, email wizard@aurawizard.com with the channel URL. We don't require ID verification because we don't hold identifying information — possession of the channel URL plus a coherent request is sufficient. If we suspect the request is malicious, we may delay action and ask follow-up questions.
7. Security
- All traffic to and from AuraWizard is encrypted with HTTPS.
- Payment information is handled exclusively by Stripe and never touches our servers.
- Custom API keys (BYOK) are held in memory only and never logged.
- The database is access-controlled and not exposed to the public internet.
- Server-side requests to YouTube and Gemini have hardened timeouts and redirect limits to prevent abuse.
No system is perfectly secure. If you suspect a security issue, please email wizard@aurawizard.com so we can investigate.
8. International transfers
We are based in the United States. Stripe, Google (YouTube + Gemini), and our hosting provider may process data in the United States or other countries. By using AuraWizard you consent to this transfer. We rely on the third parties' own safeguards (Standard Contractual Clauses, Data Processing Addenda) for these transfers.
9. Children
AuraWizard is not directed at children under 16. We do not knowingly collect data from children. If you are under 16, please don't use this service. If you believe we've inadvertently collected data from a child, email us and we will delete it.
10. Changes to this policy
If we change this policy meaningfully, we'll update the "Last updated" date at the top and post a note on the homepage for at least 14 days. For minor wording fixes we'll just update the date.
11. Contact
For anything related to this policy or your data:
wizard@aurawizard.com
That's the whole policy. If anything here is unclear, email us and we'll explain it in plain English.