Privacy Policy

Last updated: 3 October 2026

This is the human version. The legalese version is the same content, just dressed up. We don't run accounts, we don't sell data, and we don't track you around the internet. Below is exactly what happens when you use AuraWizard.

1. Who we are

AuraWizard is a one-shot YouTube channel analysis tool. You paste a channel URL, you get a one-time report. There is no account to create, no email to give us, no password to remember.

Operator: AuraWizard
Contact: wizard@aurawizard.com

If you have a question about your data, deletion, or anything in this policy, the contact email above is the way to reach us.

2. What we collect

When you submit a channel for analysis

When you pay

What we fetch from YouTube about the channel you analyze

When you submit a URL, we fetch publicly available information about that channel from the YouTube Data API: channel name, description, subscriber count, view counts, recent video titles, tags, durations, and similar public metadata. This is the same information visible to anyone who visits that YouTube channel.

What we send to Google Gemini

To generate the AI insights section of your report, we send the channel's public metadata (channel name, recent video titles, public tags, basic stats) and any optional niche tags you typed into the form to Google Gemini for analysis. We do not send your IP, your Stripe session ID, or any custom API key you provided. Google's handling of this data is governed by their API Terms.

What we store long-term in our database

For the trajectory feature (the "Your Trajectory" card that lets returning customers see how the channel has progressed over time), we store a minimal snapshot per analysis:

Those trajectory rows do not include video titles or tags. We do not store: your IP address, your name, your email, your card details, or your custom API key. The history is keyed only by the public YouTube channel ID.

The saved report

We keep one copy of the finished report, keyed by the Stripe checkout id or the invite code, so a closed tab or a restart does not throw away a report that was already generated. That copy includes the public channel stats, recent video titles, tags, and the AI tips. It does not include a YouTube API key. Reopening it requires the unguessable session id from that run. Email us and we will delete it.

What stays on your device

While you're paying through Stripe and being redirected back, your browser's localStorage temporarily holds the channel URL, tags, category, region, and content focus you submitted — not your YouTube API key. This is so we can resume your analysis after you return from Stripe. It's cleared automatically once the analysis completes. If you used the BYOK discount, we will ask you to paste your key again after checkout (it is never written to disk on our servers or in localStorage).

An invite run keeps the code, channel URL, and tags in sessionStorage only until the report page opens. The YouTube API key is not included. After a report finishes, the browser remembers that session id in sessionStorage so a refresh can reopen the saved copy.

We do not set any tracking cookies, analytics cookies, or advertising cookies of our own. Your browser may receive cookies from Stripe during checkout — that is governed by Stripe's policy, not ours.

What we do not collect

3. How we use the data

We use what we collect for exactly these purposes and nothing else:

  1. To generate your one-time analysis report.
  2. To make sure each paid Stripe session can only be redeemed once (the session ID).
  3. To prevent abuse (the temporary IP-based rate limit).
  4. To enable the trajectory feature on returning visits (the channel-keyed history).
  5. To cache YouTube API responses so we don't burn quota answering the same question twice and so reports load faster (cached entries don't contain anything user-specific — just YouTube's public data).

We do not:

4. Third parties we share data with

There are exactly three:

ServiceWhat they receiveWhyTheir policy
Stripe Your payment details (directly from your browser to them, never via us), email at checkout To process the payment stripe.com/privacy
YouTube Data API (Google) The channel URL/ID you submit To fetch the public channel data policies.google.com/privacy
Google Gemini API Public channel metadata (name, video titles, tags, stats) To generate AI insights policies.google.com/privacy

We don't use any other third-party processor. No analytics, no error monitoring with PII, no email service, no CRM.

5. How long we keep things

WhatRetention
Channel analysis history (channel ID, public metrics)Indefinitely, so the trajectory feature works long-term. You can request deletion at any time — see Section 6.
Finished report (stats, titles, tags, AI tips)Kept so you can reopen it. You can request deletion at any time.
Stripe session IDs (used-sessions table)Kept for as long as needed so a paid checkout cannot be redeemed twice. Not your card or name.
YouTube API cacheUp to 30 days for handle→channel ID maps, 7 days for tag/topic/competitor lookups, 24 hours for deep channel analysis, then automatically expired
Daily quota counters90 days, then automatically deleted
IP addresses (rate limit)A few minutes in memory only — never written to disk
BYOK custom API keysThe duration of a single request — never stored
localStorage analysis params on your deviceCleared as soon as your report is generated

6. Your rights

Depending on where you live, you may have rights under GDPR (EU/UK), CCPA/CPRA (California), the Privacy Act 1988 (Australia), or similar laws. The practical version:

To exercise any of these, email wizard@aurawizard.com with the channel URL. We don't require ID verification because we don't hold identifying information — possession of the channel URL plus a coherent request is sufficient. If we suspect the request is malicious, we may delay action and ask follow-up questions.

7. Security

No system is perfectly secure. If you suspect a security issue, please email wizard@aurawizard.com so we can investigate.

8. International transfers

We are based in the United States. Stripe, Google (YouTube + Gemini), and our hosting provider may process data in the United States or other countries. By using AuraWizard you consent to this transfer. We rely on the third parties' own safeguards (Standard Contractual Clauses, Data Processing Addenda) for these transfers.

9. Children

AuraWizard is not directed at children under 16. We do not knowingly collect data from children. If you are under 16, please don't use this service. If you believe we've inadvertently collected data from a child, email us and we will delete it.

10. Changes to this policy

If we change this policy meaningfully, we'll update the "Last updated" date at the top and post a note on the homepage for at least 14 days. For minor wording fixes we'll just update the date.

11. Contact

For anything related to this policy or your data:

wizard@aurawizard.com

That's the whole policy. If anything here is unclear, email us and we'll explain it in plain English.