Privacy Policy
Last updated: March 15, 2026
1. Introduction
Vigrower ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our website and services at vigrower.com (the "Service").
This Privacy Policy is prominently displayed and accessible at all times via the footer of our website and within the Service.
2. Use of YouTube API Services
Vigrower uses YouTube API Services to provide its core features, including video analysis, channel management, and content optimization.
By using Vigrower, you acknowledge that this Service accesses and uses YouTube API Services on your behalf.
Our use of YouTube API Services is subject to the following Google policies, which govern how your data is handled by Google:
- YouTube Terms of Service — https://www.youtube.com/t/terms
- Google Privacy Policy — http://www.google.com/policies/privacy
- Google API Services User Data Policy
We encourage you to review the Google Privacy Policy (http://www.google.com/policies/privacy) to understand how Google collects, uses, and shares your data when you interact with YouTube API Services through our platform.
3. Information We Collect
We collect the following types of information:
a. Account Information
Your email address, provided when you create an account or sign in via our OTP-based authentication system.
b. YouTube API Data (Authorized Data)
When you connect your YouTube channel to Vigrower via Google OAuth, we request access to the following data as authorized by you through Google's consent screen:
- YouTube channel information: Channel name, channel ID, subscriber count, and channel metadata.
- Video metadata: Video titles, descriptions, tags, thumbnails, view counts, like counts, comment counts, and publication dates.
- Video management: If you choose to use the "Improve Video" feature, we access the ability to update video titles, descriptions, and tags on your behalf, only when you explicitly initiate this action.
We store your OAuth access token and refresh token securely in our database to maintain your channel connection. We also store basic channel information (channel ID, channel name, subscriber count) to display in your account.
c. Publicly Available YouTube Data
When you analyze a YouTube video URL, we retrieve publicly available data from the YouTube Data API, including video metadata, channel information, and related video data. This data is not associated with your personal account unless you explicitly connect your channel.
d. Usage Data
Information about how you interact with the Service, including pages visited, features used, video analysis requests, and timestamps of activity.
e. Device and Browser Information
Browser type and version, IP address, device type, operating system, and referring URLs collected automatically when you visit our website.
4. How We Use Your Information
We use the collected information for the following purposes:
- Provide the Service: Authenticate your identity, manage your account, analyze YouTube videos, and generate AI-powered content recommendations.
- YouTube Channel Management: Display your connected YouTube channels, and update video metadata when you explicitly use the "Improve Video" feature.
- Improve the Service: Monitor usage patterns to improve features, fix bugs, and optimize performance.
- Communication: Send you service-related communications, including OTP codes for authentication and important notices.
- Security: Detect and prevent fraud, abuse, and unauthorized access to the Service.
- Legal Compliance: Comply with applicable laws, regulations, and legal processes.
5. How We Share Your Information
We do not sell, rent, or trade your personal information or YouTube API data to any third parties.
We may share your data only in the following limited circumstances:
- Service Providers: We use third-party services for hosting (server infrastructure), email delivery (sending OTP codes), and AI processing (generating content recommendations). These providers only receive the minimum data necessary to perform their function and are contractually obligated to protect your data.
- Legal Requirements: We may disclose your information when required by law, regulation, subpoena, court order, or other legal process.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, but only after obtaining your explicit prior consent.
- Security: We may share information when necessary to investigate or prevent abuse, fraud, or security threats.
We do not allow any third parties to serve content, including advertisements, within the Service. We do not use your data for advertising, retargeting, or interest-based marketing purposes.
6. Google API Services User Data Policy — Limited Use Disclosure
Vigrower's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we limit our use of Google API data as follows:
- We only use data obtained from Google APIs to provide and improve user-facing features that are prominent in Vigrower's user interface (video analysis, channel management, and content optimization).
- We do not transfer Google API data to other apps or third parties, except as necessary to provide or improve user-facing features, for security purposes, to comply with applicable laws, or as part of a merger/acquisition with your explicit prior consent.
- We do not use Google API data for serving advertisements, retargeting, personalized advertising, or interest-based advertising.
- We do not allow humans to read your Google API data, unless you have given affirmative consent to view specific data, it is necessary for security purposes (e.g., investigating a bug or abuse), it is necessary to comply with applicable law, or the data is aggregated and anonymized for internal operations.
7. Cookies and Tracking Technologies
We store, access, and collect information on your device using the following technologies:
- Session Cookies: We use cookies to maintain your authentication session (XSRF token for CSRF protection). These are essential for the Service to function.
- Local Storage: We store your authentication token in your browser's local storage to keep you signed in across page loads.
We do not use third-party tracking cookies or advertising cookies. We do not allow third parties to place, access, or recognize cookies or similar technology on your device through our Service.
You can control cookie settings through your browser preferences. Please note that disabling cookies may prevent you from using certain features of the Service.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you the Service. Specifically:
- Account data (email address) is retained until you request account deletion.
- YouTube OAuth tokens are retained while your channel is connected. When you remove a channel connection, the associated tokens are deleted from our database.
- Video analysis data (analysis history) is retained for up to 12 months, after which it is automatically deleted.
- Server logs containing IP addresses and usage data are retained for up to 90 days for security and debugging purposes.
You may request deletion of your account and all associated data at any time by contacting us (see Section 13).
9. Revoking Access & Deleting Your Data
🔒 How to Delete Your Data
You can delete some or all of your data directly from within Vigrower at any time — no need to contact us first. Use our Privacy & Data Controls page for self-service deletion.
-
Delete specific data: Go to vigrower.com/gdpr while logged in. You will find individual buttons to delete:
- Your analysis history
- Your connected YouTube channels & OAuth tokens
- Your credit transaction history
- Delete your entire account: On the same Privacy & Data Controls page, click "Delete My Account". This permanently removes your account and all associated data immediately.
- Request deletion by email: Email support@vigrower.com with subject "Data Deletion Request". We will process your request within 30 days.
- Revoke YouTube/Google access: Visit https://myaccount.google.com/connections?filters=3,4&hl=en to revoke Vigrower's access to your Google account. We will delete your stored OAuth tokens within 30 days.
What gets deleted
- YouTube OAuth tokens and channel data: Deleted immediately when you remove a channel in the app, or within 30 days of revoking access via Google.
- Analysis history: Deleted immediately via the Privacy & Data Controls page, or upon account deletion.
- Account data (email, credits): Deleted immediately upon account deletion.
- Credit transaction history: Deleted immediately via the Privacy & Data Controls page, or upon account deletion.
- Server logs: Retained for up to 90 days for security purposes, then automatically purged.
Note: Analysis results derived from publicly available YouTube data (not your personal authorized data) may be retained as anonymized aggregate records after deletion.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit using HTTPS/TLS.
- Secure storage of OAuth tokens and authentication credentials in our database.
- Access controls limiting who can access user data within our organization.
- Regular security reviews of our codebase and infrastructure.
However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
11. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data and account.
- Restriction: Request that we restrict processing of your data.
- Portability: Request your data in a structured, commonly used format.
- Withdrawal of Consent: Withdraw your consent to data processing at any time.
- Revocation: Revoke Vigrower's access to your YouTube data via the Google security settings page (see Section 9).
To exercise any of these rights, please contact us at the email address provided in Section 13.
12. Children's Privacy
The Service is not directed to individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal data from a child under the applicable age, we will take steps to delete that information promptly.
13. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy, our privacy practices, or how we handle your YouTube data, please contact us at:
- Email: support@vigrower.com
- Website: https://vigrower.com
We will respond to your inquiry within 30 days.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable laws. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. If changes materially affect how we use your YouTube API data, we will prompt you to consent to the updated policy before continuing to access that data.
Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.