Odinstat Privacy Policy
Last updated: 2026-09-20
What Odinstat Is
Odinstat is a YouTube analytics tool operated by Odinstat LLC ("Odinstat", "we"), which is the controller of the personal data described in this policy. You connect a channel you own or manage, we import its statistics through Google's official read-only APIs, and we compute analyses of your own data — which videos are outliers, how your thumbnails convert after adjusting for reach, where viewers stop watching, how long videos keep earning views. This policy explains what we collect to do that, how we use it, and how you get rid of it.
YouTube API Services
Odinstat uses YouTube API Services to access your channel analytics data. Access is read-only: the permissions we request let us view analytics but can never change your channel, videos, or settings. By using Odinstat, you agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms) and the Google Privacy Policy: https://www.google.com/policies/privacy
Google API Limited Use Disclosure
Odinstat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. In plain terms: Google user data is used only to provide the analytics features you see in Odinstat — never for advertising, never sold, never used to train AI models, and never read by humans except with your consent, for security, or to comply with law.
Account Information
When you create an account we store your email address, display name, and avatar (from Google Sign-In where applicable) via our authentication provider, Supabase. Payments are processed by Stripe; your card details never touch our servers. We store only the Stripe customer and subscription identifiers needed to manage your plan.
If you are invited to a channel as a collaborator, we store the same account information plus the role and data permissions the channel owner set for you.
Cookies & Browser Storage
Odinstat does not use advertising cookies, cross-site tracking, or third-party analytics scripts, so there is no cookie banner: everything stored in your browser is strictly necessary to run the app.
- Your sign-in session (a Supabase Auth token) is kept in your browser's local storage so you stay signed in between visits. Signing out removes it.
- Preferences you set in the app — theme, watchlist, notification and insight settings, the channel you last viewed — are kept in local storage and, where they matter across devices, in your account.
- Sign-in and sign-up forms use Cloudflare Turnstile to block bots; Cloudflare may set a short-lived cookie for that check only.
- Stripe sets its own cookies on the checkout and billing pages it hosts, under Stripe's privacy policy.
- Sentry receives technical error reports (browser type, the page, the stack trace) when something breaks. It does not receive your analytics data.
Clearing your browser's site data for odinstat.com removes all of the above.
Data We Access From YouTube
When you connect your YouTube channel, we access the following data via YouTube API Services:
- Video metadata (titles, descriptions, thumbnails, tags, duration, category, publish date)
- Daily video performance metrics (views, likes, comments, shares, watch time, average view duration and percentage, subscribers gained and lost)
- Thumbnail impressions and click-through rate (YouTube Reporting API; typically available for recent uploads only)
- Audience retention curves per video
- Traffic source breakdowns
- Audience demographics (age group, gender)
- Geographic viewer distribution (by country)
- Device type breakdowns
- Channel-level daily subscriber and view counts
- Info card and end screen performance
- Revenue data — only if you explicitly grant the monetary analytics permission during connection
We do not access your comments' text, your subscribers' identities, private messages, or anything about individual viewers. YouTube's analytics are aggregated before we ever see them.
How We Use Your Data
We use your YouTube analytics data solely to compute analyses of your own channel and show them to you. Every analysis compares your videos against your own history — never against other channels. This includes:
- Identifying videos performing far above or below your usual range
- Ranking thumbnails by click rate after adjusting for how widely each was shown
- Reading audience retention curves to find where viewers leave
- Comparing each video's retention against what is typical for its length on your channel
- Measuring how quickly each video's views fade after launch
- Breaking down where your views come from and which videos convert subscribers
- Trend, timing, and format comparisons you can switch on in Settings
- Generating scheduled reports you configure
Your data is never aggregated with other creators' data, never used to build benchmarks shown to anyone else, and never used for advertising or profiling.
AI Features
Two features use a large language model (Google Gemini, via the paid API): the Channel Assistant and per-video retention interpretations. What this means for your data:
- Every AI answer is generated from statistics we first compute from your own channel's data — the model explains numbers; it does not receive your raw YouTube data.
- Video and channel titles are replaced with anonymous placeholders before anything is sent to the model, and restored only in the answer shown to you.
- Assistant conversations are stored in our database so your chats follow you across devices. They are private to your account and deleted with it.
- Retention interpretations are cached per video so repeat views do not re-send data. When we improve the interpretation method, the cache is regenerated on next view.
- AI usage is limited per day according to your plan; we count requests, not content.
- We use paid API access, which under Google's terms is not used to train their models.
Channel Collaborators
On plans that include collaborator seats, a channel owner can invite other Odinstat users to view a channel's analytics. The owner decides, per collaborator, whether revenue, demographic, and geographic data are visible; those metrics are removed from every surface — including reports and the AI assistant — for collaborators without permission. Collaborators are either viewers (read-only) or editors (may run analyses, reports, and the assistant, using the owner's plan allowances); neither can change the YouTube connection, manage the team, or delete channel data. The owner can remove a collaborator at any time, and the collaborator can leave at any time.
Service Providers
We rely on a small set of infrastructure providers to run Odinstat. Each processes only what its role requires:
- Supabase — authentication and our PostgreSQL database (all stored data lives here)
- Stripe — payment processing; card details never touch our servers
- Google — YouTube API Services (your analytics data) and the Gemini API (AI features, anonymized as described above)
- Vercel — hosts the web app you load in your browser
- Railway — hosts our backend servers and background jobs
- Sentry — error monitoring; receives technical error reports, not your analytics data
None of these providers may use your data for their own purposes, and we never sell your data to anyone.
Data Storage, Freshness & Security
Your OAuth access and refresh tokens are encrypted at rest before being stored in our PostgreSQL database, and every database row is protected by row-level security so a query can only ever return data for channels you are entitled to.
Your analytics data is re-synced regularly and refreshed at least every 30 days in compliance with YouTube API Developer Policies. Data that has not been refreshed within 30 days is automatically deleted.
Analyses and reports you generate are stored so you can revisit them. Full analysis detail is kept for 90 days, a summary until one year, and only the headline verdict after that. Exported report files are deleted 7 days after they are created.
If we learn of a security breach affecting your personal data, we will notify you and any authority the law requires without undue delay, and tell you what happened and what we are doing about it.
Data Deletion
You are in control of deletion, and you do not need to contact us to exercise it:
- Disconnecting a channel from Settings stops all syncing and deletes the channel's imported YouTube API data immediately. Reports and saved analyses you generated are kept unless you choose "delete permanently", which removes everything about that channel.
- Deleting your account from Settings deletes your YouTube API data, analyses, reports, assistant conversations, and profile immediately, cancels any active subscription, and removes your payment profile at Stripe. One thing is kept: if the account used a free trial, we retain a keyed hash of its email address so the trial cannot be repeated by deleting and recreating the account. The hash cannot be turned back into your address and is deleted automatically 3 years after the trial started.
- If Odinstat's access is revoked from your Google account, or your sign-in expires, we detect it within 24 hours and stop syncing. Your imported data is kept for a 28-day grace period so reconnecting loses nothing (we remind you before it ends); after that the imported YouTube data is deleted automatically. Either way, all YouTube API data is gone within the 30 days YouTube's policies require.
Deleting your data from Odinstat does not affect any data stored on YouTube's own servers.
Revoking Access
You can revoke Odinstat's access to your YouTube account at any time by visiting your Google security settings: https://security.google.com/settings/security/permissions
When you revoke access, we detect this within 24 hours, stop syncing, and delete your stored API data after the 28-day grace period described above. To delete immediately instead, disconnect the channel or delete your account in Settings.
Where Your Data Is Stored & Legal Bases
Odinstat LLC is a United States company and our providers store your data on servers in the United States. If you use Odinstat from outside the U.S., your data is transferred to and processed in the U.S. Where the law requires safeguards for that transfer (for example the EU, UK, or Switzerland), we rely on our providers' standard contractual clauses and data processing terms.
For people in the EU, UK, and other places whose law asks us to name a legal basis, we process your data:
- to perform our contract with you — importing and analysing the channel you connected, running your account, billing (contract);
- with your consent — the YouTube permissions you grant at connection, including the separate revenue permission, which you can withdraw at any time by revoking access (consent);
- for our legitimate interests in keeping the service secure, preventing abuse, fixing errors, and sending you service notices, balanced against your rights (legitimate interests);
- to meet legal obligations such as tax and accounting records for payments (legal obligation).
Your Privacy Rights
Wherever you live, you can:
- See what we hold about you — everything we store is visible in the app, except the trial hash described under Data Deletion, and you can request a copy by emailing support@odinstat.com.
- Correct your account details in Settings.
- Delete your data — disconnect a channel or delete your account in Settings, immediately and without asking us (see Data Deletion).
- Take your data with you — reports export to PDF, CSV, and text from the app; ask us for a machine-readable export of anything else.
- Withdraw consent — revoke Odinstat's access in your Google security settings at any time.
- Object to or restrict processing, and complain to your local data-protection authority if you think we have got something wrong (we would rather you told us first).
We answer requests within 30 days and never treat you differently for exercising a right. We may ask you to confirm you control the account before acting on a request made by email.
California residents: we do not sell your personal information or share it for cross-context behavioural advertising, and we have not done so in the past 12 months. The rights above are available to you regardless of whether the CCPA applies to a company of our size. We do not respond to browser "Do Not Track" signals because we do no tracking to switch off.
Children
Odinstat is not directed at children. You must be at least 18 to hold an account (see the Terms of Service), and we do not knowingly collect personal information from anyone under 13. If you believe a child has created an account, email support@odinstat.com and we will delete it.
Emails We Send
We email you about your account and your plan: sign-in confirmations, receipts and renewal reminders (some sent by Stripe), payment problems, security alerts, and notices of changes to these documents. These are part of running your account and cannot be switched off while you have one. Optional notifications — sync summaries, reports ready, milestones — are controlled in Settings → Notifications. We do not send marketing email.
Third-Party Sharing
Beyond the service providers listed above (who process data only on our behalf), we do NOT share your YouTube API Data with any third parties. Your data is visible only to you and to collaborators you explicitly invite to a channel (whose access you control and can revoke at any time), and it is never aggregated across different channels or content owners.
Changes to This Policy
If we change how we handle your data, we will update this page and its "last updated" date, and notify you in the app before the change takes effect where the change is material.
Contact
Odinstat LLC is responsible for this policy. If you have questions about our privacy practices or wish to exercise your data rights, contact us at support@odinstat.com.