Account data: Your name, email address, and Google profile photo when you sign in with Google.
YouTube data: Publicly available channel information โ channel name, description, video metadata, links, and subscriber count. We do not access private video data or analytics. If you use the Comment Scanner (Creator and Creator Pro), we read the public comments on videos you own, on demand, to check for scam patterns.
OAuth tokens: If you connect your channel (paid plans), we temporarily use your Google OAuth tokens to check 2FA status and connected third-party apps. Tokens are used only within the active scan session, are never written to our database, and are discarded from memory as soon as the scan completes. See How we protect your data below for full details.
Scan results: Your security scores, findings, and recommendations are stored so you can access your history. This includes results from the Email Scanner and Comment Scanner (Creator and Creator Pro), both on-demand tools you choose to run โ an email you paste/upload, or your channel's comments, is analysed by Anthropic's Claude to produce a verdict, and the result is stored the same way as a regular scan.
WhatsApp number (optional): If you opt in to compromise alerts via WhatsApp (Creator Pro), we store the phone number you provide and use it, via Meta's WhatsApp Business Platform, only to deliver that alert.
Payment data: Payments are processed by Razorpay. We do not store your card number, CVV, or UPI details.
- To provide security scans and reports
- To send email notifications you've opted into
- To improve our audit engine
- To process payments and manage your subscription
- We never sell your data
- We never post, modify, or delete content on your YouTube channel or Google account
- We never share your data with third parties except: Razorpay (payments), Supabase (database infrastructure), Anthropic (analysing email/comment content you submit to the Email Scanner or Comment Scanner), and Meta's WhatsApp Business Platform (only if you opt in to WhatsApp alerts, and only your phone number + alert content)
Encryption in transit: All data exchanged between your browser, our servers, and third-party services is transmitted exclusively over TLS 1.2+ (HTTPS). Unencrypted HTTP connections are rejected.
Encryption at rest: Your account data, scan results, and any stored credentials are held in Supabase (PostgreSQL), which encrypts all data at rest using AES-256. Supabase is SOC 2 Type II certified.
OAuth token handling: Google OAuth access tokens you grant are used solely within the active scan session to perform the security check (verifying 2-step verification status and connected third-party apps). OAuth tokens are never written to the database and are discarded from memory as soon as the scan completes. They are transmitted only over HTTPS and are never logged.
Authentication & access controls: Every API endpoint that touches user data requires a valid JWT bearer token tied to your account. Server-side database access uses a service-role key stored exclusively in environment variables โ it is never exposed to the browser. All queries are scoped to your user ID, preventing cross-account data access.
Least-privilege principle: Our application requests only the minimum Google OAuth scopes necessary to perform a security audit (youtube.readonly and https://www.googleapis.com/auth/userinfo.email). We do not request write, upload, or account-management scopes.
Infrastructure security: The application runs on Vercel (SOC 2 Type II) with environment variables managed as encrypted secrets. No sensitive keys are committed to source code.
Securoly stores information directly in your browser using localStorage and sessionStorage โ technologies similar to cookies. Specifically:
- Authentication token (localStorage): a JSON Web Token (JWT) that keeps you signed in between sessions. It is scoped to this site only and expires when you sign out or delete your account.
- Pending scan URL (sessionStorage): temporarily saved when you start a scan before logging in, so it can be resumed after the OAuth redirect. Cleared immediately after use.
We do not use third-party advertising cookies or tracking pixels. You can clear all stored data at any time through your browser's storage settings.
Scan history is kept while your account is active. When you delete your account, all data is permanently deleted within 24 hours.
You can export, correct, or delete your data at any time from your account settings (Settings โ Danger Zone โ Delete account) or by emailing trust@securoly.com.
Revoking YouTube API access: You can revoke Securoly's authorization to access YouTube API Services at any time by visiting your Google account's security settings at myaccount.google.com/connections. Revoking access removes all OAuth permissions โ your Securoly account and scan history remain until you delete your account.
You can also disconnect YouTube from within Securoly's Settings tab at any time.
Securoly uses the YouTube API Services. Your use of those services is also subject to Google's Privacy Policy at google.com/policies/privacy.
For privacy questions: trust@securoly.com