Privacy Policy
This policy explains what personal data ythopper collects, why we collect it, how we use and protect it, who we share it with, and the rights you have over it. Written to comply with the Digital Personal Data Protection Act, 2023 (India), the EU and UK GDPR, and the California Consumer Privacy Act (as amended by the CPRA).
At a glance
The short version. The full document below has the legal specifics.
- We don't store videos. We only fetch and store the publicly available transcript of YouTube videos you submit.
- We don't sell or rent your data. Ever. Not for advertising, not for any other purpose.
- You can use ythopper anonymously. We track an anonymous browser cookie and an HMAC hash of your IP, not the raw IP, only to enforce free-plan limits.
- Your transcript goes to OpenAI. That's how we generate highlights. We don't train AI models on your data ourselves.
- You can delete your account and data at any time by contacting us. See Section 7.
1. Who we are
ythopper (“we”, “us”) is operated by YT Hopper, incorporated at Bangalore, India.
For the purposes of the DPDP Act, 2023, we are the Data Fiduciary for personal data of users in India. For GDPR purposes, we are the Data Controller for personal data of users in the European Economic Area, United Kingdom, and Switzerland. For the CCPA, we are the Business.
2. Data we collect
The categories of data we collect are limited and listed below.
2.1 Account data (when you sign in)
- Your name, as Google provides it.
- Your email address.
- Your Google profile image URL.
- Your Google account identifier.
- Sign-in metadata: account creation date, last sign-in time.
2.2 Anonymous identifiers (when you use the Service without signing in)
- A randomly generated UUID stored in a first-party cookie named
yth_anon. - An HMAC-SHA256 hash of your IP address using a server-side secret. We never store the raw IP and cannot recover it from the hash.
2.3 Usage data
- The YouTube URLs and video identifiers you submit.
- The transcript text retrieved for those videos (which is publicly available from YouTube).
- Topics, custom questions, and reels you create.
- The highlight count you choose and which highlights you exclude.
- Reel status (pending / ready / error) and timestamps.
2.4 Billing data (Pro plan only)
- Your subscription status and current billing period dates.
- Identifiers issued by our payment processor (Dodo Payments): subscription ID, customer ID, product ID.
- An audit trail of payment events received from Dodo Payments.
We do not collect or store payment card numbers, CVCs, bank account numbers, or any other raw payment credential. That data is handled directly by our PCI-DSS compliant processor.
2.5 Diagnostic data
Standard server logs may temporarily record request paths, status codes, and timestamps for operational and security purposes. We do not log full payloads, and any IP appearing in transient logs is purged on a short rolling schedule.
3. Why we collect it
We process personal data only for the specific purposes listed below, and only for as long as needed to fulfil each purpose.
We do not use your personal data for advertising, profiling for marketing, or training third-party AI models.
4. Who we share with
We share personal data only with the third-party processors listed below, only to the extent needed to deliver the Service:
- Google LLC - authentication (sign-in with Google), and operation of the embedded YouTube player.
- YouTube (Google) - we read public transcripts from YouTube and embed YouTube’s player for playback. YouTube sets its own cookies on its player; those are governed by Google’s privacy policy.
- OpenAI, L.L.C. - transcript text and your selected topics or questions are sent to OpenAI’s API to generate topic suggestions, highlight selections, and editorial bridge text. We use OpenAI’s API endpoints, which under OpenAI’s current policies are not used to train OpenAI’s models.
- Dodo Payments - payment processing for Pro subscriptions.
- Hosting and database providers - the cloud infrastructure that runs ythopper and stores account data and transcripts.
Each processor is bound by a data-processing agreement consistent with applicable law. We do not sell or rent personal data to any party. We have not done so in the preceding 12 months. We do not share personal data for cross-context behavioural advertising.
5. International transfers
Our infrastructure and the third-party processors above are located in multiple countries, which may include the United States, the European Union, and India. Where we transfer personal data internationally we rely on legally recognised safeguards, including:
- the European Commission’s Standard Contractual Clauses and applicable adequacy decisions, for transfers out of the EEA / UK;
- the cross-border-transfer mechanisms permitted under §16 of the DPDP Act, 2023, for transfers out of India;
- equivalent contractual safeguards with processors operating in other regions.
You may request a copy of the relevant transfer mechanism from us at the address in Section 14.
6. How long we keep it
We keep personal data only as long as we need it for the purpose we collected it. Specifically:
- Account data: while your account is active, plus up to 90 days after closure to handle disputes and prevent abuse, after which it is deleted or anonymised.
- Reels and transcripts: while your account is active. You may delete individual reels at any time, and we will delete on request as set out in Section 7.
- Anonymous identifiers: the cookie expires after 30 days. Hashes of the IP that accompanies a reel persist while that reel persists. Standalone IP-hash entries with no associated reel are purged after the rolling quota window (typically 7 days).
- Billing records: up to 8 years after the end of the financial year in which the transaction occurred, as required by applicable tax and accounting law in India and other jurisdictions.
- Diagnostic logs: typically 30 days, less for any IP information.
7. Your rights
Subject to applicable law, you have the following rights over your personal data:
- Access: request a copy of the data we hold about you.
- Correction: ask us to fix data that is inaccurate or incomplete.
- Erasure / right to be forgotten: ask us to delete your account and associated data, subject to retention obligations imposed by law (e.g. tax records).
- Portability: receive your data in a structured, commonly used, machine-readable format.
- Restriction / objection: object to processing based on our legitimate interests, or restrict processing while we evaluate your objection.
- Withdraw consent: where we rely on consent, you can withdraw it at any time without affecting prior lawful processing.
- Opt out of sale / sharing: we do not sell or share personal data; this right is honoured by default.
- Nominate a representative: under DPDP §14, you may nominate another person to exercise your rights in the event of death or incapacity.
- Lodge a complaint: with the supervisory authority applicable to you - the Data Protection Board of India (DPDP Act §27), your EU national supervisory authority, the UK ICO, or the California Privacy Protection Agency.
To exercise any right, email us at yash.wanvari@gmail.com or write to us at the address in Section 14. We respond within the time required by law (typically 30 days under GDPR, and within the timelines prescribed by the DPDP Act). We may need to verify your identity before acting on a request. We will never discriminate against you for exercising a right.
9. AI processing & automated decisions
We use a large language model (currently provided by OpenAI) to:
- propose 6–10 candidate learning topics from your transcript;
- identify timestamped highlight segments that match the topics or questions you selected;
- generate short editorial bridge sentences between consecutive highlights.
These outputs are statistical interpretations of the source transcript. They are not decisions about you that produce legal or similarly significant effects. You retain full control: you choose which topics to apply, which highlights to keep or exclude, and when to start or stop the Service.
If you would prefer not to have transcripts processed by an AI provider, the Service is not usable in that mode - generating highlights is the Service’s core function. You may stop using the Service at any time.
10. Security
We use industry-standard security measures appropriate to the sensitivity of the data we hold, including:
- encryption in transit (TLS) for all client and server traffic;
- encryption at rest for our managed database;
- HMAC-hashed storage of IP addresses so raw IPs cannot be recovered from our records;
- webhook signature verification with constant-time comparison and a replay-protection window to authenticate payment callbacks;
- least-privilege access controls on production systems and audit logging of administrator actions;
- regular review of third-party processor practices.
No method of transmission or storage is completely secure. If you believe your account has been compromised, please contact us immediately at yash.wanvari@gmail.com. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authorities within the timeframes required by law (e.g. 72 hours under GDPR Art. 33; the timelines prescribed by the DPDP Act and the Indian CERT-In Directions, 2022).
11. Children
The Service is not directed at children under 13 and we do not knowingly collect personal data from them. If you believe a child under 13 has provided us with personal data, contact us and we will delete it. For users under 18 (or the age of majority in your jurisdiction), use of the Service should involve a parent or legal guardian, as required by DPDP §9.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. If the changes are material, we will give reasonable advance notice (such as by email or an in-app notice). Continued use of the Service after the new policy takes effect constitutes acceptance.
13. Grievance officer (India)
In accordance with §10 of the DPDP Act, 2023, Rule 3(2) of the Information Technology Rules, 2021, and §75 of the IT Act, 2000, the following officer is designated to address privacy and data-protection grievances for users in India:
- Name
- Yash Wanvari
- Designation
- Grievance & Data Protection Officer
- yash.wanvari@gmail.com
- Postal address
- YT Hopper, Bangalore, India
We acknowledge complaints within 24 hours of receipt and aim to resolve them within 15 days, as required by Rule 3(2) of the IT Rules, 2021.
14. Contact us
For any privacy-related question or to exercise any right described in this policy:
See also our Terms & Conditions.