Revised prelaunch draft — September 4, 2026. Not yet effective for the proposed cloud monitor.
POP Channel Monitor is being developed for the owner of POP – Power Of Positivity on YouTube. This draft explains the intended data practices of the proposed cloud service. The proposed cloud monitor, its optional OpenAI API processing, and automated email delivery are not active. POP currently uses a separate, owner-assisted Codex and Chrome workflow; that existing workflow is not the cloud service described here. Final settings and safeguards must be checked before the proposed service is connected and enabled.
For privacy questions, contact pop@power-of-positivity.com.
With the channel owner's authorization, the monitor would use YouTube API Services to access information needed for private channel reviews. This may include channel and video identifiers, titles, publication details, available performance statistics, and recent published comments with associated identifiers, dates, and reply information.
Public comments can contain personal information. The design limits the comments processed and attempts to withhold sensitive material, but filtering cannot guarantee that every personal detail is removed.
The service would also handle authorization tokens, the owner's approved email details, and limited operational records needed to run checks, control costs, and avoid duplicate reports. If someone emails the contact address, their message and contact details would be used to handle their request.
The intended purpose is to prepare private performance summaries, suggested next steps, and comment-reply drafts for the channel owner's review.
Initial YouTube access is designed to be read-only. The service would not automatically publish comments or change videos, titles, thumbnails, or descriptions.
If email delivery is enabled, its Gmail permission would be send-only. That permission would not permit the monitor to read the Gmail inbox, but the Google permission itself is not restricted to one recipient. Sending only to the owner's approved address is a planned application control that must be verified before activation. Visitors to this information website are not asked to authorize access to their YouTube or Gmail accounts.
Google Cloud is the proposed hosting and storage provider. Gmail would deliver approved private reports to the owner. Reports would not be published on this website.
Optional OpenAI API processing would require separate approval of the disclosed data transfer before activation. If enabled, selected performance evidence and minimized eligible comment excerpts and identifiers would be sent to OpenAI to help prepare recommendations and reply drafts. Authorization tokens and account passwords would not be included in those requests.
OpenAI states that API inputs and outputs are not used for model training by default unless the customer opts in. Its default abuse-monitoring records may retain content for up to 30 days, with documented exceptions. Disabling response storage does not guarantee zero retention. Actual account settings and their suitability must be checked before this feature is enabled. See OpenAI's API data controls.
POP's planned use and transfer of Google account data must follow the Google API Services User Data Policy, including its Limited Use requirements, and the applicable Google Workspace user data policy. Such data would not be sold, used for targeted advertising, or used to train generalized AI models. Access would be limited to the owner and expressly authorized service providers or helpers, except where disclosure is required by law or necessary for security.
The proposed design uses protected credentials, encrypted connections, restricted access, and limited working data. These controls still require deployment testing; this draft is not confirmation that they are already operating.
The current design proposes the following retention periods. These are implementation intentions that must be tested before activation, not guarantees that are already operating:
minimal YouTube working state would expire after seven days without refresh;
daily run and claim records would expire after 35 days;
content-free budget records would expire after 90 days; and
a content-free unresolved-delivery marker would not expire automatically, so an uncertain email delivery cannot be forgotten before it is investigated and resolved.
Authorization credentials would be kept only while needed for the approved connection and then revoked, replaced, or deleted through the final operating procedure. Exact handling periods for credentials, restricted operational logs, support messages, and provider-held records must be finalized and verified before activation. Cloud expiry may be asynchronous and is not an immediate-deletion guarantee.
Email reports create separate copies in the sending and receiving mailboxes. Removing the monitor's working state would not automatically remove those emails or provider-held records. The final retention and deletion process must address those copies too.
Once connected, the owner would be able to remove the application's Google access through Google account permissions. The service must also provide a clear in-application revocation route before activation.
For privacy or deletion requests, email pop@power-of-positivity.com. Please identify the relevant channel or comment where possible; do not send passwords or authorization tokens.
Before activation, the service must have a tested process for stopping access and deleting stored user data in accordance with YouTube's requirements. For revocation through the planned in-application route, the token must be revoked immediately and Authorized Data must be deleted as soon as possible and within seven calendar days. For revocation through Google's account controls, the service must periodically recheck authorization and delete related API Data as soon as possible and within 30 calendar days. These procedures, including treatment of mailbox and provider-held copies, are not yet operationally verified.
A deletion request sent to the contact address is separate from removing Google access. POP would address copies under its control and coordinate applicable provider-held copies under the final verified procedure. Removing POP's copies would not delete the original videos, comments, or other data held by YouTube. See YouTube's developer policies.
This information site is built with Google Sites. Google may process technical information, such as IP addresses, browser information, and cookies, when providing its services. Google's own practices are described in the Google Privacy Policy.
This draft will be updated to match the verified implementation before launch. New purposes, permissions, or data-sharing arrangements would be disclosed and require appropriate consent before use. Reading this page does not authorize account access or AI processing.
POP Channel Monitor is an independent tool, not a Google or YouTube product.