Privacy
Privacy and YouTube API use.
How MartinPeniak.com and the private Project Tao — Living Postcards publisher handle authorization and operational data.
Scope
Project Tao — Living Postcards uses YouTube API Services to publish Martin Peniak’s own accepted Tao postcard videos to his own YouTube channel and to maintain their playlist, captions, localized text, and publication state. It is a private, single-operator publishing client. It does not offer public accounts or ask visitors to connect their Google accounts.
Data the publisher uses
When Martin authorizes the publisher through Google OAuth, it may receive and retain only the data needed to run and verify the relay:
- the authorized YouTube channel identity and channel ID;
- OAuth access and refresh tokens;
- video, playlist, caption, localization, processing, visibility, and publication metadata returned by YouTube;
- operational receipts linking an accepted Tao postcard and its integrity hash to the resulting YouTube video and playlist item.
The publisher does not request Martin’s Google password. It does not use the YouTube API to collect viewer identities, viewing history, contacts, advertising profiles, or unrelated channel data.
How the data is used and stored
The data is used only to upload an accepted postcard unchanged, add its captions and metadata, place it in Project Tao — Living Postcards, verify its state, prevent duplicate publication, and recover safely from interrupted uploads.
OAuth tokens are stored privately outside this public website and outside its source repository. Operational metadata and receipts are retained while the relay is active and as needed for integrity, recovery, and audit. API-derived video, status, playlist, and caption metadata is refreshed from YouTube at least every 30 days for as long as it is retained; if it cannot be refreshed, it is deleted. Immutable Tao acceptance hashes remain local provenance records and are not YouTube API data. The data is not sold, used for advertising, or disclosed to advertisers. It is transmitted to Google and YouTube only as required to provide the authorized YouTube service.
Website visitors and YouTube
The Living Postcards player uses YouTube’s privacy-enhanced embed domain and is not loaded until a visitor chooses play. After that choice, YouTube may process device, network, cookie, and playback information under Google’s policies. MartinPeniak.com does not receive the visitor’s Google credentials from the player.
Revocation and deletion
Martin can revoke the publisher’s Google access at any time from Google Account permissions. Revocation stops future API access but does not by itself remove videos already published on YouTube.
To request deletion of stored OAuth tokens or YouTube API data controlled by this publisher, use the contact page and identify the request as “Living Postcards data deletion.” The tokens and YouTube API data under Martin’s control will be deleted within 30 days, except where limited records must be retained to meet a legal obligation. Published YouTube videos can be made private or removed separately on request.
Questions
Ask directly.
Questions about this policy, the YouTube API client, access revocation, or deletion can be sent through the site’s contact form.
Contact Martin