Privacy

Analytics is optional and disabled without configuration.

The site creates no accounts and accepts no forms. When a deployment owner supplies a Google Analytics measurement ID, the browser can send page and traffic-source classification events to Google Analytics.

The classifier uses the referring domain and optional UTM parameters to separate identifiable AI-assistant referrals, organic search, YouTube, other referrals, and direct or unidentifiable visits. Some assistants and browsers suppress referrer data, so unidentified direct traffic must never be reported as proven AI traffic.

No analytics script is loaded when VITE_GA_MEASUREMENT_ID is empty. Deployment owners must review consent, disclosure, retention, and jurisdictional requirements before enabling analytics.

YouTube API Services

How We Know is operated by one individual, who also owns and publishes the @howweknowdeep YouTube channel. Publishing to that channel is done by a private command-line pipeline run on the operator’s own computer. That pipeline uses YouTube API Services. This website is where its policy is published; the website itself makes no API calls, and nothing on this website signs a visitor in or asks a visitor to authorise anything.

By using the pipeline, and by extension by using YouTube content it publishes, users are agreeing to be bound by the YouTube Terms of Service. Google’s handling of any data it receives is governed by the Google Privacy Policy.

Who authorises it, and what it can reach

Exactly one Google account authorises the pipeline: the operator’s own account, the one that owns the channel. There is no sign-in for anyone else, no multi-user installation, and no path by which a visitor to this site or a viewer of the channel can grant it access to their account. It cannot read any other person’s YouTube account, watch history, subscriptions, or personal information.

The pipeline requests only these authorisation scopes:

  • youtube.upload — to upload the channel’s own videos and set their title, description, and privacy status.
  • youtube.readonly — to read back the status of videos it has itself uploaded, so a rejected or claimed upload is noticed rather than assumed successful.

It also reads the channel’s own performance figures from the YouTube Analytics API, scoped to channel==MINE. Those reports are aggregate per-video numbers — views, estimated minutes watched, and average view percentage. They identify videos, not viewers, and contain no personal information about anyone who watches the channel.

What is stored, where, and for how long

  • OAuth tokens. The access and refresh tokens issued to the operator’s own account are written to a single file on the operator’s computer, with owner-only file permissions, in a directory excluded from version control. They are never sent to this website, never stored on this website’s servers, and never shared with anyone.
  • Video records. Video IDs, titles, descriptions, and publication status for videos the pipeline itself uploaded, kept so the same video is not published twice.
  • Aggregate channel metrics. The per-video figures described above, kept in a local file to track how the channel is performing over time.

No YouTube API data is retained for longer than 30 calendar days without being refreshed from the API. Data that is not refreshed within 30 days is deleted. Nothing obtained through YouTube API Services is sold, rented, or disclosed to any third party, and none of it is used to build a profile of any person.

Cookies and device storage

The pipeline is a command-line program with no browser interface. It sets no cookies and stores nothing on any visitor’s device. Cookie behaviour on this website is covered by the analytics section above; cookie behaviour on youtube.com is governed by the Google Privacy Policy linked above.

Third-party content and advertising

The pipeline serves no advertising and embeds no third-party advertising or content network of its own. Advertising shown alongside videos on YouTube is served by YouTube, not by this operator.

Data deletion

Revoking access. The authorising account can withdraw the pipeline’s access at any time from the Google security settings page — https://myaccount.google.com/permissions (also reachable at security.google.com/settings/security/permissions). Revoking access immediately stops the pipeline from reaching the YouTube API.

What happens on revocation. When access is revoked, or when the pipeline’s authorisation can no longer be verified, all data obtained from YouTube API Services is deleted from the operator’s storage within 7 calendar days. That includes the stored tokens, the video records, and the aggregate metrics.

Requesting deletion. A request to delete data held about you is actioned within 30 days of receipt. Because the pipeline only ever holds data belonging to the single authorising account and aggregate figures about the channel’s own videos, a request from any other person will normally be answered by confirming that no data about them is held.

Deleting a published video. Deleting a video on YouTube removes it from YouTube. Its record is dropped from the pipeline’s local files at the next run, and any page on this site referring to it is removed at the next deployment.

Questions, complaints, and deletion requests

A contact address for privacy questions and deletion requests is not yet published on this page. Until it is, the working route for withdrawing access and triggering deletion is the Google security settings page linked under Data deletion above, which requires no contact with the operator and takes effect immediately.

Changes to this policy

This policy is part of the site’s source and changes only through a deployment, so its history is the site’s deployment history. A material change to how YouTube API data is handled will be reflected here at the same time as the change itself.

See also the Terms of Service and the editorial policy.