1. About this service
Philistinie Social Studio is a private, first-party, owner-operated tool used only by its owner for the owner's social accounts. It is not offered to public users, third-party clients, or other channel owners. It manages the owner's Instagram account @philistinie, TikTok account @always_philistinie, YouTube channel @Philistinie (channel ID UC4ezzY2TsK5CQmwxIbLh_DA), and X account @philistinie2. It helps the owner review content performance, organize posts, review engagement, and prepare publishing or moderation actions for explicit approval.
2. YouTube API Services and authorization
The studio uses YouTube API Services. Its reader and writer credentials are separate. The reader is used for authorized channel, content, comment, and playlist review through the exact https://www.googleapis.com/auth/youtube.readonly scope, and for the owner's private channel-performance reporting through the exact https://www.googleapis.com/auth/yt-analytics.readonly scope. The writer requests the exact https://www.googleapis.com/auth/youtube.force-ssl scope so that a separately approved action can manage the owner's @Philistinie resources. A reader result is never treated as permission to write.
Google explains its own handling of information in the Google Privacy Policy. Use of YouTube API Services is also governed by the YouTube API Services Terms of Service.
3. Information the service may process
- Authorized platform account information such as account or channel ID, username or handle, account type, profile information, and available publishing quota.
- Owned posts, captions, media metadata, permalinks, timestamps, and performance insights.
- Comments, replies, conversations, and messages that a platform API makes available to the authorized owner.
- YouTube API Data for @Philistinie, including owned videos and Shorts, titles, descriptions, thumbnails, visibility and publication status, playlists and playlist items, comments and replies, and authorized performance statistics such as views, watch time, and engagement.
- Local editorial plans, action previews, approval records, and audit evidence needed to prevent duplicate or unauthorized actions.
- OAuth access tokens and app credentials required to connect to the platforms. These credentials are stored separately from public content in a protected owner-only environment. The service never asks for or stores a Google or YouTube password.
4. How information is used
Information is used only to:
- display owned-account analytics and engagement for review;
- organize content, captions, series, and publishing plans;
- prepare and verify specifically approved publishing actions for the exact destination account;
- review comments and messages, identify repeated engagement patterns, and prepare possible owner responses;
- manage YouTube videos, metadata, thumbnails, playlists, comments, and replies only when the owner has separately approved the exact action;
- protect the account through identity checks, audit records, and safe retries.
5. Human approval and automated decisions
The service does not publish, reply, delete, hide, moderate, or send messages merely because a schedule or trend is detected. Each remote action requires a human-readable, platform-specific preview and explicit approval from the account owner. The service does not auto-post.
6. Sharing, advertising, and device access
The service does not sell personal information, build advertising audiences, show third-party advertisements, or provide API Data to data brokers. Google user data is not used to train generalized or personalized artificial-intelligence or machine-learning models. Information is transferred only to infrastructure needed to operate the private service and to the applicable platform, including Google/YouTube, when an authorized API request is made. It is not disclosed to another person or organization for advertising, resale, credit, lending, or any unrelated purpose. The public policy pages do not use YouTube API Data and do not place advertising or cross-site tracking cookies.
7. Security and data-protection mechanisms
The studio uses concrete technical and organizational safeguards to protect Google user data against unauthorized access, alteration, loss, disclosure, or destruction:
- Google OAuth and YouTube API requests are transmitted only over HTTPS/TLS. The private dashboard is bound to a loopback interface and is reached through an encrypted SSH tunnel rather than exposed directly to the public internet.
- The dashboard requires owner authentication and protects state-changing forms with a session-bound anti-CSRF token.
- OAuth tokens and client secrets are separated from application source code and from the dashboard web process. They are stored in operating-system owner-only files with restrictive permissions. The dashboard receives only non-secret connection-status indicators.
- YouTube API Data is stored in an owner-only database on a private host with restrictive operating-system permissions. It is not stored in or served by this public policy site.
- Provider responses and audit records are sanitized before storage to remove credentials, authorization values, and signed-URL secrets.
- Remote writes run in a separate, restricted one-shot worker only after an exact action preview, explicit approval, a second confirmation, a one-use execution lease, and a destination-identity check. The dashboard web process cannot make provider calls.
Access is limited to the owner and is removed or credentials are rotated if compromise is suspected. These safeguards are reviewed when the service or its platform integrations change. No storage or transmission method can be guaranteed completely secure.
8. Storage and retention
Credentials and message content are kept in access-controlled owner-only storage. Audit records are retained to document approvals and prevent unsafe duplicate actions.
YouTube Authorized Data other than eligible analytics or statistical data is deleted or refreshed within 30 calendar days. Authorized YouTube analytics and statistical data may be retained while needed for the owner-approved purpose, but authorization and source status are rechecked at least every 30 days. Temporarily stored non-authorized YouTube API Data is deleted or refreshed within 30 calendar days. The studio uses reasonable efforts to keep displayed YouTube API Data current and labels historical snapshots with their collection time.
9. Revocation and deletion
Information is retained only while needed for account management, audit, security, or legal obligations. The owner can revoke platform access at any time. A verified direct deletion request or an owner-initiated revocation through the private studio causes the YouTube credential and related stored Authorized Data to be deleted as soon as possible and no later than seven calendar days.
YouTube/Google authorization can also be revoked through the Google security settings page. The studio performs periodic authorization checks at least every 30 days. If a Google-settings revocation is detected, related YouTube API Data and credentials are removed as soon as possible and no later than 30 days after revocation. See the data deletion instructions for the complete removal process.
10. Contact and changes
Questions, complaints about privacy practices, or deletion requests can be sent directly to the owner at philistinie@gmail.com or by direct message to the professional Instagram account @philistinie. This policy may be updated when the service or applicable platform rules change. The effective date shown on this page identifies the current version.