Privacy Policy

Effective Date: August 2025

1.1 Data Collection

We collect the following types of data when you use our app:

Personal Data:

When you log in via OAuth (Google for YouTube or Reddit login), we collect OAuth tokens that enable us to access user-approved data from YouTube and Reddit. We do not collect your email, username, or other personal account data. We will only store your OAuth token temporarily to provide functionality during your session.

Content Data:

This includes any content you brows, such as YouTube video IDs, titles, and transcripts, as well as Reddit post content (comments and titles) that you authorize for summarization. This data is used solely to generate summaries and is not shared with any third parties. We keep this data for 30 minutes only.

Usage Data:

We collect the number of requests you perform to summarize the content. Other than that, we do not collect any other usage data.

Device Information:

We may collect information about your device (e.g., device type, operating system version) to help with troubleshooting and ensure compatibility with the latest features.

1.2 Purpose of Data Use

The data we collect is used solely for the following purposes:

  • Content Summarization: To generate AI-powered summaries of user's browsed YouTube videos and Reddit posts.
  • App Functionality: To enable features like OAuth login, data deletion, and content management.

1.3 Data Retention

Content Summaries:

User-generated content and AI-generated summaries are stored for 30 minutes. If a user disconnects their account or requests deletion, all associated data be deleted from our servers immediately.

OAuth Tokens:

OAuth tokens are stored temporarily to facilitate session-based authentication with YouTube and Reddit. Tokens are removed after the session ends or upon user account disconnection.

Personal Data:

We do not retain any personally identifiable data unless it is necessary for providing services (e.g., customer support). Data will be deleted if it is no longer needed for functionality or upon user request.

1.4 Sharing and Third Parties

Third-Party Service Providers:

We may use third-party services to help us operate the app, such as Firebase for crash analytics or Google Analytics for usage statistics. These services are only given access to anonymized data and are bound by strict confidentiality.

YouTube and Reddit APIs:

Data is shared with YouTube and Reddit APIs exclusively for the purpose of retrieving video and post content the user has authorized via OAuth. These services are governed by their own privacy policies and terms of service.

We do not sell any personal or content data to third parties for advertising or other purposes.

1.5 User Rights

Right to Access:

You can request access to the data we hold about you at any time, including details about how your content is being processed.

Right to Deletion:

You have the right to delete your account, including any data associated with it (summaries and OAuth tokens). To do so, contact us directly at shapaale@gmail.com.

Right to Correction:

If any personal data we hold about you is incorrect or incomplete, you have the right to have it corrected.

Right to Withdraw Consent:

You can withdraw your consent for data collection at any time.

1.6 Security

We use industry-standard encryption methods to protect your data. Specifically:

  • OAuth Tokens: Stored securely in the device's keychain or secure storage.
  • Data Transmission: All data exchanged between your app and our servers is encrypted using HTTPS.

We continually monitor for potential vulnerabilities and apply security updates to our infrastructure to ensure user data is protected from unauthorized access.

API & OAuth Disclosure

OAuth Login

We use OAuth 2.0 for YouTube and Reddit API authentication, which allows us to fetch user-approved data.

  • YouTube OAuth Scopes: youtube.readonly (Video titles, metadata, and transcripts).
  • Reddit OAuth Scopes: Access only to authenticated user's public posts and comments.

Data Sharing and Consent

You must authorize access to your YouTube or Reddit account for content to be summarized. Data is only used for summarization and not shared with any other parties.

Compliance with API Terms

We comply with all YouTube and Reddit API terms of service and ensure that content used by the app is processed only with user consent.

Compliance with Regulations

GDPR:

If you are located in the EU, you have additional rights under the General Data Protection Regulation, including the right to request access to your personal data, request data deletion, and opt-out of processing.

PDPA:

If you are located in Singapore, we comply with the Personal Data Protection Act (PDPA) and ensure that your data is protected and processed in accordance with Singapore's privacy laws.

Changes to the Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, legal requirements, or technical developments. We will notify you of any significant changes via the app or email, and you may be required to accept the updated terms.

Contact Information

For questions or requests regarding this Privacy Policy, please contact us at:

Email: shapaale@gmail.com

Website: summify.com