Legal
Privacy Policy
Last updated: May 2026
What we collect
When you sign in with Google, we receive your display name and email address from Google. We use these only to identify your account — we never read your Gmail, Google Drive, or any other Google service unless you explicitly connect YouTube playlists (which requires a separate permission).
What we store
The following data is stored in our database (Supabase / PostgreSQL):
- Your account profile (name, email, preferences)
- YouTube video URLs you add to your inbox
- AI-generated summaries, verdicts, and key points for those videos
- Collections and tags you create
- Your watch queue order
How we use your data
Your data is used solely to provide the Too Much Yap service — showing you your video inbox, storing your triage decisions, and syncing across devices when you’re signed in. We do not sell your data. We do not use it for advertising.
AI processing
Video summaries are generated by Google Gemini (via Google AI Studio). When you request a summary, we send the YouTube video URL (and optionally a transcript) to Gemini for processing. This data is subject to Google’s Privacy Policy. We do not store the raw video data — only the AI-generated output.
Third-party services
- Supabase — database and authentication infrastructure
- Google — OAuth sign-in and Gemini AI analysis
- Vercel — hosting and serverless functions
Data retention
Your data remains in our database as long as your account is active. You can delete your account and all associated data at any time by emailing hello@toomuchyap.com. We will process deletion requests within 30 days.
Security
Data is encrypted in transit (HTTPS/TLS) and at rest. Access to the database is controlled by Supabase Row Level Security — each user can only read and write their own data. BYO API keys (if you provide your own Gemini key) are stored encrypted and never logged.
Contact
Questions about this policy? Email us at hello@toomuchyap.com.