Legal

Privacy Policy

This policy explains what 15sec collects, why we use it, who processes it, and the choices available to users and visitors.

Last updated: September 13, 2026

Questions or requests? Email support@15sec.app.

1. Scope and who we are

15sec (“15sec,” “we,” “us,” or “our”) provides tools that help YouTube creators compare video variants, route viewers, review performance, and learn from experiment results (the “Service”). This Privacy Policy applies to the Service, our website at 15sec, and related support communications.

15sec is the controller of personal information described in this policy, except where a service provider acts as a separate controller under its own terms. Contact us at support@15sec.app.

2. Privacy at a glance

  • We use Google sign-in and, only when you choose to connect a channel, YouTube API Services.
  • We use connected-channel data to provide experiments, analytics, retention comparisons, and any video upload or publishing action you expressly enable.
  • We do not sell personal information or use Google or YouTube user data for advertising.
  • We use essential authentication, security, preference, smart-link routing, product analytics, and reliability technologies. We do not use behavioral advertising trackers or session replay.
  • You can disconnect YouTube access, revoke Google permissions, or delete your 15sec account.

3. Google and YouTube data

15sec uses YouTube API Services. By using features that rely on YouTube, you are also subject to the YouTube Terms of Service. Google’s handling of information is described in the Google Privacy Policy.

Information we access

Depending on the permissions you grant and the features you use, we may access and store:

  • your Google account identifier, email address, display name, and profile image;
  • YouTube channel identifiers, title, handle, and channel image;
  • video identifiers, URLs, titles, descriptions, thumbnails, duration, publication time, and privacy status;
  • YouTube Analytics data such as views, watch time, average view duration, average percentage viewed, audience-retention data, likes, comments, shares, and subscriber changes;
  • the OAuth permissions you granted and an encrypted or otherwise access-controlled refresh token used to maintain the connection; and
  • when you request background uploads or enable auto-publish, the additional authorization needed to upload your selected video variants and thumbnail or publish the selected winning video on your channel.

How we use Google and YouTube data

We use this data to authenticate you, connect and display your channel, validate eligible videos, configure and operate experiments, route viewers, calculate and present comparisons, generate creator-facing insights, prevent abuse, troubleshoot the Service, and carry out the video uploads or optional publishing instruction you select. We do not use this data to serve advertisements, build advertising profiles, determine credit or lending eligibility, or sell it.

Background upload permission lets 15sec upload the variants you ask us to create from your files to your connected YouTube channel. Winner auto-publish is a separate choice that lets 15sec change the selected winning video from unlisted to public. You can use background uploads without enabling auto-publish.

15sec’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting and revoking access

You can disconnect a channel from the Channels page in the Service. You can also review or revoke 15sec’s access at any time through your Google security permissions. Disconnecting in 15sec immediately starts revocation of the Google token and permanent deletion from our active systems of the connected channel's YouTube API data, experiments, analytics, Learnings, creator page, routing configuration, and temporary files. Disconnecting 15sec does not delete your videos, channel, or other data stored by YouTube. If you revoke access through Google, we periodically verify authorization at least every 30 days and delete the related stored YouTube API data as soon as we detect that access can no longer be refreshed, keeping the maximum detection-and-deletion window within 30 calendar days of revocation.

4. Information we collect

Account and profile information

We collect your email address, name, profile image, account identifier, authentication records, account settings, and subscription status when you create or use an account.

Creator content and experiment information

We collect the content and instructions you submit, including uploaded source videos, alternate opening clips, thumbnails, upload metadata, short opening clips extracted from your uploads for requested analysis, variant names, experiment settings, smart-link configuration, routed-view counts, results, and generated learnings. When you use background creation, we temporarily store your source files and composed variants in private storage so processing and the requested YouTube uploads can continue after you close your browser. We send only the extracted opening clips for the requested AI analysis; complete source videos and variants are not sent for that analysis.

Billing information

Stripe processes payment-card and payment-method details directly. We receive limited billing information such as your Stripe customer and subscription identifiers, plan and renewal dates, legacy trial state, payment or subscription status, and cancellation status. We do not receive or store full payment-card numbers.

Smart-link visitor and technical information

When someone visits an experiment test link, we process a random visitor identifier, assigned variant, routing totals, and ordinary request information needed to deliver and secure the link. Our hosting and infrastructure providers may process IP address, browser or device information, timestamps, requested URLs, and diagnostic or security logs. We do not require smart-link visitors to identify themselves.

Product usage, extension, and reliability information

We collect limited information about how the website and Chrome extension are used so we can understand feature adoption, improve the creator workflow, and monitor reliability. This may include page views, explicitly named feature actions, timestamps, app or extension version, coarse browser version, workflow mode, variant count, performance measurements, and categorized failures. Signed-in product events are associated with an internal account identifier, not an email address sent as an analytics property.

The extension uses a randomly generated install identifier and may use a separate random identifier to pair milestones within one creator workflow. It may report those major milestones, their elapsed time, whether the test link was copied, and which built-in caption-template identifier was selected. It does not include caption text, video or channel identifiers, titles, filenames, URLs, page content, credentials, email addresses, support diagnostics, or raw error text in extension product telemetry. Website product analytics uses page-view, performance, reliability, and deliberately instrumented events; automatic click or form capture and session recording are disabled. Analytics page events remove query strings, URL fragments, referrer paths, and dynamic creator, experiment, and smart-link path segments before delivery. Reliability events use categorized error codes rather than raw exception messages or stacks.

Viewer notification information

If you ask to receive early-access alerts from a creator, we collect your email address, the creator you followed, subscription and unsubscribe status, consent records, and email delivery, link-click, or suppression events. Link-click analytics records one event per message without sending the destination link, recipient address, or email content to our product-analytics system. Your subscription becomes active when you submit the clearly labeled notification form. You can unsubscribe from a creator or from all 15sec notification email at any time.

Communications

We collect the contents of support requests, feedback, and other communications you send us, together with related contact information.

5. How we use information

We use information to:

  • provide, personalize, maintain, and improve the Service;
  • authenticate users, maintain sessions, and administer connected accounts;
  • create experiments, operate routing, display analytics, and generate requested insights;
  • process subscriptions and provide billing support;
  • communicate about the Service, including operational and security notices;
  • detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms;
  • comply with law and enforce or defend legal rights; and
  • create aggregated or de-identified statistics that do not reasonably identify a person or channel.

6. AI-assisted analysis

If you request AI-assisted video analysis, we may send extracted opening clips and related instructions to Google’s generative AI services to produce segment descriptions, attributes, summaries, or creator-facing insights. We store the resulting analysis with your experiment. We delete temporary processor-hosted files after processing and retry cleanup for completed or expired uploads. Temporary files also expire within the provider’s 48-hour file window.

15sec does not use your videos or Google user data to train a general-purpose model. Our production configuration is intended to use provider terms and settings that do not permit customer content to be used for general model training. AI output can be inaccurate and should be reviewed before you rely on it.

8. How we disclose information

We disclose information only as needed for the purposes described in this policy:

  • Supabase provides authentication, database, and file storage infrastructure.
  • Google and YouTube provide sign-in, YouTube APIs, connected-channel services, background video processing, and AI-assisted analysis.
  • Stripe processes payments, subscriptions, invoices, and billing-portal functions.
  • Vercel provides application hosting, delivery, operational logging, and routing configuration.
  • Upstash provides short-lived routing counters and related data infrastructure.
  • Postmark processes signup welcome messages, creator experiment alerts, delivery and link-click events, and email suppression requests.
  • PostHog processes product-usage, performance, and reliability events used to understand adoption and improve the Service. We disable session replay and advertising use.
  • Professional advisers and authorities may receive information when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish or defend legal claims.
  • Information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law and continued protection of the data.

Providers process information under their contracts with us and, where applicable, their own privacy terms. We do not authorize service providers to use Google user data for advertising.

9. No sale or targeted advertising

We do not sell personal information. We do not share personal information for cross-context behavioral advertising and do not use Google or YouTube user data for personalized advertising. If those practices change, we will update this policy and provide any legally required choices before doing so.

10. Cookies and local storage

We use the following technologies:

  • Authentication storage to keep users signed in and protect account sessions.
  • Smart-link assignment cookies containing a random visitor identifier and assigned variant, generally for up to 10 days, so a visitor receives a consistent experiment experience and views can be routed correctly.
  • Preference and session storage for drafts, interface settings, navigation state, troubleshooting information, and a creator-slug-only marker that lets a returning browser remember it already requested that creator’s notifications. This marker does not contain the viewer’s email address.
  • Product analytics storage containing a random analytics identifier used to connect page views and deliberately instrumented actions across browser sessions. It is not used for advertising or cross-site behavioral profiling.
  • Extension local storage for a random install identifier and a bounded queue of product events waiting for an authenticated delivery opportunity. This queue does not contain the creator’s video metadata or support diagnostic timeline.
  • Infrastructure logs used for delivery, reliability, fraud prevention, and security.

Because we do not currently sell personal information or use cross-context behavioral advertising, the Service does not respond differently to browser “Do Not Track” signals. Where legally required, we will honor applicable opt-out preference signals, such as Global Privacy Control, for the activities they cover. Blocking essential storage may prevent sign-in or smart-link features from working.

11. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described here, including providing the Service, complying with legal and accounting obligations, resolving disputes, and protecting the Service. Retention depends on the data:

  • account and experiment data is generally kept while your account is active and removed or de-identified after account deletion, subject to limited backups and legal requirements;
  • YouTube access tokens are kept only while the channel is connected and are revoked and deleted when you disconnect access;
  • while a channel remains connected, we verify its authorization and whether stored source videos still exist at least every 30 days; information for deleted source videos is removed or scrubbed;
  • disconnecting a channel or deleting your 15sec account permanently removes its stored YouTube API data from active systems as soon as possible; Google-side revocations are checked and removed within 30 calendar days of revocation;
  • uploaded source files, composed variants in our temporary storage, and processor-hosted AI files are temporary and scheduled for deletion after processing completes or is abandoned. Derived analysis may remain with the experiment. Videos uploaded to your YouTube channel remain there until you remove them through YouTube;
  • smart-link assignment cookies and routing counters generally expire after 10 days; and
  • pending extension telemetry is limited to 200 local events and is discarded after 30 days; accepted product and reliability telemetry is retained only as long as reasonably needed to analyze adoption, troubleshoot reliability, and improve the Service; and
  • billing, fraud-prevention, security, and transaction records may be retained longer where needed for legal, tax, audit, or dispute purposes.

Deletion from active systems may not immediately remove other, non-Google information from encrypted backups. Backup copies are isolated, expire on a limited cycle, and are not restored except for disaster recovery. Deleted Google or YouTube Authorized Data is not restored to active use.

12. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, transport encryption, private storage for uploaded content, and server-side handling of YouTube refresh tokens. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Protect your account credentials and notify us promptly of suspected unauthorized use.

13. Your choices and privacy rights

Depending on where you live, you may have the right to request access to, correction of, deletion of, or a portable copy of personal information; to restrict or object to certain processing; to withdraw consent; and to appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

You can update certain choices in the Service, disconnect a channel on the Channels page, revoke Google access through Google, and delete your account from Account settings. You may also email support@15sec.app. We may verify your identity and authority before completing a request. An authorized agent may submit a request where local law permits. We will respond within the period required by applicable law.

EEA and UK users may complain to their local data-protection authority. California residents may review information about state privacy rights at the California Attorney General’s website.

Additional California notice

In the preceding 12 months, we may have collected the following California categories of personal information: identifiers; customer records such as account and billing-contact information; commercial information such as subscription status; internet or electronic-network activity; audio, visual, and electronic content you submit; professional information you choose to provide; and inferences reflected in experiment insights. Sources include you, smart-link visitors, Google and YouTube at your direction, payment and infrastructure providers, and automatic use of the Service. We use and disclose these categories for the business purposes described in Sections 5 and 8.

We have not sold or shared these categories for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics about consumers. Where California law applies, residents may request to know, access, correct, or delete information and may appeal or use an authorized agent as permitted by law.

Automated processing

The Service automates routing and may generate experiment insights, but it is not intended to make decisions that produce legal or similarly significant effects about individuals. Contact us if you have a concern about an automated result.

14. International transfers

15sec and its providers may process information in the United States and other countries that may have different data-protection laws from your country. Where required, we rely on recognized transfer mechanisms and contractual protections for international transfers.

15. Children

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child provided information to us, contact us so we can investigate and delete it as appropriate.

16. Third-party services and links

The Service links to and interoperates with third-party services. Their privacy practices are governed by their own policies. This policy does not apply to a creator’s YouTube page, to YouTube viewers after they are redirected, or to other third-party sites and services you choose to use.

17. Changes to this policy

We may update this policy as the Service or law changes. We will post the revised version here and change the “Last updated” date. If a change materially affects how we use information, we will provide additional notice or seek consent when required. Prior versions may be requested by contacting us.

18. Contact us

For privacy questions, requests, or complaints, email 15sec at support@15sec.app. Please include enough information for us to understand and respond to your request.