Privacy Policy
How the Iké stream-management tooling accesses, uses, stores, and protects data from the YouTube channels it operates.
Effective 2 July 2026 · Bells & Pixels
Iké is stream-management tooling built by Bells & Pixels. It operates an always-on YouTube live channel on the channel owner's behalf: it creates, configures, transitions, and ends scheduled live broadcasts, keeps their metadata current, and reads channel analytics so the operator can see how each broadcast performed. This policy explains what data the tooling touches through Google APIs, why it needs each piece, and how it is kept safe. It covers the Google OAuth application presented on the consent screen as the Bells & Pixels Iké channel connect application (hosted in the bp-ike Google Cloud project) and any Bells & Pixels application that requests the same YouTube scopes.
Who this policy is for
This policy is for the YouTube channel owner who authorizes Iké to manage their channel, and for anyone reviewing how the tooling handles Google user data. Iké is not a consumer product and is not offered to the general public: it is operated for a specific channel under a one-time authorization the owner grants to Bells & Pixels.
Information we access through Google APIs
When the channel owner authorizes Iké, the owner grants exactly two Google OAuth scopes, and no others. The tooling accesses only what those scopes allow, and only for the one channel selected during consent.
youtube.force-ssl - manage live broadcasts on the authorized channel
- Create, configure, transition, and end the channel's own scheduled live broadcasts and their bound live streams.
- Update the title, description, tags, and category of the broadcasts the tooling creates.
- Read and set the advertising-monetization status of the tooling's own live broadcasts, where the channel is eligible.
yt-analytics.readonly - read channel analytics
- Read-only reporting for the authorized channel (for example views, traffic sources, and average view duration) so the operator can review how each broadcast performed. This scope cannot change anything on the channel.
How we use this information
- To run the channel's scheduled 24/7 live programming, which is the sole function of the tooling.
- To keep each broadcast's metadata correct and, where eligible, to keep advertising monetization enabled on the broadcasts the tooling creates.
- To show the operator read-only performance insights for the channel's broadcasts.
We do not use Google user data for advertising of our own, for profiling, for training generalized artificial-intelligence or machine-learning models, or for any purpose beyond operating the authorized channel.
Google API Services User Data Policy. Iké's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Iké's use of YouTube data also complies with the YouTube API Services Terms of Service and the YouTube Terms of Service, and Google's Privacy Policy applies to Google's own handling of the data.
How we store and protect it
- Server-side only. The authorization token that lets the tooling act on the channel is installed on the Bells & Pixels streaming server. It is never placed in a browser or a client device, and never emailed or transmitted in plaintext.
- Encrypted at rest. Studio session credentials held by the control plane are encrypted at rest with authenticated encryption (Fernet, AES-128-CBC with HMAC-SHA256). The encryption key is supplied from outside the credential directory, so ciphertext and key are not stored together.
- Authenticated internal traffic. Communication between the Bells & Pixels control plane and the streaming node is authenticated with HMAC-SHA256, and management interfaces are restricted to a private network.
- Least privilege. The tooling requests only the two scopes above and acts only on the single channel the owner selects at consent. It does not access the owner's Google profile, email, contacts, Drive, other channels, or anything outside YouTube.
Information we do not collect, sell, or share
- We do not sell Google user data, and we do not share it with third parties, advertisers, or data brokers.
- We do not aggregate the channel's data with data from other channels, and we do not resell analytics.
- We do not collect the channel owner's Google account profile, email contents, contacts, Drive, or Gmail. Those are outside the requested scopes.
- Humans do not read the channel's Google data except where the owner requests support, where required for a security investigation, or where required by law.
Data retention and deletion
Iké keeps Google user data only for as long as needed to operate the authorized YouTube channel, maintain the scheduled live programming, provide performance reporting to the operator, protect the tooling, and comply with applicable legal or platform obligations.
Authorization tokens. The OAuth token used to manage the channel is retained only while the channel owner keeps Iké authorized. If the owner asks Bells & Pixels to disconnect Iké or delete stored data, Bells & Pixels will revoke or remove the stored token and delete related stored Google API data as soon as reasonably possible and no later than 7 calendar days after the request.
If the owner revokes access directly through the Google Account permissions page, Iké can no longer access the channel. Bells & Pixels periodically checks whether authorization remains valid. If authorization has been revoked or the token can no longer be refreshed, Bells & Pixels will delete the stored token and related stored Google API data as soon as reasonably possible and no later than 30 calendar days after the revocation is detected or required to be detected under applicable YouTube API policies.
Broadcast and stream-management records. Iké may retain records needed to operate and troubleshoot the channel, such as broadcast IDs, stream IDs, titles, descriptions, tags, schedule times, transition history, configuration records, and operational status logs. These records are retained while Iké is authorized and operating the channel. They are deleted with the related Google API data after authorization is withdrawn, except for limited security, legal, or audit records that Bells & Pixels is required or permitted to retain.
YouTube analytics and performance data. Iké may retain YouTube Analytics API data and related channel performance reports while the channel remains authorized so the operator can review broadcast performance over time. Bells & Pixels verifies at least every 30 calendar days that Iké remains authorized to access retained YouTube API data. If authorization is withdrawn, retained YouTube analytics and performance data associated with that authorization will be deleted as described above.
Temporary cached API data. Any temporary cached YouTube API data that is not covered by the longer retention rules above is deleted or refreshed within 30 calendar days.
Backups and logs. Deleted data may remain for a limited time in encrypted backups or security logs until those backups or logs are overwritten in the ordinary course. Backup copies are not used for active channel operations and will be deleted, overwritten, or made inaccessible according to the applicable backup cycle.
Deletion requests. The channel owner may request deletion of retained Iké operational data by contacting privacy@bells-and-pixels.com. Deleting data stored by Iké does not delete data stored by YouTube. To delete or modify data on YouTube itself, the owner must use YouTube Studio, another authorized YouTube tool, or Google account controls.
Your controls
The channel owner keeps full control of the channel and of this authorization at all times:
- Revoke access at any time at myaccount.google.com/permissions by removing the Bells & Pixels application ("Iké channel connect"). Revocation takes effect immediately; no further API access is possible after it.
- Review activity on the channel directly in YouTube Studio.
- Request deletion of retained operational data by contacting us.
Children's privacy
Iké is tooling for operating a YouTube channel and is not directed to children. It does not knowingly collect personal information from children.
Changes to this policy
If this policy changes, the updated version is posted at this address with a revised effective date. Material changes affecting how the channel owner's data is used will be communicated to the owner directly.
Contact
Questions about this policy, or a request to delete retained data, can be sent to privacy@bells-and-pixels.com.