POLICIES

Privacy

Data use for the operator YouTube integration, alongside information about other services still in preparation.

Privacy

YouTube data for FLyLOFi Control operators

FLyLOFi Control uses YouTube API Services to verify the FLyLOFi channel, read live-broadcast status and chat, and send replies approved by an operator. This Google OAuth connection is restricted to authorized operators. It is not public listener registration or sign-in.

The integration accesses channel, video and chat IDs, chat display names, messages and timestamps, and operator access and refresh tokens. We do not receive or store your Google password.

Tokens are stored in a restricted file on our private VPS. Recent chat is cached in memory. Reply drafts, message IDs, delivery states and timestamps, and hashes of viewer IDs are stored in a private database to prevent duplicate sending and review operations. Access is limited to authorized operators who need it for these functions.

A reply is sent to YouTube only after an operator explicitly approves it. Google and YouTube data is used only to connect and operate the channel: we do not sell it, use it for advertising, or train AI models with it. The brand’s music and image creation is separate from this data.

You can revoke access from your Google Account permissions page. Revocation stops Google access but does not automatically delete records already stored by us. Contact the operator at the address below to request deletion of tokens and related records, or to ask questions or raise privacy concerns.

For public listeners, enabling a YouTube player connects to Google/YouTube, which may receive device information and use cookies under its own policies. Listening does not require authorizing the Control Google OAuth connection.

Other services still in preparation
The sections below outline future listener accounts, commerce and other services. They do not replace the operator YouTube disclosure above or mean those services have launched.

Before collecting data through accounts, the shop, newsletters, or contact tools, we must explain actual data use. We will not invent a controller or service providers.

01

Who is responsible

The final notice must identify the real data controller, address, working contact channel, and a data-protection contact where required by law.

Information to confirm
  • Operator name and status
  • Channel for questions and rights requests
02

What data and why

We must map data separately for listening, accounts, orders, contact, and analytics before stating categories, purposes, and legal bases for each activity.

Information to confirm
  • Data categories and sources
  • Purposes and legal basis by activity
03

Sharing and retention

Once actual audio, payment, delivery, and analytics providers are chosen, we can state recipients, destination countries, safeguards, and real retention periods.

Information to confirm
  • Providers and processing locations
  • Retention periods and deletion process
04

Your rights

Rights-request and identity-verification channels will be published before personal-data collection that needs those processes begins.

Read the data-rights framework ↗

Before publishing an operative version, we must add the operator, effective date, real contact channel and workable processes, then review them against applicable law.

Back to Help Center