What this policy covers
Picks is a product operated by Intelligent Edge Solutions LLC. This Privacy Policy applies to Picks’ websites, authenticated dashboard, public link tools, smart-link redirects, reports, APIs, and related services (together, the “Service”). Picks helps creators and publishers inspect, organize, route, monitor, and update product links.
This policy describes the information we process through Picks, why it is used, when it is shared, how long it is kept, and the choices available to you. It does not govern the privacy practices of Amazon, Google, YouTube, or another site you choose to visit.
How Picks uses YouTube API Services
Picks uses YouTube API Services for its channel-audit and YouTube Optimizer features. Use of those features is also governed by YouTube’s Terms of Service and Google’s Privacy Policy.
Data accessed with your authorization
When you connect a channel, Picks requests the https://www.googleapis.com/auth/youtube.force-ssl permission. Google describes this permission as allowing an application to view, edit, and permanently delete YouTube videos, ratings, comments, and captions. Picks requests it because the YouTube Data API requires this scope to read a connected channel’s video metadata and update video descriptions. Picks does not use it to delete videos, change video visibility, publish comments, manage ratings, or manage captions.
Picks accesses the selected channel’s ID, title, handle, uploads-playlist ID, video IDs, video titles, descriptions, publication dates, privacy-status labels, and API version markers. A short-lived access token is used in server-to-server requests and is not stored. The refresh token is stored using authenticated encryption so the connection can continue until you disconnect it or Google revokes it. Picks never asks for or stores your Google or YouTube password.
How the data is used
- Import current descriptions into your private review session.
- Find supported Amazon links and show proposed Picks replacements and disclosure text.
- Re-read descriptions immediately before a confirmed publish and skip videos whose content changed after review.
- Update only descriptions you expressly confirm. Picks preserves the current title, category, tags, language fields, and privacy status.
- Provide a conflict-safe rollback for descriptions Picks successfully updated.
Imported descriptions are processed to produce the review shown to you and are not retained by the channel-import flow. If you confirm direct publishing, the original and proposed descriptions, video IDs, and video titles are stored as workspace-bound encrypted rollback records for no more than 30 days. Picks does not sell YouTube API Data, use it for advertising, combine it across unrelated channel owners, or expose authorized data to anyone other than the authorizing workspace and its approved members.
Picks’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or secure the user-facing features described here; it is not used to determine creditworthiness or to train generalized artificial-intelligence or machine-learning models.
Public channel reports
The public channel-audit tool uses YouTube API Services to read public channel and video metadata without connecting to a user’s Google Account. Its report stores the supplied channel identifier, public channel identity, video references, extracted public links, and point-in-time findings for up to 30 days. Shared reports are unlisted, redacted, and not refreshed when viewed.
Other information Picks processes
Account and workspace information
Picks receives a stable user or organization identifier and session information from Clerk, our authentication provider. Picks does not receive your Clerk password. We process workspace names, account settings, affiliate tracking IDs, links, destinations, groups, tags, custom domains, alert addresses, integration settings, API-key metadata, and content you submit to operate the Service.
Smart-link and usage information
When someone follows a Picks smart link, the application records the event time, Cloudflare-provided country code, destination, routing reason, marketplace, device category, browser and operating-system category, language, referrer hostname, selected A/B variant, bot classification, and request latency. Picks’ click tables do not store the visitor’s raw IP address. Cloudflare may process network information as part of providing security, delivery, and operational logging.
Dashboard product analytics
Picks uses PostHog on the dashboard and account screens to record page views, a pseudonymous browser and session identifier, and the stable Clerk user identifier after sign-in. Query strings, URL fragments, and identifiers embedded in dashboard paths are removed before an event is sent. Picks disables PostHog form and element autocapture and session replay, and does not send form values, workspace content, email addresses, or names as analytics person properties.
Public tools, reports, and messages
Most public tool inputs are processed for the immediate result and are not added to a Picks workspace. Public YouTube audit reports are retained for up to 30 days. Audit-access request email addresses and the supplied channel reference are retained for up to 90 days. If you join a paid-plan waitlist, Picks stores your email address and selected plan for up to 90 days so we can contact you when access opens; joining a waitlist does not subscribe you to general marketing. If you contact us about Picks, we process the information in your message to respond and maintain appropriate support records.
Why information is used
We process information to provide and secure Picks; authenticate users; create and route links; localize destinations; produce reports; publish changes a user expressly confirms; provide rollback; detect abuse and bots; troubleshoot failures; send requested alerts; enforce limits; comply with law; and understand product reliability and dashboard usage.
Where consent is required—such as for optional third-party marketing pixels or connecting a YouTube channel—Picks asks before that processing begins. You can withdraw that consent as described below.
Cookies and similar technology
Picks and Clerk use necessary cookies or browser storage to authenticate users, protect forms, preserve a selected smart-link variant, remember a visitor’s marketing-pixel choice, and recognize the owner of an unlisted report. PostHog uses origin-local browser storage to maintain a pseudonymous product-analytics session. A marketing-consent choice is remembered for up to six months; a smart-link variant may be remembered for up to 30 days.
Customer-configured third-party marketing pixels are disabled unless the workspace enables them, the visitor is in an allowed region, and the visitor expressly consents. Global Privacy Control and Do Not Track signals suppress those pixels. A configured pixel provider receives the information inherent in the browser request to that provider and operates under its own privacy terms.
When information is shared
We do not sell personal information or YouTube API Data. Information is shared only as needed with:
- Cloudflare, for application hosting, databases, storage, queues, network delivery, abuse protection, and operational metrics.
- Clerk, for account authentication and session management.
- PostHog, for privacy-limited dashboard product analytics.
- Google and YouTube, when Picks makes the API requests you authorize or retrieves public YouTube data.
- Oxylabs or Bright Data, depending on the active product-data provider, for point-in-time Amazon product observations used in link-health checks. These observations are not Amazon-authoritative.
- Resend, when configured, to deliver requested transactional email and health alerts.
- Providers selected by a workspace, such as webhook destinations or optional marketing-pixel providers.
We may also disclose information when required by law, to protect users or the Service, or as part of a business transaction subject to appropriate confidentiality and notice. Authorized YouTube data is not shared for independent use by third parties.
Retention and deletion
- Raw smart-link click records and related exports are kept for the workspace-selected period of 30, 90, 180, or 365 days; the default is 90 days. A workspace can delete click data sooner from Settings.
- Public YouTube audit reports expire after 30 days. Audit-access requests expire after 90 days.
- Paid-plan waitlist requests expire after 90 days.
- OAuth state records expire after 10 minutes. YouTube connection metadata and the encrypted refresh token are kept only while the connection remains active and useful for the consented feature.
- Encrypted YouTube publishing and rollback records expire no later than 30 days after a run is created.
- PostHog dashboard analytics events are kept for up to 12 months.
- Operational, security, billing, and audit records are retained only as reasonably necessary for their purpose or a legal obligation. YouTube-authorized data is excluded from those records after revocation or a deletion request.
Picks revalidates an active YouTube authorization at least every 30 days. If Google reports that access was revoked or cannot be refreshed, Picks deletes the stored connection and related authorized publishing data as soon as detected and within 30 days of revocation.
Your choices and YouTube revocation
You can disconnect a channel from the YouTube Optimizer at any time. Picks will ask Google to revoke the token and then delete the encrypted credential, channel connection metadata, related publishing and rollback records, and YouTube-authorized audit details. This deletion is initiated immediately and completed within seven calendar days. Disconnecting also makes any remaining Picks rollback unavailable.
You can separately revoke Picks from Google’s third-party connections page. Picks periodically checks whether the authorization remains valid and deletes associated API Data after detecting an external revocation.
Deleting data stored by Picks does not delete a video, description, or other content stored by YouTube. To delete content from YouTube, use YouTube Studio or another authorized client that supports that action.
To request access, correction, or deletion of information associated with you—including a complete deletion of stored YouTube API Data—email support@picks.so. We will verify the request and complete a valid YouTube-data deletion request as soon as possible and within seven calendar days.
Security and international processing
Picks uses HTTPS, access controls, server-only credentials, authenticated encryption for YouTube refresh tokens and rollback descriptions, bounded data retention, and operational monitoring. No service can guarantee absolute security, so please use a strong authentication method and promptly report suspected misuse.
We and our providers may process information in countries other than the one where you live. Where required, appropriate safeguards are used for those transfers.
Children
The Service is designed for creators and business operators and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. Contact us if you believe a child supplied personal information.
Changes and contact
We may update this policy as the Service or applicable requirements change. Material changes will be identified by a new “Last updated” date and, when appropriate, an in-product notice. If a change introduces a new use of YouTube API Data, affected users will be asked to accept the updated policy before that use begins.
Questions, complaints, and privacy requests can be sent to support@picks.so. Security reports can be sent to security@picks.so.