Content Radar Privacy Policy — English draft
Product: Content Radar
Planned public URL: https://contentradar.eu/privacy
Controller: BIZNESFUN Spółka z o.o., NIP 5423515903, ul. Legionowa 10/208, 15-099 Białystok, Poland
Version: draft 2026-10-02 — requires owner/legal approval before publication
This notice describes the planned external-user service. It must not be published as a statement of an available feature until the corresponding account, deletion, export and Google OAuth functions exist and have been tested.
1. Data we process
When you connect YouTube, Content Radar requests the read-only scope https://www.googleapis.com/auth/youtube.readonly. We may process:
- your Google/YouTube account identifier and OAuth authorization tokens;
- the identifiers, titles, URLs, channel details and timestamps of videos you liked;
- your YouTube likes history. This can reveal preferences and is treated by us as behavioural data;
- text or transcripts of material selected for your radar, automated categories, relevance judgements, scores and reports;
- your categories, source settings, decisions and service activity needed to operate and secure the service;
- support, export and deletion requests and limited security logs.
We do not request permission to publish videos, modify your channel or act as you. Content Radar is not intended for children.
2. Why and on what legal basis
- YouTube connection and reading likes — consent (GDPR Art. 6(1)(a)). You choose “Connect YouTube” and authorize the read-only scope. You can withdraw consent at any time as described below. Withdrawal does not affect earlier lawful processing.
- Account, requested radar output, export and deletion — contract / steps requested before a contract (Art. 6(1)(b)).
- Security, abuse prevention and technical troubleshooting — legitimate interests (Art. 6(1)(f)), limited to what is necessary and balanced against your rights.
- Legal obligations (Art. 6(1)(c)) where records must be retained by law.
We do not use your likes to train a personalized model in this release and do not make legal or similarly significant decisions about you. A future feature that learns from individual taste requires a separate assessment, transparent notice and, where required, a DPIA and new consent before activation.
3. What the service does with likes
Content Radar checks recent liked-video identifiers so it can bring selected material into the user-visible radar. Only material that passes the configured relevance funnel is retained with its text, automated assessment and report. For rejected material, the service retains only the minimum video identifier needed to prevent repeated processing, plus short operational records. It does not sell, advertise against or create an unrelated profile from your YouTube activity.
4. Google API Services User Data — Limited Use
Content Radar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide or improve prominent user-facing Content Radar features. It is not sold, used for advertising, used to determine creditworthiness or lending, or transferred for unrelated purposes. Transfers are limited to service providers acting for us where necessary to provide or secure the feature, under appropriate agreements, or where required by law. Humans do not read Google user data except with the user's affirmative agreement for a specific item, when necessary for security or abuse investigation, to comply with law, or where data has been aggregated and anonymised for internal operations in accordance with Google's policy.
5. Service providers and international transfers
We use processors only for the stated service purpose. Some providers process data outside the EEA. The safeguards below are the provider terms found during preparation; the Controller must accept or execute each applicable DPA and verify account settings before external launch.
| Provider | Planned data/purpose | Transfer safeguard and status at 2026-10-02 |
|---|---|---|
| Google Cloud / YouTube API | OAuth, account/video/likes data, API delivery | Google Cloud Data Processing Addendum and EU-US Data Privacy Framework information. Owner acceptance/account configuration to verify. |
| OpenRouter | text sent to the selected model and output routing | DPA, including processor terms, SCC mechanism and ZDR provisions. Enable ZDR/no-training routing and verify it for the selected endpoint before launch. |
| TypeSafe AI / Jev | material text and structured questions/decisions | DPA; privacy policy; subprocessors in its Trust Center. TypeSafe states that Jev is not trained on requests/responses. Owner acceptance and transfer mechanism to verify. |
| Supadata | video URL; transcript when this path is authorized | Supadata DPA and subprocessor list, which states SCC or EU-US DPF safeguards for non-EU providers. DPA exists; owner acceptance and current list to verify. |
| Groq | audio and speech-to-text output only if the fallback is enabled | Groq Data Processing Addendum, incorporating EU SCCs. Not an external-user production path until enabled and accepted. |
| Notion | user-facing report, status and decisions | Notion Data Processing Addendum and security/compliance information. Workspace DPA and public-sharing settings to verify. |
Our own application database is planned to store Content Radar records. Hosting location, hosting processor identity, backup retention and its DPA must be inserted here after ops fixes the external production architecture; publication with this row unresolved is not approved.
6. Retention and deletion
- OAuth tokens: until you disconnect YouTube, delete your account, or the token expires/is revoked.
- Selected materials, transcripts, assessments, reports and settings: while your account is active and needed for the requested service.
- Rejected-video identifiers used only for deduplication: while the account is active, unless a shorter configurable period is adopted.
- Security logs: normally no more than 30 days unless an incident or legal duty requires a documented longer period.
- Following a valid account-deletion request: revoke/delete tokens and erase account data, materials, texts, assessments, reports, likes-derived records and live-system identifiers without undue delay and no later than 30 days. Backups are isolated from normal use and expire on their documented rotation; they are not restored except for disaster recovery.
A deletion does not cover data that must be retained by law; any exception will be isolated, access-restricted and explained. The service must not promise a deletion button until the YCA4 account/deletion implementation has passed acceptance.
7. Your choices and rights
You can withdraw YouTube access in Content Radar (once the disconnect control is released) and at Google Account — third-party connections. You may also request access, correction, deletion, restriction, objection, or portability. The planned export is a structured JSON file containing your account settings, retained source records, assessments and decisions. We normally respond within one month as required by GDPR Art. 12(3).
Until a verified privacy email exists, send requests by post to the Controller address above. Before publication, the owner must activate and test privacy@contentradar.eu and add it here. You may lodge a complaint with Poland's supervisory authority, the Prezes Urzędu Ochrony Danych Osobowych (UODO), or your local authority.
8. Security and incidents
We use access controls, secret management, transport encryption, least-privilege OAuth scopes, processor agreements, logging and documented incident response. No internet service is risk-free. Our internal response procedure is in docs/legal/breach-response.md and includes the GDPR 72-hour supervisory-notification assessment.
9. Changes
Material changes to Google-data access or use will be disclosed before they take effect. Where the legal basis is consent, we will request renewed consent. The effective public policy and the policy linked from the Google OAuth consent screen must be the same URL and version.
Sources checked
Official sources accessed 2026-10-02: Google API Services User Data Policy; Google OAuth verification requirements; GDPR text; processor documents linked in §5. This is an operational draft, not legal advice.