Skip to policy
LinkRivet
Home Privacy Terms

Privacy Policy

How LinkRivet accesses, uses, stores, shares, and deletes information, including Google and YouTube API Data.

Last updated August 9, 2026Applies to LinkRivet’s websites, dashboard, tools, and APIs
On this page
  1. What this policy covers
  2. How LinkRivet uses YouTube API Services
  3. Other information LinkRivet processes
  4. Why information is used
  5. Cookies and similar technology
  6. When information is shared
  7. Retention and deletion
  8. Your choices and YouTube revocation
  9. Security and international processing
  10. Children
  11. Changes and contact

What this policy covers

This Privacy Policy applies to LinkRivet’s websites, authenticated dashboard, public link tools, smart-link redirects, reports, APIs, and related services (together, the “Service”). LinkRivet helps creators and publishers inspect, organize, route, monitor, and update product links.

This policy describes the information LinkRivet processes, why it is used, when it is shared, how long it is kept, and the choices available to you. It does not govern the privacy practices of Amazon, Google, YouTube, or another site you choose to visit.

How LinkRivet uses YouTube API Services

LinkRivet uses YouTube API Services for its channel-audit and YouTube Optimizer features. Use of those features is also governed by YouTube’s Terms of Service and Google’s Privacy Policy.

Data accessed with your authorization

When you connect a channel, LinkRivet requests the https://www.googleapis.com/auth/youtube.force-ssl permission. Google describes this permission as allowing an application to view, edit, and permanently delete YouTube videos, ratings, comments, and captions. LinkRivet requests it because the YouTube Data API requires this scope to read a connected channel’s video metadata and update video descriptions. LinkRivet does not use it to delete videos, change video visibility, publish comments, manage ratings, or manage captions.

LinkRivet accesses the selected channel’s ID, title, handle, uploads-playlist ID, video IDs, video titles, descriptions, publication dates, privacy-status labels, and API version markers. A short-lived access token is used in server-to-server requests and is not stored. The refresh token is stored using authenticated encryption so the connection can continue until you disconnect it or Google revokes it. LinkRivet never asks for or stores your Google or YouTube password.

How the data is used

  • Import current descriptions into your private review session.
  • Find supported Amazon links and show proposed LinkRivet replacements and disclosure text.
  • Re-read descriptions immediately before a confirmed publish and skip videos whose content changed after review.
  • Update only descriptions you expressly confirm. LinkRivet preserves the current title, category, tags, language fields, and privacy status.
  • Provide a conflict-safe rollback for descriptions LinkRivet successfully updated.

Imported descriptions are processed to produce the review shown to you and are not retained by the channel-import flow. If you confirm direct publishing, the original and proposed descriptions, video IDs, and video titles are stored as workspace-bound encrypted rollback records for no more than 30 days. LinkRivet does not sell YouTube API Data, use it for advertising, combine it across unrelated channel owners, or expose authorized data to anyone other than the authorizing workspace and its approved members.

LinkRivet’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or secure the user-facing features described here; it is not used to determine creditworthiness or to train generalized artificial-intelligence or machine-learning models.

Public channel reports

The public channel-audit tool uses YouTube API Services to read public channel and video metadata without connecting to a user’s Google Account. Its report stores the supplied channel identifier, public channel identity, video references, extracted public links, and point-in-time findings for up to 30 days. Shared reports are unlisted, redacted, and not refreshed when viewed.

Other information LinkRivet processes

Account and workspace information

LinkRivet receives a stable user or organization identifier and session information from Clerk, our authentication provider. LinkRivet does not receive your Clerk password. We process workspace names, account settings, affiliate tracking IDs, links, destinations, groups, tags, custom domains, alert addresses, integration settings, API-key metadata, and content you submit to operate the Service.

Smart-link and usage information

When someone follows a LinkRivet smart link, the application records the event time, Cloudflare-provided country code, destination, routing reason, marketplace, device category, browser and operating-system category, language, referrer hostname, selected A/B variant, bot classification, and request latency. LinkRivet’s click tables do not store the visitor’s raw IP address. Cloudflare may process network information as part of providing security, delivery, and operational logging.

Public tools, reports, and messages

Most public tool inputs are processed for the immediate result and are not added to a LinkRivet workspace. Public YouTube audit reports are retained for up to 30 days. Audit-access request email addresses and the supplied channel reference are retained for up to 90 days. If you contact LinkRivet, we process the information in your message to respond and maintain appropriate support records.

Why information is used

LinkRivet processes information to provide and secure the Service; authenticate users; create and route links; localize destinations; produce reports; publish changes a user expressly confirms; provide rollback; detect abuse and bots; troubleshoot failures; send requested alerts; enforce limits; comply with law; and understand product reliability.

Where consent is required—such as for optional third-party marketing pixels or connecting a YouTube channel—LinkRivet asks before that processing begins. You can withdraw that consent as described below.

Cookies and similar technology

LinkRivet and Clerk use necessary cookies or browser storage to authenticate users, protect forms, preserve a selected smart-link variant, remember a visitor’s marketing-pixel choice, and recognize the owner of an unlisted report. A marketing-consent choice is remembered for up to six months; a smart-link variant may be remembered for up to 30 days.

Customer-configured third-party marketing pixels are disabled unless the workspace enables them, the visitor is in an allowed region, and the visitor expressly consents. Global Privacy Control and Do Not Track signals suppress those pixels. A configured pixel provider receives the information inherent in the browser request to that provider and operates under its own privacy terms.

When information is shared

LinkRivet does not sell personal information or YouTube API Data. Information is shared only as needed with:

  • Cloudflare, for application hosting, databases, storage, queues, network delivery, abuse protection, and operational metrics.
  • Clerk, for account authentication and session management.
  • Google and YouTube, when LinkRivet makes the API requests you authorize or retrieves public YouTube data.
  • Oxylabs or Bright Data, depending on the active product-data provider, for point-in-time Amazon product observations used in link-health checks. These observations are not Amazon-authoritative.
  • Resend, when configured, to deliver requested transactional email and health alerts.
  • Providers selected by a workspace, such as webhook destinations or optional marketing-pixel providers.

LinkRivet may also disclose information when required by law, to protect users or the Service, or as part of a business transaction subject to appropriate confidentiality and notice. Authorized YouTube data is not shared for independent use by third parties.

Retention and deletion

  • Raw smart-link click records and related exports are kept for the workspace-selected period of 30, 90, 180, or 365 days; the default is 90 days. A workspace can delete click data sooner from Settings.
  • Public YouTube audit reports expire after 30 days. Audit-access requests expire after 90 days.
  • OAuth state records expire after 10 minutes. YouTube connection metadata and the encrypted refresh token are kept only while the connection remains active and useful for the consented feature.
  • Encrypted YouTube publishing and rollback records expire no later than 30 days after a run is created.
  • Operational, security, billing, and audit records are retained only as reasonably necessary for their purpose or a legal obligation. YouTube-authorized data is excluded from those records after revocation or a deletion request.

LinkRivet revalidates an active YouTube authorization at least every 30 days. If Google reports that access was revoked or cannot be refreshed, LinkRivet deletes the stored connection and related authorized publishing data as soon as detected and within 30 days of revocation.

Your choices and YouTube revocation

You can disconnect a channel from the YouTube Optimizer at any time. LinkRivet will ask Google to revoke the token and then delete the encrypted credential, channel connection metadata, related publishing and rollback records, and YouTube-authorized audit details. This deletion is initiated immediately and completed within seven calendar days. Disconnecting also makes any remaining LinkRivet rollback unavailable.

You can separately revoke LinkRivet from Google’s third-party connections page. LinkRivet periodically checks whether the authorization remains valid and deletes associated API Data after detecting an external revocation.

Deleting data stored by LinkRivet does not delete a video, description, or other content stored by YouTube. To delete content from YouTube, use YouTube Studio or another authorized client that supports that action.

To request access, correction, or deletion of information associated with you—including a complete deletion of stored YouTube API Data—email support@linkrivet.com. LinkRivet will verify the request and complete a valid YouTube-data deletion request as soon as possible and within seven calendar days.

Security and international processing

LinkRivet uses HTTPS, access controls, server-only credentials, authenticated encryption for YouTube refresh tokens and rollback descriptions, bounded data retention, and operational monitoring. No service can guarantee absolute security, so please use a strong authentication method and promptly report suspected misuse.

LinkRivet and its providers may process information in countries other than the one where you live. Where required, appropriate safeguards are used for those transfers.

Children

The Service is designed for creators and business operators and is not directed to children under 13. LinkRivet does not knowingly collect personal information from a child under 13. Contact us if you believe a child supplied personal information.

Changes and contact

LinkRivet may update this policy as the Service or applicable requirements change. Material changes will be identified by a new “Last updated” date and, when appropriate, an in-product notice. If a change introduces a new use of YouTube API Data, affected users will be asked to accept the updated policy before that use begins.

Questions, complaints, and privacy requests can be sent to support@linkrivet.com. Security reports can be sent to security@linkrivet.com.

© 2026 LinkRivet · Built for thoughtful recommendations.
PrivacyTermsYouTube TermsContact