Google API Limited Use Disclosure
Last updated: 12 September 2026
This disclosure explains how Aicut GmbH, Richard-Wagner-Str. 38, 53115 Bonn, Germany ("aicut", "we") accesses, uses, stores, transfers and protects information received from Google APIs in connection with Google Sign-In and YouTube features ("Google User Data"). It complements our Privacy Policy and is intended to satisfy the transparency expectations of the Google API Services User Data Policy, including the Limited Use requirements.
1. Policy commitment
aicut's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google User Data is handled only in ways that are consistent with your expectations, with the feature you explicitly enable, with the permissions (scopes) you grant on Google's consent screen and with what is needed to operate that feature.
2. Which Google APIs we use and why
(a) Google Sign-In
If you choose to sign in with Google, we receive the basic account information needed to authenticate you and create or link your aicut account: your email address, your name, your profile picture and your Google account identifier, as provided by Google and authorized by you. Sign-in is operated through our authentication provider Supabase.
(b) YouTube publishing and channel view
If you connect a Google account to publish to YouTube from within aicut, we request the scopes youtube.upload and youtube.readonly and use the YouTube Data API to:
- upload a video you explicitly select or schedule for publishing, or that an automation campaign you configured publishes on your behalf;
- set the metadata you provide for it (title, description, tags, category, visibility, made-for-kids flag);
- return the upload result and processing status to you;
- read your channel name, channel ID and avatar so you can pick the channel to publish to;
- read the list of videos on your channel with their public statistics (views, likes, comments) to show your channel performance inside aicut and to link a post back to the aicut video it was made from.
We use Google APIs only after you intentionally enable the relevant feature and grant the corresponding permissions through Google's consent screen. If you do not use Google Sign-In or connect YouTube, we do not access any Google User Data.
3. Categories of Google User Data we receive
- Account identifiers: email address, name, profile picture, Google account ID.
- Authorization data: OAuth access tokens, refresh tokens and token metadata (scopes, expiry).
- YouTube channel data: channel ID, title and avatar; the IDs, titles, publish dates and public statistics of videos on the channel; the IDs, processing status and response data of videos uploaded through aicut.
- The YouTube metadata you enter in aicut for a video you publish.
We do not request or seek access to Google data unrelated to these functions.
4. How we use Google User Data
- To provide the feature you requested: authenticate your login, connect your channel, execute the uploads you initiate or schedule, and show your channel performance.
- To maintain and secure the service: prevent unauthorized access, detect fraud and abuse, and keep our systems reliable.
- To support you: diagnose and resolve upload or connection errors when you ask us for help.
We do not use Google User Data for any purpose that is incompatible with the Limited Use requirements.
5. Limited Use: what we do not do
- We do not sell Google User Data.
- We do not use Google User Data for advertising, including retargeting, personalized or interest-based advertising, or for tracking you across services.
- We do not use Google User Data to develop, improve or train generalized or non-personalized AI or machine-learning models, including large language models. Google User Data is only ever used for the features you enabled.
- We do not transfer Google User Data to third parties, except to provide or improve the feature you requested, with your explicit consent, for security purposes such as investigating abuse, to comply with the law, or as part of a merger or acquisition with prior notice to you and continued adherence to this disclosure.
- No human at aicut reads Google User Data, except with your explicit consent (for example when you ask us to troubleshoot a connection), for security purposes, to comply with the law, or where the data has been aggregated and anonymized for internal operations.
6. Transfers and sharing
- Processors: Google User Data is stored and processed by our infrastructure providers (Supabase for authentication and database, Vercel for hosting, Amazon Web Services for the video upload pipeline) under data processing agreements, with access limited to what is necessary.
- Google and YouTube: to perform an upload or read your channel, data is exchanged with Google's systems as part of the API transaction.
- Legal compliance: we may disclose Google User Data where required by law or a lawful request by a public authority, or to protect rights, safety and security, to the extent permitted by law.
We never provide Google User Data to third parties for their own marketing purposes.
7. Data minimization
- We request only the scopes reasonably necessary for the feature you enable.
- If you do not enable Google or YouTube features, we do not access Google User Data.
- Processing is limited to the specific action you take, such as an upload you start.
8. Storage, retention and deletion
- Tokens: when you connect a YouTube channel we store the OAuth access and refresh tokens so that later uploads and scheduled or automated posts work without repeated logins. Tokens are stored in our database with access restricted to the systems that need them and are transmitted only over TLS.
- Retention: we keep Google User Data only as long as needed to maintain the connection you requested and provide the feature, to comply with legal obligations, or to resolve disputes.
- Deletion on disconnection: when you remove a YouTube account inside aicut, we stop API access and delete the stored tokens immediately. When you delete your aicut account, all connected accounts and their tokens are deleted with it. If you revoke access on Google's side, our stored tokens become invalid and are removed the next time they fail or when you delete the connection.
9. Your controls
- Within aicut: remove a YouTube account on the Channels page at any time.
- Via Google: revoke aicut's access under Third-party apps & services in your Google Account.
After revocation, aicut can no longer access Google APIs on your behalf unless you authorize it again.
10. Security
We protect Google User Data with transport encryption (TLS), role-based access controls and least-privilege access, row-level access rules in our database, logging and monitoring of security events, and regular security reviews. No internet transmission is perfectly secure, but we take commercially reasonable measures against unauthorized access and misuse.
11. YouTube API Services
aicut uses YouTube API Services. By using the YouTube features you also agree to the YouTube Terms of Service and acknowledge the Google Privacy Policy.
12. Contact
Questions about this disclosure or our handling of Google User Data: Aicut GmbH, Richard-Wagner-Str. 38, 53115 Bonn, Germany, info@aicut.pro.