Privacy Policy
Last updated: October 9, 2026
1. About MCRU
MCRU is a private tool for preparing, publishing and measuring video. In this policy, “we”, “our” and “us” mean MCRU’s operator, and “you” means the owner of a YouTube channel connected to MCRU. The operator uses MCRU for the YouTube channels the operator owns. MCRU has no public sign-up and does not offer accounts to third parties. This policy explains what data MCRU accesses and stores, how it is used, and how access can be withdrawn.
2. YouTube API Services
MCRU uses YouTube API Services. Using MCRU means you agree to be bound by the YouTube Terms of Service. How Google handles your data is described in the Google Privacy Policy.
MCRU’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Data we access
MCRU accesses a YouTube channel only after the channel owner approves access on Google’s consent screen. These are the permissions we request and what each one is for:
| Permission (OAuth scope) | What it is used for |
|---|---|
youtube.upload | Upload videos to the connected channel. |
youtube.force-ssl | Change a video’s title, description, visibility and scheduled publication time, and read comments on the operator’s own videos. |
youtube.readonly | Read channel and video information: channel ID, title, list of videos, status and public statistics. |
yt-analytics.readonly | Read YouTube Analytics reports for the connected channel: views, watch time, average view duration and percentage, audience retention, and subscribers gained and lost. |
MCRU never sees your Google password. It does not access your email or contacts, or any other data outside the approved permissions.
4. Data we store
MCRU keeps a copy of some of the data it accesses, so the operator can see results over time:
- channel ID and channel title;
- the list of the channel’s videos, with their titles, publication status and scheduled times;
- YouTube Analytics figures for those videos and for the channel, such as views, watch time, audience retention and subscriber changes;
- the text of viewer comments on the operator’s videos, for a limited time (see section 8);
- the authorization tokens that Google issues when you approve access.
5. How we use the data
We use Google user data only for these features in MCRU:
- publishing and scheduling the operator’s videos on the connected channels;
- showing how published videos perform;
- reading viewer comments on the operator’s videos;
- helping the operator decide what to make next.
We do not use Google user data for advertising. We do not sell it, and we do not pass it to data brokers or advertising platforms. We do not use it to train generalized artificial intelligence models.
6. Sharing
We share Google user data only with the hosting providers that store it for the operator, or when the law requires disclosure. Only the operator reads the data.
7. Security
- Authorization tokens are stored encrypted on servers controlled by the operator. They are used only for the actions described above.
- Data in transit is protected with HTTPS.
- Only the operator can open the workspace.
8. Retention and deletion
- YouTube Analytics data is kept while the channel owner’s authorization is valid. At least every 30 days, MCRU checks that the authorization is still valid and that the video still exists.
- Other data obtained through your authorization, such as comment text, is kept for no more than 30 days unless it is refreshed.
- If you disconnect a channel in MCRU, we revoke its token immediately and delete the data we obtained through it within 7 days. If you revoke access in your Google account settings, we delete that data within 30 days.
- You can ask us at any time to delete the data we hold about your channel. We will do so as soon as possible and within 7 days. Deleting our copy does not change the data that YouTube or Google holds.
9. Withdrawing access
You can withdraw MCRU’s access to your Google account at any time on this Google page: https://security.google.com/settings/security/permissions. You can also write to us (see section 13) and we will disconnect the channel.
10. Cookies
This public website is static. It sets no cookies and runs no analytics or advertising trackers. Your browser may cache the pages as usual. The private workspace uses only the cookies needed to keep the operator signed in.
11. Children
MCRU is not directed to children and does not knowingly collect data from them.
12. Changes to this policy
We may update this policy, and the date at the top shows the latest version. If we change how we use Google user data, we will ask for your consent again before the new use begins.
13. Contact
For privacy questions, complaints or deletion requests, write to support@nexa.gdn.