Uploader

Privacy Policy

Last updated: 30 June 2026

Who we are

Uploader (the "App") is an internal web application operated by Maneks Plus d.o.o. ("we", "us", "our") and used by our marketing team to build and manage Google Ads campaigns for the Google Ads accounts we own or manage, and to upload videos to YouTube channels we own or manage. The App is not available for public sign-up. Contact: sandi@maneks.eu.

Scope

This policy describes what information the App collects, how it is used, and how it is protected. The App accesses the Google Ads API, YouTube API Services, and the Google Drive API (read-only). By using the App you also agree to be bound by the YouTube Terms of Service, and you acknowledge Google's Privacy Policy.

Data we collect

The App stores only what is necessary to build campaigns and perform uploads on the user's behalf:

  • Account information: name, email, and a hashed password for the App's own login (Laravel Breeze).
  • Google OAuth tokens: access and refresh tokens, stored encrypted at rest. Tokens are scoped to the OAuth scopes the user grants: adwords (Google Ads), youtube.upload / youtube / youtube.readonly (YouTube), and drive.readonly (Google Drive, read-only).
  • Google Ads data: the IDs and names of the Google Ads accounts under your manager account, and the campaigns, budgets, assets and ads that the App creates or reads back (including their status and Google-assigned IDs).
  • Product catalog data (our own): brands, products, SKUs, marketing images and videos, and the ad copy generated for them.
  • YouTube channel metadata (per connected channel): channel ID, display name, and thumbnail URL; plus video upload metadata (title, description, tags, privacy, scheduled time, and the YouTube video ID returned after upload).
  • Operational data: job status (queued, running, completed, failed) and error messages.

We do not collect viewer analytics, watch-time data, comments, search history, ad-performance data about other advertisers, or any data about other YouTube or Google users.

How we use the data

  • Google Ads: OAuth tokens are used to call the Google Ads API (GoogleAdsService.Search and GoogleAdsService.Mutate) to read your accounts and to create and manage campaigns, budgets, assets and ads in the accounts you authorize. Campaigns are created paused for human review.
  • YouTube: tokens are used to call the YouTube Data API endpoints channels.list, videos.insert, videos.list, videos.delete, and thumbnails.set to upload and manage video on the channels you authorize.
  • Google Drive: read-only access is used solely to import product images from a Drive folder you explicitly choose. We do not read or modify any other Drive files.
  • Ad copy generation: product information (names, descriptions, attributes) is sent to OpenAI to generate ad headlines and descriptions. See "Third parties" below.
  • Source files: uploaded video files are stored on our server only until the upload completes, then automatically deleted from disk.

YouTube API Services compliance

The App uses YouTube API Services. By using the App you agree to the YouTube Terms of Service and acknowledge Google's Privacy Policy. We do not transfer YouTube API data to any third party, and we do not use YouTube API data for personalised advertising or to infer information about other users. In particular, YouTube data is never sent to OpenAI or any other third-party service.

Google Ads API & Google user data

The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Ads and Google Drive data are used only to provide the App's campaign-building and asset-import features for the accounts you authorize, are not sold, and are not used for advertising to other users.

Data retention

  • OAuth tokens are retained until the user disconnects the account or revokes access in their Google Account permissions.
  • Google Ads account and campaign records are retained while the connection is active; the campaigns themselves live in your Google Ads account and are managed there.
  • Catalog data and YouTube upload records are retained until deleted from the App.
  • Source video files are deleted from our server automatically once an upload succeeds.

Security

  • OAuth tokens are encrypted at rest using Laravel's encrypted cast (AES-256-CBC with the application key).
  • Passwords are stored as bcrypt hashes; we never store passwords in plaintext.
  • All web traffic is served over HTTPS (Let's Encrypt).
  • Access to the App requires authentication; public registration is disabled.

Revoking access

You can revoke the App's access to your Google account at any time by visiting myaccount.google.com/permissions. Revoking access invalidates the App's OAuth tokens for that account immediately. You may also disconnect a connected account inside the App, which removes its stored tokens.

Third parties

The App communicates with Google APIs (the Google Ads API, the YouTube Data API v3, the Google Drive API, and Google OAuth 2.0) and with OpenAI. OpenAI is used only to generate ad copy from our own product information (product names, descriptions and attributes). No YouTube data, no Google Ads performance data, and no personal user data is sent to OpenAI. No data is shared with any other third party.

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent revision.

Contact

Questions about this policy? Email sandi@maneks.eu.