On this page we fully and transparently describe how our platform's YouTube integration works, which permissions it uses, which data is processed, and how users stay in control of their data at all times.
This page remains permanently public and serves both users and the YouTube/Google review team as a central source of information about our implementation of the YouTube Data API v3.
Use of YouTube API Services: companycore uses YouTube API Services for this integration. The Google Privacy Policy additionally applies. You can revoke companycore's access to your Google account at any time via the Google security settings. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service.
companycore ai is a B2B SaaS platform through which registered companies can plan and publish short
videos (YouTube Shorts) to their own YouTube channel – either entirely manually, or with the help of an
AI tailored to the brand, which creates title and description suggestions. Only video content provided
or approved by the user is uploaded – never automated series without review.
Every post must be manually reviewed, confirmed and scheduled with a date and time by the
user. Title, description and visibility are set exclusively by the user – companycore never adds to
or shortens them.
Only after this active approval is the video automatically uploaded to YouTube at the scheduled
time via a scheduled server-side process (cron job). No upload happens without prior, explicit user
confirmation.
Note on approval status: Until Google completes our YouTube API compliance audit, YouTube forces every video uploaded through our app to "private" – regardless of the visibility chosen in the editor, and with no way for us to reverse it. This restriction is applied by YouTube itself; our app shows it on the connection card once the channel is connected and in the editor, and offers only "Private" until then.
Video uploads only, via videos.insert (YouTube Shorts: vertical, up to 180 seconds). YouTube
has no image-post format; the API offers no such function, and companycore therefore does not upload videos
generated from still images.
youtube.upload – uploading videos to the connected channel (videos.insert with
title, description, visibility and the fields from section 4)youtube.readonly – identifying the connected channel (channels.list with
mine=true: channel id, title, @handle; refreshed at least every 30 days) and reading the
processing status of the videos we uploaded only (videos.list)
We do not request the broader youtube or youtube.force-ssl scopes. Editing or
deleting after upload is not possible through our integration; rescheduling or withdrawing happens only within
our own system while the video has not been uploaded yet – afterwards the user edits it directly in YouTube
Studio.
< or >)status.embeddable) and "Notify subscribers"
(notifySubscribers) – on by default, can be switched off by the userWe store: the YouTube channel identifier, channel title, channel handle (@handle), a channel picture address (not displayed), the encrypted access and refresh tokens, and their expiry times. Tokens are stored exclusively AES-256-GCM encrypted; our database runs in the EU region (eu-central-1, Frankfurt). Scheduled and published posts additionally carry a copy of the channel identifier and channel title so the calendar can show which channel a post belongs to. We refresh the channel title and handle (including these copies) via the API at least every 30 days, or delete them when access no longer exists (section 9).
We do not store subscribers, comments, other videos, or analytics data.
If a user mentions another channel by @handle in a YouTube description, our server checks with an API key from the
same Google Cloud project whether that channel exists (channels.list with forHandle). Only
public channel data (id, title, handle) is read; no user token is used. The result is held transiently in memory for
at most 7 days and never stored in a database. We do not check other platforms this way.
Users have two independent ways to revoke their connection:
a) Via our app: Backstage → Connections offers "Disconnect". On confirmation, we actively revoke the token with Google and immediately remove from our database the tokens, the stored channel data (channel identifier, title, handle) and the copies of channel identifier and title on scheduled and published posts. What remains in your calendar are the posts themselves (text, video, status) and the link to a video already published on YouTube. Disconnecting at companycore does not delete any videos on YouTube – videos already uploaded stay on your channel and can only be edited or deleted in YouTube Studio. The disconnect dialog in the app says so.
b) Via your Google security settings: security.google.com/settings/security/permissions → remove companycore. Our system detects access revoked this way at the latest during the next scheduled refresh of the channel data (every 29 days) or on the next upload attempt and then immediately deletes the entire connection (tokens, channel identifier, channel title, handle) and the copies of channel identifier and title on your posts — in any case within 30 days of your revocation.
Alternatively, a short email to jan@companycore.ai is sufficient.
state parameter and CSRF protection
For questions about the integration, permissions, or data handling:
jan@companycore.ai
companycore ai UG (haftungsbeschränkt)
Sömmeringstraße 69, 50823 Cologne, Germany
HRB 124109 (Cologne local court)
Managing director: Jan Bennefeld
This page is updated continuously as the YouTube API, permissions, or processes we use change. Every change is documented here transparently.