Privacy Policy
DKSL Analytics Reader — effective and last updated: September 4, 2026
The short version: DKSL Analytics Reader is used by one person — its owner — to read the audience statistics for his own YouTube channel. It cannot upload, edit, publish or delete any video, and it cannot change the channel. It creates exactly one thing: a YouTube reporting job, a standing request for the daily statistics reports that thumbnail impression data is only available through. It stores a single OAuth refresh token on his own computer. There is no server, no database, and no data collected from anybody else.
1. Who this policy covers
This policy covers DKSL Analytics Reader (the “Reader”), a desktop tool written and used by Dustin Paulson to view analytics for the DK Security Lab YouTube channel, which he owns. The Reader is not distributed, not sold, and has no other users.
2. Use of YouTube API Services
The Reader uses YouTube API Services. By using it, its owner is agreeing to the YouTube Terms of Service. Google’s handling of data is described in the Google Privacy Policy. Access granted to the Reader can be reviewed and revoked at any time at Google security settings.
3. The one scope it uses, what that scope cannot do, and the one thing the Reader creates
The Reader requests exactly one OAuth scope:
https://www.googleapis.com/auth/yt-analytics.readonly
That scope cannot upload a video, change a title or description, alter a thumbnail, publish or unpublish anything, post or read comments, or delete any content. It reads statistics — with the one exception set out immediately below.
One thing the Reader creates, stated plainly because “read-only” would otherwise be misleading: a YouTube reporting job. Thumbnail impressions and click-through rate are not available from the Analytics API at all — they come only from the Reporting API, which requires registering a standing job that YouTube then generates a report against each day. Creating that job is a write, and it leaves an object in the owner’s YouTube account until it is deleted. It holds no video content, changes nothing about the channel or its videos, and can be removed at any time (section 7). The Reader creates one such job and nothing else.
The separation from the DK Security Lab Uploader is deliberate, and the reporting job above is the limit of what the Reader writes. The Uploader is a different application, with its own OAuth client and a wider scope that the Reader does not hold — that scope, and what the Uploader does with it, are set out in the Uploader’s own privacy policy.
4. What is stored, and where
On the owner’s own computer, encrypted with the Windows Data Protection API so that only his account can read them: one OAuth refresh token, and the OAuth client identifier and secret issued by Google. Analytics figures retrieved from the API are displayed and may be written to a local file on that same machine. Nothing is transmitted anywhere except to Google’s own API endpoints.
One thing is stored outside that machine: the reporting job described in section 3. It lives in the owner’s own YouTube account rather than on any server — there is no server — and it records only which daily report YouTube should generate. It holds no video content and no analytics figures. Deleting it is covered in section 7.
5. What does not exist
There is no server, no hosted component, no database, no analytics or telemetry about the person using the Reader, no advertising, no profiling, and no sharing or sale of data to any third party. The Reader contains no network code other than requests to Google’s APIs.
6. Data about other people
The Reader reads aggregate audience statistics for the owner’s own channel — counts, durations, traffic sources and search terms, as YouTube reports them. YouTube provides these aggregated, and the Reader has no way to identify an individual viewer and does not attempt to. It cannot read any other channel.
7. Retention and Deletion
The stored token and any saved figures live only on the owner’s computer and are deleted by deleting those files. Revoking the Reader’s access at Google security settings invalidates the stored token immediately and permanently.
The reporting job described in section 3 does not live on the owner’s computer
— it lives in his YouTube account, so deleting local files does not remove it. It is deleted
with an authorised DELETE to the Reporting API’s jobs endpoint, and
revoking the Reader’s access stops any further reports being retrieved. Reports YouTube has
already generated expire on YouTube’s own schedule: 60 days for a standard report and 30 days
for the backfilled historical ones.
8. Children
The Reader is not directed to children and is used by one adult, its owner.
9. Changes to this policy
If the Reader ever changes what it accesses, this page is updated before that change takes effect, and the date at the top of the page changes with it.
10. Contact
Questions about this policy, or a deletion request:
sentineltutorial@gmail.com
See also the Terms of Service and the DK Security Lab section home.