Last updated: 7 September 2026
Clever Arts Ltd (Клевър Артс ООД), a company registered in Bulgaria (company no. 203987047, VAT BG203987047), with registered office at 2 Eliezer Kalev St., Plovdiv, Bulgaria, trading as CreatorWarden ("we", "us"), operates creatorwarden.com. This policy explains what data we handle, why, who processes it for us, how long we keep it, and how you have it deleted.
We are the data controller for the purposes of the EU General Data Protection Regulation (GDPR), and we apply the same standard to everyone who uses the service, wherever they live. Our managing director is Bozhidar Yanakiev. You can reach us at [email protected], or by post at the registered office above.
This application uses YouTube API Services. By using it you agree to the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy.
The short version. We read only what is already public on YouTube: a little public information about your videos through the official YouTube Data API, and the content of each public video as read and described for us by Google's Gemini service. We never sign in as you, we never ask for access to your Google Account, and we never download your videos. We do not sell or share your data, we do not use it to train AI models, and we delete it on request within 7 days.
When you request a free scan we process:
To produce the report we read, through the official YouTube Data API, public information about the videos: their identifiers, titles, duration and whether they are public. We use this only to show you which video a finding belongs to; it plays no part in the assessment itself. Then Google's Gemini service reads each public video directly from its YouTube address and returns to us a written description of it — what is said, what is shown, and any text on screen. That description can contain personal data about you and about people who appear or speak in the video. Our system assesses the description against YouTube's published policies. The free scan is fully automatic: no person reads your videos or the description.
Paid tiers work the same way, on more videos. You give us the link to your channel. Through the YouTube Data API we read only the identifiers and publication dates of your public videos, to count them and to prepare export links for you. You then export the list of your videos (identifiers, titles, durations) from your own YouTube Studio Analytics and send us the files. We never ask you to connect your Google Account or to invite us into YouTube Studio; the export is something you do yourself, and only the channel owner can do it. We request no access of any kind to your account and cannot upload, edit, delete or publish anything.
| Data | Why we need it |
|---|---|
| Identifiers and publication dates of your public videos, from the YouTube Data API | To count your videos and prepare the export links. Not used in the assessment. |
| Your YouTube Studio export (video identifiers, titles, durations) | The catalogue we work from. Titles from your export may be assessed against the title rules; we never take titles from the API for that. |
| Description of each public video, produced by Google's Gemini service | The material our assessment is made on. It is our observation of the public video, not a caption or transcript file from YouTube. |
| Files you choose to give us (Shield): your own original video or text files | Only if you send them, to give the assessment more context than the public video alone. |
| Notices or decisions you received from YouTube (Warden Case) | Only if you send them, to prepare your case file. |
| Billing details (name, company, address, tax number) | To invoice you and to keep the records the law requires. |
In the Deep Audit and in Shield, a named CreatorWarden reviewer reads material findings before you receive them. We ask for your consent to that before any person reads anything about your channel.
Our site is served by Cloudflare. Cloudflare processes standard request data (such as IP address and user agent) to deliver the site and protect it from abuse. We set no cookies and use no local storage, advertising cookies or third-party tracking scripts. We send email through Resend; every message we send includes our postal address and an unsubscribe link, and we send marketing only to people who have asked for it. Our own team is notified of a new request only by a count — that notification carries no personal data.
CreatorWarden's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the YouTube API Services Developer Policies. Specifically:
On automated analysis and AI. Your assessments are produced with the help of an AI model — Google's Gemini, used through Google's paid API under a data processing agreement, with your data not used to train Google's models. The video description and the assessment are generated by AI and every report says so. In the paid tiers, material findings are checked by a person before delivery. If we ever use another AI provider on your data, we will name it here first.
We store findings — the clause, the evidence and the date — rather than copies of your catalogue.
| What | Retention |
|---|---|
| Data from the YouTube Data API | Refreshed or deleted within 30 days |
| Video descriptions produced by Gemini — free scan | Deleted once your report is produced |
| Video descriptions produced by Gemini — paid tiers | Kept while the service runs, deleted within 30 days after it ends |
| Your YouTube Studio export | Kept while the service runs, deleted within 30 days after it ends |
| Your reports, findings and channel record | Kept while the service runs; available for export for 30 days after it ends, then deleted |
| Files and notices you gave us | Deleted within 30 days after the last deliverable they were used for |
| Your request and consent record (email, video links, time, IP) | Kept as evidence of your consent for 3 years after our last contact with you, or until you ask us to delete it |
| Billing records | As required by Bulgarian and EU accounting law |
Whatever the period, you can ask for deletion at any time: email us and we delete your data within 7 days. Deleting data held by us changes nothing on YouTube — your channel and videos are untouched.
We do not hold any access to your Google Account or YouTube channel, so there is nothing to revoke. Should we ever ask for authorised access in future, you would be able to withdraw it at any time at security.google.com/settings/security/permissions, and we would say so here first.
You have the right to access, correct, delete, restrict or object to our processing of your personal data, the right to receive it in a portable format, and the right to withdraw consent at any time. Our legal bases are performance of a contract (delivering the service you asked for), your consent (for the free scan and for any person reading your findings), our legal obligations (accounting), and our legitimate interest in operating and securing the service. People who appear in a video we assess may exercise the same rights.
Write to [email protected] and we will respond within 30 days. You also have the right to complain to the Bulgarian Commission for Personal Data Protection (cpdp.bg) or to your local supervisory authority.
If you live outside the EU. We apply the rights above to you as well. In the United Kingdom you may also complain to the Information Commissioner's Office. In Brazil you have the rights of the LGPD and may contact us as the person responsible for data protection at the address above. In Canada, Australia, India and elsewhere, the local privacy laws that apply to you are honoured on the same basis. We do not sell personal data and never have.
| Provider | Role | Transfer safeguard |
|---|---|---|
| Google — YouTube Data API | Source of public video information; Google acts as an independent controller of YouTube | Google's own terms and privacy policy |
| Google — Gemini API (paid tier) | Processor: reads public videos and produces the description we assess; Google keeps prompts only briefly, for abuse detection | Google's data processing addendum; SCC / Data Privacy Framework |
| Cloudflare | Processor: hosting, the request form, and the store for your request and consent record | Cloudflare's data processing addendum; SCC / Data Privacy Framework |
| Resend (United States) | Processor: sends our email to you | Resend's data processing addendum; SCC |
Payment today is by invoice; if we add a card payment provider we will name it here. Where a provider processes data outside the European Economic Area, we rely on the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
The service is for professional creators aged 18 or over. We do not knowingly collect personal data from anyone younger.
If we change this policy we will update the date at the top, and for material changes we will notify active subscribers by email.