Plain language, no fine-print tricks

Privacy Policy

Last updated: 23 July 2026

Saucefox (“we”, “us”) provides creators with resource pages (“vaults”) whose downloads can unlock after a viewer verifies a YouTube subscription or, where a creator enables it, submits an email address. Saucefox uses YouTube API Services. This policy comprehensively describes the user information and YouTube API Data that we access, collect, store, or otherwise use; the purposes for which we process it; the people and service providers that may process it; and the choices available to you. Contact: support@saucefox.com.

By using Saucefox features that access YouTube API Services, you also agree to be bound by the YouTube Terms of Service. Google's handling of information is described in the Google Privacy Policy. Saucefox is not endorsed by or affiliated with YouTube or Google.

1. Complete YouTube API Data inventory

A. Public channel and video metadata

A creator may enter a public YouTube channel URL, handle, channel ID, or video URL. Using our server-side YouTube API key, Saucefox may access the following public YouTube API Data:

  • channels.list(part=snippet, id=…) or channels.list(part=snippet, forHandle=…) — channel ID, channel title, handle or custom URL, profile-image URL, and channel description.
  • videos.list(part=snippet, id=…) — video ID, title, description, thumbnail URL, and the publishing channel ID.

We use this public metadata to resolve the channel selected by the creator, display an ownership confirmation, compare an optional ownership code placed in the public channel description, and pre-populate a vault from a public video. Channel ID, title, handle, profile-image URL, and verification state are stored with the creator's channel record. Imported video ID, title, description, thumbnail URL, and channel ID are stored with the related vault only when the creator chooses to import that video. The full channel description is processed only during resolution or ownership verification and is not stored.

Stored public channel metadata remains while the creator keeps the channel connected. Stored imported video metadata remains while the related vault exists. It is deleted when the creator deletes the corresponding vault or account, or after we complete a valid deletion request. Creators may edit imported vault text independently of YouTube after import.

B. Viewer subscription verification

When a viewer chooses “Verify with YouTube”, they sign in with Google and grant exactly one read-only permission: https://www.googleapis.com/auth/youtube.readonly (“View your YouTube account”). This is the narrowest Google permission that allows Saucefox to check a subscription. The viewer flow requests no openid, email, or profile permission and requests no ID token.

  • channels.list(part=id, mine=true)accesses the raw ID of the viewer's own YouTube channel. It is used only to create the pseudonymous identifier described below.
  • subscriptions.list(mine=true, forChannelId=…)accesses only whether the signed-in viewer is subscribed to the specific creator channel associated with the vault. Saucefox does not fetch, collect, or store the viewer's subscription list.

These are the only YouTube API calls made with viewer authorization. Saucefox cannot and does not post, like, comment, subscribe, upload, edit, or delete anything on the viewer's behalf.

The raw viewer channel ID is transformed immediately on our server into a salted SHA-256 hash and is then discarded. The raw channel ID is never written to our database, logs, analytics, cookies, or responses. We store only the salted hash, the creator channel being checked, the vault and creator association, the eligible or ineligible verification result, timestamps, a limited failure reason where applicable, and the resulting unlock-session record. We use this pseudonymous data to return the result, prevent repeated verification, enforce a short retry cooldown, remember a valid unlock, prevent abuse, and calculate Saucefox funnel metrics.

Viewer verification and unlock records are retained for no more than 30 days and then deleted automatically. Aggregate funnel counters do not contain a viewer identity. Any derived metrics are clearly identified as Saucefox-generated rather than YouTube metrics.

C. Creator channel-ownership verification

A creator may prove ownership using a one-time Google authorization. The creator grants the same read-only youtube.readonly permission. Saucefox calls only channels.list(part=id, mine=true), accesses the creator's own channel ID, and compares it with the channel the creator claimed. We store the verified channel ID, verification method, verification status, and verification time so we can restrict channel management and vault publication to the owner. We do not fetch or store the creator's videos, subscriptions, playlists, comments, or other private account content through this authorization.

The creator's verified channel ID and verification record remain while the channel is connected to an active Saucefox account. They are deleted when the creator account is deleted or after a valid deletion request.

D. OAuth tokens and data we do not retain

  • Viewer and ownership-flow OAuth access tokens exist only in server memory during the single verification request. They are never stored in a database, log, analytics event, browser storage, or cookie.
  • We request access_type=online, do not request offline access, and never request, receive, or store a refresh token.
  • The viewer flow does not receive or store the viewer's Google email address, name, profile image, Google account ID, or ID token.
  • Saucefox does not use YouTube API Data for advertising, credit, surveillance, or sale, and does not combine it with third-party advertising profiles.

2. How information is used and who can access it

What the viewer and creator see

The viewer receives only the result needed for the selected vault: eligible, ineligible, retry later, or error. The relevant creator may see aggregated, Saucefox-generated funnel counts, such as verification attempts, successful unlocks, and downloads. Creators do not receive the viewer's raw channel ID, salted channel hash, Google identity, access token, subscription list, or an individual viewer profile.

Internal access

Saucefox systems process the data automatically for the purposes described above. Access by Saucefox personnel is restricted to authorized operators who need it for user-requested support, security and abuse investigation, maintenance, or legal compliance. We do not routinely permit humans to read Google user data.

External processing and disclosure

We do not sell, rent, license, or disclose Google user data to advertisers, data brokers, or unrelated third parties. The following service providers process limited information solely to operate Saucefox under our instructions:

  • Google and YouTube receive OAuth and YouTube API requests and return the specific API Data described in Section 1.
  • Vercel hosts the Saucefox web application and transiently processes HTTPS requests, OAuth callbacks, and the request-scoped access token in application memory. The token is discarded before the request ends and is not placed in Vercel logs or persistent storage.
  • Supabase / PostgreSQL stores creator account data, connected-channel and vault metadata, the salted viewer identifier, verification and unlock records, and first-party funnel events. It does not receive or store Google OAuth access or refresh tokens or a raw viewer channel ID.
  • Cloudflare R2 stores creator-uploaded vault files in a private bucket. It does not receive YouTube API Data or Google OAuth tokens. Files are delivered only through signed links that expire after 10 minutes.

We may disclose the minimum information necessary if required by applicable law, court order, or to address an immediate security threat. If Saucefox is involved in a merger, acquisition, or asset sale, users will receive notice before personal information becomes subject to a materially different privacy policy.

Limited Use disclosure

Saucefox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with the user's affirmative agreement for specific data, when necessary for security or abuse investigation, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

3. Creator account information

Creators may register with an email address and password or use Google Sign-In. Google Sign-In for the creator's Saucefox account is separate from both YouTube verification flows described above. It may provide the creator's Google account identifier, email address, name, and profile image to establish and authenticate the account. We store the creator's email address and name in the Saucefox user record; the authentication session may temporarily contain the account identifier and profile image. We use this information only for account access, security, support, and service communications.

We also store creator-supplied vault content and files, settings, billing status, and necessary service records. A password is stored only as a one-way password hash. Creator account information remains while the account is active and is deleted when the account is deleted, subject to narrow records we must retain for security, fraud prevention, tax, or other legal obligations.

4. Viewer emails (only when typed)

Some creators enable optional email collection. An email address is collected only when the viewer types it into a Saucefox form — never from Google or YouTube. Each submission stores the address, timestamp, related vault and creator, and the version of the consent text shown. It is used for the purpose stated beside that form and is available to the selected creator. Viewers may request deletion at any time via support@saucefox.com.

5. Cookies and first-party analytics

Public vault pages use no third-party analytics trackers and set no advertising or analytics cookies. First-party funnel events such as page viewed, unlock clicked, verification result, and download are recorded server-side using the pseudonymous and aggregate practices described above. Strictly necessary cookies include a short-lived, HttpOnly sign-in state cookie used to prevent OAuth request forgery and an HttpOnly unlock cookie that remembers a successful verification for up to 30 days. Creator dashboard authentication uses a strictly necessary session cookie.

6. Revoke access, deletion, and your rights

You can revoke Saucefox's Google access at any time from your Google Account permissions. Because Saucefox never stores a YouTube OAuth token, revocation prevents any future authorization unless you explicitly consent again.

To erase pseudonymous verification data associated with your YouTube channel, email support@saucefox.com with the subject “Viewer data deletion request”. We will use a one-time channel identification step solely to locate the salted hash, then delete related verification and unlock records as soon as possible and no later than seven calendar days after a valid request. Deleting Saucefox data does not delete data held by YouTube.

You may request access, correction, export, restriction, or deletion of personal information by writing to support@saucefox.com. Creators may also request deletion of their account, connected channel records, vault metadata, and private vault files. We will respond in accordance with applicable data-protection law.

7. Security and changes

We use HTTPS, access controls, private file storage, short-lived signed download links, HttpOnly cookies, and data minimization to protect the information described above. No online service can guarantee absolute security. We will update this page when our practices change and adjust the “Last updated” date above. Material changes will be communicated through the service or by email where appropriate.