Content Radar

Content Radar Privacy Policy — English draft

Product: Content Radar
Planned public URL: https://contentradar.eu/privacy
Controller: BIZNESFUN Spółka z o.o., NIP 5423515903, ul. Legionowa 10/208, 15-099 Białystok, Poland
Version: draft 2026-10-02 — requires owner/legal approval before publication

This notice describes the planned external-user service. It must not be published as a statement of an available feature until the corresponding account, deletion, export and Google OAuth functions exist and have been tested.

1. Data we process

When you connect YouTube, Content Radar requests the read-only scope https://www.googleapis.com/auth/youtube.readonly. We may process:

We do not request permission to publish videos, modify your channel or act as you. Content Radar is not intended for children.

2. Why and on what legal basis

We do not use your likes to train a personalized model in this release and do not make legal or similarly significant decisions about you. A future feature that learns from individual taste requires a separate assessment, transparent notice and, where required, a DPIA and new consent before activation.

3. What the service does with likes

Content Radar checks recent liked-video identifiers so it can bring selected material into the user-visible radar. Only material that passes the configured relevance funnel is retained with its text, automated assessment and report. For rejected material, the service retains only the minimum video identifier needed to prevent repeated processing, plus short operational records. It does not sell, advertise against or create an unrelated profile from your YouTube activity.

4. Google API Services User Data — Limited Use

Content Radar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is used only to provide or improve prominent user-facing Content Radar features. It is not sold, used for advertising, used to determine creditworthiness or lending, or transferred for unrelated purposes. Transfers are limited to service providers acting for us where necessary to provide or secure the feature, under appropriate agreements, or where required by law. Humans do not read Google user data except with the user's affirmative agreement for a specific item, when necessary for security or abuse investigation, to comply with law, or where data has been aggregated and anonymised for internal operations in accordance with Google's policy.

5. Service providers and international transfers

We use processors only for the stated service purpose. Some providers process data outside the EEA. The safeguards below are the provider terms found during preparation; the Controller must accept or execute each applicable DPA and verify account settings before external launch.

Provider Planned data/purpose Transfer safeguard and status at 2026-10-02
Google Cloud / YouTube API OAuth, account/video/likes data, API delivery Google Cloud Data Processing Addendum and EU-US Data Privacy Framework information. Owner acceptance/account configuration to verify.
OpenRouter text sent to the selected model and output routing DPA, including processor terms, SCC mechanism and ZDR provisions. Enable ZDR/no-training routing and verify it for the selected endpoint before launch.
TypeSafe AI / Jev material text and structured questions/decisions DPA; privacy policy; subprocessors in its Trust Center. TypeSafe states that Jev is not trained on requests/responses. Owner acceptance and transfer mechanism to verify.
Supadata video URL; transcript when this path is authorized Supadata DPA and subprocessor list, which states SCC or EU-US DPF safeguards for non-EU providers. DPA exists; owner acceptance and current list to verify.
Groq audio and speech-to-text output only if the fallback is enabled Groq Data Processing Addendum, incorporating EU SCCs. Not an external-user production path until enabled and accepted.
Notion user-facing report, status and decisions Notion Data Processing Addendum and security/compliance information. Workspace DPA and public-sharing settings to verify.

Our own application database is planned to store Content Radar records. Hosting location, hosting processor identity, backup retention and its DPA must be inserted here after ops fixes the external production architecture; publication with this row unresolved is not approved.

6. Retention and deletion

A deletion does not cover data that must be retained by law; any exception will be isolated, access-restricted and explained. The service must not promise a deletion button until the YCA4 account/deletion implementation has passed acceptance.

7. Your choices and rights

You can withdraw YouTube access in Content Radar (once the disconnect control is released) and at Google Account — third-party connections. You may also request access, correction, deletion, restriction, objection, or portability. The planned export is a structured JSON file containing your account settings, retained source records, assessments and decisions. We normally respond within one month as required by GDPR Art. 12(3).

Until a verified privacy email exists, send requests by post to the Controller address above. Before publication, the owner must activate and test privacy@contentradar.eu and add it here. You may lodge a complaint with Poland's supervisory authority, the Prezes Urzędu Ochrony Danych Osobowych (UODO), or your local authority.

8. Security and incidents

We use access controls, secret management, transport encryption, least-privilege OAuth scopes, processor agreements, logging and documented incident response. No internet service is risk-free. Our internal response procedure is in docs/legal/breach-response.md and includes the GDPR 72-hour supervisory-notification assessment.

9. Changes

Material changes to Google-data access or use will be disclosed before they take effect. Where the legal basis is consent, we will request renewed consent. The effective public policy and the policy linked from the Google OAuth consent screen must be the same URL and version.

Sources checked

Official sources accessed 2026-10-02: Google API Services User Data Policy; Google OAuth verification requirements; GDPR text; processor documents linked in §5. This is an operational draft, not legal advice.