Privacy Policy
English reference translation. The Japanese original is the legally binding version.
YTDir Privacy Policy
Last updated: May 12, 2026 (version 1.2)
White Label Inc. ("we", "us" or "the Company") establishes this Privacy Policy (this "Policy") as set out below with respect to the handling of personal information in the cloud service "YTDir" (the "Service") provided by the Company, in compliance with the Act on the Protection of Personal Information of Japan (the "APPI") and other applicable laws, regulations and guidelines.
Article 1 (Business Operator Information)
| Item | Details |
|---|---|
| Name | White Label Inc. (株式会社ホワイトラベル) |
| Representative | Ryuto Tanaka, Representative Director |
| Address | Yamato Building 405, 1-6-16 Kanda-Izumicho, Chiyoda-ku, Tokyo 101-0024, Japan |
| Personal Information Protection Manager | Ryuto Tanaka (contact: info@whitelabel-inc.com) |
Article 2 (Personal Information We Collect)
In connection with providing the Service, we may collect the following information.
(1) Information provided directly by the user
- Name and display name (handle)
- Email address and telephone number (optional)
- Authentication credentials (password, passkey, two-factor authentication codes)
- Organization name, job title, industry, website URL
- Information obtained in the course of inquiries and support
- Images uploaded by the user to the Service (facial photographs, reference images, competitor thumbnails, etc.)
- Prompts, scripts, plans and channel information entered by the user into the Service
(2) Payment-related information
Credit card information, billing address, billing name, purchase history and similar data. Card authentication data such as credit card numbers and security codes are collected and managed directly by our payment processor (Stripe, Inc.) and are not stored on our servers.
(3) Information collected automatically through use of the Service
- IP address, cookie ID, device identifiers, browser type and language settings
- Referrer, access timestamps, pages viewed, time spent, operation logs
- API and AI feature invocation logs, error logs, token consumption
- Session replay (only when an error occurs)
(4) Information obtained from third-party services
- Where the user has authorized an authentication integration: authentication status provided by Clerk, and basic Google account information (name, email address, profile image)
- Public metadata relating to a YouTube channel URL entered by the user (retrieved via the YouTube Data API)
Article 3 (Methods of Collection)
We collect the personal information described above by the following methods.
- Entry by the user into forms on the Service's website
- Automatic collection of logs and similar records as the user operates the Service
- Collection through authentication integrations (Clerk, Google OAuth, etc.)
- Retrieval of public information about channels and videos specified by the user via third-party public APIs (YouTube Data API, SerpAPI, Composio, Supadata, etc.)
Article 4 (Purposes of Use)
We use the personal information we collect within the scope of the following purposes.
- Providing the Service, continuously improving its features, and authentication and authorization
- Executing AI features on the Service (generative AI, image generation, agent features)
- Calculating fees, billing, and providing information to our payment processor
- Verifying user identity, authenticating users, and preventing unauthorized use
- Providing notices regarding the Service, including changes, suspension and termination
- Responding to inquiries and support requests, and managing contracts
- Statistical analysis of usage of the Service, quality improvement, new feature development, and marketing
- Failure analysis, security incident response, and legal compliance
- Transferring data in connection with a business succession, merger, corporate split, business transfer or similar event necessary for the operation of the Service
- Other purposes incidental to the purposes listed above
Where we use personal information beyond the scope of the purposes of use set out above, we will obtain the prior consent of the individual concerned.
Article 5 (Provision to Third Parties)
Except where permitted under the APPI or other laws and regulations, we do not provide personal information to third parties without the user's consent.
However, the following cases are not treated as provision to a third party.
- Where handling is entrusted to a subcontractor within the scope necessary to achieve the purposes of use
- Where information is provided in connection with a business succession arising from a merger, corporate split, business transfer or other cause
- Where permitted under the APPI or other laws and regulations
Article 6 (Subcontractors and Third-Party Services)
In providing the Service, we use the following subcontractors, each of which handles personal information for the purpose stated. We require appropriate security control measures and supervise their implementation by entering into data processing agreements (DPAs) and taking other necessary contractual measures with each subcontractor, or by relying on the standard data processing terms published by each subcontractor.
(1) Subcontractors currently in use
| Service | Provider | Purpose of handling | Principal countries of storage and processing |
|---|---|---|---|
| Clerk | Clerk Inc. | Authentication, identity verification, organization management | United States |
| Convex | Convex, Inc. | Database and backend processing | United States |
| Stripe | Stripe, Inc. / Stripe Japan K.K. | Payment processing and subscription billing | United States, Japan |
| Vercel | Vercel Inc. | Hosting and delivery | United States |
| OpenAI | OpenAI, L.L.C. | AI model execution (generative AI features) | United States |
| Google Gemini / YouTube Data API | Google LLC | AI model execution and retrieval of public YouTube information | United States |
| Composio | Composio Inc. | YouTube search and video detail retrieval | United States |
| Supadata | Supadata Inc. | Video transcript retrieval | United States |
| SerpAPI | SerpApi, LLC | Keyword research and search result retrieval | United States |
| Sentry | Functional Software, Inc. (Sentry) | Error monitoring and session replay (on error) | United States |
| Better Stack | BetterStack s.r.o. | Service monitoring and uptime notification | Czech Republic (European Union) |
| Resend | Resend, Inc. | Transactional email delivery | United States |
(2) Subcontractors planned for adoption
| Service | Provider | Purpose of handling | Principal countries of storage and processing |
|---|---|---|---|
| PostHog | PostHog Inc. | Product analytics and feature improvement | United States, Ireland (European Union) |
Subcontractors planned for adoption will be reflected in list (1) above when use actually begins, and will be recorded in the revision history of this Policy. For the certifications and third-party audits held by each subcontractor, please refer to the security and compliance information published by that provider.
(3) Handling of data by AI model providers
Under the enterprise and API terms of use that we rely on, the APIs of AI model providers such as OpenAI and Google Gemini do not, as a general rule, use customer input for additional training of AI models. For the most recent data handling policies of each provider, please also refer to their published policies (for example, OpenAI: https://openai.com/policies/api-data-usage-policies/). If handling changes as a result of a change to an AI provider's terms, we will inform users by revising this Policy or by giving notice within the Service.
Article 7 (Provision of Personal Information to Third Parties in Foreign Countries)
As described in Article 6, the Service uses cloud providers located in foreign countries as subcontractors, and therefore users' personal information may be stored and processed on servers in those countries.
(1) Names of the foreign countries concerned
- United States of America
- European Union (Czech Republic, Ireland, etc.)
- Japan (part of payment processing)
(2) Systems for the protection of personal information in those countries
- United States: there is no comprehensive federal personal information protection law; sector-specific laws apply, including state laws (such as the California CCPA / CPRA), the Federal Trade Commission Act, HIPAA and the GLBA. For details, please refer to the "Survey of Systems for the Protection of Personal Information in Foreign Countries" published on the website of the Personal Information Protection Commission of Japan.
- European Union (Czech Republic, Ireland, etc.): the General Data Protection Regulation (GDPR) applies. The GDPR is directly applicable legislation providing a high level of protection for personal data within the EEA.
(3) Measures taken by those third parties to protect personal information
We require subcontractors located in foreign countries to protect the rights of individuals and to implement security control measures on an ongoing basis, through the conclusion of data processing agreements (DPAs), acceptance of the standard data processing terms published by each provider, or the application of contractual terms equivalent to the standard contractual clauses (SCCs) under the GDPR. Each subcontractor implements security control measures such as encryption, access control, log auditing and data breach notification arrangements. The status of third-party audits (SOC 2, ISO 27001, etc.) held by each subcontractor and the specifics of their handling can be confirmed from each provider's privacy policy and security information pages (links are published on the Service's website). Upon request, we will respond without delay through our contact desk regarding the measures taken by each subcontractor to protect personal information.
Upon request, we will respond without delay regarding the measures taken by each subcontractor to protect personal information. Please contact info@whitelabel-inc.com.
Article 8 (Security Control Measures for Personal Information)
We take the following security control measures to prevent the leakage, loss or damage of personal information.
Organizational security control measures
- Appointment of a Personal Information Protection Manager
- Establishment and operation of handling rules, with periodic inspection and correction
Human security control measures
- Regular education and training for employees
- Obtaining confidentiality undertakings
Physical security control measures
- For in-house devices on which we handle personal information, we implement lock management and measures to prevent loss and theft.
- The physical environment of servers and other equipment that store and process personal information depends on the data centers operated by the subcontractors (cloud providers) listed in Article 6. We continuously verify the effectiveness of physical security control measures such as entry and exit management and lock management through those subcontractors' security certifications and published materials.
Technical security control measures
- Minimization of access privileges (role-based access control)
- Encryption of communications (TLS 1.2 or higher) and encryption at rest
- Detection of anomalous access and log auditing
- Multi-factor authentication (passkey support)
Understanding of the external environment
For each of the foreign countries listed in Article 6, we confirm that country's personal information protection system and continuously verify the effectiveness of our security control measures.
Article 9 (Cookies and Other Tracking Technologies)
We may use technologies such as cookies, local storage, session storage, server logs, tracking pixels and SDKs in the Service for purposes including improving user convenience, improving the Service and detecting unauthorized access.
They are used principally for the following purposes.
- Retaining authentication information (Clerk sessions, etc.)
- Storing the user's environment and operation history
- Performance measurement and error monitoring (Vercel Analytics, Sentry)
- Product analytics (PostHog, planned)
Users may disable cookies through their browser settings; however, doing so may make some features of the Service unavailable.
Article 10 (Retention Period and Deletion)
We retain personal information only for the period necessary to achieve the purposes of use.
- While an account is active: we retain the information necessary to use the Service
- On account deletion: except for information that we are required to retain for business or legal reasons (payment records, tax records, etc.), we promptly delete or anonymize the information
- Backup data: deleted from backups within 90 days at the latest after deletion
- Information for which a separate retention period is prescribed by law: retained in accordance with that statutory retention period
Article 11 (Requests for Disclosure, Correction, Suspension of Use, etc.)
Users may make the following requests with respect to their own personal information held by us, in accordance with the APPI.
- Request for notification of the purpose of use
- Request for disclosure (including disclosure by electronic record)
- Request for correction, addition or deletion
- Request for suspension of use or erasure
- Request for suspension of provision to third parties
- Request for disclosure of records of provision to third parties (Article 33, Paragraph 5 of the APPI)
Please submit requests to the contact desk below, together with a copy of identity verification documents (driver's license, My Number card, etc.). We will confirm the content of the request and respond within a reasonable period.
- Email: info@whitelabel-inc.com (subject line: "Request regarding retained personal data")
Identity verification is carried out by matching against the registered email address and by our prescribed identity verification form. Where a request is made by an agent, we may separately request submission of a power of attorney.
Article 12 (Complaints and Contact Desk)
For inquiries or complaints regarding this Policy or the handling of personal information, please contact us at:
- Email: info@whitelabel-inc.com
- Hours: weekdays 10:00 - 18:00 (excluding weekends, public holidays and the year-end and New Year period)
Article 13 (Handling in OEM and Multi-Tenant Environments)
- The Service includes an "OEM / multi-tenant" capability that allows OEM partners (agencies, corporations, etc.) to resell and operate the Service under their own trade name and brand.
- Where a user uses the Service through an OEM partner, the Company (White Label Inc.) handles personal information as the platform provider of the Service, and that OEM partner handles personal information as the business operator dealing directly with that user. The division of roles and the scope of handling between the two are made clear to the user at sign-up and are set out in the privacy policy established by that OEM partner.
- Where there is a discrepancy between the privacy policy established by an OEM partner and this Policy, this Policy takes precedence with respect to the platform portion of the Service (personal information handled directly by the Company), and the OEM partner's privacy policy takes precedence with respect to the portion handled directly by that partner.
- The personal information of each tenant is technically logically separated on a per-tenant basis and is, as a general rule, not provided to other tenants.
Article 14 (Use by Minors)
The Service is, as a general rule, intended for use by persons aged 18 or over. Minors must obtain the consent of a person with parental authority or a statutory representative before using the Service.
Article 15 (Revision of this Policy)
- We may revise this Policy in response to amendments to laws and regulations, changes to the content of the Service, and similar circumstances.
- Where we make a material change, we will give prior notice of the content of the revised Policy and the date on which it takes effect, by posting within the Service or by sending an email to the user's registered email address, allowing a reasonable period of advance notice (as a guide, at least 30 days).
Article 16 (Use of YouTube API Services)
-
The Service uses the YouTube API Services provided by Google (the YouTube Data API v3 and the YouTube Analytics API) in order to provide YouTube channel analytics features to users.
-
To use these features, the user must authenticate with a Google account (OAuth 2.0) and grant the Service access to the following scopes.
Scope Purpose https://www.googleapis.com/auth/yt-analytics.readonlyRetrieval, via the YouTube Analytics API, of aggregate metrics such as views, watch time, subscriber trends, traffic sources and audience demographics https://www.googleapis.com/auth/youtube.readonlyRetrieval, via the YouTube Data API, of public metadata for the user's own channel, including basic channel information, video list, titles, publication dates and thumbnail URLs -
The types of information retrieved through the YouTube API Services are as follows.
- Basic channel information: channel ID, channel title, subscriber count, total view count, total video count
- Video metadata: video ID, title, publication date and time, thumbnail URL, video duration
- Channel analytics metrics (aggregate values): daily and monthly views, watch time, average view duration, impressions, CTR, subscriber gains and losses
- Audience attributes (aggregate values): only anonymized aggregate data such as age group, gender, country, device and playback location
- Traffic sources: search keywords (aggregate), external referrer URLs (aggregate), and traffic via suggested videos
We do not collect comment text, personal information of comment authors, chat logs, information identifying individual viewers, or any other personal information of third parties on the YouTube platform.
-
The purposes of use of the information retrieved are, in addition to Article 4 of this Policy, limited to the following with respect to information retrieved from the YouTube API Services.
- Aggregation and chart display on the user's own analytics dashboard
- Generation of improvement recommendation reports by AI (the GPT family) for the purpose of supporting the user's own channel operation strategy
- Feeding those recommendations back into the content generation features of the Service (idea planning and script generation) as a feedback loop
We do not use information retrieved from the YouTube API Services for sale to third parties, advertising targeting, disclosure to other users, or additional training of AI models under any circumstances.
-
Handling of OAuth tokens: OAuth access tokens and refresh tokens authorized by the user are encrypted with AES-256-GCM and stored in the Service's database (Convex). The token encryption key is stored separately in the runtime environment as an environment variable, and no third party, including database administrators, can view plaintext tokens.
-
Cache retention period: for performance reasons and to protect YouTube API quota, retrieved analytics data is cached for up to 24 hours. After that period, the cache is automatically refreshed with the latest data the next time the user uses the Service.
-
Revocation of access: users may revoke access at any time by either of the following methods.
- Pressing the "Disconnect YouTube" (YouTube連携を解除する) button shown on the analytics screen of the Service
- Revoking the Service's access from "Security > Third-party access" in the Google account settings (https://security.google.com/settings/security/permissions)
Depending on the revocation route, we completely delete that user's YouTube-related data (including OAuth tokens, channel analytics caches, video metadata and connection metadata) from the Service's database within the following periods.
- Revocation via the disconnect button inside the Service: within 7 days
- Revocation from Google account settings: within 30 days
-
Concurrent application of YouTube's privacy policy: before using the YouTube integration features of the Service, users should also review the following policies published by Google.
- YouTube Terms of Service: https://www.youtube.com/t/terms
- Google Privacy Policy: https://policies.google.com/privacy
This Policy applies to the YouTube integration features of the Service together with those policies.
-
Display of YouTube Brand Features: the Service may display YouTube icons, logos and names in accordance with Google's "YouTube Brand Guidelines". These are trademarks of Google LLC and are not trademarks of the Company.
Revision History
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2026-04-30 | Initial version |
| 1.1 | 2026-05-05 | Added Article 16 (Use of YouTube API Services). In connection with the release of the YouTube Analytics integration, the scopes used, information retrieved, purposes of use, token storage, cache period and revocation methods were made explicit. |
| 1.2 | 2026-05-12 | Revised Article 16, Paragraph 7. To comply with Google OAuth developer policy §III.D.2, the deletion deadline for each revocation route was made explicit (in-app revocation = within 7 days / revocation from Google account settings = within 30 days). The revocation URL was corrected to security.google.com/settings/security/permissions. |