Privacy Policy

English reference translation. The Japanese original is the legally binding version.

YTDir Privacy Policy

Last updated: May 12, 2026 (version 1.2)

White Label Inc. ("we", "us" or "the Company") establishes this Privacy Policy (this "Policy") as set out below with respect to the handling of personal information in the cloud service "YTDir" (the "Service") provided by the Company, in compliance with the Act on the Protection of Personal Information of Japan (the "APPI") and other applicable laws, regulations and guidelines.


Article 1 (Business Operator Information)

ItemDetails
NameWhite Label Inc. (株式会社ホワイトラベル)
RepresentativeRyuto Tanaka, Representative Director
AddressYamato Building 405, 1-6-16 Kanda-Izumicho, Chiyoda-ku, Tokyo 101-0024, Japan
Personal Information Protection ManagerRyuto Tanaka (contact: info@whitelabel-inc.com)

Article 2 (Personal Information We Collect)

In connection with providing the Service, we may collect the following information.

(1) Information provided directly by the user

(2) Payment-related information

Credit card information, billing address, billing name, purchase history and similar data. Card authentication data such as credit card numbers and security codes are collected and managed directly by our payment processor (Stripe, Inc.) and are not stored on our servers.

(3) Information collected automatically through use of the Service

(4) Information obtained from third-party services


Article 3 (Methods of Collection)

We collect the personal information described above by the following methods.

  1. Entry by the user into forms on the Service's website
  2. Automatic collection of logs and similar records as the user operates the Service
  3. Collection through authentication integrations (Clerk, Google OAuth, etc.)
  4. Retrieval of public information about channels and videos specified by the user via third-party public APIs (YouTube Data API, SerpAPI, Composio, Supadata, etc.)

Article 4 (Purposes of Use)

We use the personal information we collect within the scope of the following purposes.

  1. Providing the Service, continuously improving its features, and authentication and authorization
  2. Executing AI features on the Service (generative AI, image generation, agent features)
  3. Calculating fees, billing, and providing information to our payment processor
  4. Verifying user identity, authenticating users, and preventing unauthorized use
  5. Providing notices regarding the Service, including changes, suspension and termination
  6. Responding to inquiries and support requests, and managing contracts
  7. Statistical analysis of usage of the Service, quality improvement, new feature development, and marketing
  8. Failure analysis, security incident response, and legal compliance
  9. Transferring data in connection with a business succession, merger, corporate split, business transfer or similar event necessary for the operation of the Service
  10. Other purposes incidental to the purposes listed above

Where we use personal information beyond the scope of the purposes of use set out above, we will obtain the prior consent of the individual concerned.


Article 5 (Provision to Third Parties)

Except where permitted under the APPI or other laws and regulations, we do not provide personal information to third parties without the user's consent.

However, the following cases are not treated as provision to a third party.


Article 6 (Subcontractors and Third-Party Services)

In providing the Service, we use the following subcontractors, each of which handles personal information for the purpose stated. We require appropriate security control measures and supervise their implementation by entering into data processing agreements (DPAs) and taking other necessary contractual measures with each subcontractor, or by relying on the standard data processing terms published by each subcontractor.

(1) Subcontractors currently in use

ServiceProviderPurpose of handlingPrincipal countries of storage and processing
ClerkClerk Inc.Authentication, identity verification, organization managementUnited States
ConvexConvex, Inc.Database and backend processingUnited States
StripeStripe, Inc. / Stripe Japan K.K.Payment processing and subscription billingUnited States, Japan
VercelVercel Inc.Hosting and deliveryUnited States
OpenAIOpenAI, L.L.C.AI model execution (generative AI features)United States
Google Gemini / YouTube Data APIGoogle LLCAI model execution and retrieval of public YouTube informationUnited States
ComposioComposio Inc.YouTube search and video detail retrievalUnited States
SupadataSupadata Inc.Video transcript retrievalUnited States
SerpAPISerpApi, LLCKeyword research and search result retrievalUnited States
SentryFunctional Software, Inc. (Sentry)Error monitoring and session replay (on error)United States
Better StackBetterStack s.r.o.Service monitoring and uptime notificationCzech Republic (European Union)
ResendResend, Inc.Transactional email deliveryUnited States

(2) Subcontractors planned for adoption

ServiceProviderPurpose of handlingPrincipal countries of storage and processing
PostHogPostHog Inc.Product analytics and feature improvementUnited States, Ireland (European Union)

Subcontractors planned for adoption will be reflected in list (1) above when use actually begins, and will be recorded in the revision history of this Policy. For the certifications and third-party audits held by each subcontractor, please refer to the security and compliance information published by that provider.

(3) Handling of data by AI model providers

Under the enterprise and API terms of use that we rely on, the APIs of AI model providers such as OpenAI and Google Gemini do not, as a general rule, use customer input for additional training of AI models. For the most recent data handling policies of each provider, please also refer to their published policies (for example, OpenAI: https://openai.com/policies/api-data-usage-policies/). If handling changes as a result of a change to an AI provider's terms, we will inform users by revising this Policy or by giving notice within the Service.


Article 7 (Provision of Personal Information to Third Parties in Foreign Countries)

As described in Article 6, the Service uses cloud providers located in foreign countries as subcontractors, and therefore users' personal information may be stored and processed on servers in those countries.

(1) Names of the foreign countries concerned

(2) Systems for the protection of personal information in those countries

(3) Measures taken by those third parties to protect personal information

We require subcontractors located in foreign countries to protect the rights of individuals and to implement security control measures on an ongoing basis, through the conclusion of data processing agreements (DPAs), acceptance of the standard data processing terms published by each provider, or the application of contractual terms equivalent to the standard contractual clauses (SCCs) under the GDPR. Each subcontractor implements security control measures such as encryption, access control, log auditing and data breach notification arrangements. The status of third-party audits (SOC 2, ISO 27001, etc.) held by each subcontractor and the specifics of their handling can be confirmed from each provider's privacy policy and security information pages (links are published on the Service's website). Upon request, we will respond without delay through our contact desk regarding the measures taken by each subcontractor to protect personal information.

Upon request, we will respond without delay regarding the measures taken by each subcontractor to protect personal information. Please contact info@whitelabel-inc.com.


Article 8 (Security Control Measures for Personal Information)

We take the following security control measures to prevent the leakage, loss or damage of personal information.

Organizational security control measures

Human security control measures

Physical security control measures

Technical security control measures

Understanding of the external environment

For each of the foreign countries listed in Article 6, we confirm that country's personal information protection system and continuously verify the effectiveness of our security control measures.


Article 9 (Cookies and Other Tracking Technologies)

We may use technologies such as cookies, local storage, session storage, server logs, tracking pixels and SDKs in the Service for purposes including improving user convenience, improving the Service and detecting unauthorized access.

They are used principally for the following purposes.

Users may disable cookies through their browser settings; however, doing so may make some features of the Service unavailable.


Article 10 (Retention Period and Deletion)

We retain personal information only for the period necessary to achieve the purposes of use.


Article 11 (Requests for Disclosure, Correction, Suspension of Use, etc.)

Users may make the following requests with respect to their own personal information held by us, in accordance with the APPI.

Please submit requests to the contact desk below, together with a copy of identity verification documents (driver's license, My Number card, etc.). We will confirm the content of the request and respond within a reasonable period.

Identity verification is carried out by matching against the registered email address and by our prescribed identity verification form. Where a request is made by an agent, we may separately request submission of a power of attorney.


Article 12 (Complaints and Contact Desk)

For inquiries or complaints regarding this Policy or the handling of personal information, please contact us at:


Article 13 (Handling in OEM and Multi-Tenant Environments)

  1. The Service includes an "OEM / multi-tenant" capability that allows OEM partners (agencies, corporations, etc.) to resell and operate the Service under their own trade name and brand.
  2. Where a user uses the Service through an OEM partner, the Company (White Label Inc.) handles personal information as the platform provider of the Service, and that OEM partner handles personal information as the business operator dealing directly with that user. The division of roles and the scope of handling between the two are made clear to the user at sign-up and are set out in the privacy policy established by that OEM partner.
  3. Where there is a discrepancy between the privacy policy established by an OEM partner and this Policy, this Policy takes precedence with respect to the platform portion of the Service (personal information handled directly by the Company), and the OEM partner's privacy policy takes precedence with respect to the portion handled directly by that partner.
  4. The personal information of each tenant is technically logically separated on a per-tenant basis and is, as a general rule, not provided to other tenants.

Article 14 (Use by Minors)

The Service is, as a general rule, intended for use by persons aged 18 or over. Minors must obtain the consent of a person with parental authority or a statutory representative before using the Service.


Article 15 (Revision of this Policy)

  1. We may revise this Policy in response to amendments to laws and regulations, changes to the content of the Service, and similar circumstances.
  2. Where we make a material change, we will give prior notice of the content of the revised Policy and the date on which it takes effect, by posting within the Service or by sending an email to the user's registered email address, allowing a reasonable period of advance notice (as a guide, at least 30 days).

Article 16 (Use of YouTube API Services)

  1. The Service uses the YouTube API Services provided by Google (the YouTube Data API v3 and the YouTube Analytics API) in order to provide YouTube channel analytics features to users.

  2. To use these features, the user must authenticate with a Google account (OAuth 2.0) and grant the Service access to the following scopes.

    ScopePurpose
    https://www.googleapis.com/auth/yt-analytics.readonlyRetrieval, via the YouTube Analytics API, of aggregate metrics such as views, watch time, subscriber trends, traffic sources and audience demographics
    https://www.googleapis.com/auth/youtube.readonlyRetrieval, via the YouTube Data API, of public metadata for the user's own channel, including basic channel information, video list, titles, publication dates and thumbnail URLs
  3. The types of information retrieved through the YouTube API Services are as follows.

    • Basic channel information: channel ID, channel title, subscriber count, total view count, total video count
    • Video metadata: video ID, title, publication date and time, thumbnail URL, video duration
    • Channel analytics metrics (aggregate values): daily and monthly views, watch time, average view duration, impressions, CTR, subscriber gains and losses
    • Audience attributes (aggregate values): only anonymized aggregate data such as age group, gender, country, device and playback location
    • Traffic sources: search keywords (aggregate), external referrer URLs (aggregate), and traffic via suggested videos

    We do not collect comment text, personal information of comment authors, chat logs, information identifying individual viewers, or any other personal information of third parties on the YouTube platform.

  4. The purposes of use of the information retrieved are, in addition to Article 4 of this Policy, limited to the following with respect to information retrieved from the YouTube API Services.

    • Aggregation and chart display on the user's own analytics dashboard
    • Generation of improvement recommendation reports by AI (the GPT family) for the purpose of supporting the user's own channel operation strategy
    • Feeding those recommendations back into the content generation features of the Service (idea planning and script generation) as a feedback loop

    We do not use information retrieved from the YouTube API Services for sale to third parties, advertising targeting, disclosure to other users, or additional training of AI models under any circumstances.

  5. Handling of OAuth tokens: OAuth access tokens and refresh tokens authorized by the user are encrypted with AES-256-GCM and stored in the Service's database (Convex). The token encryption key is stored separately in the runtime environment as an environment variable, and no third party, including database administrators, can view plaintext tokens.

  6. Cache retention period: for performance reasons and to protect YouTube API quota, retrieved analytics data is cached for up to 24 hours. After that period, the cache is automatically refreshed with the latest data the next time the user uses the Service.

  7. Revocation of access: users may revoke access at any time by either of the following methods.

    Depending on the revocation route, we completely delete that user's YouTube-related data (including OAuth tokens, channel analytics caches, video metadata and connection metadata) from the Service's database within the following periods.

    • Revocation via the disconnect button inside the Service: within 7 days
    • Revocation from Google account settings: within 30 days
  8. Concurrent application of YouTube's privacy policy: before using the YouTube integration features of the Service, users should also review the following policies published by Google.

    This Policy applies to the YouTube integration features of the Service together with those policies.

  9. Display of YouTube Brand Features: the Service may display YouTube icons, logos and names in accordance with Google's "YouTube Brand Guidelines". These are trademarks of Google LLC and are not trademarks of the Company.


Revision History

VersionDateChanges
1.02026-04-30Initial version
1.12026-05-05Added Article 16 (Use of YouTube API Services). In connection with the release of the YouTube Analytics integration, the scopes used, information retrieved, purposes of use, token storage, cache period and revocation methods were made explicit.
1.22026-05-12Revised Article 16, Paragraph 7. To comply with Google OAuth developer policy §III.D.2, the deletion deadline for each revocation route was made explicit (in-app revocation = within 7 days / revocation from Google account settings = within 30 days). The revocation URL was corrected to security.google.com/settings/security/permissions.