Security and permissions
This page is based on behaviors that can be verified in the product codebase. It does not contradict the Privacy Policy — see that page for full detail.
Chrome permissions and why
storage
To store session preferences, language and extension settings on device. Not used to permanently dump your video content into Chrome storage.
activeTab / scripting
To read and (when you ask) fill title, description and tag fields on YouTube Studio pages. Runs in the Studio context.
sidePanel
To show the Youtio UI in Chrome’s side panel.
cookies
So your youtio.com session can be recognized in the extension for account-linked features.
Host permissions (studio.youtube.com, youtube.com, youtio.com…)
To write Studio fields, display channel imagery and call the Youtio API securely. Not used on arbitrary websites.
What data is processed?
Account email and profile fields; connected YouTube channel IDs; YouTube OAuth access/refresh tokens (AES-256-GCM encrypted in the app database); a signed JWT session cookie. For authenticated generation runs, inputs you provide (video URL, title, description, transcript) and generated metadata drafts may be stored on Generation records. UsageLog stores action type and credit cost only (no raw transcript field). Most free web tools run in the browser; tools that call the server (such as Promise Match) send inputs for that request.
What is sent to AI providers?
For authenticated generation, your transcript and other metadata fields are included in the text prompt sent to configured AI providers (e.g. OpenAI / Gemini). Thumbnail image flows may send a truncated transcript sample. Free Promise Match requests send title, thumbnail text, opening (hook) text, niche, audience and language. AI providers’ own retention policies cannot be verified from this product’s code.
Results and analytics
Generated titles, description, tags, scores and thumbnail fields may be stored on Generation records for your account. Product analytics (dataLayer) blocks email, name, token, password and long-content keys and does not send a raw transcript parameter. Promise Match share cards are generated client-side and do not include the full transcript.
Retention and deletion
This page does not invent exact day counts. Connected channels and encrypted tokens remain until you disconnect or delete your account. Account deletion removes Generation rows (including transcript), Channel rows (including tokens), UsageLog, profile templates and related app records. Feedback rows and hosting / AI-provider logs may fall outside that deletion path. You can also revoke access in Google Account permissions.
AI output and your review
AI suggestions can be wrong or inappropriate. Always review title, description, tags and cover text before publishing. Youtio does not guarantee performance, CTR or ranking.
YouTube / Google relationship
Youtio is an independent product. It is not officially affiliated with, endorsed by, or partnered with YouTube or Google. YouTube is a trademark of Google LLC.