Privacy Policy
Last updated 3 October 2026
The short version
The main points. The rest of this policy gives the detail.
- You sign in with Google. Kuapy receives your email address and your Google account ID. There is no Kuapy password.
- Kuapy asks Google for read-only access to YouTube (the
youtube.readonlypermission). It uses it only to read your subscriptions and the public details of channels and new videos. It never posts, never changes your subscriptions and never touches the rest of your Google account. - Summaries are written by a language model from transcripts supplied by a transcript provider. Nothing is edited by hand. The transcript provider receives only public video IDs. The language model service receives transcripts, video titles, descriptions and channel names, summaries and category names, but never your email address, your Google account ID or your subscription list.
- Kuapy has no ads, no advertising or tracking cookies and no outside analytics service, and we never sell your data. Thumbnails, channel icons and videos come from YouTube, which may show its own ads and set its own cookies (see Cookies and storage on your device).
- To improve the service, Kuapy keeps its own record of what you do in your digest, such as which summaries you open and which videos you play. The record is deleted after 90 days, is never used for ads and is never sold, and you can object to it (see Your reading activity in Kuapy).
- Your data is stored by our hosting provider, Railway, in the United States.
- You can delete your account at any time. We delete your data within 7 days.
- You can remove Kuapy’s access at any time in your Google Account permissions.
Who is responsible for your data
Kuapy is run by Condor LLC, the controller of your personal data: it decides why and how your data is used. In this policy, “Kuapy”, “we” and “us” mean Condor LLC.
- Name: Condor LLC
- Address: 15442 Ventura Blvd., Ste 201-3022, Sherman Oaks, CA 91403, USA
- Email: info@kuapy.com
Kuapy has not appointed a data protection officer. For any question about your data, write to the email address above.
Google user data: what Kuapy accesses and stores
This section and the four after it cover only the data Kuapy receives from Google, called “Google user data” in this policy. All other data is covered in Other data Kuapy handles.
What Kuapy asks Google for. When you sign in, Google asks you to give Kuapy three permissions:
- Sign-in (
openid): confirms who you are. Kuapy receives your Google account ID, a code that identifies your Google account. - Email address (
email): Kuapy receives your email address, and accepts it only if Google has verified it. - Read-only YouTube access (
youtube.readonly): lets Kuapy view your YouTube account without changing it. Kuapy uses it only to read your subscriptions and the public details of channels and new videos.
What Kuapy reads from YouTube. Through the YouTube API, Kuapy reads:
- your subscriptions: for each channel you subscribe to, its ID, name, description and thumbnail image address;
- public channel details: each channel’s name, description, thumbnail image address, list of uploads and the topic categories YouTube gives it;
- public details of new videos: title, description, publication date, length, thumbnail image address, view, like and comment counts, player size (used to recognise YouTube Shorts), and whether the video is public or a live stream.
What Kuapy stores.
- Your Google account ID and email address, to identify your account.
- A refresh token from Google, encrypted. It lets Kuapy renew its read-only access each day without asking you to sign in again.
- Your subscription list, and the channel and video details above, including the titles, lengths, thumbnails and counts shown in your digests.
- A record of what you do in your digest, such as opening a summary, which includes the YouTube IDs of the video and its channel (see Your reading activity in Kuapy).
Kuapy does not store the short-lived access tokens that Google issues. They stay in memory and expire after about an hour.
What Kuapy never accesses. Your Google password; your name or profile photo; your watch history, your own likes and comments, your uploads or your own playlists; and any other Google service, such as Gmail, Drive or Contacts. Kuapy never posts, subscribes, unsubscribes or changes anything in your YouTube or Google account.
Google user data: how Kuapy uses it
Kuapy uses Google user data only to provide and improve the features you see in Kuapy:
- to sign you in and keep your account separate from everyone else’s;
- to show your subscriptions, so you can choose which channels appear in your digest;
- to suggest a category for each channel, which you can rename;
- to find new videos from the channels you chose, and check that each one is public, finished, not a YouTube Short and not too long to summarise;
- to sort each new video by type, from its title, channel name, description and the start of its transcript, so your digest can group similar videos;
- to show each video’s title, channel, channel icon, length, thumbnail and YouTube’s view, like and comment counts in your digest, with a link to the video on YouTube;
- to translate video titles, summaries and syntheses into the language you chose for Kuapy;
- to write a short synthesis for each category, from the titles and summaries of that day’s videos;
- to count the videos Kuapy processes for you each month;
- to improve these features, and to build recommendations in future, from the record of what you do in your digest, which includes the YouTube IDs of the videos and channels involved. The person who runs Kuapy sees only statistics from it, never which videos or channels you opened (see Your reading activity in Kuapy).
Your subscriptions and your digests are shown only to you. Kuapy reads your YouTube data when you load or refresh your subscriptions in Kuapy, and once a day to prepare your digest.
Channel and video details are public and the same for everyone. To find new videos, Kuapy requests these public details in batches for all members, each time using one member’s read-only access. A request made with your access may therefore include public videos from channels that other members chose. These requests read only public details: they never read another member’s account, and no other member’s access is ever used to read your subscriptions.
Kuapy does not use Google user data for any other purpose.
Limited Use of Google user data
Kuapy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice:
- Kuapy uses Google user data only to provide and improve the features described in this policy, which you can see in Kuapy.
- The record of your reading activity includes the YouTube IDs of the videos and channels involved. Kuapy uses it only to improve features you see in Kuapy, such as recommendations in future, and to give the person who runs Kuapy statistics that never show which videos or channels you opened. It is never used for advertising and never sold (see Your reading activity in Kuapy).
- Kuapy does not use Google user data for advertising, including personalised, retargeted or interest-based ads.
- Kuapy does not sell Google user data, and never transfers it to advertising platforms, data brokers or information resellers.
- Kuapy does not use Google user data to decide creditworthiness or for lending.
- Kuapy does not use Google user data to build databases or profiles for any other purpose.
- Kuapy does not use Google user data to train generalised or non-personalised artificial intelligence or machine learning models.
- Kuapy transfers Google user data only as described in Google user data: who it is shared with: to provide these features, to keep Kuapy secure, to comply with the law, or, with your explicit consent given in advance, as part of a merger, acquisition or sale of assets.
- No person reads your Google user data, except: with your agreement for specific data, for example to help with a support request; when needed for security, such as investigating abuse or a bug; to comply with the law; or when the data is aggregated and used for internal operations, as the law allows.
- Everyone who works on Kuapy, including contractors, must follow these rules.
Google user data: who it is shared with
Kuapy shares Google user data only with these service providers, and only to run Kuapy:
- Railway, our hosting provider, stores it on servers in the United States (US West). Railway acts on our instructions.
- OpenRouter, which passes each request to the provider of the model in use (currently models made by OpenAI and by TypeSafe), receives: the titles of the videos in a category and the name of that category, to write the category’s synthesis; each new video’s title, channel name and description, to sort it by type; and video titles, to translate them into the language you chose. None of them ever receives your email address, your Google account ID or your subscription list.
- ChocoData, our transcript provider, receives the public ID of each new video, to supply its transcript. It receives nothing that identifies you.
- Google receives Kuapy’s requests to its sign-in service and to the YouTube API.
Kuapy never sells Google user data and never shares it for advertising. More about these providers: Who receives data and Transfers outside the European Economic Area.
Google user data: retention, deletion and revoking access
- Google account ID and email address: kept while your account exists.
- Refresh token: kept, encrypted, while your account is connected to Google. When you delete your account, Kuapy revokes it at Google straight away and deletes it.
- Access tokens: never stored.
- YouTube data (your subscriptions, and channel and video details, including those shown in past digests): refreshed from YouTube or deleted at least every 30 days. A past digest shows each video’s current title, channel name and length, and shows view, like and comment counts only for 30 days. Data that Kuapy no longer needs is deleted.
- Reading activity (which includes the YouTube IDs of videos and channels): each record is deleted 90 days after Kuapy receives it (see Your reading activity in Kuapy).
Delete your data. You can delete your account and all its data at any time, in Kuapy or by writing to us. Kuapy deletes it within 7 days (see Deleting your account and data). This does not delete anything on YouTube or in your Google account.
Revoke access. You can remove Kuapy’s access at any time on the Google security settings page: https://security.google.com/settings/security/permissions. Kuapy checks regularly that its access still works. If you revoke it, or Kuapy can no longer renew it, Kuapy stops using your Google user data straight away and deletes your account and the data linked to it within 30 days.
Other data Kuapy handles
Besides Google user data, Kuapy handles the following.
- Your choices: which channels you include in your digest, any category names you write, the language you read Kuapy in and the plan you chose.
- Your digests: the daily editions made for you, with the summary of each video and the synthesis for each category.
- Time zone: used to decide which morning a new video belongs to. It is Madrid time by default.
- Usage records: which videos were processed and delivered for you, and when, to count the videos Kuapy processes for you each month.
- Account records: when your account was created, when you last signed in, and the state of your subscription sync, for example when it last ran and whether it failed.
- Reading activity: what you do in your digest, such as opening a summary or starting a video, kept for 90 days (see Your reading activity in Kuapy).
- Operating records: when videos were processed and what each step cost. Some of these records contain your Kuapy account number and your category names.
- Messages: if you write to us, your email address and what you tell us.
- Technical data: like any website, Kuapy receives your IP address and browser details when you visit. Kuapy’s own software does not log them. Our hosting provider handles them to deliver the pages and may record them in its technical logs.
- Error logs: when something goes wrong, Kuapy’s server writes a technical error report. These reports can contain your Kuapy account number, but Kuapy is built not to write email addresses, tokens or other account details into them.
Data about videos, not about you. Kuapy also keeps a transcript and a summary for each public video it processes. They are shared by every member who follows the same channel, so each video is summarised only once. They contain no data about you.
People who appear in videos. Transcripts and summaries can include the names and words of people who appear in, or are mentioned in, public videos. They come from the videos’ public transcripts. Kuapy uses them only to summarise those videos for members, based on our legitimate interest (Article 6(1)(f) GDPR), and sends them only to the providers that make summaries (see Who receives data). Transcripts are deleted 30 days after Kuapy fetches them. Anyone who appears in a video can use the rights in Your rights, including the right to object, by writing to info@kuapy.com.
Your reading activity in Kuapy
Kuapy keeps its own record of some of the things you do in your digest, to improve Kuapy. It uses no outside analytics service for this, and it adds no cookie and uses no browser storage (see Cookies and storage on your device).
What is recorded. A record is made when you:
- open a video’s summary in your digest;
- click a channel’s name among a topic’s sources on the Today page;
- follow a source link, for example from a point in a topic overview to the video’s summary, or out to the original video on YouTube;
- start a video in the player inside Kuapy. This counts only once YouTube’s player reports that the video is actually playing;
- have a card come into view: at least a quarter of a video card in the Videos list appears on your screen.
Apart from cards coming into view, only your own actions count. For example, a summary that is already open when the page loads, or that opens because you followed a link to it, is not recorded as opened.
Each record holds: a random identifier for the record; your Kuapy account number; the edition it belongs to and its date; the YouTube IDs of the video and its channel; the category the video has in your digest; the kind of action and the part of the page it came from; the card’s position in the list, when there is one; and the time Kuapy’s server received it.
What is not recorded. These records contain no email address, IP address, browser details, referring page, search terms or web addresses. Kuapy does not measure how long you read or watch, and records nothing you do outside Kuapy, including on YouTube.
Your browser keeps new records in memory for a moment, then sends them only to Kuapy’s own server, as part of your signed-in session. Nothing is written to your device, and records not yet sent are dropped when you sign out.
Why we keep it. To learn which parts of Kuapy are useful and improve them; to build recommendations in Kuapy in future (Kuapy makes none yet, and we will update this policy before it does); and to give the person who runs Kuapy statistics. On a private owner page, the owner can see only statistics: how many members were active in the last 24 hours, 7 days and 30 days; how often each kind of action happened and how many different videos were involved, overall and for each account; and when each account was last active. The owner page never lists which videos or channels you opened, and a card coming into view never counts as being active.
Legal basis. Our legitimate interests (Article 6(1)(f) GDPR) in improving Kuapy and understanding how it is used. We have weighed them against your interests and rights: the record covers only what you do inside your own digest, identifies you only by your Kuapy account number, is kept for 90 days, is never used for advertising or sold, and is not passed to any other company except our hosting provider, Railway. You can object at any time.
How long, and your choices. Each record is deleted automatically 90 days after Kuapy receives it, and your records are deleted with your account. You can ask us at any time to delete them, or object to this use (Article 21 GDPR), by writing to info@kuapy.com. If you object, we stop recording your activity and delete the records we hold. Objecting does not change your digest.
Automated summaries, not automated decisions
Kuapy makes its summaries automatically:
- Our transcript provider, ChocoData, supplies the transcript of each new video. It receives only the video’s public ID.
- A decision model made by TypeSafe, reached through OpenRouter, sorts each new video by type, from its title, channel name, description and the first 1,500 words of its transcript.
- A language model, reached through OpenRouter, writes each video’s summary from its transcript. It also writes a short synthesis for each category from the titles and summaries of that day’s videos and the name of the category. If you read Kuapy in a language other than English, it also translates the titles, summaries and syntheses you see.
- Nobody at Kuapy edits the summaries by hand. They can contain mistakes (see the Terms of Service).
The summaries describe videos, not you. Kuapy makes no decision about you based solely on automated processing, and does no profiling, that has legal or similarly significant effects on you (Article 22 of the General Data Protection Regulation, the GDPR). Kuapy’s automatic choices concern videos only, for example whether a video is public, finished and short enough to summarise.
Why we use your data: purposes and legal bases
The law requires a legal basis for each use of personal data. These are ours:
- Providing Kuapy (signing you in, reading your subscriptions, finding new videos, making and showing your digests, counting the videos processed for you, and answering your questions as a member): performance of our contract with you, that is, the Terms of Service (Article 6(1)(b) GDPR). Google also asks for your permission on its own screen. That permission controls Kuapy’s access to your Google account, and you can withdraw it at any time.
- Keeping Kuapy secure and working (error logs, backups, cost control, fixing problems and checking the quality of summaries): our legitimate interests (Article 6(1)(f) GDPR).
- Recording your reading activity in Kuapy (improving Kuapy, building recommendations in future and the owner’s statistics): our legitimate interests (Article 6(1)(f) GDPR), weighed in Your reading activity in Kuapy.
- Answering messages from people who are not members: our legitimate interest in replying to you (Article 6(1)(f) GDPR).
- Meeting legal duties (for example, keeping records of data protection requests, or answering lawful requests from authorities): legal obligation (Article 6(1)(c) GDPR).
Our legitimate interests are keeping Kuapy secure, reliable and affordable to run, preventing abuse, and improving the features you use, including by learning which parts of Kuapy members use. For these we use as little personal data as we can, mostly totals and data about videos. You can object to this use at any time (see Your rights).
Who receives data
We share personal data only with the providers below, and only as far as needed to run Kuapy. Service providers act on our instructions.
- Railway (hosting): runs Kuapy’s servers and database in the United States (US West), and keeps its backups and technical logs. It holds all the data described in this policy.
- OpenRouter and the providers of the models it passes each request to (currently models made by OpenAI and by TypeSafe), for summaries, translations and sorting videos by type: they receive transcript text, video titles, descriptions and channel names, summaries and category names. They never receive your email address, your Google account ID or your subscription list.
- ChocoData (transcripts): receives the public ID of each new video. It receives no personal data.
- Google (sign-in and YouTube API): receives Kuapy’s sign-in and YouTube requests, and handles them under the Google Privacy Policy.
- Our email provider: stores the emails we exchange with you.
- Authorities, courts and professional advisers: only when the law requires it, or to establish or defend legal claims.
Kuapy uses no email marketing, advertising or outside analytics service, and never sells personal data. If Kuapy is ever merged with or sold to another company, we will tell you first, and your Google user data will be transferred only with your explicit consent.
Transfers outside the European Economic Area
Kuapy is run by Condor LLC from the United States. Your data is processed in the United States, where Condor LLC and the service providers that handle it are based. If you live in the European Economic Area (EEA) or the United Kingdom, this means your data is handled outside your region. The rights in this policy still apply to you.
How long we keep data
- Account data (account ID, email address, your choices, digests, usage and account records): while your account exists. We delete it within 7 days after you delete your account or ask us to.
- Google user data: as described in Google user data: retention, deletion and revoking access. YouTube data is refreshed or deleted at least every 30 days.
- Transcripts: the transcript text is deleted 30 days after Kuapy fetches it. Video summaries are kept while any member’s digest includes them.
- Operating records: kept for accounting and cost control. When your account is deleted, the parts that link them to you are deleted or anonymised within 7 days.
- Reading activity: each record is deleted automatically 90 days after Kuapy receives it, and sooner if you ask us or delete your account.
- Messages: as long as needed to deal with them. Records of data protection requests are kept blocked, so they are used for nothing else, for up to 3 years, to show how we handled them.
- Cookies: 7 days for the sign-in cookie, 10 minutes for the sign-in security cookie and 1 year for the language cookie (see Cookies and storage on your device).
- First-digest record: when Kuapy prepares your first digest, it keeps a coded fingerprint of your Google account ID (a keyed hash, from which the ID cannot be read back) and the date. It is kept after your account is deleted, so that a new account on the same Google account does not get a second free first digest. This relies on our legitimate interest in preventing abuse (Article 6(1)(f) GDPR), and you can object to it by writing to us.
- Technical logs kept by our hosting provider: for the period set by Railway’s own log retention rules.
- Backups: taken daily and rotated out within about a week. Data deleted from Kuapy can stay in a backup until that backup expires, about a week later. If we ever restore a backup, we delete again anything that had been deleted.
How we protect your data
- Every connection to Kuapy is encrypted with HTTPS (TLS).
- Refresh tokens are encrypted before they are stored, with a key kept apart from the database.
- Access tokens stay in memory and are never saved or logged.
- The database runs on a private network and cannot be reached directly from the internet.
- Only the people who run Kuapy can access its systems, and only when their work needs it.
- The sign-in cookie is signed, is sent only over HTTPS and cannot be read by scripts on the page.
- Kuapy never sees or stores your Google password.
No system is perfectly secure. If a breach puts your data at risk, we will tell the competent data protection authority and, where the law requires it, you, without undue delay.
Your rights
Under data protection law, you have the right to:
- access your data and get a copy of it;
- correct data that is wrong or incomplete;
- delete your data;
- restrict how we use it, for example while we check a complaint;
- object to uses based on our legitimate interests (Article 21 GDPR), such as the record of your reading activity;
- portability: receive the data you gave us in a common, machine-readable format, or have it sent to another provider;
- withdraw your consent at any time where we rely on it, without affecting what we did before;
- not be subject to automated decisions that have legal or similarly significant effects on you. Kuapy makes none.
To use any of these rights, write to info@kuapy.com from the email address linked to your account, so we can confirm it is you. It is free. We reply within one month. If a request is complex, we may take up to two more months, and we will tell you why.
If you live in the European Union or elsewhere in the European Economic Area, you can also complain at any time to the data protection authority of the country where you live. You can find it at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. If you live in the United Kingdom, you can complain to the Information Commissioner’s Office (ICO) at https://ico.org.uk.
Deleting your account and data
You can delete your account and all its data at any time:
- in Kuapy: open your account and choose to delete it; or
- by email: write to info@kuapy.com from the email address linked to your account.
Kuapy then revokes its access at Google straight away and deletes your account and all data linked to it within 7 days, except a record of your request, which is kept blocked for up to 3 years only to show how we handled it, and the first-digest record (see How long we keep data). The deleted data leaves our backups about a week later.
Deleting your Kuapy data does not delete anything on YouTube or in your Google account. Your subscriptions and videos stay as they are.
Unchecking a channel removes it from future digests. It does not delete past digests.
Do you have to give us your data?
No law requires you to give us any data. But to use Kuapy you must sign in with Google and allow read-only access to YouTube: without it, Kuapy cannot see your subscriptions or make your digest.
Children
Kuapy is not meant for children. You must be at least 18 years old to use it. We do not knowingly collect data from anyone younger. If you think a child has given us data, write to us and we will delete it.
Changes to this policy
We will update this policy when Kuapy or the law changes. The date at the top shows when it last changed. If we make an important change, we will tell you in Kuapy or by email before it applies. We will never use your data, including Google user data, for a new purpose without telling you first and, where the law or Google’s rules require it, asking for your consent again. Earlier versions are available on request.
Contact
For any question, request or complaint about privacy, write to info@kuapy.com, or by post to Condor LLC, 15442 Ventura Blvd., Ste 201-3022, Sherman Oaks, CA 91403, USA. We reply within one month.