1. Who we are
Yellcano is a viewer-engagement platform for people who stream. A creator runs a private console and adds an overlay to their broadcasting software; their audience sends messages, sounds and clips from a shared page or from the creator's own chat, and those interactions air on the stream. “Yellcano”, “we” and “us” mean the operator of the Yellcano service. “You” means whoever is reading — a creator using the product, or a viewer interacting with a creator's page.
This policy covers the Yellcano service and this website. It does not cover the streaming platforms you connect to Yellcano; those are governed by their own policies.
This website itself collects nothing. These pages are static files. They set no cookies, run no analytics, load no third-party scripts or fonts, and embed no trackers. Our web host records ordinary server request logs, and nothing else happens here.
2. Data we collect
If you are a creator
- Your account and sign-in details, and the settings that make your page yours — display name, page address, branding, published voices, prices, chat commands, blocklist.
- Your connected streaming platforms: which platform, which channel, and the credentials that platform issues so we can read your chat. Those credentials are always stored encrypted.
- Voice Lab material, if you create a custom voice: the reference recording you upload and the consent recording that accompanies it.
- Operational records of what aired on your stream, and of moderation decisions you made.
If you are a viewer
- What you send: the message text, the voice, sound or clip you chose, and the resulting receipt.
- Your identity, at the level you chose to give it. You can send as a guest with no account at all. If you sign in with Kick, Twitch or Google, we store the account identifier that provider returns and your display name, so your points, favourites and receipts follow you between devices.
- Your points balance and the ledger of how it moved.
- If you pay for an interaction: the payment record and status. Card details go directly to our payment processor — Yellcano never receives or stores a card number.
Technical data, for everyone
- Request logs: IP address, user agent, the page or endpoint requested, and the time. These are how we enforce rate limits and investigate abuse.
- A derived, non-reversible key we use to recognise a returning sender for moderation purposes. When a creator blocks somebody, they act on a label — they never see the underlying key material.
3. How we use it
We use data to do the things the product is for, and for nothing else:
- To run the service: accept an interaction, check it against the rules, render speech, and put it on the stream it was sent to.
- To enforce limits and safety: rate limits, quotas, the content floor, creator blocklists, blocks and mutes.
- To take a payment or move points, where the creator has priced an interaction and you elected to pay for it.
- To keep the service working: diagnosing faults, investigating abuse, and keeping backups.
- To answer you when you contact support.
We do not sell your data. We do not share it with advertisers or data brokers, we do not use it to serve or target advertising, and we do not build advertising profiles.
We do not use your content to train AI models. Speech is generated for the interaction you asked for. Neither your messages nor data from a connected account is used to train or fine-tune any model.
4. YouTube live chat and connected accounts
This section applies only if you connect a streaming account to Yellcano. If you never do, nothing in it applies to you. It is written in full because the YouTube connection involves Google user data, and you are entitled to know exactly what happens to it.
Yellcano uses YouTube API Services. By connecting a YouTube channel you are also bound by the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy, published at http://www.google.com/policies/privacy (also reachable at https://policies.google.com/privacy).
What we access
We request exactly one Google permission:
https://www.googleapis.com/auth/youtube.readonly. It is read-only.
With it we make three kinds of request to the YouTube Data API, and no others:
- Your channel's identity — once, at the moment you connect, so we can show you which channel you just linked and let you confirm it is the right one. We receive the channel's name, its id, and its thumbnail.
- Your active broadcast — to find the live chat belonging to the stream you are currently running.
- The messages in that live chat — the message text, its id, and the display name and channel id of the viewer who sent it. This is the data the feature runs on.
We do not read your videos, your playlists, your subscribers, your analytics, your comments, or your private channel settings, because the permission we hold does not grant them.
What we cannot do
Yellcano cannot send a message, delete a message, moderate, ban, upload, or change anything at all on your channel. This is not a promise about our intentions — it is a property of the permission we hold, and there is a second lock behind it. The set of permissions Yellcano is allowed to request is a fixed list, and every write-capable YouTube permission sits on an explicit deny list that is checked when Google hands us the credential. If a credential ever came back carrying a write permission, we would reject it and the connection would fail rather than be saved.
Why this permission and not a narrower one
YouTube does not publish a chat-only or read-chat-only permission.
youtube.readonly is the narrowest permission that authorises all three requests
above. Every alternative that would let us read live chat — youtube,
youtube.force-ssl, and the youtubepartner permissions — also
grants write access to your channel. We will not ask for those.
How we use it
Google user data obtained through this connection is used for one purpose: operating the live interaction features you turned on. A message read from your chat is checked against the rules you configured and, if it qualifies, becomes an interaction on your stream. That is the whole of it.
How we store it
- Credentials. The access and refresh tokens Google issues are encrypted before they are written to the database, using AES-256-GCM with a key derived per installation and a unique salt for every record. Each encrypted value is cryptographically bound to the record it belongs to, so a token cannot be moved between records. They are never written in plain text, and never logged.
- Chat messages. Messages are read while you are live, turned into the on-screen interaction you configured, and are not kept as a chat archive. What persists is the record of the interaction that ran on your stream — your own product data, which you can moderate and review.
- Channel identity. The channel name, id and thumbnail are kept for as long as the connection exists, so the app can show you what is connected.
How we share it
Google user data is not shared with anyone. Data obtained from your connected YouTube channel is not sent to advertisers, data brokers or AI model providers, is not included in analytics, and is not transferred to any third party. It stays inside the feature you connected it for. Speech is synthesised from the message text of an interaction that has already been admitted; nothing else from the connection leaves our systems.
How long we keep it
- Credentials are retained only while the connection is active. They are deleted immediately when you disconnect the channel in Yellcano, when you revoke access from your Google account, or when your Yellcano account is deleted.
- Live chat messages are not retained as an archive. They are processed while you are streaming; only the record of the on-screen interaction they triggered persists, as your own product data.
- Channel identity is deleted when the connection is removed.
The limits we accept
Yellcano's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data, we do not use it for advertising, and we do not use it to train or fine-tune AI models. No human at Yellcano reads your chat data — it is processed automatically. The exceptions are the ones the Limited Use requirements themselves allow: with your explicit agreement while we help you with a support request, where it is necessary to investigate abuse or a security problem, or where we are legally compelled.
How to disconnect or revoke access
Two independent ways, and either one is enough.
- From Yellcano. Disconnect the channel from your chat settings. The stored credentials are deleted immediately.
- From Google. You can revoke Yellcano's access to your Google account at any time from the Google security settings page at https://security.google.com/settings/security/permissions (also reachable at https://myaccount.google.com/permissions). Revoking there ends our access even if you never open Yellcano again.
Signing in with Google as a viewer
Viewers may sign in to a creator's page with Google. That is a separate, ordinary sign-in that
requests only your basic profile and email address (openid, email,
profile). It requests no YouTube permission and makes no YouTube API call
on your behalf. It is revoked from the same Google page linked above.
Questions or complaints about a connected account
Email [email protected] with any question or complaint about how Yellcano handles data from your connected account. We respond within 30 days.
5. Sharing
We share data only in these circumstances:
- On the stream, by design. An interaction you send is meant to be seen and heard by that stream's audience. Send accordingly.
- With the creator you sent it to. A creator sees the interactions sent to their own page, so they can moderate them.
- Service providers who make the product work: hosting and infrastructure, our payment processor, and the speech providers used for custom voices. They handle only what their task requires, and only on our instruction.
- Legal obligation — where we are compelled by valid legal process, or where disclosure is necessary to investigate abuse or protect someone's safety.
- Google user data is never shared with anyone, as set out in section 4.
We do not sell personal data, and we have never done so.
6. Retention
- Account data is kept while your account exists, and deleted when it is closed.
- Connected-account credentials are deleted immediately on disconnect, revocation, or account deletion.
- Live chat messages are not archived. See section 4.
- Interaction records and receipts are kept so a creator can review what aired and a viewer can check a receipt; receipts and viewer sessions expire after 30 days, and a guest session expires after 24 hours of inactivity.
- Generated speech audio is swept automatically once it stops being used, on a short cycle. A line that is sent repeatedly is kept a while longer so it does not have to be regenerated; a line nobody sends again is deleted.
- Payment records are kept as long as tax and accounting law requires.
- Request logs are kept for a short period for abuse investigation and then discarded.
- Backups are encrypted and rotate on their own schedule, so deleted data can persist in a backup for a short window before it ages out.
7. Your rights and choices
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, object to or restrict how we use it, or receive it in a portable form. You can exercise any of these by emailing [email protected] from the address associated with your account, or by telling us enough to identify your account. We respond within 30 days.
- Disconnect a platform at any time from your settings, or revoke from the provider's own security page.
- Send as a guest if you would rather not have an account at all. A guest can send, pay and track a receipt; a guest send is always anonymous.
- Ask a creator to remove an interaction from their own history; creators control their own page's records.
If you are in the UK or EEA and you believe we have handled your data improperly, you may complain to your local data protection authority. We would rather you told us first.
8. Cookies and local storage
We use cookies only for things that cannot work without them, and never for advertising or cross-site tracking:
- Session cookies that keep you signed in, and short-lived cookies that bind an in-progress sign-in to the browser that started it.
- Local storage on your own device for conveniences: your recent sends, your favourite voices, and whether you had a panel open. It never leaves your browser, and clearing your browser data clears it.
This marketing site sets no cookies at all and uses no local storage.
9. Security
- All traffic is encrypted in transit.
- Platform credentials are encrypted at rest with AES-256-GCM, with per-record salts and keys bound to the record they belong to.
- The public-facing part of the service and the private creator console run as separate deployments; the public one holds no owner credentials, so a fault on the public surface cannot reach them.
- Stock-voice speech synthesis runs on our own hardware, in a restricted container with no network access at all.
- Database backups are encrypted before they leave the machine.
No system is perfectly secure. If you believe you have found a vulnerability, please email [email protected] and give us a reasonable chance to fix it before disclosing it.
10. Children
Yellcano is not directed at children. You must be at least 13 years old to use it, and old enough to hold an account on any platform you connect. If you believe a child has given us personal data, email [email protected] and we will delete it.
11. International transfers
The Yellcano service is hosted in Europe, and that is where your data lives. The service providers named in section 5 may process data in other countries; where they do, transfers rely on the safeguards those providers offer, such as standard contractual clauses.
12. Changes
We will update this policy when the product changes. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will make that clear in the product rather than relying on you noticing a new date, and where the change requires your agreement we will ask for it.
13. Contact
Yellcano — [email protected]
That address reaches us for privacy questions, data requests, complaints, and anything about a connected account. We respond within 30 days, and usually much sooner.