Privacy Policy
Working version
This is the current working version of this page. It says what we actually do, in plain English, and it's in final review before launch. If anything material changes, existing users will be told by email — never by a silent edit.
The short version: we collect the minimum needed to run Chewbr. We don't sell your data, and we don't train AI models on your content. We advertise Chewbr on other platforms, and those platforms may set cookies when you arrive from one of our ads. Analytics and ad measurement on this site only run if you say yes. You can see, export or delete everything we hold. The rest of this page is the detail.
1. Who's responsible for your data
The data controller is CRS STORE LTD (company number 12670925), registered office: Lion And Lamb, Fore Street, Ashton, Helston, England, TR13 9RW — registered with the UK Information Commissioner's Office under number ZA912808. When Chewbr Ltd is incorporated it becomes the controller, on the same promises (interim trading explains why and when). Data questions: chris@chewbr.net.
2. What we collect, and why
Your account. Name, email address, and — if you use one — a password, stored scrambled (hashed), never in plain text. If you sign in with Google: your Google account ID, name, email and avatar. Why: running your account. Legal basis: contract.
Your YouTube channel — only if you connect it. Channel name, handle, ID, avatar, description, country, subscriber/view/video counts, and your channel analytics (views, watch time, click-through rate, retention and similar) are accessed read-only for the features you connected. If you publish through Chewbr, we also request permission to upload or schedule videos you choose and set a custom thumbnail on your own channel — those writes run only when you start that action. Chewbr does not edit, delete, or otherwise change your YouTube library unless you ask it to publish. Section 3 covers how we use Google user data. Why: analytics and optional publishing. Basis: contract.
What you create in Chewbr. Ideas, scripts, video plans, checklist progress, calendar entries, notes. It's yours — we hold it for you, and use it only to run the service. Basis: contract.
Video files you publish through Chewbr. Staged on secure storage (AWS S3) while the upload to your YouTube channel runs, and kept no longer than the upload needs. Basis: contract.
Payments. Handled entirely by Stripe — we never see or store card numbers. We keep your plan, billing status, billing email and renewal dates. Basis: contract, plus legal obligation for tax records.
Product analytics — only with your consent. If you accept analytics in the cookie banner, we use PostHog, hosted on EU servers, to see which features get used and where people get stuck. It's linked to your account while you're signed in and reset when you sign out. It exists to improve the product — never for advertising, never sold, never shared. Basis: consent — withdraw anytime in cookie settings.
Error reports. When something crashes, Sentry captures the technical details (what broke, roughly where, and the state around it) so we can fix it. Basis: legitimate interest — keeping the thing working.
Emails. Account emails — verification, password resets — go through Resend. The newsletter goes through Beehiiv, only if you signed up, with an unsubscribe link in every send. Basis: contract for account email; consent for the newsletter.
Push notifications. Only if you turn them on. We store the subscription token your browser gives us; switch them off anytime in Settings or your browser. Basis: consent.
Support. Email chris@chewbr.net and we keep the thread, so you never have to explain twice. Basis: legitimate interest.
Security. IP addresses, briefly, for rate-limiting and abuse protection. Basis: legitimate interest.
3. How Chewbr uses Google user data
Connecting a Google account is optional. When you do, Chewbr uses YouTube API Services. You also agree to the YouTube Terms of Service. Google describes its own handling of your data in the Google Privacy Policy.
What we access. Sign-in: Google account ID, name, email, and avatar. YouTube connect: channel name, handle, ID, avatar, description, country, subscriber/view/video counts, and analytics such as views, watch time, click-through rate, and retention. Publishing: permission to upload or schedule videos you choose, and to set a custom thumbnail on your own channel. We hold OAuth tokens only so those calls can run.
How we use it. Google user data is used only to provide Chewbr features you asked for:
- Sign-in and account. Create and recognise your Chewbr account from your Google identity.
- Channel profile. Show your connected channel in Settings and related screens, and refresh that profile while you use the service.
- Analytics. Display your own channel statistics inside Chewbr — views, watch time, CTR, retention, and similar reports.
- Publishing. Upload or schedule a video you choose to your own YouTube channel, and set a thumbnail when you start that action. Chewbr does not post, edit, or delete content on your channel unless you start it.
We do not use Google user data for advertising, credit checks, lending, or unrelated databases. We do not sell it. We do not use it to train AI or machine-learning models.
Chewbr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Where we store it. Channel profile fields and OAuth tokens live in our application database on Railway (encrypted at rest by the host). Files staged for a YouTube upload sit briefly in AWS S3 in Ireland (eu-west-1) and are removed when the upload finishes. Section 4 covers security in more detail.
Who we share it with. We do not sell Google user data or give it to data brokers. It is not sent to Google Ads, PostHog, Beehiiv, or other marketing tools. The hosts that run Chewbr (Railway; AWS S3 for upload staging) may process it as part of hosting, and Google receives API calls when we use YouTube API Services for you. Beyond that, we disclose it only if the law requires. Section 5 lists every processor.
Cached channel data refreshes roughly hourly while you use the service. You can disconnect at any time: in Chewbr Settings, or by revoking access at Google security settings. Disconnect or delete your account and the cached Google data goes with it.
4. How we protect Google and other user data
Passwords are hashed, never stored in plain text. Sessions use secure cookies. Traffic to Chewbr runs over HTTPS/TLS. Account data, OAuth tokens, and content live in our database and object storage on hosts that encrypt data at rest (Railway for the app database; AWS S3 for upload staging). Access is limited to the processors listed under “Who else touches your data”, each seeing only what their job needs. We do not sell Google user data or use it for advertising.
5. Who else touches your data
A small set of service providers, each seeing only what their job needs:
| Service | Job | Where |
|---|---|---|
| Stripe | Payment processing | US/global |
| Sign-in + YouTube APIs | US/global | |
| PostHog | Product analytics (consent only) | EU |
| Google Ads | Ad measurement / conversions (consent only) | US/global |
| Meta | Ad measurement / conversions (consent only) | US/global |
| Sentry | Error reports | US |
| Resend | Account emails | US |
| Beehiiv | Newsletter (consent only) | US |
| AWS S3 | Upload staging | Europe (Ireland) — eu-west-1 |
| Railway | Hosting + database | US |
No data brokers. No selling, ever. Google Ads and Meta on chewbr.net are consent-gated conversion measurement only — they do not receive YouTube API data or other Google user data from the app connection.
OpenAI Ads measurement. If you accept advertising cookies, the OpenAI Measurement Pixel on chewbr.net may send conversion events after a ChatGPT ad click (for example a lead from the free audit). With advanced matching enabled, hashed form details (such as email) may be included so OpenAI can attribute the conversion. OpenAI is an independent controller of that measurement data under its own privacy policy — not Chewbr’s processor. We only load the pixel when you consent; we do not control how OpenAI uses the data it receives.
6. Sending data abroad
Some of the providers above are US-based. Those transfers are protected by the UK Extension to the EU–US Data Privacy Framework, or by the UK's standard contractual safeguards (the IDTA), depending on the provider. Product analytics deliberately stays on EU servers.
7. How long we keep things
| Data | How long |
|---|---|
| Account + your content | While your account is active; deleted within 30 days of account deletion |
| Payment and tax records | 6 years (UK legal requirement) |
| Support email threads | 2 years |
| Error reports | About 90 days |
| Upload staging files | Only as long as the upload runs |
| Analytics | Deleted with your account, or when you withdraw consent |
8. Your rights
Under UK GDPR you can ask us, at any time, to: access everything we hold about you · correct anything wrong · delete your account and data · export your data in a portable format · restrict or object to processing based on legitimate interest · withdraw consent for anything consent-based (analytics, newsletter, push).
One email does it: chris@chewbr.net. We respond within a month — usually much faster. If you're unhappy with how we've handled something, you can complain to the UK Information Commissioner's Office at ico.org.uk — though we'd rather hear it from you first, so we can actually fix it.
9. Children
Chewbr is for people 13 and over. We don't knowingly hold data on anyone younger; if that's somehow happened, email us and it's gone.
10. Changes
Updates appear on this page with a new date at the top. Material changes get an email before they take effect — never a silent edit.
11. Contact
chris@chewbr.net. Chris reads everything.
Last updated: 30 July 2026 — pre-launch working version.
Trading as: Currently CRS Store Ltd; will be assigned to Chewbr Ltd on incorporation.