Privacy Policy
Overview
Aarothon is a local-first Windows application for stream automation. This policy explains what data Aarothon accesses, why it is used, where it is processed and how you can remove it.
Google and YouTube data we access
If you choose YouTube Direct and sign in with Google, Aarothon requests the single read-only scope https://www.googleapis.com/auth/youtube.readonly. Depending on your live channel state, the app may access:
- Your YouTube channel identity needed to confirm the connected channel.
- Current or upcoming live broadcast and live chat identifiers and status.
- Live chat events exposed by the YouTube API, including supported Super Chat, Super Sticker and membership event metadata.
Aarothon does not request permission to upload, edit or delete YouTube content.
How the data is used
Google user data is used only to provide features you activate: identifying the active live stream, showing donation or membership events, and applying your local timer, notification, goal, spinwheel and leaderboard rules. Aarothon does not use Google user data for advertising or sell it.
Storage and processing
- On your computer: the Google refresh token is encrypted with Windows DPAPI for the current Windows user and machine. Access tokens are kept in memory and are not written to the app database.
- OAuth broker: Aarothon's credential broker processes authorization-code exchange, refresh and revocation requests. It does not persist OAuth tokens in a database or include them in application logs.
- Local stream data: events and settings you choose to retain are stored in the portable app's local data folder and remain under your control.
Sharing
Aarothon does not sell Google user data or share it with advertisers or data brokers. Data is transmitted only as needed between your app, Google's OAuth and YouTube API services, and Aarothon's stateless credential broker to deliver the requested feature.
Google API Limited Use
Aarothon's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
OAuth credentials remain on your computer until you disconnect YouTube Direct, remove the portable data folder, or revoke access in your Google Account. Aarothon's disconnect action attempts to revoke the Google refresh token and then removes the local encrypted credential. You control the retention and deletion of local event history from within the app.
Security
We use PKCE, strict OAuth state validation, loopback-only callbacks, encrypted local credential storage, short-lived access tokens and server-side secret management. No security measure is absolute; please report suspected issues through the support page.
Your choices
YouTube Direct is optional. You may use other supported donation sources without connecting a Google Account. You can review or revoke Aarothon's access at Google Account connections.
Contact
For privacy questions or deletion assistance, email huygiatrng@gmail.com.