Separate platform identities
A Polita account can connect separate Twitch, Kick and YouTube
identities. Polita does not assume that usernames are the same
across those services.
Each connection is verified directly with the relevant platform
and stored using that platform's permanent account or channel ID,
username or handle, display name and connection status.
Google OAuth and YouTube access
When a user selects Login with YouTube or Connect YouTube, Polita
requests read-only YouTube access through Google OAuth.
Polita uses this permission to identify the YouTube channel
authorised by the user. Polita retrieves the permanent YouTube
channel ID, channel title, public handle or custom URL when
available, and public profile image.
How the information is used
- To verify the channel authorised by the user.
- To connect it to the correct Polita account.
- To display the verified channel in Connections.
- To support Polita badges, username paints and chat cosmetics.
- To prevent duplicate or conflicting account connections.
What Polita does not do
Polita does not use this access to upload, edit or delete videos,
change channel settings, manage comments, read private messages or
act publicly on behalf of the user.
Polita does not infer a YouTube channel from a Twitch username,
Kick username, Google email address or another platform identity.
Data protection and security
Polita uses technical and organisational safeguards to protect
Google and YouTube account information and other sensitive account
data against unauthorised access, disclosure, alteration or misuse.
-
Connections between users and Polita are protected in transit
using HTTPS/TLS. Polita also uses HTTP Strict Transport Security
(HSTS) so supported browsers use secure HTTPS connections.
-
Polita limits Google and YouTube access to the permissions needed
for the disclosed feature. The current YouTube connection requests
read-only access to identify and verify the channel authorised by
the user.
-
Google and YouTube data is limited to information needed to provide
the connected-account feature, such as the verified channel ID,
handle or username, display name and related Polita account
mapping.
-
Access to account data is limited to Polita systems and service
components that require it to operate the relevant account,
authentication, security or support functions.
-
Polita uses security controls intended to reduce common web risks,
including secure transport requirements, framing restrictions,
content-type protections, referrer controls and restricted browser
permissions where applicable.
-
Google OAuth access tokens used for the current YouTube connection
flow are handled only for the authorised purpose described in this
policy and are not exposed as public profile information.
-
Users can disconnect YouTube from Polita, revoke Polita's access
through their Google Account, and request deletion of retained
account information as described below.
Polita reviews its data-handling and security practices as the
service develops and may update these safeguards where appropriate.
No method of internet transmission or electronic storage can be
guaranteed to be completely secure.
Storage and retention
Polita stores the verified YouTube channel ID, handle or username,
display name, connection state and mapping to the user's Polita
account.
The Google access token used during the current connection flow is
not stored permanently in the Polita platform-account database.
Disconnecting YouTube removes the active connection. Polita may
retain a limited verified identity mapping so the same channel can
reconnect to the correct Polita account and to prevent duplicate,
conflicting or abusive connections.
Sharing, advertising and Limited Use
Polita does not sell Google user data. Google and YouTube account
data is not used for personalised advertising, credit decisions or
unrelated user profiling.
Polita's use and transfer of information received from Google APIs
complies with the Google API Services User Data Policy, including
the Limited Use requirements.
Disconnecting, revoking and deleting data
Users can disconnect YouTube through
Settings > Connections.
Users can separately revoke Polita's Google access through the
third-party access controls in their Google Account.
Users may contact Polita support to request deletion of retained
account information, subject to legal, security, fraud-prevention
and legitimate service-integrity requirements.
Third-party services
Google and YouTube are independent third-party services with their
own terms, privacy policies and account controls. Polita is not
owned, operated or endorsed by Google or YouTube.