Zelnyo
Back to Zelnyo

Privacy · Version 2026-09-07.1

Privacy Policy

This policy explains what data Zelnyo receives, why it is used and how you remain in control.

Effective 2 September 2026

Data controller

The data controller is Clément Patigny, a French sole trader publishing Zelnyo.

Contact
contact@zelnyo.com
Address
173 rue de Courcelles, 75017 Paris, France

How Zelnyo uses TikTok

TikTok connections provide Zelnyo with the public profile, account statistics and public-video metadata authorised through Login Kit and Display API: titles, dates, duration, links, views, likes, comments and shares. OAuth tokens are encrypted. Zelnyo records recurring snapshots to calculate changes that TikTok does not provide as historical series. This data is also used for the dashboards, comparisons, editorial annotations and AI-assisted reports you request. Zelnyo never publishes, edits or deletes your TikTok content.

If the provider revokes access to TikTok or the authorisation becomes invalid, Zelnyo keeps the connection and data already imported; updates are paused until you reauthorise. Only the explicit “Disconnect and delete data” action attempts to revoke the token and permanently deletes the local connection, tokens, imported videos, snapshots, annotations and associated reports. Use remains subject to the TikTok Terms and TikTok Privacy Policy.

Data we process

Zelnyo only processes data needed to provide and secure the service:

  • Google account: account identifier, name, email address, profile image and session information.
  • Authorised YouTube channels: identifiers, names, thumbnails, channel statistics and sync status.
  • YouTube content and Analytics: titles, thumbnails, publishing dates, length, visibility, views, likes, comments, watch time, retention, engagement, thumbnail impressions, impression click-through rate and subscriber changes when supplied by the official YouTube Analytics and YouTube Reporting APIs.
  • Authorised TikTok accounts and content: technical identifier, display name and profile image, follower, following, like and video counts, plus public-video titles, descriptions, covers, dates, duration, links, views, likes, comments and shares.
  • Authorisation data: encrypted OAuth tokens, granted permissions and expiry dates.
  • Launch waitlist: email address and consent records when you ask to hear about public availability.
  • Technical data: essential session cookies, theme preference, IP address and logs needed for security, diagnostics and operation.
  • Error reports: stack trace, route without parameters, runtime, browser or device, and error date. Request bodies, cookies, headers, URL parameters, local variables and user identity are excluded.
  • AI-assisted reports: when requested, Zelnyo sends OpenAI a limited summary of the metrics, comparisons, titles and annotations needed to produce the report. Email addresses, OAuth tokens and account identifiers are not sent.

Zelnyo does not request or store your Google, YouTube or TikTok passwords, personal watch history or payment details.

Purposes and legal bases

  • Providing your private workspace, connecting authorised channels or accounts and producing requested analyses: performance of the service.
  • Securing accounts, preventing abuse, diagnosing errors and maintaining availability: Zelnyo’s legitimate interests.
  • Notifying you about public availability: your consent, which you may withdraw at any time.
  • Responding to requests and meeting applicable requirements: legal obligation where relevant.
  • Generating requested AI summaries and hypotheses: performance of the service.

Account data and the relevant YouTube or TikTok authorisation are required for connected features. Without them, Zelnyo cannot import the data or display the corresponding analyses.

Google and YouTube services

Zelnyo uses the official YouTube API Services in read-only mode. It accesses and stores the data described above only to display your channels, combine their metrics and produce analyses visible to you.

Zelnyo never publishes, edits or deletes YouTube content. YouTube data is not sold, used for advertising or shared with unauthorised third parties.

When you request an AI-assisted report or video analysis, only the limited data described above is sent to OpenAI as a technical service provider. API data is not used to train OpenAI models unless Zelnyo explicitly opts in and informs you beforehand.

Google user data is hosted in Zelnyo’s PostgreSQL database at Neon and processed by the application running on Vercel. Upstash receives only the technical identifiers, timestamps and states required for rate limiting and synchronization coordination. When you explicitly request an AI-assisted analysis or report, OpenAI receives only the limited summary of YouTube data needed to provide that visible feature. Zelnyo does not intentionally send Google user data to Sentry.

Except for these technical providers and purposes, Zelnyo does not share, transfer or disclose Google user data. The data is never sold or used for advertising, profiling, targeting, creditworthiness or training general-purpose artificial intelligence models. Zelnyo’s use of this data adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your use is also subject to the YouTube Terms of Service and the Google Privacy Policy.

You can revoke access from the Channels page or your Google security settings. Removing data from Zelnyo never deletes content stored by YouTube.

Data security

Zelnyo applies technical and organisational measures designed to protect account and connected-platform data against unauthorised access, disclosure, alteration or destruction.

  • Communications between your browser, Zelnyo and Google or TikTok APIs are protected in transit with HTTPS/TLS.
  • Google and TikTok OAuth tokens are encrypted by Zelnyo before storage, and the encryption secrets are kept separately in the hosting provider’s secured configuration.
  • Authentication, authorisation controls and ownership filters limit every user to the channels, content, reports and analyses associated with their own account.
  • Administrative and technical access is restricted to operational, security or legal needs. Logs and error reports exclude OAuth tokens, request bodies, cookies and detailed YouTube or TikTok data.
  • Hosting providers apply their own security and encryption controls to the infrastructure and backups they operate. Data is deleted according to the periods below and after access to the relevant platform is removed.

Service providers and transfers

The following providers may process only the data needed for their role:

Vercel
Application hosting, web infrastructure and technical logs.
Neon
PostgreSQL hosting on AWS Europe (eu-west-2), London, United Kingdom.
Upstash
Redis hosting in London, used to coordinate synchronisation and rate limits.
Google and YouTube
Google authentication, OAuth authorisation and the requested YouTube data.
TikTok
OAuth authorisation and the requested TikTok data supplied through Login Kit and Display API.
Sentry
Technical error monitoring in the European region, without Session Replay or audience analytics.
OpenAI
On-demand AI-assisted reports based on a limited summary of relevant data.

Where a provider processes data outside the European Economic Area, the transfer must rely on an accepted legal mechanism such as an adequacy decision or appropriate contractual safeguards.

How long we keep data

  • Account and sessions: while the account is in use; expired sessions are removed during normal maintenance.
  • YouTube metadata: while authorisation remains active and the data is needed; metadata is refreshed or deleted at least every 30 days.
  • YouTube Analytics and statistics: up to 36 months from the relevant period or snapshot, including while updates are paused pending reauthorisation. After that period, the last recorded subscriber count for each month may be retained while the channel remains connected to preserve its historical evolution.
  • TikTok data: while the connection is retained and the data is needed to provide the service, including while updates are paused pending reauthorisation. Detailed account snapshots are kept for up to 36 months. After that period, the last recorded follower count for each month may be retained while the TikTok account remains connected to preserve its historical evolution. Associated data is deleted through the explicit disconnect-and-delete action or when the Zelnyo account is deleted.
  • Derived metrics and analyses: YouTube elements are kept for up to 36 months. TikTok elements are kept while the connection is retained and they are needed for the service. All may be deleted earlier with the related report, connection or account.
  • Provider revocation: if Google or TikTok revokes access, Zelnyo keeps the connection and data already imported; updates are paused until reauthorisation. Remote revocation does not by itself trigger local deletion.
  • Explicit disconnection and deletion: the “Disconnect and delete data” action attempts to revoke the provider token, then permanently deletes the local connection and associated data from Zelnyo’s database. A remote revocation failure does not prevent the local deletion requested by the user.
  • Launch waitlist: until consent is withdrawn or for up to three years after consent or the latest contact.
  • Technical logs and Sentry errors: up to 30 days unless an incident or legal requirement justifies longer retention.
  • OpenAI abuse monitoring logs: up to 30 days under the applicable API terms.
  • Backups: until the provider’s configured technical retention period expires.

Cookies and similar technologies

Zelnyo only uses cookies or equivalent mechanisms required for authentication, session security, the YouTube or TikTok OAuth flows and your theme preference.

No advertising, profiling, cross-site tracking, Session Replay or optional audience analytics is currently enabled, so no advertising consent banner is displayed.

Your rights

Where applicable, you may request access, correction, deletion, restriction, objection or portability. You may withdraw waitlist consent at any time.

Send requests to contact@zelnyo.com. Zelnyo will respond within one month unless the law permits an extension.

You may also lodge a complaint with the French data protection authority, the CNIL, or your local supervisory authority.