TubeResearcher
FeaturesPricing
Join Waitlist

Privacy Policy

1. Scope and controller

This Privacy Policy explains how personal data is processed when you visit tuberesearcher.com, join the waitlist, create an account, purchase or use TubeResearcher, contact us, or otherwise interact with the Service. It is effective as of 9 September 2026.

The controller is Tim Leimkühler, trading as Leimkühler Data Consulting, Luise-Rinser-Str. 8, 47506 Neukirchen-Vluyn, Germany. Email: support@tuberesearcher.com. No data protection officer has been appointed because the statutory requirements for such an appointment are currently not met.

2. Categories of data and sources

We process account and contact data such as name, email address, user ID and authentication status; contract and billing data such as plan, invoices, payment status, tax and billing address information; service data such as prompts, messages, channel identifiers, research settings, generated results, feedback and usage allowances; technical data such as IP address, timestamps, device, browser, operating system, referral URL, log and security events; consent and communication records; and public channel or video information obtained from YouTube or other public sources.

We obtain data directly from you, automatically from your browser or device, from service providers used to operate the Service, from payment and authentication providers, and from public sources such as publicly accessible YouTube pages or authorised APIs. Please do not include special-category data, secrets, payment-card data or personal data that is unnecessary for your research in prompts.

3. Purposes and legal bases

We process data to provide accounts, subscriptions, research and support; take steps before and perform contracts (Article 6(1)(b) GDPR); comply with tax, accounting, consumer-protection, sanctions and other legal obligations (Article 6(1)(c) GDPR); protect, secure, troubleshoot and improve the Service, prevent fraud and abuse, establish or defend legal claims, and analyse public channel information for the requested research (Article 6(1)(f) GDPR); and operate optional analytics or send marketing communications where you have consented (Article 6(1)(a) GDPR).

Our legitimate interests are operating a secure and commercially viable SaaS product, understanding aggregate product use, improving functionality, protecting users and systems, enforcing agreements, responding to requests, and providing the competitive channel research requested by Customers. Where we rely on legitimate interests, we consider the nature of the data, reasonable expectations, safeguards and potential effects on individuals. You may object as described below.

4. Website delivery and STRATO hosting

The website and related infrastructure are hosted by STRATO AG in Germany. When the Service is accessed, server logs may include the requested resource, date and time, amount of data transferred, referrer, browser and operating-system information, IP or anonymised host information and error data. Processing is necessary to deliver, secure and troubleshoot the Service and is based on Article 6(1)(b) and (f) GDPR as applicable.

STRATO states that hosting data is stored in German data centres and that hosting logs are made available for up to six weeks, while shorter periods may apply to error logs. We enter into an Article 28 GDPR data-processing agreement with STRATO where required.

  • STRATO privacy information

5. Registration, login and Clerk

We use Clerk to create and authenticate accounts, manage sessions and help prevent unauthorised access. Depending on the login method, Clerk processes identifiers, email address, authentication factors, session and device information, IP address, timestamps and security events. If optional Google or Apple sign-in is enabled and selected, the relevant provider also processes the data required for that sign-in under its own privacy terms.

This processing is necessary to take steps at your request, perform the user agreement and protect the Service under Article 6(1)(b) and (f) GDPR. Clerk acts primarily as our processor for Customer personal data and also as an independent controller for certain account and business-administration data. Clerk may process data outside the EEA using recognised transfer mechanisms including the EU-US Data Privacy Framework where applicable and Standard Contractual Clauses as a fallback.

  • Clerk Privacy Policy
  • Clerk Data Processing Addendum

6. Research inputs, results and OpenAI

When you use the Research Agent, we process prompts, instructions, selected channels and competitors, public channel and video information, generated responses, usage metadata and feedback to provide the requested research, maintain conversation history, measure allowances, prevent abuse and improve reliability. The legal basis is Article 6(1)(b) GDPR and, for security and service improvement, Article 6(1)(f) GDPR.

Selected Customer Input and contextual public data are transmitted to OpenAI Ireland Ltd. to generate responses. OpenAI acts as a processor for API Customer Data under its business data-processing terms. OpenAI states that API data is not used to train its models by default unless the customer opts in. Depending on the API endpoint and configuration, abuse-monitoring logs may be retained for up to 30 days, while application state can remain until deleted. We will configure supported requests to avoid model training and unnecessary persistence.

Do not enter sensitive personal data, private credentials or confidential third-party information into the Research Agent. Automated results do not make decisions producing legal or similarly significant effects about you.

  • OpenAI Data Processing Addendum
  • OpenAI API data controls

7. Public YouTube information

At a Customer's request, we may collect and analyse publicly accessible channel names, handles, channel and video identifiers, titles, descriptions, thumbnails, publication dates, view and engagement statistics and related public metadata. The source is YouTube or an authorised service providing that information. We do not require access to a Customer's YouTube account for the currently described functions.

Where public information relates to identifiable creators, processing is based on Article 6(1)(f) GDPR: our and our Customers' legitimate interest in research, comparison and improvement of public-facing content. We limit the data to public professional or creator activity, use safeguards against unrelated profiling, and provide a right to object. Contact us if you want us to review or remove personal data relating to you. Where YouTube API Services are used, Google may process technical request information under its own terms.

  • YouTube Terms of Service
  • Google Privacy Policy

8. Payments and Stripe

We use Stripe Payments Europe, Limited and its affiliates for checkout, recurring payments, invoices, subscription management, tax-related functions and fraud prevention. Stripe may process name, email, billing address, tax information, transaction amount, payment method, partial card details, IP address, device identifiers and risk signals. Complete payment-card details are entered directly into Stripe-controlled interfaces and are not made available to us.

We process contract and payment status data under Article 6(1)(b) GDPR, tax and accounting information under Article 6(1)(c) GDPR, and fraud-prevention data under Article 6(1)(f) GDPR. Stripe may act as our processor and as an independent controller for regulated payment, compliance and fraud-prevention purposes. Stripe may transfer data internationally using applicable adequacy decisions, the EU-US Data Privacy Framework or Standard Contractual Clauses.

  • Stripe Privacy Policy
  • Stripe Privacy Center

9. Waitlist, email and Brevo

If you join the waitlist or subscribe to product news, we process your email address, consent record, signup source, delivery and interaction data to send the requested communications and document consent. We use Brevo, operated for German customers by the applicable Brevo/Sendinblue entity, to manage lists and send messages.

Marketing email is based on consent under Article 6(1)(a) GDPR and Section 7 German Unfair Competition Act. Where legally permitted, essential service and contract communications are based on Article 6(1)(b) or (f) GDPR. You may unsubscribe from marketing at any time through the link in each message or by contacting us. Withdrawal does not affect processing before withdrawal. We may retain a suppression record to ensure that no further marketing is sent.

  • Brevo Privacy Policy

10. Optional analytics and PostHog

With your prior consent, we use PostHog Cloud EU, hosted in Frankfurt, for website and product analytics. Depending on the enabled configuration, PostHog may process a pseudonymous identifier, account or user ID, pages and features used, clicks and interactions, referral information, device and browser data, approximate location derived from network data, timestamps, errors and experiment assignments. Session replay will not be enabled unless it is separately disclosed and configured to mask form fields and personal content.

Optional analytics are based on Article 6(1)(a) GDPR and Section 25(1) TDDDG. Analytics are not loaded before consent. You can reject or withdraw consent at any time through Cookie Settings without affecting the lawfulness of earlier processing. We configure PostHog Cloud EU, disable IP capture where available, avoid capturing form values and research-message content, and set analytics data retention to no more than 12 months unless a shorter period is appropriate.

  • PostHog Privacy Policy
  • PostHog GDPR guidance

11. Support and other communications

When you contact us or report content, we process your contact details, message, attachments, related account information and follow-up correspondence to answer the request, perform the contract, protect rights and comply with legal obligations. The legal basis is Article 6(1)(b), (c) or (f) GDPR depending on the request. Do not send unnecessary sensitive information by email.

12. Cookies and similar technologies

Strictly necessary technologies are used to deliver pages, preserve security choices, authenticate users and maintain sessions. These may include Clerk cookies such as __session, __client, __client_uat and temporary handshake cookies; their exact duration depends on the session and security configuration. Stripe may set cookies required for checkout, authentication and fraud prevention, including cookies such as m and __stripe_mid. Necessary access to or storage on your device is based on Section 25(2) TDDDG; related personal-data processing is based on Article 6(1)(b) or (f) GDPR.

PostHog analytics identifiers and other non-essential measurement technologies are used only after consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. Cookie Settings must show the providers, purposes and current lifetimes detected in the live configuration. Consent choices are stored so that they can be respected, and withdrawing consent must be as easy as granting it. Browser settings can delete cookies, but blocking necessary cookies may prevent login or payment functions.

13. Recipients and processors

Personal data is disclosed only as necessary to hosting, authentication, analytics, email, AI, payment, accounting, security and professional service providers; authorised contractors bound by confidentiality; payment networks and financial institutions; public authorities where legally required; and parties involved in legal claims or a business reorganisation. Our principal technology providers for the described Service are STRATO, Clerk, PostHog, Stripe, Brevo and OpenAI.

We enter into data-processing agreements under Article 28 GDPR where a provider acts on our behalf. Some providers also act as independent controllers for their own compliance, security or regulated services. We do not sell personal data and do not use it for cross-context behavioural advertising.

14. International transfers

Some providers or subprocessors are located outside Germany or the EEA, including in the United States. Where personal data is transferred to a country without an applicable adequacy decision, we rely on safeguards such as the European Commission's Standard Contractual Clauses and, where appropriate, supplementary measures. Where a recipient is validly certified, a transfer may rely on the EU-US Data Privacy Framework. You may request information about the applicable safeguard by contacting us.

15. Retention

We retain personal data only for as long as needed for the stated purpose and then delete or anonymise it unless law requires or permits longer retention. Account and research data are generally retained while the account is active and deleted or anonymised after account deletion, subject to a limited backup cycle and legal holds. Optional PostHog analytics data is retained for no more than 12 months. OpenAI API retention depends on the endpoint and configuration and may include abuse-monitoring logs for up to 30 days. STRATO hosting logs may be available for up to six weeks.

Unsubscribed marketing contacts are removed from active mailing lists; a minimal suppression and consent record may be retained for up to three years to document and respect the request. Ordinary support inquiries are generally deleted three years after completion. Business correspondence may be retained for six years, accounting records and invoices generally for eight years, and other records for up to ten years where tax or commercial law requires. Data relevant to claims may be retained until the applicable limitation period and any proceeding have ended.

16. Your rights

Subject to the legal conditions, you may request access, correction, deletion, restriction, data portability, and information about recipients. You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f) GDPR; we will stop unless compelling legitimate grounds or legal claims justify continuation. You may object to direct marketing at any time without giving reasons.

Where processing is based on consent, you may withdraw consent at any time with effect for the future. You may exercise rights through your account where available or by emailing support@tuberesearcher.com. We may request proportionate verification and will normally respond within one month. Rights may be limited by statutory exceptions, including retention duties and the rights of others.

17. Complaints

You have the right to lodge a complaint with a data-protection supervisory authority, particularly in the EU Member State of your habitual residence, place of work or the alleged infringement. The supervisory authority responsible for our establishment is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen). We invite you to contact us first so that we can address the concern directly.

  • LDI NRW complaint information

18. Security

We use technical and organisational measures appropriate to the risk, including encrypted transmission, access controls, least-privilege practices, authentication controls, backups, logging, dependency maintenance and contractual safeguards. No internet service is completely secure. You are responsible for protecting your account, using secure devices and promptly reporting suspected compromise.

19. Children

The Service is intended only for persons aged 18 or older. We do not knowingly collect personal data from children through user accounts. If you believe a person under 18 has created an account or submitted personal data, contact us so that we can investigate and take appropriate action.

20. Required data and automated decision-making

Account, authentication, billing and necessary research data must be provided to create an account, conclude and perform a paid contract or use the relevant feature. Without it, we cannot provide that function. Marketing and optional analytics data are voluntary and are not required for the Service.

We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Service providers such as Stripe may use automated fraud and risk systems under their own responsibilities; payment may be declined or reviewed as a result.

21. Changes to this policy

We may update this Privacy Policy when the Service, providers or legal requirements change. The current version and effective date will be published here. If a change materially affects registered users, we will provide an additional notice where appropriate. We will request new consent before using personal data for a materially different purpose where consent is required.

Product

FeaturesPricingBlog

Company

AboutCareersPress

Support

ContactChangelogStatus

Legal

Privacy PolicyTerms of ServiceImprint
FeaturesPricingBlog
AboutCareersPress
ContactChangelogStatus
Privacy PolicyTerms of ServiceImprint

© 2026 TubeResearcher. All rights reserved.

Help us improve TubeResearcher

We use optional analytics to understand how people use our website and improve the product. Learn more in our Privacy Policy.