Privacy policy
Last updated July 24, 2026.
What we collect
When you sign in, we store your email address and a unique account ID. When you connect a platform (YouTube, Instagram, Threads, Bluesky, or X), we store the access tokens needed to read your comments and publish on your behalf, plus the platform account details you connect (handle, display name, profile ID).
When you use the inbox or compose tools, we cache the comments and posts you fetch so the app loads quickly, and we store the posts you publish through Output.
If you subscribe, Stripe (on the web) or Apple (in the iOS app) processes your payment. We do not see or store your card number — we store your subscription status and renewal date.
YouTube
Output uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.
We request a single scope, youtube.force-ssl, and use it to list your recent uploads, read the comments on them, and post replies you write. We store your OAuth tokens, your channel and uploads-playlist IDs, and a cache of recent comments — author name, avatar URL, comment text, like count and timestamp.
You can revoke Output's access to your YouTube account at any time from Google's security settings, or by disconnecting the channel in Accounts.
How long we keep things
Cached comments are deleted 30 days after they were last fetched, and are refreshed from the platform whenever you open the inbox. Notification records — which comments you have already been alerted about — are deleted on the same 30-day cycle.
Analytics keeps the numbers it charts (views, likes, comment counts, follower counts) for as long as your account exists. The underlying API responses those numbers were read from are discarded after 30 days.
Credentials are kept until you disconnect the platform or delete your account.
What we don't do
We don't sell your data. We don't read your comments or posts for any purpose other than displaying them to you and, if you use AI reply suggestions, generating a suggested reply. We don't post anything without you clicking publish.
AI reply suggestions
If you use the paid AI reply suggestion feature, the comment text and a few of your own past replies (for tone) are sent to Anthropic's Claude API to generate a suggestion. This text is not used to train models.
Deleting your data
Disconnecting a platform in Accounts revokes and deletes the stored credentials for that platform. Deleting your account deletes your credentials, cached comments, and publish history. Contact us to request deletion.
Contact
Questions about this policy: hi@simonstawski.com.