Summary and scope
This policy applies to Creator Finder, a local desktop application currently created and used by its developer to manage videogame campaigns. It also describes this static website.
1. Controller
XOTOX STUDIO
Independent developer
Contact: xotoxoficial@gmail.com
XOTOX STUDIO is responsible for the Creator Finder practices described in this policy.
2. What Creator Finder is
Creator Finder is a private, local application used to discover creators, assess relevance for videogame campaigns, organize candidates, record professional contact routes, and manage outreach. It is not a SaaS product and provides no public access.
The application uses YouTube Data API v3 to query public information and may use Gmail OAuth when the user voluntarily connects their own Google account.
3. Data accessed and purpose
| Source | Information | Purpose |
|---|---|---|
| YouTube Data API | Search results; channel IDs, names, descriptions, public statistics, and uploads playlists; and public video IDs, titles, descriptions, dates, tags, categories, and statistics. | Discovery, filtering, relevance review, caching, and duplicate prevention. |
| Gmail, when authorized | Recipients, subject lines, and content of prepared or sent messages; draft, message, and thread IDs; and, within known campaign threads, reply sender, subject, date, snippet, and content. | Create drafts, send expressly approved messages, and check campaign-related replies. |
| Public sources | Professional contact routes published by creators or their representatives and associated with the creator. | Prepare relevant professional contact. Creator Finder does not claim to obtain private information. |
| Application use | Campaigns, review decisions, outreach states, history, and do-not-contact flags. Legacy scores are isolated and disabled. | Manage the local workflow, retain context, and prevent repeated or unwanted contact. |
Advanced suitability metrics based on YouTube API Data — including NOXEN Match, thematic categories, and activity/relevance scoring — are disabled in the reviewed build. They are not calculated, recalculated, or used for automated decisions while YOUTUBE_DERIVED_METRICS_APPROVED=false. They will only be enabled if the applicable YouTube approval for derived metrics is granted.
4. YouTube Data API Services
Creator Finder uses YouTube Data API Services to query public information needed to discover and evaluate channels and videos related to videogame campaigns.
- It does not sell data obtained through the YouTube API.
- It does not give third parties access to YouTube API Data.
- It does not attempt to avoid or circumvent YouTube API quotas.
- It uses caching, deduplication, batching where appropriate, quota budgets, and information reuse to reduce redundant requests.
Creator Finder conservatively applies a maximum age of 30 days to non-authorized YouTube API Data. Before display or use, expired data is refreshed through the appropriate official endpoint; if refresh is unavailable, including because quota is exhausted, the data is invalidated or deleted and is not used as current. Campaign history, notes, user decisions, and do-not-contact state are separated through provenance and internal identifiers.
The baseline build does not extract emails from YouTube descriptions, comments, chat, or YouTube pages and does not scrape YouTube or Google. Contact discovery is limited to manual entries and external public websites legitimately linked by the creator.
5. Gmail and user authorization
Gmail OAuth is used only when the user chooses to connect a Google account. Authorization is incremental and contextual:
https://www.googleapis.com/auth/gmail.compose: find and retrieve minimal draft metadata, create drafts, and send the draft or message expressly approved by the user;https://www.googleapis.com/auth/gmail.readonly: read a Gmail thread whose ID is already associated locally with a campaign message, in order to check for a reply and record its follow-up data.
gmail.compose is requested when draft/send is connected. gmail.readonly is requested separately only when the user explicitly activates reply tracking. Without read-only access, drafts and sending remain available while reply reading stays disabled. Checks are limited to known campaign threads; Creator Finder does not search the general mailbox, mark messages read, move messages, or modify labels. Creator Finder does not sell Gmail content, use it for third-party advertising, or share it with third parties.
6. Data obtained through Google APIs — Limited Use
Access, use, storage, and transfer of information received through Google Workspace scopes is limited to providing the visible Creator Finder features described in this policy: preparation, approved sending, and follow-up of campaign communications.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
The statement above follows the disclosure example published in the Google Workspace API User Data and Developer Policy. Creator Finder does not use Gmail data to create, train, or improve generalized artificial intelligence models.
7. Stored data and retention
Creator Finder stores data primarily on the device where it runs. It may retain a database and application files needed for caching, duplicate prevention, do-not-contact flags, campaigns, internal relevance signals, review decisions, operational history, contacts, emails, outreach states, and active account authorization.
Local operational records are kept while needed for application functionality, campaign history, and duplicate prevention unless an applicable policy requires a shorter period. YouTube API Data is refreshed or invalidated/deleted no later than 30 days and is never presented as current after expiry. Local data obtained through Gmail is retained until no longer needed or until the user uses the disconnect-and-delete control.
8. Processing basis and applicable rights
Creator Finder processes information needed for user-requested features and for the developer's legitimate interest in identifying relevant professional collaborators for its own campaigns, always subject to an appropriate assessment, applicable law, and the right to object. OAuth authorization enables technical access to Google; it does not replace any other legal requirement that may apply.
Where recognized by applicable data protection law, a person may request access, correction, deletion, restriction, or object to processing of information concerning them. Requests may be sent to xotoxoficial@gmail.com. A complaint may also be submitted to the competent data protection authority.
9. Control, revocation, and deletion
Revoke Google access
The user can review or revoke Creator Finder's access through their Google Account connections settings.
Deletion and privacy questions
Under Settings → Privacy and compliance, the user can revoke the token through Google's official endpoint, delete token.json, and erase locally stored Gmail-derived metadata and replies without deleting the developer OAuth client file. The user can also erase all stored data for one creator by creator_internal_id; this removes Creator Finder data, not information held by YouTube.
For deletion assistance or privacy questions, email xotoxoficial@gmail.com.
Public contacts and do-not-contact requests
A creator or representative may use the same email to request a correction or ask that a public contact route not be used. Creator Finder maintains states intended to respect do-not-contact decisions and prevent duplicates.
10. Third-party services
Creator Finder relies on external services governed by their own terms and policies:
- YouTube Terms of Service
- YouTube API Services Terms of Service
- YouTube API Services Developer Policies
- Google Privacy Policy
- Google API Services User Data Policy
- Google Workspace API User Data and Developer Policy
Creator Finder is not an official Google or YouTube product and is not affiliated with, endorsed by, or sponsored by either company.
11. Changes to this policy
This policy will be updated if features, requested permissions, or data-handling practices change. The revision date appears at the top of this page.