Privacy Policy

Last updated: April 10, 2026

1. Introduction

ThriftyThumbs ("we," "us," or "our") operates the website at thriftythumbs.com and provides a YouTube thumbnail A/B testing and generation platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

Account Information

When you create an account, we collect your email address and any profile information you provide.

YouTube Data

When you connect your YouTube channel, we access the following through Google OAuth with your explicit consent:

  • YouTube channel information — channel name, ID, and subscriber count
  • Video metadata — titles, thumbnails, view counts, and publish dates
  • YouTube Analytics — impressions, click-through rates, watch time, and view duration for videos you are actively testing
  • Thumbnail management — we upload and swap thumbnails on your videos as part of A/B testing

We only access YouTube data necessary to provide our A/B testing and analytics features. We do not access your private messages, comments, playlists, or financial information from YouTube.

Payment Information

Payments are processed by Stripe. We do not store your credit card number, CVV, or full payment details on our servers. Stripe handles all payment data in accordance with PCI-DSS standards. We store only your Stripe customer ID and subscription status.

Usage Data

We collect information about how you use the Service, including:

  • Pages visited and features used
  • Thumbnails generated and tests created
  • Browser type, device information, and IP address
  • Referral source and UTM parameters

Cookies & Session Recording

We use essential cookies for authentication and session management. We use PostHog for anonymized session recording and product analytics to improve the Service. Session recordings do not capture passwords, payment details, or personal data entered into forms.

3. How We Use Your Information

  • To provide and maintain the Service, including A/B testing and thumbnail generation
  • To rotate thumbnails and titles on your YouTube videos during active tests
  • To calculate test results, analytics, and statistical significance
  • To process payments and manage your subscription
  • To send transactional emails related to your account and tests
  • To improve the Service based on usage patterns
  • To detect and prevent fraud, abuse, or security incidents

4. YouTube API Services

ThriftyThumbs uses YouTube API Services. By using our Service, you agree to be bound by the YouTube Terms of Service.

You can revoke ThriftyThumbs' access to your YouTube data at any time through your Google Account permissions page. Upon revocation, we will stop accessing your YouTube data. You can also disconnect your channel from within the ThriftyThumbs settings page.

Google's Privacy Policy applies to data collected through YouTube API Services: https://policies.google.com/privacy.

5. Google API Limited Use Disclosure

ThriftyThumbs' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only use YouTube data to provide and improve the A/B testing and analytics features you have requested
  • We do not transfer YouTube data to third parties except as necessary to provide the Service (e.g., displaying your analytics back to you)
  • We do not use YouTube data for advertising, selling data, or building user profiles for unrelated purposes
  • We do not allow humans to read your YouTube data unless you have given affirmative consent, it is necessary for security purposes, or it is required by law

6. Data Storage & Security

Your data is stored securely using Supabase (hosted on AWS) with row-level security policies that ensure users can only access their own data. All data is transmitted over HTTPS/TLS encryption. YouTube OAuth tokens are stored encrypted and are only used to perform actions you have authorized.

AI-generated thumbnails are stored in cloud storage and are accessible only to the account that created them. We do not use your thumbnails, prompts, or YouTube data to train AI models.

7. Data Sharing

We do not sell your personal information. We share data only with:

  • Stripe — for payment processing
  • Google/YouTube APIs — to perform A/B testing and fetch analytics
  • Google Gemini — to generate AI thumbnails (only your text prompts and reference images you explicitly provide are sent)
  • Supabase — for data hosting and authentication
  • Vercel — for application hosting
  • PostHog — for anonymized product analytics

We may also disclose information if required by law or to protect our rights and safety.

8. Data Retention

We retain your account data for as long as your account is active. Test results, snapshots, and analytics data are retained for up to 12 months after a test completes. AI-generated thumbnails are retained until you delete them or close your account.

When you delete your account, we will delete your personal data, YouTube tokens, and generated content within 30 days. Aggregated, anonymized analytics may be retained for product improvement.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Export your data in a portable format
  • Opt out of non-essential tracking
  • Withdraw consent for YouTube data access at any time

To exercise any of these rights, contact us at the email below.

10. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or your data, contact us at: support@thriftythumbs.com