Privacy Policy
Last updated: August 24, 2026
This policy explains what information DrutoScan collects through this website and the premium dashboard, why, and how it's protected. It applies to drutoscan.com and any DrutoScan dashboard or application.
1. Information we collect
Information you provide
- Contact details submitted through the Contact or Request Premium Access forms (name, email, company/creator name, website, social profile links, and the content of your message).
- Account information if you register or are invited into the dashboard (email address, hashed password — never your password in plain text).
- Case and evidence material you submit for account recovery, brand protection, or reporting assistance (screenshots, links, identity or ownership documentation you choose to provide).
- Content you submit to the Content Risk Scanner for analysis.
Information collected automatically
- Basic technical data such as IP address, browser type, device type, and pages visited, for security and performance purposes.
2. What we don't collect
We do not collect or store passwords for your third-party social media or platform accounts. Where DrutoScan connects to a platform on your behalf, it uses that platform's official OAuth or API authentication — DrutoScan never asks for or stores your Facebook, Instagram, YouTube, or TikTok password.
3. How we use information
- To evaluate and respond to access requests, support messages, and cases.
- To provide the services you request — recovery guidance, content risk analysis, brand monitoring, reporting assistance, and publishing.
- To maintain security, prevent abuse, and comply with legal obligations.
- To improve the platform. We do not sell your personal information.
4. Content submitted for scanning
Text, images, and video submitted to the Content Risk Scanner are used to generate your risk assessment. We do not publish scanned content and do not use it to train third-party models without your consent.
5. Sharing
We do not sell personal information. We may share information with service providers who help us operate DrutoScan (e.g. hosting, email delivery) under confidentiality obligations, or where required by law.
6. Data retention
We retain account, case, and support information for as long as needed to provide the service and meet legal obligations, and delete or anonymize it afterward.
7. Your choices
You can request access to, correction of, or deletion of your personal information by contacting support@drutoscan.com.
8. Security
We take reasonable technical and organizational measures to protect your information. See our Security page for what's implemented today and what's planned. No online service can guarantee absolute security.
9. Google API Services / YouTube integration
DrutoScan's Social Publisher feature lets you optionally connect a YouTube channel through Google's own OAuth 2.0 authorization process. This section explains that integration specifically.
What we access, and why
- When you click "Connect YouTube," Google asks you to sign in and approve DrutoScan for two specific permissions: reading basic information about your own channel (its ID, title, and thumbnail — the
youtube.readonlyscope) and uploading videos to your channel on your instruction (theyoutube.uploadscope). We request only these two scopes — never full account access, never your Google password, and never access to Gmail, Drive, or any other Google service. - We use this access solely to identify which channel you connected (so it displays correctly in Connected Accounts) and to publish or upload video content you explicitly create and submit through the Social Publisher.
How your data is used
DrutoScan's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use YouTube/Google data for advertising, and we do not sell it.
Token storage and security
OAuth access and refresh tokens are encrypted at rest on our servers and are never exposed to your browser, included in any API response, written to application logs, or stored in plain text. They are used only, server-side, to make the specific API calls described above.
Retention, disconnecting, and revoking access
Tokens are retained only while your YouTube connection remains active. Clicking "Disconnect" in Connected Accounts immediately marks the connection inactive on our side. You can additionally revoke DrutoScan's access at any time directly from your Google Account, independent of DrutoScan, at myaccount.google.com/permissions — doing so immediately invalidates any token we hold, whether or not you've also disconnected it in DrutoScan.
10. Children's privacy
DrutoScan is not directed at children under 13, and we do not knowingly collect personal information from them.
11. Changes to this policy
We may update this policy as the platform evolves. Material changes will update the date above.
12. Contact
Questions about this policy, including our use of Google/YouTube data: support@drutoscan.com.
