Legal

Privacy Policy

Last updated: August 24, 2026

This policy explains what information DrutoScan collects through this website and the premium dashboard, why, and how it's protected. It applies to drutoscan.com and any DrutoScan dashboard or application.

1. Information we collect

Information you provide

  • Contact details submitted through the Contact or Request Premium Access forms (name, email, company/creator name, website, social profile links, and the content of your message).
  • Account information if you register or are invited into the dashboard (email address, hashed password — never your password in plain text).
  • Case and evidence material you submit for account recovery, brand protection, or reporting assistance (screenshots, links, identity or ownership documentation you choose to provide).
  • Content you submit to the Content Risk Scanner for analysis.

Information collected automatically

  • Basic technical data such as IP address, browser type, device type, and pages visited, for security and performance purposes.

2. What we don't collect

We do not collect or store passwords for your third-party social media or platform accounts. Where DrutoScan connects to a platform on your behalf, it uses that platform's official OAuth or API authentication — DrutoScan never asks for or stores your Facebook, Instagram, YouTube, or TikTok password.

3. How we use information

  • To evaluate and respond to access requests, support messages, and cases.
  • To provide the services you request — recovery guidance, content risk analysis, brand monitoring, reporting assistance, and publishing.
  • To maintain security, prevent abuse, and comply with legal obligations.
  • To improve the platform. We do not sell your personal information.

4. Content submitted for scanning

Text, images, and video submitted to the Content Risk Scanner are used to generate your risk assessment. We do not publish scanned content and do not use it to train third-party models without your consent.

5. Sharing

We do not sell personal information. We may share information with service providers who help us operate DrutoScan (e.g. hosting, email delivery) under confidentiality obligations, or where required by law.

6. Data retention

We retain account, case, and support information for as long as needed to provide the service and meet legal obligations, and delete or anonymize it afterward.

7. Your choices

You can request access to, correction of, or deletion of your personal information by contacting support@drutoscan.com.

8. Security

We take reasonable technical and organizational measures to protect your information. See our Security page for what's implemented today and what's planned. No online service can guarantee absolute security.

9. Google API Services / YouTube integration

DrutoScan's Social Publisher feature lets you optionally connect a YouTube channel through Google's own OAuth 2.0 authorization process. This section explains that integration specifically.

What we access, and why

  • When you click "Connect YouTube," Google asks you to sign in and approve DrutoScan for two specific permissions: reading basic information about your own channel (its ID, title, and thumbnail — the youtube.readonly scope) and uploading videos to your channel on your instruction (the youtube.upload scope). We request only these two scopes — never full account access, never your Google password, and never access to Gmail, Drive, or any other Google service.
  • We use this access solely to identify which channel you connected (so it displays correctly in Connected Accounts) and to publish or upload video content you explicitly create and submit through the Social Publisher.

How your data is used

DrutoScan's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use YouTube/Google data for advertising, and we do not sell it.

Token storage and security

OAuth access and refresh tokens are encrypted at rest on our servers and are never exposed to your browser, included in any API response, written to application logs, or stored in plain text. They are used only, server-side, to make the specific API calls described above.

Retention, disconnecting, and revoking access

Tokens are retained only while your YouTube connection remains active. Clicking "Disconnect" in Connected Accounts immediately marks the connection inactive on our side. You can additionally revoke DrutoScan's access at any time directly from your Google Account, independent of DrutoScan, at myaccount.google.com/permissions — doing so immediately invalidates any token we hold, whether or not you've also disconnected it in DrutoScan.

10. Children's privacy

DrutoScan is not directed at children under 13, and we do not knowingly collect personal information from them.

11. Changes to this policy

We may update this policy as the platform evolves. Material changes will update the date above.

12. Contact

Questions about this policy, including our use of Google/YouTube data: support@drutoscan.com.