Legal

Privacy policy

Last updated · September 5, 2026

What we collect to run an account, watch the channels you add, and send webhooks you configure — and what we do not.

Read together with the terms of service.

Summary

Spike watches YouTube channels you add and surfaces uploads that cross a view threshold. We collect the minimum needed to run your account and show those events.

  • We do not sell your personal data.
  • We do not train AI or machine learning models on your account or on YouTube data we retrieve.
  • We do not run advertising or third-party analytics cookies.
  • You can deactivate the account in settings. Email us if you want the stored data deleted.

This policy should be read together with our terms of service.

Who we are

Spike for YouTube is operated by Artem Starostenkov, a sole proprietor (jednoosobowa działalność gospodarcza) in Poland, trading as Artem Starostenkov Software (NIP 9512459479). References to “Spike”, “we”, “us”, or “our” mean Artem Starostenkov. The data controller for personal data processed under this policy is Artem Starostenkov. You can reach us at direct@spike.yt.

Information we collect

Account. When you sign up we collect your email address. You may later add a display name and an optional password. Passwords are stored as a hash. We send short-lived 6-digit codes to verify email and reset a password; those codes are stored hashed and expire in minutes.

Content you create. Projects (name, description, color), watches (YouTube channel id, title, thumbnail URL, view threshold, time window, status), webhook endpoints (name, HTTPS URL, signing secret, status), and API keys (name, prefix, hash, last used time).

Events and deliveries. When a watch fires we store the video id and title, channel id and title, publish time, public view count, threshold, window, and — when we can calculate it — views added in about the last hour. For webhooks we store delivery status, attempts, last HTTP status, and a short error. We do not persist the response body from your endpoint.

Billing. Paid subscriptions are processed by Stripe. We never see or store your card number. We store the Stripe customer id, subscription id, price id, plan, status, channel limit, and period dates so we can give you the right limits. Stripe’s processing is described in the Stripe privacy policy.

Hosting metadata. Our host may see standard request data (timestamp, route, response code, IP address) to serve the site and stop abuse. We do not store IP addresses in the product database.

How we use information

  • To create and operate your account, including sign-in codes and an optional password.
  • To watch the channels you add and show threshold events in the dashboard.
  • To POST signed webhooks to URLs you configure, and to expose watches and events on the API.
  • To send service email (sign-in codes, password resets, billing receipts, security notices).
  • To process payments, enforce plan limits, prevent abuse, and meet legal obligations.

We do not use your personal data for behavioral advertising and we do not sell or rent it.

YouTube data

We retrieve publicly available metadata for channels you explicitly add: channel id, title, and thumbnail; and, for matching uploads, video id, title, thumbnail, publish time, and public view counts. We do not access private videos, private comments, or a YouTube account login.

That metadata is stored so watches and the dashboard can work. If you configure a webhook or call the API, the same public fields may be sent to you. You are responsible for any endpoint you point us at.

Spike is not affiliated with YouTube or Google. Use of YouTube is also governed by the YouTube Terms of Service and the Google Privacy Policy.

Sharing of information

We share information only with the services needed to run Spike, and only the minimum they need:

  • Hosting (Vercel).
  • Email delivery (OVH SMTP, from Spike at our spike.yt mailbox).
  • Payments (Stripe).
  • YouTube, to retrieve public metadata for channels you add.

We may also disclose information if required by law, to protect Spike and its users, or in connection with a corporate transaction such as a sale of the service. We will never sell your personal data.

Data retention

  • Account, projects, watches, events, webhooks, API keys, and delivery log: kept while the account is active or deactivated (deactivation is recoverable from our side).
  • If you ask us to delete the account, we remove that product data. Billing records may be kept as required by tax and accounting law.
  • Email codes expire within minutes and are invalidated when a new code is issued.
  • The session cookie lasts 14 days.
  • Deleting a watch stops that condition. Past events stay until you or we delete them.
  • Hosting and mail providers may keep short-lived operational logs on their side.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. In the dashboard you can edit your name, change or remove a password, deactivate the account, revoke keys and webhooks, and export recent events.

Email direct@spike.yt to request access or deletion, or if a stored event is about you and you want it reviewed. Include the account email (or enough to identify the record). We will respond within 30 days or sooner when applicable law requires it.

Security

We use TLS in transit, hashed passwords, hashed API keys, an httpOnly session cookie, and least-privilege access to the systems that run the product. No service can guarantee perfect security.

Cookies

Spike sets a small number of first-party cookies needed to run the product:

  • spike_session — keeps you signed in (httpOnly, 14 days).
  • spike_project — remembers the project selected in the dashboard (httpOnly, about 400 days).

The browser may also keep local UI preferences on your device (for example sidebar collapsed state). Those are not cookies and are not sent to us as account data.

We do not use advertising or third-party tracking cookies. Blocking cookies will prevent sign-in.

International transfers

Spike is operated from Poland and served from Vercel. Stripe handles payments and OVH sends email. Those providers may process information in the United States, Europe, or other regions. Transfers remain subject to applicable data protection law.

Children

Spike is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

Changes

We may update this policy from time to time. If we make material changes we will notify you by email or in-product banner. The “Last updated” date at the top of this page always reflects the current version.

Contact

Questions about this policy or your data?

  • Artem Starostenkov, trading as Artem Starostenkov Software
  • NIP 9512459479
  • Email direct@spike.yt