Privacy
What Cynder accesses, how it is used, where it is stored, and how to remove it.
Cynder is an analytics service for game studios. It collects figures a studio already has access to on other platforms, on that studio's instruction, and shows them back to that studio. This page describes what that means in practice.
YouTube data
Cynder uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service and the Google Privacy Policy.
What Cynder accesses
When a studio connects a YouTube channel, Cynder reads that channel's own analytics and video details through Google's APIs, using the read only permissions the studio grants: channel and video statistics, audience analytics, and video metadata.
Cynder asks for two permissions and no others. It does not request permission to view revenue figures, and it cannot upload, edit or delete anything on the channel.
How Cynder uses it
The data appears in the connected studio's own Cynder workspace, as analytics about that studio's channel and videos. Cynder does not use it for advertising, does not sell it, and does not share it with anyone outside the studio's own workspace. It is not used to train machine learning models.
Cynder's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Where it is stored
Captured data is stored in Cynder's database in the European Union, separated per studio. Pages Cynder builds from it may also be cached by Cynder's web host for up to an hour, so they open quickly, and only in the host's European Union region.
How Cynder protects it
Data is encrypted whenever it travels: between a person's browser and Cynder, between Cynder and Google's APIs, and between Cynder's servers and its database, all over HTTPS or TLS.
Data is encrypted where it is stored. Cynder's database and file storage are encrypted at rest by its hosting provider. The credentials that authorise a YouTube connection are encrypted a second time, with AES-256-GCM, before they are stored. The key is held on Cynder's servers and never in the database, so a copy of the database alone does not give access to a channel.
Each studio's data is kept apart by row-level security in the database, so a person signed in to one studio cannot read another studio's data. The stored connection credentials cannot be read by any signed-in account at all; only Cynder's own servers can use them, and the service that collects the data runs with a restricted database role.
Authorised Cynder operators can access stored data only to support and operate the service.
How long it is kept
Cynder does not retain YouTube data that has not been refreshed from Google's APIs within the last thirty days, except when it first notices the gap after that point: then it shows a deletion date and keeps the data for ten more days so the studio is told first. Data is kept while the connection is active and is removed when it ends.
While a connection is working, the daily collection is what refreshes the data, so nothing expires. If collection stops, because the permission failed or because nothing was collected, the thirty days run from the last successful collection rather than from when the gap was noticed. Cynder shows the date on the Sources page and on Home from day twenty, and deletes the collected data on day thirty if collection has not started again. If Cynder first notices the gap after day thirty, it still shows the date first and keeps the data for ten more days from that notice, so nothing is deleted without a dated warning. Connecting the channel again before that date keeps the history. After it, the data collected from that channel is deleted.
Ending a connection
A studio can disconnect YouTube in Cynder at any time, under Settings, Sources. A studio can also withdraw Cynder's access directly from their Google account permissions.
Disconnecting in Cynder stops collecting from the channel, deletes the stored credentials, and deletes the YouTube data captured under that permission. It also asks Google to withdraw the permission. If that request does not reach Google, the entry stays on the Google account permissions page above and can be removed there.
Withdrawing the permission at Google stops Cynder reading the channel, and Cynder deletes the stored credentials the next time it tries to use them. The connection stays listed in Cynder so it can be repaired, which means what was already captured is still there, until the thirty days above run out. Disconnecting in Cynder removes it straight away instead, and it can also be removed on request.
Steam reviews
A studio can ask Cynder to collect the public Steam reviews of its own game. That collection runs on the studio's own machine and the reviews are stored there, in a file the studio keeps. Cynder's servers receive counts and dates about that file, never the reviews themselves, so the studio can see how far the collection has got.
The reviews leave the studio's machine only when somebody in the studio presses Send to Atlas on the Reviews page. Nothing sends them automatically. When sent, they go to storage in the European Union that only that studio's workspace can reach, the copy on the machine stays where it is, and the Reviews page shows when the send happened and how many reviews it carried. The reviews are public Steam data about the studio's own game and are not shared with anyone outside the studio's workspace.
Account data
Cynder stores the email address a person signs in with, which studio they belong to, and a record of the collections Cynder ran on that studio's behalf. The collection software also reports when the operating system on the studio's machine last started (a restart, not a sleep or a quick shutdown), so that a restart which paused collection until the next sign-in can be stated as that, rather than read as a machine that was off. Signing in with Google shares that address with Cynder and nothing else.
Getting in touch
For a question about this policy, or to ask for data to be removed, write to tsgeorge@gmail.com.
Last updated 9 October 2026