Privacy Policy
1. Who we are
ETF Pulse is an English-language educational brand about exchange-traded funds. It is operated by Tarık Ergün, an individual (the "operator", "we"). ETF Pulse is not a company offering services to the public, and this website does not provide accounts or sign-in for visitors.
2. What this policy covers
This policy describes:
- the internal publishing tool that ETF Pulse uses to publish videos to its own YouTube channel, and the YouTube data it accesses through Google OAuth; and
- this website.
The publishing tool is used only by the operator, for the operator's own ETF Pulse channel. It is not offered to other users and does not access any other person's Google account or YouTube channel.
3. YouTube data accessed through Google OAuth
The channel owner authorizes the tool through Google's OAuth consent screen. The tool requests exactly two scopes:
https://www.googleapis.com/auth/youtube.upload— to upload videos to the channel;https://www.googleapis.com/auth/youtube.readonly— to view the channel's own videos, so that an upload can be verified and not repeated.
With these permissions the tool reads:
- Channel information: the authorized channel's ID and title, and the ID of its uploads playlist.
- The channel's recent uploads: video IDs, and for those videos their title, description, tags, privacy status and processing status. These are used to find a video this tool published earlier.
- Video categories: the YouTube category list, to confirm the category ETF Pulse declares for its videos.
It writes only one thing: a new video upload (the video file with its title, description, tags, category, privacy status and the declarations YouTube requires, such as made-for-kids and synthetic-media status). It does not edit or delete existing videos, and it does not read comments, analytics, subscribers, messages, or any data about viewers.
4. How we use that data
YouTube data obtained through Google OAuth is used only to:
- publish videos to the ETF Pulse channel, after the operator has approved each exact video version;
- verify, after an upload, that the video exists on the channel with the requested visibility, title and description;
- help prevent duplicate uploads, by checking the channel's recent uploads for a video this tool already published.
It is not used for advertising, profiling, or any purpose other than these publishing functions. It is not provided to any AI model.
5. Where data is stored, and for how long
The tool runs on the operator's own computer. There is no ETF Pulse server or cloud database.
- OAuth refresh token. Stored by the operator in a local configuration file (
.env) on that computer. It is not stored in source code, logs or run records. - Access tokens. Requested from Google for a single operation, held in memory only, and never written to disk or logged.
- Publishing records. For each upload, a local database on the same computer keeps: the YouTube video ID and URL, the requested visibility, the publication time, the metadata that was sent (title, description, tags, visibility and declarations), and the verification result (whether the video was found, its processing status, its visibility and whether its metadata matched). These records exist so that the operator can audit what was published and so that the same video is not published twice.
- Other reads. Channel titles and recent-upload information read during a check are shown to the operator in the terminal and are not stored, apart from what a publishing record above contains.
Secret tokens are never written to run records, reports or logs, and are never disclosed to anyone.
Publishing records are kept until the operator deletes them. There is currently no automatic expiry. Videos uploaded to YouTube remain on YouTube, under YouTube's own terms, until they are deleted there.
6. Sharing
We do not sell, rent or share YouTube data obtained through Google OAuth with anyone. The data passes only between the operator's computer and Google's APIs. It would be disclosed only if required by law.
7. Google API Services User Data Policy and Limited Use
ETF Pulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data obtained through Google OAuth is:
- used only to provide the publishing functions described above;
- not transferred to others, except as necessary to provide those functions, to comply with law, or as part of a merger or acquisition with notice;
- not used for serving advertisements;
- not read by humans, except by the operator for the operator's own channel, or where necessary for security, legal compliance or with the operator's consent;
- not used to develop, improve or train generalized AI or machine-learning models.
8. Security
Credentials are kept out of source code and version control and are masked in the tool's output. Each access token is used for one operation only. These measures reduce risk but no system is completely secure; we cannot guarantee absolute security.
9. Revoking access and deleting data
- Revoke access: the channel owner can remove the tool's access at any time from their Google Account, under Third-party apps & services. After that the stored refresh token no longer works and the tool can no longer upload or read anything.
- Delete local data: the refresh token is deleted by removing it from the local configuration file; publishing records are deleted by deleting the tool's local data directory. There is no separate deletion service, because no copy exists elsewhere.
- Videos: uploaded videos are managed and deleted in YouTube Studio.
Questions about this data can be sent to the contact address below.
10. Visitors to this website
This website is a set of static pages. The pages themselves set no cookies, run no analytics, and load no third-party scripts, fonts or trackers.
The site is served by Cloudflare (Cloudflare Pages), which also provides its DNS, routes its traffic and protects it against attacks and abuse. To do this, Cloudflare processes technical data about each visit on its own infrastructure, such as your IP address, the URL you request, traffic routing data and system configuration information (for example, your browser's request headers). Cloudflare uses this data to provide, operate and secure its services and to detect and block malicious activity, under its own privacy policy and terms. Some of Cloudflare's security features can set strictly necessary cookies of their own, for example when your browser is asked to pass a security check.
We have not enabled Cloudflare Web Analytics, and we have not enabled Cloudflare's optional retention of HTTP request logs. This does not mean that Cloudflare processes no data: the processing described above happens whenever the site is visited.
11. Messages you send us
Email sent to contact@etfpulse.page is forwarded by Cloudflare Email Routing to the operator's personal mailbox, which is hosted by Google (Gmail). The operator receives your email address, the message and anything attached to it, and uses them only to read and answer your message. Messages stay in that mailbox until the operator deletes them; there is no automatic deletion. If you ask for your messages to be deleted, the operator checks the mailbox by hand and deletes the messages concerned. Cloudflare and Google process the message under their own policies while delivering and storing it, and may keep their own copies or records as those policies describe.
12. Changes to this policy
If the publishing tool's data practices change, this policy will be updated first, and the "last updated" date above will change. Material changes to how Google user data is used will be reflected here before they take effect.
13. Contact
Privacy questions and requests: contact@etfpulse.page