Effective: September 3, 2026 · YouTube data-use disclosure 2026-08-24.v2
Gomnee is an invite-only organic-growth workspace. This policy applies to Gomnee's public website, web application, and integrations. Gomnee, Google, and YouTube are distinct services.
Information Gomnee handles
- Account and workspace information supplied through invitation, authentication, setup, support, and product-review flows.
- Company context, website material, strategies, plans, drafts, approvals, and other content you add to or create in a workspace.
- Read-only Google Search Console and YouTube data that a workspace owner chooses to connect, as detailed below.
- Essential cookie, device, usage, security, and diagnostic data needed to authenticate users, operate the service, prevent abuse, and investigate failures.
Google Search Console data
Gomnee requests only the Google scope webmasters.readonly to read Search Console data for a property you are authorized to access. This scope does not let Gomnee change a website, Search Console property, or Google account, and Gomnee does not request Google profile, email, or sign-in scopes for this connection.
Gomnee accesses and stores the selected property identifier and access level plus imported search-performance data such as date, query, page, country, device, search type, clicks, impressions, and average position. Gomnee uses this data to verify property access, display the workspace's Analytics, ground the customer-visible strategy and planning features the user chooses to run, and evaluate published content. It is available only inside the authorized workspace.
Refresh credentials are encrypted and kept only on the server. Access tokens remain in process memory for bounded provider requests and are not placed in browser state, product analytics, or application logs. Gomnee never receives or stores your Google password.
YouTube API data
Gomnee uses YouTube API Services and requests only the Google scopes youtube.readonly (“View your YouTube account”) and yt-analytics.readonly (“View YouTube Analytics reports”). The purpose is to import the official library from one channel the creator owns or manages, identify each video's official YouTube format when it is reportable, and make the library usable as source material inside that creator's Gomnee content workspace.
Gomnee accesses and stores only:
- channel ID, title, thumbnail, and the channel's uploads-playlist identifier; and
- video and playlist-item IDs, canonical YouTube links, titles, thumbnails, duration, publication time, visibility, live status, and the official creator-content type returned by YouTube Analytics or an explicit Unclassified status when no activity row is returned.
Gomnee makes one bounded Analytics activity query per imported page to retrieve official creator-content type. The report requires a views metric, but Gomnee discards that metric and the raw report after validation and stores no YouTube performance data. Gomnee does not collect video or audio files, transcripts, comments, revenue, views, engagement metrics, search terms, or Google or YouTube login credentials. It does not modify channels or videos and does not infer Shorts from duration, URL shape, title, or thumbnail. Imported metadata is refreshed about once per day while authorization remains active.
How data is used
Gomnee uses information to provide and secure the requested workspace, synchronize authorized integrations, save user decisions, respond to support requests, maintain and improve reliability, and comply with legal obligations. Where applicable, these activities rely on the performance of the service agreement, your consent, Gomnee's legitimate interest in operating a secure product, or a legal obligation. Google user data is used only for the specific customer-facing purposes described in this policy.
When a user invokes a bounded AI feature, Gomnee may send the minimum relevant normalized workspace context and evidence through Vercel AI Gateway to OpenAI solely to produce the result shown in that feature. Provider-side response storage is disabled. Those providers are not authorized to use Gomnee customer data for advertising or model training.
How data is shared
Gomnee does not sell personal information or Google user data and does not use it for advertising, credit decisions, or surveillance. Data is disclosed only to service providers needed for authentication, hosting, database operation, managed OAuth, AI inference, monitoring, and support; when you direct Gomnee to interact with a connected service; for security; or when required by law. Providers may process data only for their contracted service and under access controls appropriate to their role. Nango manages YouTube OAuth connections and token refresh; Search Console credentials remain in Gomnee's encrypted server-side store.
Gomnee's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Humans do not read Google user data except with the user's affirmative permission for support, when necessary for security or legal compliance, or when the data has been aggregated for lawful internal operations.
Cookies and device data
Gomnee and its authentication and infrastructure providers may use cookies or similar browser storage required for sign-in, security, preferences, and reliable service operation. Gomnee does not permit third-party advertising on the product.
Retention, revocation, and deletion
Workspace information is retained while the workspace is active and afterward only as reasonably needed for recovery, security, disputes, and legal obligations. Retention also follows the lifecycle of each connected service.
Disconnecting Search Console immediately stops new use and sync, requests Google revocation, and destroys the local credential after revocation is confirmed. Previously imported historical Analytics remain part of the workspace until its account data is deleted or you request their deletion.
YouTube Authorized Data is retained only while needed for the connected library and an active authorization. The product rechecks access during daily synchronization. If authorization is lost, Gomnee stops display and starts durable deletion automatically.
The authorizing owner can choose Disconnect and delete YouTube data in Gomnee at any time. Gomnee then programmatically revokes its Google access, deletes the managed connection, and removes channel, video, staging, and sync data. Product access stops immediately; cleanup normally targets 15 minutes and must complete no later than seven calendar days. Deleting Gomnee's copy never deletes or changes content held by YouTube.
You can also revoke Gomnee through Google Account security permissions. You may request access, correction, export, restriction, objection, or deletion where applicable through the support contact below. Pseudonymous, non-content security and audit evidence may be retained where needed to prove authorization or deletion, prevent abuse, resolve disputes, or meet legal obligations.
Security and international processing
Gomnee uses encrypted transport, server-only integration credentials, workspace authorization, least-privilege access, bounded provider calls, and redacted operational records. No internet service can promise absolute security. Gomnee and its providers may process data in countries other than yours, subject to applicable transfer and contractual safeguards.
Children
Gomnee is a business service and is not directed to children under 18. Gomnee does not knowingly collect personal information from children.
Google and YouTube policies
Use of the YouTube integration is subject to the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy.
Policy changes and contact
Gomnee may update this policy as the service or legal requirements change. Material changes will be presented with a new effective date. If Gomnee materially changes how it accesses or uses Google API data, the product will provide notice and obtain renewed consent where required before using the data in that new way.
Questions, privacy requests, and deletion requests can be sent to fede@wedreamlabs.io. You may also complain to the privacy regulator available in your jurisdiction.