Who we are
VidWorth is a subscription attribution product for YouTube channels and the businesses behind them. It measures how videos drive tracked link clicks, form leads, booked calls and revenue. Anyone can create an account at www.vidworth.co; each account gets its own isolated workspace, and access to a workspace's data is governed by membership and invitations.
Two roles matter for the rest of this document. For your account and your workspace settings, we are the data controller. For the lead, booking and visitor data you bring in from your own YouTube channels, forms and CRM, you are the controller and we act as your processor: it is your data, we hold it to show it back to you, and we act on your instructions about it.
What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Name, email address, hashed password or Google account id | Sign you in, secure the account, contact you about the service |
| Workspace | Channels connected, tracked links, destinations, preferences | Run the product |
| YouTube | Video titles, thumbnails, publish dates, view counts, daily analytics | Show per-video performance |
| Click | Time, hashed visitor identifier, user agent, country, referring video | Count unique non-bot clicks and attribute them |
| Conversion | Name, event details, intake answers, hashed email, UTM tags, click id | Show which video produced a lead, call or payment |
| Support | What you write on the support form, the address you give, and a hashed identifier for the sending device | Answer you, and track the request until it is closed |
We do not buy data, sell data, or run advertising. There is no advertising pixel on the product, and no third-party tracker follows you around the internet on our behalf.
Google & YouTube data
When you connect a YouTube channel you manage, the app requests read access to that channel's videos and analytics, and permission to update video descriptions and post comments on your behalf. We use this strictly to:
- list the channel's uploaded videos and their view counts;
- read per-day view statistics via the YouTube Analytics API;
- add a tracked link to a video's description or first comment when you explicitly choose to;
- show the comments left on the channel's videos, and post a reply as the channel when you write one.
Comments are read live from YouTube each time you open the page and are never copied into our database — we do not store commenter names, profile pictures or comment text.
The app's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, never used to train an AI model, and is not read by a human except with your explicit consent, for security purposes, to comply with the law, or where the data is aggregated and anonymised.
You can revoke the app's access at any time from your Google account's third-party access page, or by disconnecting the channel in VidWorth.
Connected tools
You choose which tools to connect. Each one is connected per channel and can be disconnected at any time from the Integrations page. We only ever request the narrowest permissions the feature needs, and every connection below is read-only on the vendor's side.
GoHighLevel
If you install our GoHighLevel app or connect a HighLevel sub-account, we receive contacts, form submissions and calendar appointments for that sub-account, along with the attribution data attached to them. We request four read-only permissions — locations.readonly, contacts.readonly, forms.readonly and calendars/events.readonly — and hold no write permission of any kind.
- We never create, edit or delete anything in your HighLevel sub-account. There is no write scope in the list, so the app is structurally incapable of it.
- HighLevel data is used only to attribute your own conversions and display them to your workspace. It is never sold, never shared with other customers, and never used to train an AI model.
- Uninstalling the app stops delivery immediately. We mark the connection disconnected and stop receiving events. Data already recorded stays in your workspace so past reports remain readable, and you can ask us to delete it.
Scheduling, form and checkout tools
Calendly, Cal.com, Typeform, Tally, ClickFunnels and any tool you point at our generic webhook deliver bookings, form responses and payments to us as they happen. From those we store the person's name, the event or form details, the answers they gave to that tool's intake questions, and the UTM tags that identify the video. Their email address is stored only as a one-way hash.
Intake answers may contain whatever the person chose to type, so avoid asking for sensitive information — health, financial or identity details — in the questions on forms you connect.
Clicks & visitors
When someone follows one of your tracked links, we log the event so it can be attributed to a video.
- No raw IP addresses are stored. An IP is combined with a daily-rotating salt and one-way hashed, solely to tell two visitors apart for the purpose of counting unique clicks. The rotation means the identifier cannot be used to follow anyone across days.
- Emails are stored as a one-way hash, so the same person can be recognised across two tools without us keeping a readable address list.
- The optional tracking script, if you add it to your own site, records page views and form submissions for the channel it is scoped to. It sets no advertising cookies and follows nobody across other websites.
AI assistant
The console includes an optional assistant that answers questions about your own data. When you use it, your question and the workspace data needed to answer it are sent to our model provider to generate the response. That data is used to answer your question and for nothing else — it is not used to train a model. Google user data is excluded from this path entirely. If you never open the assistant, nothing is sent.
Tokens & secrets
OAuth refresh tokens, API keys and private integration tokens are encrypted at rest with AES-256-GCM. They are never logged, never displayed in the interface, and never returned by any API. They are used only to make the calls described in this policy.
Who else touches your data
We use a small number of infrastructure providers to run the service. They process data only to provide their service to us, under contract:
| Provider | Purpose |
|---|---|
| Hosting provider | Runs the application and serves the site |
| Managed Postgres provider | Stores the database |
| Transactional email provider | Delivers password resets, receipts and support mail |
| AI model provider | Generates assistant answers, only when you use the assistant |
Beyond these, we do not share your data with third parties. We disclose data only where the law compels it, and only to the extent it compels.
Retention & deletion
- Attribution data is retained while your account is active, because a report over last year needs last year's data.
- Disconnecting a channel or an integration stops all new collection immediately and keeps what was already recorded, so past reports stay readable.
- Closing your account deletes your workspace data within 30 days, except anything we must keep for legal or accounting reasons.
- Deletion on request — ask and we will delete a specific lead, a channel's history, or everything. We confirm in writing when it is done.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict its processing, and to complain to a data protection authority. Every list in the product exports to CSV, and any of these requests can be made at scriptwriter.spaceleads@gmail.com. We answer within 30 days.
If you are an end customer of one of our customers — you booked a call and landed in someone's dashboard — send your request to the business you dealt with, or to us and we will route it to them. They decide what happens to their own records.
Security
- Everything is served over HTTPS; credentials are never transmitted in the clear.
- Passwords are stored using a slow, salted one-way hash — never in a readable form.
- Tokens and vendor credentials are encrypted at rest with AES-256-GCM.
- Every vendor webhook that carries a signature is signature-verified before it is accepted.
- Workspace isolation is enforced on every query; membership decides what you can see.
No system is perfectly secure. If you believe you have found a vulnerability, please tell us at scriptwriter.spaceleads@gmail.com before disclosing it publicly, and we will work with you on a fix.
Changes to this policy
We update this policy when the product changes. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will tell account holders by email before it takes effect.
Contact
Questions about this policy, requests to access or delete your data, or anything else: scriptwriter.spaceleads@gmail.com, or the support page. See also the Terms of Service.
