# Privacy Policy — YouTube Allowlist
Effective date: 06/27/2026 Provider: Youtube Allowlist (“we”, “us”) Contact: ethanjosephstar@gmail.com
## Overview
YouTube Whitelist restricts YouTube on managed (e.g. school) devices to a list of channels, playlists, and videos approved by a student’s teachers. Approved lists are managed by teachers and synced from Google Classroom. To deliver the right approved list to the right student, the extension identifies the signed-in user and our backend matches them to their classes.
## What we collect
We do not collect browsing history, search queries, watch history, keystrokes, location, payment data, or advertising identifiers. We use no advertising or analytics SDKs.
## How we use the data
Solely to provide the service: determining each student’s approved YouTube content and keeping it current. We do not sell or rent personal information, and we do not use it for advertising, profiling, or any purpose unrelated to the extension’s single purpose.
## Google API data — Limited Use
Our use of information received from Google APIs (including Google Classroom) adheres to the Google API Services User Data Policy, including the Limited Use requirements. Classroom data is used only to provide the approved-content feature, is not transferred to third parties except as necessary to provide the service or as required by law, is not used for advertising, and is not read by humans except for security, legal compliance, or with the school’s consent.
## Schools, student data, and children (FERPA / COPPA)
The extension is deployed by schools for use by students, who may be under 13. The school is the data controller; we act as a service provider/processor under a data processing agreement, processing student data only on the school’s instructions. The school provides any consent required under COPPA and authorizes access to Google Classroom data. We support FERPA obligations, including not using education records for unauthorized purposes and deleting or returning data at the school’s request.
## Sharing
We do not sell personal information. We share data only with Google APIs (as needed to read rosters and post materials on a teacher’s authorized behalf), service providers bound to protect the data, and where required by law.
## Security
Data is transmitted over encrypted connections (HTTPS), and access to backend data is restricted. No method is perfectly secure, but we take measures appropriate to the sensitivity of student data.
## Retention on a teacher’s authorized behalf), service providers bound to protect the data, and where required by law.
## Security
Data is transmitted over encrypted connections (HTTPS), and access to backend data is restricted. No method is perfectly secure, but we take measures appropriate to the sensitivity of student data.
## Retention
We retain rosters and approved lists as long as needed to provide the service, and delete or return them on the school’s request. Locally cached data remains in the browser until the extension is removed.
## Changes to this policy
We may update this policy; material changes will be reflected by a new effective date. Continued use after an update constitutes acceptance.
## Contact
Questions or data requests? Email ethanjosephstar@gmail.com.