Legal

Privacy Policy

We believe in full transparency. Here's exactly how StatFlare collects, uses, and protects your data.

Last updated: August 18, 2026

Overview

StatFlare ('we', 'our', or 'us') is committed to protecting your privacy. This Privacy Policy explains what information we collect when you use statflare.in, how we use it, who we share it with, and the choices you have. By using StatFlare you agree to this policy. If you do not agree, please stop using the Service.

Information We Collect

Account information

When you sign in with Google or GitHub via Supabase Auth, we receive your name, email address, and profile picture. We store this in your StatFlare profile to provide personalised features such as saved history.

Search history

For logged-in users, we store the channel handles, profiles, and URLs you have analysed so you can revisit them from your History page. Lookups by signed-out visitors are recorded anonymously — we keep only what was looked up and when, with no account, IP address, or any other identifier attached — so we can measure how often each tool is used.

Saved content

If you save an analysis or add a creator to your Watchlist, we store that entry against your account — the handle, display name, thumbnail, follower counts, and for saved analyses the channel snapshot and AI insights generated at the time. You can delete any of these from your History and Watchlist pages at any time.

QR codes you create

If you create a dynamic QR code, we store the code's short link, its destination URL, an optional label, and its scan count against your account, so the link keeps working and can be edited or deactivated later. Static QR codes and barcodes are generated entirely in your browser and are never sent to us.

QR scan analytics

When someone scans one of your dynamic QR codes, we record the scan so we can show you analytics. For each scan we store the time, approximate location (country, city, and city-level coordinates), device type, operating system, browser, the referring page, and an irreversible hash used only to tell repeat scans apart from unique ones. The location is derived from the visitor's IP address at our edge network and is city-level only — it is not GPS or precise device location. We do not store the scanning visitor's IP address, and the hash cannot be reversed to recover it. Scanners are often not StatFlare users, so see the dedicated section below.

Usage data

For logged-in users we track the number of analyses run per day to enforce the daily credit limit (10 credits/day, plus extra credits earned by watching a rewarded ad). Signed-out visitors have no daily quota and are limited only by short-term request rate limits. Your IP address is held in memory transiently for that rate limiting and is never written to our database.

YouTube data

We fetch publicly available data from the YouTube Data API v3 on your behalf. For an ordinary analysis this data is fetched fresh each time and is not tied to you. Some public channel data is cached or stored on our servers so the Service can work — a short-lived cache behind the Creator Time Machine, periodic public statistics snapshots that power growth-over-time charts, and a full snapshot kept with any analysis you explicitly save. All of it is public information about the channel being looked up, not personal data about you.

Device and log data

Our hosting providers (Vercel and Render) automatically collect standard server logs including IP address, browser type, pages visited, and timestamps. This data is used for security, debugging, and performance monitoring.

How We Use Your Information

To provide the Service

We use your information to deliver analytics, AI insights, search history, and all core platform features.

To enforce rate limits

We track daily usage to ensure fair access to our YouTube API quota and prevent abuse.

To improve StatFlare

Aggregate, anonymised usage patterns help us identify which features are most valuable and fix bugs.

To display advertising

We use Google AdSense to serve ads on the platform. Google may use cookies and similar tracking technologies to deliver personalised ads based on your interests and browsing history. See the Third-Party Services section for more detail.

To comply with the law

We may process your data when required by applicable laws, court orders, or to protect the safety and rights of our users.

Third-Party Services

Google AdSense

StatFlare displays advertisements via Google AdSense. Google and its partners use cookies (including the DoubleClick cookie) to serve ads based on your prior visits to our site and other sites on the internet. You can opt out of personalised advertising at adssettings.google.com or by visiting youronlinechoices.eu (EU users). Google's Privacy Policy is available at policies.google.com/privacy.

Supabase

Our database and authentication provider. Your account data is stored in Supabase (PostgreSQL) hosted on AWS. See supabase.com/privacy.

YouTube Data API v3

We use Google's YouTube Data API to fetch public channel statistics. This is subject to Google's Privacy Policy at policies.google.com/privacy.

Anthropic (Claude API)

Channel data is sent to Anthropic's Claude API to generate AI insights. No personally identifiable information is included in these requests. See anthropic.com/privacy.

Vercel & Render

Our frontend is hosted on Vercel and backend on Render. These platforms collect standard server logs. See vercel.com/legal/privacy-policy and render.com/privacy.

Vercel Analytics

We use Vercel Analytics for privacy-friendly, cookieless page-view analytics. No personal data is stored.

Connected YouTube Channel Data (YouTube API Services)

We use YouTube API Services

StatFlare's optional 'Connect your channel' feature uses YouTube API Services. By connecting your channel, you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms). Information accessed through these APIs is handled in accordance with the Google Privacy Policy (https://policies.google.com/privacy).

What we access (only with your consent)

If — and only if — you choose to connect your channel, Google asks you to grant read-only access to your YouTube account and YouTube Analytics (the youtube.readonly, yt-analytics.readonly, and yt-analytics-monetary.readonly scopes). We use this access for a single purpose: to identify your own channel and display your private analytics — views, watch time, audience retention, estimated revenue, traffic sources, demographics, and per-video stats — back to you, the channel owner.

Limited Use

StatFlare's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Your YouTube Analytics data is shown only to you, the authenticated channel owner. We do not sell or transfer it to third parties, do not use it for advertising, and do not use it to train AI or machine-learning models. No humans read this data except where you explicitly request support, or where required for security or to comply with the law.

What we store

We do not store your YouTube Analytics data — it is fetched live from Google each time you open your channel dashboard and is shown only to you. The only item we retain is your Google OAuth refresh token, which is encrypted at rest and used solely to refresh access so we can display your analytics. We never store your Google password.

Revoking access

You can disconnect your channel at any time from the 'My Channel' page in StatFlare, which deletes your stored token. You can also revoke StatFlare's access directly from your Google Account at https://myaccount.google.com/permissions.

If You Scanned a QR Code

This section is for people who scanned a StatFlare-powered QR code without necessarily visiting StatFlare themselves. When you scan a dynamic QR code created by a StatFlare user, you pass through our short link (statflare.in/q/...) before being redirected to the destination. We log that redirect so the code's owner can see how their code is performing. We record the time, your approximate location (country, city, and city-level coordinates inferred from your IP address by our edge network — not GPS), your device type, operating system and browser, the page that referred you, and an irreversible hash that lets us count unique scans without identifying you. We do not store your IP address, and the hash cannot be reversed back into it. We do not build a profile of you, do not track you across other sites, and do not sell this data. Requests that we identify as bots or link previews are redirected without being logged at all. The QR code's owner sees only aggregate counts and breakdowns, never anything that identifies you individually. To ask about or object to this processing, contact us at gavitjayesh08@gmail.com.

Cookies & Tracking Technologies

We and our third-party partners use cookies, web beacons, and similar tracking technologies. Essential cookies keep you signed in. Google AdSense sets advertising cookies to personalise ads. You can manage cookies in your browser settings or opt out of advertising cookies at adssettings.google.com. Disabling essential cookies will prevent sign-in. See our full Cookie Policy for details.

Data Retention

We retain your account information, saved analyses, Watchlist, and QR codes for as long as your account is active. Scan analytics for a QR code are retained for as long as that code exists and are deleted with it. If you request account deletion, all associated personal data is permanently removed within 30 days. Anonymised records that identify no one — such as the tool-usage rows described above, which carry no account, IP address, or other identifier — may be retained indefinitely for aggregate analytics.

Children's Privacy

StatFlare is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us at gavitjayesh08@gmail.com and we will delete it promptly.

Your Rights

  • Access: request a copy of the personal data we hold about you.
  • Correction: request that we correct inaccurate or incomplete data.
  • Deletion: request that we delete your personal data ('right to be forgotten').
  • Portability: request your data in a machine-readable format.
  • Objection: object to processing of your data for direct marketing or profiling.
  • Opt-out of personalised ads: visit adssettings.google.com.

Contact Us

To exercise any of your rights, or if you have questions about this Privacy Policy, contact us at gavitjayesh08@gmail.com. We will respond within 30 days. For complaints related to data protection in the EU/EEA, you may also contact your local data protection authority.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a new 'Last updated' date. Continued use of StatFlare after changes constitutes your acceptance of the revised policy.

Have a question about this policy?

We'll respond within 48 hours.

Contact us →