Privacy

Oscar by Korets is operated by HutFlex LLC. It helps you understand the performance of YouTube channels, Instagram professional accounts, Facebook Pages, TikTok accounts and Google Analytics website properties that you choose to connect.

Your Oscar account

You sign into Oscar with a Google account. Oscar receives your verified Google account identifier and email address to create a private workspace and keep your saved connections separate from other users. Signing into Oscar does not authorize access to a YouTube channel or another social account. You choose each connection separately and may use a different account to authorize it. Google Analytics requires its own read-only authorization; signing into Oscar does not grant access to website analytics. Platform connections are available only when their setup, testing and required approvals permit them.

Data and purpose

With your permission, Oscar reads channel or account identifiers, profile information, published media information, and performance metrics such as views, reach, watch time and engagement. This connection does not request permission to publish posts, upload videos, send messages or manage advertising.

Facebook access is limited to a Page you select and its posts. TikTok reports current profile and public-video engagement counters; it does not provide watch-time, retention or historical daily analytics through this integration. Available metrics differ by platform.

Google Analytics reports include the selected property identifier, website traffic, events and source information. You choose the property from the resources accessible to the Google account you authorize. Oscar can read these reports through its GA4 connector or the official Google Analytics MCP running inside Oscar. A short-lived access token is passed to that private runtime only to retrieve the requested report; Google refresh tokens and application credentials stay in the account backend. Both methods use the same selected property and connection permissions.

Storage and access

Oscar runs on Cloudflare. Your Oscar account, server sessions and saved connection records are stored in a private PostgreSQL database hosted by Supabase. Saved platform access and refresh tokens are encrypted before they are stored, and access to connection records is restricted to the signed-in Oscar account that owns them. Application secrets and the encryption key are held in the Cloudflare service. Oscar does not collect your social-platform passwords. OAuth credentials are not sent to an AI model. If you request an analysis through a connected AI application, the requested analytics results are returned to that application and are also subject to its privacy settings and policies.

Oscar does not sell connected-platform user data, use it for advertising, or use it to train general-purpose AI models. Access is limited to providing the features you request, investigating a specific issue with your permission, security, or legal obligations.

Cookies and third parties

The public information pages do not set tracking cookies or display third-party advertising. Oscar uses a secure, HTTP-only session cookie to keep you signed in and short-lived cookies to protect authorization requests. The Oscar session lasts up to seven days and is invalidated when you sign out or delete your Oscar account. Hosting providers may process technical request information needed to operate and secure the service. Requested reports are shared with a connected AI application only when you ask it to perform the analysis; check that application's data controls before using it.

Retention

Connection credentials are retained only while needed for your active authorization. Oscar retrieves analytics on demand. Stored YouTube account metadata must be refreshed or deleted within 30 days. On an account-verified deletion request, associated stored connection data is removed as soon as possible and within 7 calendar days. Revoked or invalid connections must be removed, including associated data, within 30 days of revocation through Google. Access tokens are refreshed as needed when you request a report. Oscar does not continuously collect analytics in the background. Encrypted database backups may retain deleted records until the hosting provider’s backup retention period ends; those copies are not used by the active service.

Disconnect or delete

Revoke Google access in Google Account connections, or Instagram access in Instagram Apps and Websites. For Facebook or TikTok, remove Oscar through the platform's connected-app or app-permissions settings. To delete a connection, sign into your Oscar accounts and select Disconnect and delete connection data. To delete your Oscar account and all its saved connections, use Delete all Oscar account data; this also signs out every Oscar session. Oscar attempts platform permission revocation where supported and tells you when you need to remove the grant in the platform settings. For help or an account-verified deletion request, contact yaroslav@korets.net. We verify the request belongs to the account holder before removing stored credentials and profile metadata. Disconnecting Oscar does not delete your platform content.

Google API data

Oscar uses YouTube API Services. Oscar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. YouTube data is also subject to the Google Privacy Policy.

Contact

Operator: HutFlex LLC. For privacy, access or deletion questions, email yaroslav@korets.net.