Is it safe to connect your channel?
What you allow on Google’s screen
Connecting happens on Google’s own page, so Runsheet never sees your Google password. What it receives is a token for the permissions listed on that screen, and nothing else.
- See your channel and videos (
youtube.readonly), so the library, your running order and the analytics can show your own content back to you. - Upload videos (
youtube.upload), to publish the videos you queue. - Manage your videos and playlists (
youtube), to make the changes you ask for on your own channel: set a thumbnail, file a video into a playlist, update a title, description, tags or translations, publish a video now when you press the button, and delete one only after you type its title to confirm and ten minutes pass with an Undo link. - See your YouTube Analytics (
yt-analytics.readonly), optional: watch time, retention and click-through for your own channel. Untick it on Google’s screen and everything else keeps working.
Google reviewed how Runsheet uses the first three and approved it on 30 September 2026. Runsheet follows the Google API Services User Data Policy, including its Limited Use rules: your Google user data is never sold, never used for advertising, and never used to train a model.
What Runsheet does not do
- It does not keep your video files. A video goes from your browser straight to YouTube over an upload session Runsheet opens for you. The bytes never pass through its servers.
- It does not change your channel on its own. Everything that changes it is something you scheduled, pressed or approved. Cue, the built-in assistant, only suggests: each change it proposes waits as a card until you press Approve.
- It does not reach past YouTube. The permissions cover your channel. They do not cover Gmail, Drive, Photos or your contacts.
How the connection is protected
- The token Google gives Runsheet is encrypted with AES-256-GCM before it is written to the database. The key lives only in the server’s environment, and the token is decrypted in memory for the length of one request, when Runsheet acts for you.
- Every database table is protected by row level security, so one account cannot read another’s rows.
- AI apps you connect, such as Claude, ChatGPT or Cursor, get their own keys. Runsheet keeps only a hashed copy of each, never the key. A new key can read and nothing more unless you tick more when you make it, and publishing now and deleting are never switched on for you.
- If Runsheet is ever down, your scheduled videos still publish. A scheduled video is uploaded to YouTube private with a publish time, and YouTube flips it live itself.
Taking your access back
- Disconnect a channel in Settings and Runsheet deletes its tokens and everything it recorded about it, immediately.
- Or revoke Runsheet at myaccount.google.com/permissions and it loses access to your channel.
- To delete the whole account, email kalpesh@buildifyapp.in and it is done within seven days. Your videos on YouTube are never touched by any of this.
Who is behind it
Runsheet is a Buildify product, made by Kalpesh Mahida and operated as a sole proprietorship by Mahida Kalpesh Jayantilal. The person who answers your email is the person who wrote the code. The full detail of what is stored, and why, is on the privacy page; about says what one person building it means for you.
Found something that exposes another creator’s data or YouTube access? Mail kalpesh@buildifyapp.in with SECURITY in the subject and it goes to the top of the pile. The policy is on the contact page.
Questions about safety
Is Runsheet safe to connect to my YouTube channel?
Yes. You grant a short list of YouTube permissions on Google's own screen, Runsheet encrypts the token Google gives it, it changes your channel only when you schedule, press or approve something, and you can remove its access in one click at myaccount.google.com/permissions.
Can Runsheet see my Google password?
No. You sign in on Google's own page. Runsheet receives a token for the permissions you grant, never your password.
Can Runsheet delete my videos?
Only when you ask. Deleting a video from YouTube needs you to type its exact title, and it waits ten minutes with an Undo link before it happens. An AI app you connect can delete only if you tick that permission when you make its key, and it is capped at five a day.
Does Runsheet keep a copy of my videos?
No. Your file goes from your browser straight to YouTube. Runsheet keeps the title, description, tags, schedule and the daily view counts, not the video.
What happens to my data if I stop using Runsheet?
Disconnect the channel in Settings and its tokens and everything recorded about it are deleted immediately. To delete the whole account, email the address on the contact page and it is done within seven days. Your videos on YouTube are never touched.
Has Google approved Runsheet?
Google reviewed the three YouTube permissions Runsheet uses to schedule and publish, and approved them on 30 September 2026. Runsheet follows the Google API Services User Data Policy, including its Limited Use rules.