Privacy

What is processed and retained.

The upload-kit workflow is copy-only, but “not published” does not mean “not processed.” This notice describes the service’s current behavior.

Effective August 8, 2026.

Data you submit

The service processes the YouTube URL you submit, fetched captions, public video metadata, the upload-kit outputs you request, and an optional Amazon Associates tracking ID. Generated summaries, chapters, tags, physical-product names, timestamps, Amazon links, and description edits are displayed in the browser. The latest finished kit, selected outputs, and optional tracking ID are also stored on your device so you can restore them later. For signed-in creators, the service also stores generated kit metadata, transcript-local product evidence, proposed product candidates, confirmation choices, and link-health results in the creator product library. Associate tracking IDs are removed from those server-side product records and remain a browser preference unless you create a smart link. A smart link separately stores its public name, original and current ASIN and canonical Amazon destination, status, optional tracking ID, and destination-change history under your account. Current and retired public smart-link names are also reserved against reuse.

Research report downloads

Downloading a gated research PDF requires an email address. The service stores the normalized address, report name, first and most recent download times, download count, and whether you selected the separate optional checkbox for occasional research and product updates. An unchecked box is not treated as marketing consent. The address and those download details are also sent to the service operator’s verified internal inbox as a lead notification. The address is not placed in the PDF or sent to product-generation, transcript, product-analytics, or session-replay providers.

Accounts and usage enforcement

Clerk handles authentication and its session cookies. The generation API stores keyed hashes derived from a Clerk user ID or, for guests, Cloudflare’s client-IP header plus browser attributes. Resource IDs are also hashed. The usage database does not store raw IP addresses, raw user agents, or transcript text. These pseudonymous records enforce distinct-video upload-kit quotas and short-window rate limits.

External processors

TranscriptAPI may receive a YouTube video ID to retrieve captions. OpenRouter or Anthropic receives transcript text and public video metadata to generate the requested upload-kit fields. When configured, Bright Data receives generated product search terms to try to resolve direct Amazon product pages. It also receives canonical Amazon product URLs for scheduled or creator-requested health checks of confirmed products; without it, the service builds Amazon search links locally and monitoring cannot run. When you open a raw Amazon link, your browser contacts Amazon directly. When someone opens a MonetizeMentions smart link, Cloudflare first handles the smart-link request and the service redirects the browser to the stored Amazon product. Smart-link redirect clicks are not currently turned into creator analytics. Clerk processes account and session data. Cloudflare provides hosting, network security, operational metrics, logs, the durable usage database, and delivery of internal lead notifications. Google hosts the operator inbox that receives those notifications. Stripe processes checkout, payment, and subscription records. PostHog receives page views, a pseudonymous anonymous ID or Clerk user ID, and allowlisted product events such as plan, aggregate output counts, timing, error category, and Amazon destination type. PostHog does not receive transcript text, Amazon links or tags, raw YouTube URLs, video titles, creator email, or API keys. Autocapture and session replay are disabled. LogRocket receives production session interaction, visible page text and imagery, performance and error telemetry, the client IP address, and allowlisted product-funnel events. It uses the IP address to derive approximate city, region, and country and to support IP-based session search. Visible replay content can include the selected video’s displayed metadata and generated upload-kit output. The application replaces form values with placeholder text; hides Clerk authentication and account UI; removes URL query strings and network bodies and headers; and disables console capture. Signed-in sessions are associated only with the immutable Clerk user ID, not a name or email. Known Agents receives non-smart-link edge visit metadata: the request path without its query string, method, response status, content type, duration, Cloudflare client IP, user agent, a referrer with its query string removed, and selected agent identification, signature, protocol-version, and session headers. Ordinary application bodies are not sent. On JSON MCP, ACP, or UCP interactions up to 250 KB, Known Agents may also receive protocol method, tool, client, error, and structured agent-commerce response data. Smart-link redirects are completed before this reporting and remain excluded. Each provider handles data under its own terms and privacy notice.

Retention

Successful fetched transcripts and model-generated upload-kit data may remain in the application cache without an automatic expiration so repeat generations avoid another billable upstream request. Failed upstream responses are not cached. Usage-resource hashes are retained for up to 400 days; rate-limit buckets are retained for up to 30 days. The latest kit and preferences in browser storage remain until you clear site data or replace the kit. Signed-in creator kits, product evidence, confirmations, current health status, smart links, and smart-link destination history currently have no automatic expiration and remain until they are removed in response to a deletion request. A JSON export of smart links includes original destinations, current and retired URL names, and change history. After a smart link is renamed or removed, a minimal reservation containing its normalized public name and opaque link ID is retained indefinitely so another creator cannot take over a URL that may remain in a published description. Study-download email records are retained in D1 for up to 24 months after the most recent download. Internal lead notifications may remain in the operator mailbox until they are deleted. LogRocket keeps session and analytics data according to the retention period configured for this project. Known Agents keeps edge visit and agent-protocol data according to the retention configured for that service. Hosting, authentication, and upstream providers may keep operational or security logs under their own retention schedules.

Publishing and product-link review

The service does not connect to your YouTube account, modify a video, or publish metadata. Generated descriptions, chapters, tags, and product links require creator review. Product URLs are restricted to HTTPS Amazon domains, and an optional tracking ID is accepted only in Amazon’s letters, numbers, and hyphens format. The generated Amazon disclosure is a starting point, not legal advice. Monitoring can be delayed, fail, or misclassify a listing. It never changes a confirmed product without your approval. When you approve a replacement, any matching smart-link destination updates while its published URL remains the same; raw links in existing YouTube descriptions remain unchanged until you paste updated copy. You can disable a smart link at any time, which makes it return a not-found response.

Account and deletion requests

Account controls are available through the Clerk profile menu. Use the public contact channel for a privacy or deletion request, whether or not you have an account. Some cached records use only non-reversible hashes and may not be linkable back to an account. Any research or product email sent after an optional opt-in will include a way to withdraw that consent.