SentrisMG Suite
Privacy policy
Effective October 8, 2026
1. About this policy
SentrisMG Suite (the "app") is the production and publishing system available at erp.sentrismg.com. It is built and operated by Sentris SLU, a company of the Principality of Andorra that trades as Sentris Media Group ("we", "us"). This policy explains what information the app accesses, collects, stores, uses and shares, and the choices you have.
It applies to everyone who signs in to the app and to every owner of a YouTube channel who connects that channel to it. You must agree to this policy before using the app; signing in or connecting a channel means you agree to it.
SentrisMG Suite uses YouTube API Services. By using the app you also agree to be bound by the YouTube Terms of Service. How Google handles data is described in the Google Privacy Policy (www.google.com/policies/privacy).
2. Who uses the app
Access is by invitation only, and there is no public sign-up. Accounts belong to our production team and contractors, and to a small number of partner creators we invite. Each partner works in a separate workspace and sees only the channels and data of that workspace.
People we send a review link to can open a single video cut or script without an account. They do not see any YouTube data.
3. Google user data the app accesses
The app reads a channel's private data (analytics, revenue, private videos and playlists) and makes changes on YouTube only with an authorization granted by a Google account that owns or manages the channel. A channel is normally authorized when that account signs in with Google from the channel's settings page. The Sentris workspace also holds one workspace-wide authorization, granted by the Google account that manages Sentris Media Group's own channels; the app uses it for those channels when they have no authorization of their own.
The app requests these permissions, shown here as Google shows them on its consent screen:
View your YouTube account youtube.readonly
Reads the channel's identity (to confirm the right channel was connected), its About description, branding settings and their translations, its videos (titles, descriptions, tags, thumbnails, visibility, publish dates, durations and translations, including private and scheduled videos) and its playlists, including private ones.
View YouTube Analytics reports for your YouTube content yt-analytics.readonly
Reads YouTube Analytics reports for each of the channel's videos, by day: views, watch time, average view duration, likes, comments, subscribers gained and lost, traffic sources, audience retention, and audience breakdowns by age group, gender, country, device, playback location and subscription status, plus the YouTube search terms and suggested videos that brought viewers, and, for the channel as a whole, subscribers gained and lost by day, to know its exact subscriber count. It also reads the YouTube Reporting API report of thumbnail impressions and click-through rate. To do that, the app creates one reporting job on the channel, named "sentris-reach-" followed by the channel's short name in the app.
View monetary and non-monetary YouTube Analytics reports for your YouTube content yt-analytics-monetary.readonly
Reads the estimated revenue of each video, by day, for the channel owner's financial reporting.
Manage your YouTube videos youtube.upload
Uploads a finished video file to the channel when a team member presses Upload, with the title, description, tags, category, translations, thumbnail, schedule, visibility and audience settings that team member chose.
See, edit, and permanently delete your YouTube videos, ratings, comments and captions youtube.force-ssl
When a team member asks, it sets video thumbnails, updates video titles, descriptions, tags and their translations, and adds videos to playlists. It posts the channel's own prepared comment under a video once the video is public. It keeps the channel's About description translated into the languages the channel has chosen, and sets the channel's default language when translations need one.
Although Google's wording for these permissions includes deleting, the app never deletes videos, playlists, ratings, comments or captions on YouTube, never rates videos, and never changes a video's visibility unless a team member chooses to. Every change the app makes on a channel is recorded in the app's activity log.
Public YouTube data, read without anyone's permission
The app also uses the YouTube Data API with our own API key, which needs no one's permission, to read public information: statistics, titles, descriptions, thumbnails and public comments (with the commenter's display name) of connected channels' videos, and the public channels and videos of other creators our team follows for research. It also receives YouTube's public notifications when a connected channel publishes a video.
4. How we use it
We use Google user data only to provide the app's features to the workspace that connected the channel:
- linking each published video to its production record, and keeping titles, descriptions and thumbnails in the app in step with YouTube;
- reporting how videos and channels perform, and how much revenue they earn, to the channel's owner and team;
- uploading, scheduling and updating the channel's own videos when a team member asks;
- summarizing what viewers say in public comments, so the team can improve future videos;
- planning and writing new videos, including with AI, using the titles and performance of earlier videos, such as their audience retention.
SentrisMG Suite's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data, and we do not use it for advertising, for data brokers or information resellers, or for credit or lending decisions. We do not use it to develop, improve or train artificial intelligence or machine-learning models, and the AI services that process it for us are set not to train on it. We never use Google APIs, including the YouTube APIs, to create, upload or distribute AI-generated non-consensual intimate imagery, sexually explicit content, or any sexualized depiction of a real person.
5. Who can see it
A channel's data is visible only to members of the workspace that connected it, and only to the extent their role allows: for example, revenue figures need a separate permission. Members of one workspace cannot see another workspace's channels or data.
As the operator, Sentris SLU staff can access stored data when you ask us for support, to keep the app secure, or when the law requires it.
Team members can connect their own AI assistant (Claude, by Anthropic) to the app. The assistant can then read the workspace data that member is allowed to see, including YouTube Analytics reports, and that data is processed by Anthropic under the member's own Claude account and its settings.
6. Service providers we share data with
We share data only with these providers, only as needed to run the app's features:
- Hetzner Online hosts the servers and stores all of the app's data, in Helsinki, Finland (European Union).
- Anthropic provides the AI models behind the app's AI features. It receives the content each feature needs: the text of public comments with the video's title, without commenter names, for comment summaries; video titles and descriptions and the channel's About text, for drafting and translation; video titles and performance figures, including audience retention, for planning and writing new videos; and the reference images our designers choose, which can include YouTube video thumbnails, for thumbnail design. Our Anthropic accounts are set so that this content is not used to train Anthropic's models.
- Higgsfield generates images for thumbnail design. It receives the reference images our designers choose, which can include YouTube video thumbnails, and passes them to the image model chosen for the design, such as models by Google, OpenAI or ByteDance.
- Vast.ai rents us the machines that edit videos automatically. While a video is being edited, its machine receives that video's production files (script, voiceover, footage) and read-only access to the workspace's information in the app, including video titles and YouTube Analytics reports such as views, audience retention and traffic sources, but not revenue figures.
- ElevenLabs makes voiceovers and sound effects. It receives the text of our scripts.
- Epidemic Sound supplies licensed music. It receives the searches our editing machines make.
- Rentry and Telegraph host the public pages that list the sources of our videos. They receive each video's working title and its list of sources.
- Google delivers the app's notification emails through Gmail; they can include channel and video names.
- GitHub (Microsoft) stores a monthly backup copy of the app's database for up to 90 days.
We may also disclose data when the law requires it. We would ask for your consent before any transfer as part of a sale or merger of our business.
7. Data about people who sign in
For each account we store the name, username, email address, role and workspace membership; the work done in the app (tasks, reviews, uploaded files, comments, messages) and its activity history; for people we pay, payment and invoice records; and optional two-factor sign-in settings. We also keep a log of requests to the app, including IP addresses, for 90 days, and records of sign-ins and of API requests, including IP addresses and browser details, without a fixed expiry. We use this to run the app, to pay people, to keep the app secure and to keep a record of the work.
8. Cookies, browser storage and content in the app
The app stores information on your device only for its own operation:
- a session cookie that keeps you signed in for up to 7 days, a security cookie that protects forms, and a short-lived cookie that carries on-screen messages;
- browser local storage for interface preferences, and copies of recently visited pages that make going back faster.
The app sets no advertising or analytics cookies of its own. Its pages load fonts from Google Fonts and scripts from jsDelivr, and some pages show YouTube thumbnails and other images loaded from YouTube's and Google's image servers. The team's knowledge and SOP pages can also embed video players from YouTube, Vimeo, Loom and Google Drive, play video or audio files hosted on other websites, and load scripts, styles and fonts from cdnjs and unpkg. Those players and files are served by the companies that host them, which may place or read their own cookies on your device and, in YouTube's case, show advertisements. Each of these services receives your IP address and browser details when it delivers its content.
9. How we protect data
- All traffic to the app is encrypted with HTTPS, and browsers are told to always use it.
- Google authorization tokens are encrypted when stored.
- Access is limited by role and by workspace, and every connection to a channel is checked to be the channel it claims to be.
- Repeated failed sign-ins are blocked, and two-factor sign-in is available to every account.
- Every channel connection and every change the app makes on YouTube is recorded in an activity log.
10. How long we keep data
- YouTube Analytics, reporting and statistics data is kept as the workspace's record of how its videos performed. While a channel is active in the app, the app uses its authorization every day, which confirms at least every 30 days that access is still granted. For a channel that is paused or archived in the app, stored data is kept but is neither refreshed nor re-checked until the channel is active again.
- Video and channel information is refreshed from YouTube every day while the channel is active in the app. Private video details and playlists are refreshed whenever a team member reloads them.
- Public comments on the most-discussed videos are re-read every week. Comments are kept together with the summaries made from them, including comments later removed from YouTube.
- Public data about channels we follow for research is refreshed while the channel is followed. The view-count history of their videos is kept for trend research, including after a channel is unfollowed when the team chooses to keep its videos.
- Authorization tokens are kept, encrypted, until the channel is disconnected, which deletes them at once.
- Account data is kept while the account exists. Request logs are kept for 90 days, as described in section 7.
- Backups: copies of the database are kept on our servers, and for up to 90 days with GitHub. Data we delete from the app at your request is not removed from backup copies made earlier, which we keep until we remove them.
11. Disconnecting and deleting data
A channel's owner can disconnect it at any time with Disconnect on the channel's settings page. That revokes, at Google, the authorization granted for that channel and deletes its stored tokens immediately. The app then stops reading the channel's private data and stops making changes to the channel with that authorization. It still reads the channel's public data with our API key, as described in section 3, and for Sentris Media Group's own channels the workspace-wide authorization stays in place until it is removed.
In addition to our own process for deleting stored data, you can revoke the app's access at any time from your Google Account at security.google.com/settings/security/permissions.
Data collected while a channel was connected stays in the app as the workspace's record unless you ask us to delete it. To delete stored data relating to you or to your channel, email contact@sentrismg.com from the account's or the channel owner's email address. We delete it from the app as soon as possible and within 7 calendar days. Deleting data stored by SentrisMG Suite does not in any way affect data stored by YouTube. To delete data on YouTube itself, use YouTube or another app authorized to delete that data.
12. Legal bases for using data
Under Article 6.1 of Andorran Law 29/2021 we rely on these legal bases:
- Account data and the work done in the app: performing our contract or collaboration with you (Article 6.1.b).
- Channel data the app reads or changes with a channel owner's Google authorization: the consent the owner gives when connecting the channel (Article 6.1.a). The owner can withdraw it at any time by disconnecting the channel or by removing the app's access in their Google Account, without affecting what was done before. Data already collected is then kept as the workspace's record of how its videos performed, on the basis of our legitimate interest in keeping that record (Article 6.1.f), until you ask us to delete it (section 11).
- Public YouTube data, including public comments with the commenter's display name, and public data about channels we follow for research: our legitimate interest in understanding how viewers react to videos and in researching the market for our own (Article 6.1.f).
- Request logs and security records: our legitimate interest in keeping the app and its data secure (Article 6.1.f).
- Payment and invoice records: our legal obligation to keep accounting records (Article 6.1.c).
Where we rely on legitimate interest, you can object at any time (section 13).
13. Your rights
Under Andorran Law 29/2021, on the protection of personal data, and, where it applies, the European Union's GDPR, you can ask us for access to your personal data, and to correct, delete, restrict or receive a copy of it, or object to how we use it. Write to contact@sentrismg.com. You can also complain to the Andorran Data Protection Agency (Agència Andorrana de Protecció de Dades).
The app's data is hosted in the European Union, which Andorran law treats as offering adequate protection. Some of the providers above, including Anthropic, Higgsfield, Vast.ai, ElevenLabs, GitHub and Google, process data in the United States. Google and GitHub are certified under the EU-U.S. Data Privacy Framework, which the European Commission has recognized as adequate. You can ask us at contact@sentrismg.com which safeguard applies to any other provider.
14. Children
The app is a working tool for adults and is not directed to children.
15. Changes and contact
When this policy changes, we publish the new version at this address with a new effective date. If a change affects how the app uses Google user data, we tell every affected user in the app and by email before it takes effect, and ask them to agree to the updated policy before the app uses their Google user data in the new way. For any question or complaint about the app's privacy practices, contact Sentris SLU (Sentris Media Group), Principality of Andorra, at contact@sentrismg.com.