Mayd It LLC / Privacy
Privacy Policy
Last updated 20 July 2026. Plain English, no boilerplate: what mayd-it.com collects, what our YouTube publishing tool does with data, what the employee portal stores, and how to make us delete any of it.
- We are Mayd It LLC, a small software company in Washington State, USA.
- This website runs no analytics and no advertising, and sets no tracking cookies. The only cookie we ever set is the sign-in session for our own staff portal.
- Our YouTube tool publishes our own clips to our own channel. It stores our own Google sign-in tokens on one office PC and nothing else. It has no other users and reads no YouTube data.
- We never sell or rent personal data.
- Want something deleted? Email bmay@mayd-it.com and we will do it within 7 days.
1. Who we are, and what this policy covers
mayd-it.com is operated by Mayd It LLC, a limited liability company registered in the State of Washington, United States (UBI 606 247 926). Mayd-It Games is the brand we release games under, and "May'd it" is the consumer brand on this site; both are brands of Mayd It LLC, not separate companies.
Mayd It LLC is responsible for the personal data described here. For any privacy question, complaint, or deletion request, email bmay@mayd-it.com. A real person reads that inbox and we aim to answer privacy requests within 7 calendar days.
This policy covers mayd-it.com itself (including the data-tools pages, the guides, and the employee portal) and the YouTube publishing tool we operate. Several of our products live on their own subdomains and are described by their own policies where they differ; the game site, for example, has its own at deflekt.games.mayd-it.com/privacy. The section on YouTube API Services below is identical on both, and applies to the same single tool.
2. YouTube API Services
We run an in-house tool called DEFLEKT Marketing Machine. It cuts short clips of our own gameplay footage and uploads them to the one YouTube channel we own. This tool uses YouTube API Services.
Because it uses YouTube API Services, two other documents apply on top of this one:
- The YouTube Terms of Service, at https://www.youtube.com/t/terms. By using this API Client you agree to be bound by the YouTube Terms of Service.
- The Google Privacy Policy, at https://policies.google.com/privacy, which governs what Google itself does with data. Nothing in our policy changes or overrides Google's.
Revoking our access to your Google account
Access granted to our tool can be revoked at any time from the Google security settings page: https://myaccount.google.com/permissions (the same page is also reachable at https://security.google.com/settings/security/permissions). Removing our app there immediately invalidates the tokens we hold, and the tool can no longer upload anything. In practice the only Google account our tool has ever been granted access to is our own studio account.
What the tool accesses
- One YouTube channel, which we own. Nothing else.
- One permission scope:
https://www.googleapis.com/auth/youtube.upload. That is upload-only. We deliberately did not request any broader scope. - One API endpoint:
videos.insert. That is the call that uploads a video. - It reads nothing. The tool does not list, search, download, or analyse videos, channels, comments, playlists, subscribers, or viewer data. There is no analytics or reporting call anywhere in it.
What it stores, and where
The only thing the tool stores is the channel owner's own OAuth tokens (an access token and a refresh token). They are written into a local configuration file on the studio owner's own Windows PC, in his own office.
The tool itself has no backend server, no database, no cloud storage and no analytics pipeline. It runs entirely on that one PC: nothing it touches is uploaded to any system Mayd It LLC operates, and it never sends YouTube API Data anywhere except back to YouTube. It stores no YouTube API Data of any kind and no data about any viewer, subscriber, or other person.
This is a statement about the marketing tool, not about every system we run. This website is hosted by Netlify and runs a private staff-login function, described in the "Employee portal" section below. That function is entirely separate from the tool described here and never receives YouTube API Data.
How we use, process and share that information
- Use: the tokens are used for one purpose only, which is to prove to Google that we are allowed to upload a video to our own channel.
- Processing: the tool reads the token from disk, sends it to Google as an authorization header, and writes the refreshed token back to disk. That is the whole of it.
- Sharing: the tokens are sent to Google / YouTube, and to nobody else, because Google is the party they authenticate us to. They are not shared with any other third party, any contractor, any advertiser, or any data broker.
- We do not sell, rent, trade, or transfer this information; we do not use it for advertising or ad targeting; we do not use it to build profiles of anyone; and we do not use it to train machine-learning models.
Limited Use
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion of data
- YouTube API Data: none is retained, because none is ever obtained. There is nothing to expire. Were we ever to store authorized data, it would be deleted or refreshed within 30 days, as YouTube's developer policies require.
- OAuth tokens are kept only for as long as the tool is in use. They are deleted by revoking access at the Google security settings page linked above, and by clearing them from the local configuration file. Both are done by the channel owner on his own machine, and either one stops the tool working.
- Deletion requests. Anyone may ask us to delete data we hold about them by emailing bmay@mayd-it.com. We will action it within 7 calendar days and confirm by reply. You do not need an account, and you do not need to explain why.
There are no third-party users, and no third-party content
This tool is a first-party publishing tool for Mayd It LLC. It is not a product, not a service, not licensed, sold, or made available to anyone outside the company, and it has no user base beyond the one person who owns the channel. It therefore handles no third-party user information at all.
The tool does not allow any third party to serve content or advertisements through it, and it displays no advertising itself.
How the clips are made, and what we disclose on them
For transparency, since the videos say so themselves: the gameplay in our clips is played by an automated AI test pilot, captured on our own machine, and cut automatically. Nothing publishes without a human reviewing it and clicking approve. Every caption and video description carries this line: "Gameplay by our AI test pilot. DEFLEKT is made by one human + a lot of AI." The link in each description points at our own site and carries UTM tags so we can tell which clip sent someone there; those tags identify the clip, not the viewer.
3. This website
mayd-it.com is a set of static pages hosted by Netlify (Netlify, Inc., United States), plus one serverless function that powers the staff portal described in section 4. Here is everything the public part of the site does.
No analytics, no advertising, no tracking
We run no analytics of any kind on this site: no Google Analytics, no tag manager, no Plausible, Fathom, Matomo, Hotjar, Clarity, or anything similar. There are no advertising pixels, no session recording, no social media trackers, and no third-party embeds. We do not build visitor profiles and we do not sell or share anything about you.
Cookies and device storage
Browsing the public pages of this site sets no cookies at all and stores nothing in your
browser's local or session storage. The only cookie this domain ever sets is mi_sess, the
strictly necessary sign-in cookie for our own employee portal, described in section 4. If you are not a member
of our staff signing in, you will never receive it. There is no cookie banner because there is nothing
optional to consent to.
Google Fonts
Our pages, including this one, load their typefaces from Google Fonts. That means your
browser fetches files from fonts.googleapis.com and fonts.gstatic.com, and as part of
any such request Google receives your IP address and your browser's user-agent string. That is
a transfer of data to Google and we would rather tell you than not. What Google does with it is governed by the
Google Privacy Policy. We
receive nothing back from it, and if you block those domains the site still works in a fallback typeface.
Server logs
Like every website, this one has to receive your request in order to answer it. Netlify, as our host, processes your IP address and request details to deliver the page and keeps standard server logs for security and reliability. We do not build reports from them or connect them to anything else. Our host also applies standard security headers to every page.
Links out
The module cards and the footer link to our other products and to third-party sites such as the Apify Store and Steam. Those have their own terms and privacy policies, and we are not responsible for them.
4. The employee portal
The link marked "Employee Login" leads to a private portal for people who work at Mayd It LLC. It is not open to the public and there is no self-service sign-up. It is described here for completeness, because it is the one part of this domain that processes personal data in a meaningful way.
- Credentials. Each account has a username and a password. Passwords are never stored:
what is stored is a
scrypthash with a per-user random salt. Optional two-factor authentication stores a TOTP secret so authenticator-app codes can be verified. - Session cookie. Signing in sets a cookie called
mi_sess. It isHttpOnly,Secure,SameSite=Strict, and expires after 12 hours. It carries a signed username and expiry and nothing else. It is strictly necessary to keep a signed-in user signed in, it is not used for analytics or advertising, and signing out clears it. - Where it is stored. Accounts and the published company ledger live in Netlify Blobs, a storage service run by Netlify in the United States.
- Ledger refresh requests. When a signed-in employee asks for a fresh ledger, a Netlify
Form submission named
ledger-refreshrecords the request time and the requesting username, so we know who asked. Nothing else is captured. - Retention. Account records are kept while the person works with us and are deleted when they no longer do. Sessions expire on their own after 12 hours.
5. Data tools and guides
The data-tools pages and their guides are reading material. They collect nothing beyond what section 3 describes, they set no cookies, and they have no forms. The tools themselves are published on the Apify Store and run on Apify's platform under Apify's terms and privacy policy, not on this site.
6. Who else receives data, in full
- Netlify, Inc. (United States) - hosts this website, runs the portal function, and stores the portal's data and form submissions.
- Google LLC (United States) - serves the webfonts, and is the destination for our own video uploads and the OAuth tokens that authorize them.
That is the entire list. We use no advertising networks, no data brokers, no customer data platforms, and no marketing automation.
7. Children
This site and our tools are not directed at children under 13, and we do not knowingly collect personal information from them. If you believe we hold information about a child, tell us at bmay@mayd-it.com and we will delete it.
8. Where data is processed
Mayd It LLC is in the United States, and all of the services above process data in the United States. If you are in the European Economic Area, the United Kingdom, or elsewhere outside the US, using this site means your data is handled in the US. The only routine transfer that happens without you doing anything is the Google Fonts request described in section 3.
9. Your choices
- Ask for a copy of anything we hold about you, or ask us to correct it.
- Ask us to delete it. No account and no justification needed, done within 7 days.
- Revoke our Google access at https://myaccount.google.com/permissions.
- Block Google Fonts in your browser if you would rather Google not see the request.
All of these go to the same place: bmay@mayd-it.com.
10. Changes to this policy
If we change what we collect or how we handle it, we will change this page and update the date at the top. This page is linked from the footer of the site so it stays easy to find.
11. Contact
Privacy questions, complaints, and requests, including anything about our use of YouTube API Services:
Mayd It LLC
Washington State, United States · UBI 606 247 926
bmay@mayd-it.com