SourceIndex

Legal

Privacy Policy

Draft, pending legal review Last updated October 7, 2026

This is a draft. It describes what SourceIndex actually does today, in plain English, but a lawyer hasn't reviewed it yet. The reviewed version will replace it at this address, and we'll note what changed.

SourceIndex lets AI agents research YouTube videos: search, read transcripts, get timestamped summaries and cite the original video. This page explains what we store about you while that happens, and what you can do about it.

The short version

  • We store your email, your agent's usage history (for 12 months) and what you've paid for.
  • You can delete any history item, or all of it, at any time.
  • When you delete history, we keep only an anonymous count of which videos were read, so creators are still credited. It can't be traced back to you.
  • Card details go to Stripe. We never see your card number.
  • No ads, no ad trackers, and we don't sell your data.

Who we are

SourceIndex is run by TooAvid Technologies LLC ("we", "us"). We decide how your data is used, which makes us the controller of it. Questions go to hello@sourceindex.ai.

SourceIndex is not affiliated with or endorsed by YouTube or Google.

What we store

If you join the waitlist

  • Your email address, and whether you said you're a builder or a creator (optional).
  • The page you signed up from, your browser's user-agent string, and a salted one-way hash of your IP address. We never store the IP address itself; the hash only lets us limit repeated sign-ups.
  • When you signed up, whether our welcome email was sent, and whether you unsubscribed.
  • A note that your email has 100 free credits waiting, and whether they've been given to an account.

If you create an account

  • Account: your email address. If you sign in with Google, also your name and profile picture as Google shares them. We don't use passwords: you sign in with Google or with a one-time link and code sent to your email.
  • Agent connections: each app you connect (for example "Claude Code"), when it was connected and last used, and whether you've disconnected it.
  • API keys: a name you choose, the first few characters, and a one-way hash of the key. We can't read your key back after we show it to you once.
  • Agent usage history: each request your agent makes through SourceIndex: which tool it used, what it sent (search terms, video IDs, time ranges), how many results came back, how many credits it cost, and when. Requests are grouped into research runs so you can browse them in History.
  • Usage of videos: which videos and channels your agent read or summarized, and how much of each. We use this for billing and to share subscription revenue with creators.
  • Credits and plan: your credit balance, grants and spending, your plan and billing period, and a record that your email has received its free sign-up credits (so they're given once per email).

If you pay

Payments are handled by Stripe. Stripe collects your card details, billing address and tax information directly; we never see or store your full card number. We keep the Stripe customer and subscription IDs, your plan, payment status and invoice history.

When you visit our sites

sourceindex.ai sets no cookies and runs no analytics or ad trackers. The SourceIndex web app keeps your sign-in session in your browser's storage so you stay signed in. Like any website, our hosting providers log requests (IP address, time, the page requested, errors) to keep the service running and secure; those logs are kept for a short time.

If you email us

We keep the emails you send to hello@sourceindex.ai so we can reply and keep track of the conversation.

Video content

To answer your agent, we fetch public information about YouTube videos: titles, descriptions, chapters, channel names and captions. We cache transcripts and summaries and reuse them for anyone who asks about the same video, which keeps costs down. This cache is about videos, not about you: it doesn't record who asked, except through your own history above.

Summaries are written by an AI model from the video's transcript, title and channel name. Your search terms, account and history are not sent to the model.

Whenever we show or cite a transcript, we link to the original video at the right timestamp. Creators can opt their channel out; once they do, its transcripts and summaries are no longer served.

How we use it

  • To run the service: sign you in, connect your agents, answer their requests and show you your history.
  • To bill you: count credits, apply your plan and stop runaway costs (we pause expensive operations if an account's costs pass a safety limit).
  • To pay creators: share part of subscription revenue with the channels agents actually used.
  • To email you: sign-in links, the waitlist welcome email, your invite, receipts and important account notices. Waitlist emails have an unsubscribe link.
  • To keep the service safe: limit abuse, investigate errors and protect accounts.
  • To meet legal obligations, such as tax and accounting records.

We don't use your history to train AI models, and we don't let our providers do so.

Where the law asks for a legal basis (for example in the EU and UK), we rely on performing our contract with you (running the service and billing), our legitimate interests (security, preventing abuse, crediting creators with anonymous counts) and legal obligations (tax records). For optional emails, we rely on your consent, which you can withdraw by unsubscribing.

How long we keep it

  • Agent usage history: 12 months. Each night we remove history older than that, in the same way as a deletion you make yourself (below).
  • Account, connections and keys: until you delete your account. Revoked keys stop working at once.
  • Payment and invoice records: as long as tax and accounting law requires (usually several years).
  • Waitlist entries: until launch invites are sent and for a while after, or until you ask us to remove yours.
  • Anonymous usage counts: kept, because they carry no personal data and they're how creators get paid for what agents read.
  • Hosting logs: a short period set by each provider, typically days to weeks.

Deleting your data

In the web app's History, you can delete a single request, a whole research run, everything from one agent, or all of your history.

What happens when you delete history. The requests, search terms and run names disappear from your account and from our records linked to you. What stays is an anonymous count of which videos were read and how much, with no user ID, no connection, no run and no search terms. We keep it so creators are still credited for reads that really happened. To split each month's creator share by subscriber, the count carries a code made with a secret key from your account ID and the month; without that secret it can't be turned back into an account, and nobody outside SourceIndex has it. Every deletion is logged by count only, without any user details.

Deleting your account. Email hello@sourceindex.ai from the address on your account and we'll delete it. (A delete button in the app is coming.) That removes your account, connections, keys, history and credits. We keep anonymous usage counts as above, invoices as required by law, and a record that your email received free sign-up credits so they aren't given twice. Stripe keeps its own payment records under its own policy.

Leaving the waitlist. Use the unsubscribe link in any waitlist email to stop emails. To remove your entry completely, email us.

Who processes it

We use these companies to run SourceIndex. Each one handles data only to provide its service to us, under its own data-protection terms.

ProviderWhat forWhat it handles
SupabaseDatabase and sign-in (US East)Everything in "What we store", except card details
Fly.ioServers that run the SourceIndex API and agent connection (US East)Your agent's requests while they're processed; request logs
CloudflareThis website, DNS, email forwarding, file storageWaitlist sign-ups in transit, cached video text, request logs, emails to hello@sourceindex.ai
ResendSending emailYour email address and the emails we send you
OpenAIWriting video summariesPublic video transcripts, titles and channel names only; not your account or searches
DecodoFetching public YouTube pagesThe search terms and video IDs your agent asks about; not your account
UpstashRequest queue and rate limitsShort-lived job and counter data
StripePayments and sales taxCard and billing details, email, plan, invoices
GoogleSign in with Google, if you use itYour Google sign-in

Our data is stored in the United States. If you're outside the US, your data is transferred there; we rely on our providers' standard contractual clauses or equivalent safeguards for that.

Google and YouTube data

Sign in with Google. We ask Google only for your email address, name and profile picture, and use them only to create and sign in to your SourceIndex account. We don't ask for access to your Gmail, Drive, contacts or anything else.

Connecting a YouTube channel (creators, coming later). When channel claiming opens, a creator will be able to prove they own a channel by signing in with Google and granting read-only access to their YouTube account. We'll use it only to identify the channels you own and to show you their statistics; we won't post, edit or delete anything. You can revoke access at any time in your Google Account permissions.

SourceIndex uses YouTube API Services. By using those features you agree to the YouTube Terms of Service, and Google's handling of data is described in the Google Privacy Policy.

SourceIndex's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We don't sell Google user data, use it for advertising, or use it to train AI models.

What we never do

  • Sell or rent your personal data.
  • Show ads, or share your data with advertisers or data brokers.
  • Train AI models on your history.
  • Show one user another user's history. Each account's data is walled off at the database level.

We share data outside the providers above only if the law requires it (for example a valid court order, and we'll tell you if we're allowed to), to protect people or the service from harm, or if SourceIndex is sold or merged, in which case this policy keeps applying to your data and we'll tell you first.

Your rights

Wherever you live, you can ask us to show you, export, correct or delete the personal data we hold about you, or to stop using it for something. Email hello@sourceindex.ai and we'll answer within 30 days. We may need to confirm the request comes from you.

Depending on where you live (for example the EU, the UK or California), you may have further rights, including objecting to some uses and complaining to your local data-protection authority. We don't sell or "share" personal data for advertising as California law defines it.

Security

Connections are encrypted. API keys are stored only as hashes, sign-in uses Google or one-time codes instead of passwords, and the database blocks any account from reading another's rows. No system is perfectly secure; if a breach affects your data, we'll tell you as the law requires.

Children

SourceIndex is for adults. You must be 18 or older to create an account, and we don't knowingly collect data from children. If you think a child has given us data, email us and we'll delete it.

Changes

We'll update this page when what we do changes, and change the date at the top. For significant changes, we'll email account holders before they take effect.

Contact

TooAvid Technologies LLC, operating SourceIndex
hello@sourceindex.ai