Site information

Privacy policy

How Professor Plays Bass handles site, account, and Google user data.

Last updated: September 2, 2026

Overview

Professor Plays Bass is a music catalog, blog, and private production workspace. Public visitors can browse published content. Authorized administrators can sign in to manage the catalog and connect a YouTube channel through Google OAuth.

Information this site handles

  • Public visits: the site records daily aggregate page counts by page, content item, and whether the visitor was signed in. These analytics do not retain an IP address, a visitor identifier, or the browser user-agent string.
  • Signed-in accounts: the site stores the local Django account information supplied by its authentication system, permissions, a user-configured public display name, and security and audit records needed to operate private features.
  • Local browser storage: the site stores a light or dark theme preference in the browser. Authentication and form-security cookies are used when a user signs in or submits a form.
  • Blog comments: a visitor who chooses to comment supplies a public display name and private email address. The site stores a separate commenter identity, comments, replies, reactions, verification records, submission times, and a secret-keyed digest derived from network and browser information for spam prevention. It does not store the raw IP address with the comment. Comments remain private until approved; email addresses are never displayed publicly.
  • Operational records: the hosting environment may retain short-lived security and error logs needed to operate and protect the service.
  • Contact requests: a visitor who uses the private contact form supplies a name, email address, topic, and message. The application sends that information through its configured email provider to a monitored private inbox and does not store the message in the application database. The email provider and receiving mailbox may retain it according to their operational retention settings. A secret-keyed digest derived from network and browser information is cached for up to one hour to limit abusive submissions; the raw IP address is not stored with the request.

Google and YouTube data

A staff administrator may voluntarily connect a Google account that owns or manages a YouTube channel. Professor Plays Bass uses YouTube API Services and requests only the following three OAuth scopes. It does not request access to the administrator's Google profile, email, contacts, files, advertising data, or YouTube revenue data.

  • youtube.force-ssl: Google describes this scope as permission to see, edit, and permanently delete YouTube videos, ratings, comments, and captions. This application uses it only to read an already linked, channel-owned video before a write; apply an administrator-confirmed title, description, visibility, and embedding setting to that video; list channel-owned playlists; check whether the video is already in a selected playlist; and add it to that playlist. The application does not delete or upload videos and does not read, create, edit, or delete ratings, comments, or captions.
  • youtube.readonly: used to identify and display the connected channel, its channel ID, and its uploads playlist, and to provide the read authorization required for YouTube Analytics report queries. It does not permit the application to change YouTube content.
  • yt-analytics.readonly: used to retrieve and display non-monetary channel reports for administrator-selected date ranges, including views, estimated minutes watched, subscribers gained, and subscribers lost. The application does not request the monetary analytics scope or access estimated revenue or advertising-performance reports.

The site stores the channel ID and name, uploads-playlist ID, granted scopes, token-expiration metadata, an encrypted OAuth refresh token, and synchronized playlist identifiers, names, and privacy states. YouTube Analytics responses are cached for up to one hour and are not added to the site's permanent traffic analytics. OAuth access tokens are not stored in the application database.

Every YouTube write is initiated and confirmed by an authenticated staff administrator. The application does not publish, modify, or organize YouTube content automatically and does not use these permissions for planned or unimplemented features.

How information is shared

Google user data is sent to Google only as needed to complete the administrator-requested YouTube actions described above. It is not sold, used for advertising, shared with data brokers, or transferred to OpenAI or MusicBrainz. Authorized site administrators can view the connected channel, synchronized playlists, and analytics inside the private application interface. Hosting and database providers may process application data only as needed to run, secure, and maintain the service and are not permitted to use it for their own purposes.

The site's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Embedded media

Published pages may contain players or images supplied by YouTube, Vimeo, or SoundCloud. Loading or using that media can send the visitor's IP address and browser information to the selected provider under that provider's privacy policy. YouTube videos use YouTube's privacy-enhanced embed domain where supported. The site does not sell advertising, but an embedded provider may supply its own content or advertisements under its terms and privacy policy.

Google and YouTube terms

Google's handling of data is described in the Google Privacy Policy. By connecting or using this application's YouTube features, authorized administrators also agree to the YouTube Terms of Service.

Retention, security, and deletion

Google authorization data is retained while the YouTube integration is connected. Refresh tokens are encrypted at rest, and integration details are restricted to authorized staff. Disconnecting YouTube revokes the Google authorization before deleting the locally stored OAuth credential, channel connection, and synchronized playlist records. Operational audit entries may retain the staff actor, time, action, outcome, and a YouTube video identifier or playlist title so the site can document that a connection or publishing action occurred. YouTube Analytics responses expire from the application cache after no more than one hour. A deletion request also applies to YouTube API data present in those audit entries. Commenter identities, comments, reactions, and their abuse-control digests remain until a moderator deletes them. Used and expired verification records may be removed as operational housekeeping.

A Google user can also revoke access from their Google security settings. A user may request deletion through the contact method below; requests made directly to the site operator are completed as soon as possible and within seven calendar days. When a Google-side revocation is detected, the application deletes the stored OAuth credential and associated YouTube API data as soon as possible and within 30 calendar days of revocation. Disconnecting or requesting deletion removes data stored by this application but does not delete videos, playlists, analytics, or other data stored by YouTube. YouTube data must be deleted through YouTube or another authorized client that supports that action.

Your choices

Public visitors can browse without creating an account. Browser settings can remove the saved theme preference and control cookies. Authorized users can change their public display name. A staff administrator can disconnect the YouTube integration at any time or request deletion of stored YouTube API data. A commenter may ask the site operator to remove a comment. These requests can be submitted through the private contact form.

Contact

For privacy questions, complaints, or requests to delete stored data, use the site's private contact form.

Changes to this policy

This policy may be updated when the site's features or data practices change. The revision date above identifies the current version.