Skip to main content

Security

Current product controls

Account Sign-In

  • Sign in with Google or a one-time email link
  • TitleHook does not store account passwords
  • Google access tokens are used during sign-in and are not stored by TitleHook
  • Sessions use signed, HTTP-only cookies
  • You can revoke other sessions from Settings

YouTube Access Boundary

Channel analysis currently uses only public YouTube Data API results. Adding a channel does not sign TitleHook into that YouTube account and does not give TitleHook permission to edit it.

Private YouTube Analytics is not currently connected. TitleHook cannot see private impressions, click-through rate, traffic sources, audience retention, revenue, or private subscriber information.

Application Controls

  • HTTPS protects traffic between your browser and TitleHook
  • Authenticated routes verify a signed session before returning user data
  • Admin routes require an allowlisted owner account
  • Abuse-prone endpoints use validation and rate limits
  • Billing events require signed webhook requests
  • Security headers restrict framing, content types, and cross-origin behavior

Customer Data Separation

Account details such as your email and first name, plus channels, conversations, projects, competitors, history, usage, and preferences, are keyed to the signed-in account. Requests for those records check the current session on the server.

Customer workspace content is not intended to appear in another customer's account. If you see data that does not belong to you, stop using the affected page and report it immediately.

Payments

Stripe hosts checkout and billing management. TitleHook stores subscription references and status, but does not receive or store your full card number, or CVC.

Subscription changes are checked server-side before account access is updated.

Account Control

You can revoke other sessions or permanently delete your account from Settings. Account deletion purges user-owned app data and attempts to cancel an active subscription. The action is irreversible.

Current Limitations

No internet service can promise perfect security or uninterrupted availability. TitleHook keeps claims limited to controls that exist in the current product and reviews authentication, billing, deletion, rate-limit, and channel-data paths before release.

Report a Security Issue

Send a reproducible description to security@titlehook.com. Do not include another person's private data, run destructive tests, or disrupt the service. Good-faith reports are reviewed based on risk.

Security Questions

Does TitleHook access my YouTube account?

No. The current channel scan reads public YouTube Data API results for the channel you add. It does not sign in to that YouTube account or receive permission to edit it.

Private impressions, click-through rate, traffic sources, audience retention, revenue, and private subscriber data are not currently connected.

What personal data do you collect?

Account details, channels, chat conversations, projects, competitors, title history, saved items, preferences, plan usage, and service errors.

Public YouTube metadata is stored for channels you add. See the Privacy Policy for the full list.

Is my payment info secure?

Stripe hosts checkout and billing management. TitleHook stores subscription references and status, but does not receive or store your full card number or CVC.

Can I delete my account?

Yes, from Settings. The deletion flow purges user-owned account and workspace data and attempts to cancel an active subscription.

A small number of operational records may remain only in anonymized or legally required form. Deletion is irreversible.

Tracking cookies or ad pixels?

No advertising or retargeting pixels. We use session and sign-in protection cookies plus Google Analytics 4 for basic product usage.

Browser tracking protection or an ad blocker can block analytics without preventing the core product from working.

Do you sell or share my data?

We never sell or rent personal data, use it for targeted advertising, or expose one customer's workspace to another customer.

Operational services receive only what is needed to provide sign-in, billing, chat requests, analytics, and public YouTube channel data.

How does authentication work?

You can sign in with Google or a one-time email link. TitleHook does not store account passwords.

Sessions use signed, HTTP-only cookies, and other sessions can be revoked from Settings.

What if there's a security breach?

Report suspected exposure to security@titlehook.com. We will investigate, contain the issue, preserve necessary evidence, and notify affected users when required by applicable law.

What privacy rights can I exercise?

Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, or receive a portable copy of your data.

Contact support@titlehook.com from the email linked to your account. We may need to verify ownership.