Privacy
Last updated October 9, 2026
Snapshot is a Chrome extension that makes share cards from your YouTube Studio numbers. It's built so that we hold as little as possible: your stats are read and drawn in your own browser, and our server mostly keeps your public profile. This policy covers the Snapshot extension, this website (snap.st), our API (api.snap.st, and api.stat.yt for versions before 0.5.0) and the Snapshot Discord bot (bot.stat.yt). Using them is also subject to our Terms.
Who we are
"Snapshot", "we" and "us" mean the people who run Snapshot. We are the controller of the personal data described here. For anything about your data, email i@built.so.
Snapshot was called stat.yt until October 2026. Same product, same accounts.
Snapshot is an independent product. It is not affiliated with, endorsed or sponsored by YouTube or Google.
What the extension reads, in your browser
- Your YouTube Studio data. While you use Snapshot on studio.youtube.com, it reads your videos' titles and thumbnails and their analytics: views, views per hour and per day, click-through rate, retention, subscribers gained, your channels' subscriber counts and, if your channel earns money, the video's estimated revenue. These are used only to draw your card. They are never sent to our server or to anyone else.
- Revenue is off by default. A video's estimated revenue goes on a card only when you turn it on for that video and confirm. It's drawn in your browser and never sent to our server; it reaches others only if you share the card.
- Your YouTube sign-in. Snapshot never asks for your Google password. To ask Studio for your numbers, it makes the same requests Studio's own page makes, inside the Studio tab. To do that it reads your YouTube session cookie in that tab and turns it into the one-time signature Studio expects, exactly as Studio does. The cookie and the signature go only to studio.youtube.com; Snapshot never stores them and never sends them to us or anyone else.
- Channels you manage for someone else. If you use Studio for a channel you have access to, Snapshot reads that channel's numbers the same way. Only share them if you're allowed to (see our Terms).
What stays in your browser
- Your cards and exports. Images and videos are made on your computer. Nothing is uploaded unless you share it yourself. Backgrounds and music you add stay on your computer too.
- Your Snapshot key. Your account is a key pair made in your browser instead of a password. The private key is kept in Chrome's extension storage (synced by Google to your other computers if Chrome sync is on) and in any backup file you save. It never reaches our server.
- Settings and small caches, in Chrome's extension storage: your card settings; a copy of your public profile
(with your Google email masked, like
e•••@gmail.com, if you saved your @ with Google); your linked channels' latest subscriber counts and when they were read, so a card can show your total across channels; the IDs of up to 200 videos you agreed to show revenue for; the video you last picked; and the day the extension last reported its version (see below).
What our server keeps
Only what's needed to show your @ on cards and keep it yours:
- your @handle
- your public key, which checks that changes to your account come from you
- your profile picture, if you upload one
- the YouTube channels you link: each channel's ID, name, @handle and picture link. No stats from Studio.
- the day you made your account, and the time of your last change, which stops old requests from being sent again
- badges we add by hand (for example "Staff"), and whether we've let your account use a 1-character @
- only if you choose Save your @ with Google: your Google account's email address and its account ID
- only if you join the leaderboard: the day you joined, and the public numbers described below
Your Snapshot profile is public. Anyone can look up an @ and see its picture, the channels linked to it, its public key, the day it was made and its badges. That includes cards where you've hidden your channel, since they still show your @. Your Google email is never in your profile; only you see it, masked.
We (the people who run Snapshot) can see the account list, including the Google emails saved with it, to run the service, help you, and enforce our Terms, for example by renaming or removing an @.
Saving your @ with Google (optional)
You can save your @ with a Google account, so you can get it back on another computer or after reinstalling by
signing in with Google. Snapshot asks Google only for your email address and account ID (the openid and
email scopes). Nothing that gives access to your YouTube channel, Gmail, Drive or anything else.
- We keep the email and Google's account ID only to find your @ when you sign in with Google, to keep each Google account to one @, and to contact you about your account if we need to. They're never shown on your profile or cards, never shared and never sold, and never used for ads.
- Signing in with Google on a new computer moves your account to that computer's new key. The old key stops working; we keep a record that it was replaced so the old browser knows it's signed out.
- You can stop saving with Google anytime from your profile. The email and account ID are deleted from our server right away, as they are when you delete your account. You can also remove Snapshot's access in your Google Account settings.
Snapshot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google APIs will also adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
The leaderboard (optional, when available)
The leaderboard is off for everyone unless you join it from your profile, and only channels you've proven you control can be on it. To prove a channel is yours, you put a short code we give you in the channel's public description, and our server reads that channel's public YouTube page to check it. While you're on the leaderboard, our server reads your verified channels' public subscriber and view counts from YouTube's public channel pages up to once a day and keeps a daily copy for up to 60 days. Never anything from Studio or the extension. The leaderboard publicly shows your @, the channel's name and those public numbers. Leave anytime: you're taken off at once and those copies are deleted.
Counts and security
- Claim limit. To stop people from grabbing lots of @s, each network can claim 5 a day. For that the server counts claims per network for the current day, under a one-way code made from your network address with a secret key. It never stores the address, the count isn't linked to which @s were claimed, and it's deleted the next day.
- Version counts. Once a day the extension tells our server which version of Snapshot it is, so we know when it's safe to stop supporting old versions. The server only adds one to that day's count for that version: no ID, no address, no time. Counts are deleted after 60 days.
- Hosting. Our server, this site and the bot run on Cloudflare, which receives your IP address and basic request details to deliver and protect them, and may keep limited logs under its own privacy policy. Connections to us are encrypted (HTTPS).
What we don't do
- No ads, no ad trackers, and no third-party analytics, in the extension or on this site.
- We don't sell your personal information, and we don't share it for targeted advertising.
- No use of your data to decide creditworthiness or for lending.
- No cookies on this site.
Who else is involved
- Cloudflare hosts our server, database, picture storage, this site and the bot, as our service provider.
- Google runs the sign-in page if you choose to save your @ with Google, and Chrome sync if you use it. Google's handling of your data is covered by the Google Privacy Policy.
- YouTube: the extension talks to YouTube Studio and loads video and channel pictures from YouTube's image servers, which see your IP address like any image request. The extension's font comes with it, and this site serves its own, so nothing is loaded from Google Fonts.
- Discord, for the bot (below).
Besides these, we only disclose personal data if the law requires it, to protect people or the service from fraud or abuse, or as part of a merger or sale of Snapshot, in which case this policy keeps applying to your data.
The Snapshot Discord bot
The bot posts cards about public YouTube videos in Discord servers that have added it, and can give server roles by subscriber count. It uses the YouTube API Services to read public channel and video data. By using it you agree to the YouTube Terms of Service, and YouTube's handling of data is covered by the Google Privacy Policy.
- Tracked channels. For channels a server chooses to track, the bot keeps public data: channel ID, name and picture, and public video titles, view, like and comment counts. Nothing private.
- Verify. If you press Verify, Discord asks you to let Snapshot see your Discord account and connected accounts. The bot reads your Discord user ID and the YouTube channel you've linked to Discord, looks up its public subscriber count, and tells Discord the count so the server can give you roles. It keeps your Discord user ID, that channel's ID, its subscriber count and when you verified. Your Discord sign-in is used for this one check and never stored. A short-lived cookie (10 minutes) on bot.stat.yt protects the sign-in from forgery.
- To remove your verification, unlink the bot in Discord (User Settings, Authorized Apps) and email us, or verify again with no YouTube channel linked, which deletes the record.
Why we use your data (legal bases)
- To provide Snapshot (your @, profile, linked channels, signing back in): needed to perform our agreement with you (our Terms).
- Things you switch on (saving with Google, the leaderboard, showing revenue on a card, Discord verification): your consent, which you can withdraw anytime as described above.
- Keeping Snapshot safe and working (the claim limit, replay protection, version counts, enforcing our Terms, the bot's public channel data): our legitimate interests in running a secure, working service, which we keep small.
- The law: when we have to keep or disclose something to comply with it.
How long we keep it
- Your account (@, public key, picture, linked channels, badges): until you delete it, or we remove it under our Terms.
- Your Google email and account ID: until you stop saving with Google or delete your account.
- An old profile picture: deleted as soon as you replace or remove it.
- Leaderboard copies of public numbers: up to 60 days, and deleted when you leave.
- Claim counts: until the next day. Version counts: 60 days.
- A deleted account's public key: 15 minutes, so old requests can't bring it back.
- Public keys replaced by a Google sign-in, and a 1-character @ permission we granted (with a note of the @ it was for): kept with the key, with no set end date.
- Discord verification: until you remove it or verify again.
- Cloudflare's database backups keep deleted data for up to 30 days, after which it's gone.
Your rights
Depending on where you live (for example in the EU, UK or California), you can ask to access, correct, delete or get a copy of your personal data, object to or restrict how we use it, and withdraw consent. Most of this you can do yourself in the extension: edit or delete your profile, stop saving with Google, or leave the leaderboard. For anything else, email i@built.so. Since Snapshot has no passwords, we may ask you to prove the account is yours, for example by making a change from the extension or from the Google account saved with it. We answer within one month (45 days for California requests), and never treat you worse for using your rights. You can also complain to your data protection authority (in the UK, the ICO).
California. In the last 12 months we've collected these categories of personal information: identifiers (your @, public key, Google email and account ID, Discord user ID), the profile picture you upload, and public information about YouTube channels you link or verify. We get it from you, from Google when you sign in with it, from Discord when you verify, and from YouTube's public pages. We use it only for the purposes above. We don't sell or share personal information (as California law defines those words), and we don't use sensitive personal information to infer things about you.
International transfers
Cloudflare and Google handle data in many countries, including the United States. When personal data from the EU, UK or Switzerland goes abroad, we rely on safeguards such as the EU-US Data Privacy Framework (and its UK and Swiss extensions) or the European Commission's Standard Contractual Clauses, as offered by those providers.
Children
Snapshot is not directed to children. You must be at least 13 to use it (and old enough to use YouTube where you live), and if you're under 18 you need a parent's or guardian's permission. We don't knowingly collect personal data from children under 13; if you think we have, email us and we'll delete it.
Cookies and local storage
This site sets no cookies and uses no local storage. The extension keeps the items listed under "What stays in your browser" in Chrome's extension storage. The bot sets the one short-lived cookie described above, only while you verify. None of these are used for tracking or ads.
Why the extension asks for what it does
- studio.youtube.com: to read your numbers there, in your browser, and to add the Snapshot button to Studio.
- Storage: to keep your settings and your key.
- Side panel and scripting: to show the card editor next to Studio, and to connect to a Studio tab that was already open when you installed Snapshot.
- Identity: to open Google's sign-in window when you choose to save your @ with Google. It doesn't let Snapshot see your Google account on its own.
Deleting your data
To delete your account, click the Snapshot icon in Chrome's toolbar, open your profile and choose Delete account. Your @, profile picture, linked channels, badges, leaderboard entry and Google email (if saved) are removed from our server right away, and the @ is free for anyone. Your public key is kept for 15 more minutes so old requests can't bring the account back, and Cloudflare's database backups keep deleted data for up to 30 days. If you can't get into your account anymore, email us from the Google account it's saved with, or with other proof that it's yours.
Removing the extension from Chrome deletes what it stored in your browser, but not your account on our server, so delete the account first if you want it gone. Cards you've already shared are copies outside our control.
Security
There are no passwords to leak: changes to an account must be signed with a key that never leaves your browser, and all connections are encrypted. No system is perfectly secure, so keep a backup of your key private and don't share it. If we learn of a breach affecting your data, we'll tell you and the authorities where the law requires.
Changes
If this policy changes, the new version will be posted here with a new date. If a change affects what the extension collects or how it's used, we'll also tell you in the extension before it applies and, where needed, ask for your consent again.
Contact
Email i@built.so.
Snapshot is not affiliated with, endorsed or sponsored by YouTube or Google. YouTube, YouTube Studio, Google and Chrome are trademarks of Google LLC. Discord is a trademark of Discord Inc.