Privacy Policy

Last updated 31 August 2026

Histify is a Chrome extension and companion web dashboard that finds the music videos in your own YouTube watch history or liked videos and helps you save them into a YouTube playlist. This policy explains exactly what data that involves, where it goes, and how to get rid of it.

The short version: we only handle your own YouTube data, only to build your playlists, and we never sell it or use it for advertising.

1. Who processes your data

Histify operates the extension and the dashboard. For any privacy question, write to elfatmemaj@gmail.com.

2. What we collect

Account details. If you create a dashboard account we store your name, email address, a hashed password, and — if you sign in with Google — your Google account ID and profile picture. If you enable two-factor authentication or a passkey, we store the credentials needed to verify it.

Google / YouTube authorisation. Both the extension and the dashboard ask you to grant access to your YouTube account:

  • The extension uses Chrome's built-in Google sign-in. The resulting access token stays inside your browser and is sent to our server only as proof of who you are when you press Sync.
  • The dashboard asks separately for permission to manage your YouTube playlists, so it can create them for you while your browser is closed. Those access and refresh tokens are stored encrypted in our database.
  • Scopes requested: your email address and basic Google account ID (to identify you), and YouTube access (to read your liked videos and create playlists).

Music video data. When you open your YouTube history page, the extension reads the video IDs already displayed on that page in your browser. It then asks the YouTube Data API for each video's title, channel name, thumbnail URL, duration, and category, and keeps only the videos YouTube classifies as music. If you choose to sync, those music entries are stored on our server against your account, along with where they came from (history or liked videos), when they were collected, and whether you have saved or dismissed them.

Playlist activity. When you save a playlist, we record its title, its privacy setting, how many tracks were requested, how many succeeded or failed, and when the run started and finished, so the dashboard can show you progress.

Technical data. Standard web-server and session records, including your IP address, browser user agent, and error logs. These are used to keep the service working and secure.

3. What we do not collect

  • We do not track your browsing. The extension's page script runs only on youtube.com/feed/history and nowhere else.
  • We do not store non-music videos, watch timestamps, or anything else from your history beyond the music entries described above.
  • We do not download, copy, or host any video or audio content — only titles, thumbnails, and links to YouTube.
  • We use no advertising networks, no third-party analytics, and no tracking cookies. Cookies are used only to keep you signed in.

4. How we use it

Your data is used solely to run the features you asked for: signing you in, showing your music tracks on the dashboard, and creating or adding to YouTube playlists on your behalf. We do not sell, rent, or share your data with anyone for advertising, profiling, or any unrelated purpose, and we do not use it to train machine-learning models.

5. Google API Services disclosure

Histify uses YouTube API Services. Its use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. By using this service you also agree to the YouTube Terms of Service, and Google's own handling of your data is described in the Google Privacy Policy.

You can review or revoke this application's access to your Google account at any time at myaccount.google.com/permissions.

6. Who else sees your data

  • Google / YouTube — every metadata lookup and playlist change is a request to YouTube's API, made with your own authorisation.
  • Our hosting and database provider — which stores the data on our behalf.
  • Legal authorities — only where we are legally required to disclose.

That is the complete list. There is no one else.

7. How long we keep it

Synced tracks stay on your dashboard until you dismiss them or delete your account. Deleting your account removes your profile, your stored tracks, your playlist history, and your stored YouTube tokens. Disconnecting YouTube in settings revokes and deletes the stored tokens immediately. Signing out of the extension clears everything it had cached in your browser, and uninstalling it removes that cache entirely.

8. Security

Traffic is served over HTTPS, passwords are stored only as hashes, and YouTube access and refresh tokens are encrypted at rest. No system is perfectly secure, so please use a strong, unique password and enable two-factor authentication if the account matters to you.

9. Your choices

You can view and correct your details in settings, dismiss or delete synced tracks, disconnect YouTube, delete your account outright, and request a copy of your data by emailing us. Depending on where you live you may also have statutory rights of access, correction, deletion, and portability — we will honour those requests either way.

10. Children

This service is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

11. Changes

If this policy changes we will update the date at the top of this page. Significant changes will be announced in the dashboard before they take effect.

12. Contact

Questions, requests, or complaints: elfatmemaj@gmail.com.