English
1. Who we are
The data controller is 佛山欧宿科技有限公司. OUSU Tech is our public-facing brand and OUSU Global Marketing is the product covered by this policy.
Contact: shiyongg2111@gmail.com.
2. Product and OAuth architecture
The Windows Overseas Operations Desktop Assistant provides secure sign-in, a dedicated browser and necessary assisted operations. Google OAuth uses a server-side Web application flow. OAuth callback handling, authorization-code exchange, token storage and Google API calls are completed on the server.
A platform administrator may enter a Google Client Secret in Desktop Assistant under Operations Admin → Interfaces & Keys. It is submitted to the server over HTTPS and encrypted there. It is not hard-coded into frontend source or the installer, is not persistently stored on the desktop, and the server does not return the plaintext Client Secret after saving. Configuration lists expose only whether fields are configured and non-secret configured values.
OAuth Access Token and Refresh Token are exchanged, encrypted, stored and used only by the server and are never returned to the web frontend or desktop client.
3. Data we may process
- Google account authorization information, granted scopes and expiry information.
- YouTube channel ID and channel name.
- OAuth Access Token and Refresh Token, encrypted on the server.
- Videos, publishing status, titles, descriptions and other required metadata.
- Comments and comment replies.
- Channel and video analytics data.
- Google Ads accounts, campaigns, advertising actions and performance metrics.
- Business account, operator and audit information needed for access control and tenant isolation.
Google access requested
Depending on the functions authorized by the customer, the application may request these scopes under a least-permission approach:
- https://www.googleapis.com/auth/youtube.upload
- https://www.googleapis.com/auth/youtube.readonly
- https://www.googleapis.com/auth/youtube.force-ssl
- https://www.googleapis.com/auth/adwords
4. How data is used
- Bind a customer's own YouTube channel.
- Upload and publish videos and query publishing status.
- Read and reply to comments.
- Display channel and video analytics.
- Create or manage advertising actions only after customer confirmation.
- Maintain authorization, security, troubleshooting and audit records necessary to provide the service.
5. Security and access
Secrets and OAuth credentials are encrypted at rest on the server. Access is restricted by platform role, enterprise tenant and the minimum permissions needed for a requested operation. Tenant data is logically isolated, and administrative and API operations are subject to authentication and access control.
We do not sell personal data. No security certification or endorsement by Google, YouTube or Meta is claimed.
6. Sharing and legal requirements
Data may be processed by infrastructure, storage, security, communication and platform API providers only as needed to operate the service. We may disclose the minimum required data when required by applicable law, a valid legal process, or to protect users and the service.
7. Retention and deletion
We retain information only while it is needed for an active authorization, service delivery, security, dispute handling, financial audit or legal obligation. Actual retention depends on account status, requested functions, backup cycles and applicable requirements; we do not claim a single fixed period that does not match those facts.
Users may revoke OAuth access in Google Account third-party access, submit a request through our Data Deletion page, or contact the public email above.
8. Your rights and children
Subject to applicable law, users may request access, correction, export, restriction, objection, authorization revocation or deletion. We may verify identity before acting. The product is intended for business users and is not directed to children.
9. Official policies
中文
一、我们是谁
数据控制方为佛山欧宿科技有限公司;对外品牌为 OUSU Tech;本政策适用的产品为 OUSU Global Marketing。
公开联系邮箱:shiyongg2111@gmail.com。
二、产品与 OAuth 架构
Windows“海外运营桌面助手”负责安全登录、专用浏览器和必要的辅助操作。Google OAuth 采用服务器端 Web 应用模式;OAuth 回调、授权码交换、Token 保存和 API 调用均在服务器端完成。
平台总管理员可在桌面助手“运营总后台 → 接口与密钥”中输入 Google Client Secret,并通过HTTPS提交到服务器加密保存。Client Secret 不写死在前端源码或桌面安装包中,不在桌面本地持久化;保存后服务端不会把明文Client Secret重新返回。配置列表仅显示“已配置”状态、已配置字段及允许公开的非敏感配置值。
OAuth Access Token 与 Refresh Token 始终由服务器交换、加密保存和使用,不返回网页前端或桌面客户端。
三、可能处理的数据
- Google 账号授权信息、授权范围和有效期。
- YouTube频道ID和频道名称。
- 在服务器端加密保存的 OAuth Access Token、Refresh Token。
- 视频、发布状态、视频标题、描述等必要元数据。
- 评论及评论回复。
- 频道和视频分析数据。
- Google Ads账号、广告计划及广告指标。
- 用于访问控制和多租户隔离的企业账号、操作人员与审计信息。
申请的 Google 权限
根据客户实际授权使用的功能,应用按最小权限原则申请以下范围:
- https://www.googleapis.com/auth/youtube.upload
- https://www.googleapis.com/auth/youtube.readonly
- https://www.googleapis.com/auth/youtube.force-ssl
- https://www.googleapis.com/auth/adwords
四、数据用途
- 绑定客户自己合法持有或获授权的频道。
- 上传和发布视频、查询发布状态。
- 读取和回复评论。
- 展示频道及视频分析数据。
- 仅在客户确认后创建或管理广告操作。
- 维持授权、安全、故障排查和必要审计。
五、安全与访问控制
敏感配置和 OAuth 凭据在服务器端加密保存;系统按平台角色、企业租户和最小权限控制访问,并对不同企业的数据进行逻辑隔离。管理操作和 API 操作均需要相应身份认证与权限。
我们不出售个人数据,也不宣称获得 Google、YouTube 或 Meta 的安全认证、合作或背书。
六、第三方处理与法律要求
为提供服务,基础设施、对象存储、安全、通信及平台 API 服务商可能在必要范围内处理数据。适用法律、有效法律程序或保护用户及服务所需时,我们可能披露最少必要信息。
七、保留、撤销与删除
我们仅在有效授权、服务交付、安全、争议处理、财务审计或法定义务所需期间保留信息。实际期限取决于账号状态、所使用功能、备份周期及适用要求,不虚构统一固定期限。
用户可在 Google 账号第三方访问管理页面撤销 OAuth 访问,也可通过数据删除页面申请删除,或联系公开邮箱。
八、用户权利与未成年人
在适用法律允许范围内,用户可提出访问、更正、导出、限制、反对、撤销授权或删除请求;执行前我们可能核验身份。本产品面向企业用户,不面向未成年人。