privacy

Last updated: September 1, 2026

TasteDump (“the Service,” “we,” “us”) is a personal inspiration bank that gathers the videos you’ve saved on other platforms into one gallery. This policy explains what we collect, why, who we share it with, and the choices you have. We aim to collect as little as the Service needs to work.

What we collect

  • Account detailsA username and the credentials you use to sign in. If you use a passkey, we store its public key and credential ID (never a password or biometric — those stay on your device). If you create an API token, we store a hashed reference to it.
  • Connected accountsWhen you connect X (Twitter) or Google, we store the account identifier and the access and refresh tokens needed to read your data, encrypted at rest. Reads of your X data use your own token, not anyone else’s.
  • Content you saveMetadata about the videos you’ve bookmarked or saved — links, titles, authors, thumbnails, and any notes, categories, or “why this works” text you add. We also cache compressed copies of some media so the gallery loads quickly.
  • Payment informationIf you buy credits, payment is handled by Stripe. We never receive or store your full card number — Stripe does. We keep a record of the transaction (amount, date, a Stripe reference, and a credit ledger) and, if you provide one, a receipt email address.
  • Technical & anti-abuse dataYour IP address and basic request data, used to rate-limit abuse and, where enabled, a Cloudflare Turnstile check to keep bots out of sign-up and checkout. We keep short-lived logs of syncs and webhook events to operate the Service.

How we use it

  • To run the ServiceAuthenticate you, fetch and display the videos you’ve saved, and store your notes and organization.
  • To process paymentsApply credits you purchase and meter usage against them.
  • To keep it secureDetect and prevent abuse, fraud, and automated sign-ups or purchases.
  • To operate and improveDiagnose problems and keep the Service reliable.

We do not sell your personal information, and we do not use it for advertising.

Who we share it with

We share data only with the service providers that make the Service work, and only as needed:

  • X (Twitter) & GoogleTo authenticate you and read the bookmarks or saves you ask us to import.
  • StripePayment processing. See Stripe’s own privacy policy.
  • CloudflareThe Turnstile bot check on sign-up and checkout, where enabled.
  • Vercel & TursoHosting, database, and file storage for the Service’s data and cached media.

We may also disclose information if required by law, or to protect the rights, safety, and integrity of the Service and its users.

Cookies

We use cookies that are necessary for the Service to function — for example, to keep you signed in and to secure the sign-in flow. Cloudflare Turnstile may set its own cookies where it is enabled. We do not use advertising or cross-site tracking cookies.

Google / YouTube data

When you connect Google to import YouTube videos, we request the https://www.googleapis.com/auth/youtube.readonly scope, which is read-only. We read only your own YouTube data: the videos in your Liked Videos playlist or a playlist you choose, and their titles, thumbnails, and durations.

This data is used solely to display those videos in your own gallery on TasteDump. We do not use it for advertising, and we do not share it except with the service providers listed above (hosting and storage) that are necessary to operate the Service. Access and refresh tokens are encrypted at rest. Disconnecting Google in Settings deletes the stored tokens immediately; imported video metadata can be deleted along with your account as described above.

TasteDump’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention & your choices

  • Disconnect an accountYou can disconnect X or Google at any time in Settings; we delete the stored tokens for that connection.
  • Delete your dataYou can ask us to delete your account and the content associated with it. Some records tied to completed payments may be retained where required for legal or accounting reasons.
  • AccessYou can ask for a copy of the personal data we hold about you.

We keep personal data only as long as your account is active or as needed to provide the Service and meet legal obligations.

Security

Connected-account tokens are encrypted at rest, passkeys are stored as public keys only, and API tokens are stored hashed. No system is perfectly secure, but we take reasonable measures to protect your data.

Children

The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal information.

Changes

We may update this policy from time to time. Material changes will be reflected by the “last updated” date above.

Contact

Questions about this policy or your data? Reach us at wafflehaque@gmail.com.

TasteDump is a personal project. This policy describes current practices and is not legal advice.