Privacy policy
Last updated 31 August 2026
This policy explains what FS Content Creation ("we", "us") collects when you use Dash (the "Service"), why we collect it, and what we do with it. FS Content Creation is the controller of that data.
Who this applies to
The Service is closed: accounts are created by invitation. This policy covers the people who sign in and the social media accounts they choose to connect.
What we collect
Account data
- Your name and email address, provided when your account is created.
- A hashed password, and the timestamps of your sessions.
- The workspace you belong to and your role in it.
Data from connected Google accounts
If you connect a Google account to manage a YouTube channel, we request the
youtube.force-ssl scope and store:
- Your Google account id and the email address on that account, to show you which account is connected.
- OAuth access and refresh tokens, encrypted at rest, used only to call the YouTube Data API on your behalf.
- Public metadata for the channels that account owns: channel titles, video titles and ids.
- Public comments left on those videos, including the comment text, its author's public display name and channel id, and the time it was posted.
Data from connected Facebook pages
- Page ids and names, and the public posts published on those pages.
Technical data
- Server logs containing IP address, user agent and requested URL, kept for security and debugging.
- A session cookie, and a "remember me" cookie if you ask to stay signed in. We do not use advertising or analytics cookies.
Why we use it
- To authenticate you and keep your workspace separate from every other workspace.
- To show comments and posts from the accounts you connected, and to let you moderate the comments on your own channels.
- To keep the Service working: rate limiting, quota accounting, error diagnosis and abuse prevention.
We do not use your data, or data received from Google APIs, to build advertising profiles, to train machine learning or artificial intelligence models, or for any purpose unrelated to providing the features you asked for.
Google API Services Limited Use disclosure
Dash uses YouTube API Services. Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely: data obtained from Google APIs is used only to provide the features described above, is never sold, never transferred to third parties except as described under "Sharing" below, and is never used for advertising.
By using the Service you also agree to the YouTube Terms of Service. Google's own handling of your data is described in the Google Privacy Policy.
Sharing
We do not sell personal data. We share it only with the providers needed to run the Service: our hosting provider, which stores the database and logs, and our transactional email provider, which delivers invitations and password resets. Both act on our instructions. We also disclose data where the law requires it.
Retention
- Account data is kept while your account exists, and deleted within 30 days of the account being removed.
- Comments, posts and channel metadata are kept while the connection exists, and deleted when you disconnect the account or the workspace is deleted.
- OAuth tokens are deleted immediately when you disconnect a Google account, or when Google reports the grant as revoked.
- Server logs are kept for 30 days.
Revoking access
You can disconnect a Google account from inside the Service at any time, which deletes the stored tokens. Independently of us, you can revoke Dash's access from your Google account's security settings. Revoking there stops all further access immediately.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Raise the request with the person who invited you to the workspace, or through the contact details below, and we will respond within 30 days. If you are in the EU or UK, you may also complain to your local data protection authority.
Security
Traffic is served over HTTPS. OAuth tokens are encrypted at rest with an application key that is not stored alongside the database. Access to production data is limited to the people who operate the Service.
Children
The Service is not directed at children under 16 and we do not knowingly create accounts for them.
Changes
If this policy changes materially we will update the date above and notify account holders by email before the change takes effect.
Contact
FS Content Creation.