Your Data, Your Rules
Last updated: September 5, 2026
We collect what we need to send you good LA. Nothing we don't.
- We collect emails for the VIBES newsletter and to unlock Garrett's Mom.
- Our email service provider handles delivery + open/click tracking.
- Our database provider stores your subscription, Guides you publish, and (if you opt in) Curator favorites.
- Top Studio Videos uses public YouTube API data. It does not require Google sign-in or access private account data.
- We don't sell your data. We don't train models on your personal data.
- You can unsubscribe or delete your data anytime by emailing hello@curationsla.com.
CurationsLA uses YouTube API Services for Top Studio Videos, a weekly list of public uploads from the studio, streamer, network and entertainment channels we track. It is a CurationsLA selection of channels, not an official YouTube chart.
- Public data we access: video and channel IDs, titles, channel names, thumbnails, upload dates, durations, public view, like and comment counts, and public availability and embedding status.
- No Google sign-in:Top Studio Videos uses a server-side API credential. It does not request access to your Google or YouTube account, watch history, subscriptions, contacts, private videos, or login credentials. We do not request YouTube OAuth permissions or store viewers' YouTube access or refresh tokens.
- How we use and process it:A scheduled server-side job retrieves public uploads for the completed Los Angeles calendar week, stores their metadata, and sorts the videos by YouTube's returned public view count. We display those records with source links and an update date. The upload week is not a measurement of views earned during that week. Channel selection and browsing tabs are CurationsLA's organization of the list, not YouTube classifications or endorsements.
- Internal and external sharing:CurationsLA's authorized staff and operators can access the stored public metadata to maintain the feature. Our scheduled-job, hosting, database and edge-network providers process it to collect, store, secure and deliver the list. Displayed video metadata is public to readers. The API capture does not receive viewers' private YouTube account information. We do not sell YouTube API data or use it to train AI models.
- Thumbnails before playback:Video thumbnails load directly from YouTube's image host, i.ytimg.com. Those image requests can disclose your IP address and browser or device information to Google before you choose playback. A thumbnail request is separate from loading the player.
- Playback and cookies:A YouTube player is not loaded until you choose to play a video in Top Studio Videos. The player loads from youtube-nocookie.com, YouTube's privacy-enhanced embed domain; this does not mean that playback is anonymous or that no data is sent. Google and YouTube receive device, network and playback interaction information, may serve advertisements, and may use cookies or similar technologies under the Google Privacy Policy. Their native controls, links, captions and advertising remain available.
- Site measurement and logs: Separately from the public API capture, Google Analytics and Ahrefs process site-usage information such as page visits and referrals. When Google Analytics is available, selecting a video also sends its public video ID as a content-selection event. CurationsLA staff use this information for usage and performance analysis. Our hosting and edge providers process request information for delivery, diagnostics and abuse prevention. None of these events grants us access to your private YouTube account.
- Retention and deletion:Public YouTube API metadata is subject to YouTube's requirement that it be refreshed or deleted within 30 days. The weekly job replaces stored metadata and counts with current API values and removes videos that are no longer public when detected. Unrefreshed weeks expire from our public list after 29 days. We do not currently keep a separate history of old view counts; any extension requires YouTube's explicit written approval.
- Request deletion or ask a privacy question: Email hello@curationsla.com with the subject βTop Studio Videos data requestβ and identify the information or video/channel URL concerned. Do not send a password or an access token. We may ask for the minimum information needed to locate your data and verify the request. For stored user data related to YouTube API Services, we delete it as soon as possible and within 7 calendar days of a deletion request. This shorter period applies instead of our general response window below. Deleting data held by CurationsLA does not delete a video, account or other information held by YouTube; use YouTube's own account controls for that.
- Google access controls: In addition to requesting deletion from CurationsLA, you can review and revoke access granted to third-party apps through Google Connections. Top Studio Videos does not request an account authorization, so using this feature does not create a YouTube account-access grant to revoke. Removing an app connection at Google is separate from asking us to delete information we hold.
Using YouTube features is also subject to the YouTube Terms of Service. Google explains how it handles information in the Google Privacy Policy.
Email + name β when you subscribe to VIBES, unlock Garrett's Mom, or submit a venue/event.
Guides you publish β title, content, your verified email, optional display name (only shown publicly if you toggle byline).
Engagement signals β email opens, clicks, and on-site interactions such as page views and link clicks. Google Analytics and Ahrefs help us measure usage, referrals, and site performance. We use those measurements to improve CurationsLA, not to build or sell advertising profiles.
Cookies + local storage
admin_sessionβ HMAC-signed session for staff/curators. HttpOnly, 7-day max age.portal_location_idβ remembers which business location an owner is managing.gm_subscriber(localStorage) β keeps you unlocked in Garrett's Mom for 7 days.- Our edge network and hosting providers set a small number of operational cookies (DDoS protection, edge routing). We don't set any ad-tech cookies.
Server logs β our edge network and hosting providers keep short-lived access logs (IP, user-agent, path). Used to debug and stop abuse. Rotated within ~30 days.
- We don't use advertising pixels or sell audience profiles. We use Google Analytics and Ahrefs for site measurement, referrals, and performance reporting.
- We don't buy data from data brokers.
- We don't do cross-site tracking.
- We don't collect SSN, government ID, or precise location (unless you explicitly share an address).
- We don't train external LLMs on your personal data. AI features pass your prompt to our enterprise AI provider under contractual data-protection terms β your inputs aren't used to train their models.
- Deliver the VIBES newsletter
- Unlock Garrett's Mom and the Guide publishing flow
- Personalize what we recommend if that feature is enabled
- Run the magic-link auth flows for business owners, officials, and curators
- Detect and stop abuse (rate limiting, spam filtering)
- Improve the platform β aggregate metrics only, never sold
Service providers under contract β same operational scope, can't use your data for their own marketing:
- Edge network provider β DDoS protection, DNS, edge routing
- Hosting provider β site infrastructure
- Database provider β data storage, magic-link auth
- Email service provider β newsletter delivery + click/open tracking
- Analytics providers β Google Analytics and Ahrefs for usage, referral, and performance measurement
- Geocoding provider β address lookup (address only, no email)
- Enterprise AI provider β Garrett's Mom inference
- Payment processor β paid features only (e.g., Curator Card when launched)
We'll only share data with law enforcement when legally required (subpoena, court order) and will fight overbroad requests.
Wherever you are, you can:
- Access β see what we have on you
- Correct β fix anything wrong
- Delete β nuke your account and all linked data
- Port β get a copy of your data in a machine-readable format
- Unsubscribe β every email has a 1-click unsubscribe link
- Object β say no to specific uses (e.g., engagement-based personalization)
Email hello@curationsla.comfrom your subscribed address and we'll respond within 14 days. California residents have additional CCPA/CPRA rights β same process, just say βCCPA request.β EU/UK residents have GDPR/UK-GDPR rights β same process, just say βGDPR request.β
- Subscription records: kept while active, deleted within 30 days of unsubscribe (we keep an audit row showing unsubscribe happened β no other PII).
- Published Guides: kept indefinitely as part of the public CurationsLA archive (unless you delete them or your account).
- Server logs: ~30 days.
- Email engagement events (open/click): ~12 months.
- Web analytics: retained under our configured provider settings and deleted or aggregated when no longer needed for measurement.
- AI prompt logs (Garrett's Mom): ~90 days for debugging + abuse review, then deleted.
All traffic uses TLS. Admin sessions are HMAC-signed (constant-time verification). Subscriber tokens are HMAC-signed. Webhook callbacks verify signatures. We don't store passwords β we use magic links and HMAC tokens.
Found a vulnerability? See /.well-known/security.txt. We respond within 24 hours for critical issues.
CurationsLA isn't directed at children under 13. We don't knowingly collect data from kids. If you're a parent/guardian and think your kid signed up, email us β we'll delete it.
We'll update this policy as the platform grows. For material changes, we'll change the date at the top and notify subscribers via VIBES. Continuing to use the Services after updates means you accept them.
Privacy questions, data requests, complaints: hello@curationsla.com. Security disclosures: security@curationsla.com (or see /.well-known/security.txt).
π΄ Good Vibes Only Β· curationsla.com