YTKARA LEGAL
Product Overview Terms of Use
// LEGAL — DATA & PRIVACY

YTKara Privacy Policy

This policy applies to the YTKara karaoke application at holicede.com/karaoke, operated by HOLICEDE. It describes what information YTKara accesses, collects, stores, uses and shares — including YouTube API Services data and technologies that store or access information on your device. Last updated: September 29, 2026.

1 // Who We Are

YTKara is a private karaoke party application developed and operated by HOLICEDE (holicede.com), an independent software laboratory based in Canada. YTKara lets a licensed host open a temporary party room; guests join from their phones with a 6-digit room PIN — no guest accounts required.

We practice data minimization: YTKara collects and retains only what is technically necessary to run karaoke sessions. We do not sell, rent, or monetize personal information, and we do not run third-party behavioral advertising.

2 // YouTube API Services

YTKara uses YouTube API Services — specifically the YouTube Data API v3 (search.list, videos.list), the YouTube oEmbed endpoint, and the YouTube IFrame Player API — to provide song discovery and in-browser video playback. By using YTKara you agree to be bound by the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy.

WHAT YTKARA RETRIEVES VIA YOUTUBE API SERVICES

  • YouTube video IDs
  • Video titles
  • Channel names
  • Video thumbnail URLs
  • Public availability / embeddability status

YTKara does not download, record, rehost, modify, or redistribute YouTube audio or video. Playback is rendered exclusively through the official YouTube embedded player directly from YouTube's servers. YTKara does not access your Google account and does not use YouTube authorized (OAuth) data — no YouTube login is ever requested.

3 // Information YTKara Collects and Stores

ACCOUNT INFORMATION (HOSTS)

Party hosts sign in with a HOLICEDE account (WordPress/WooCommerce on holicede.com). YTKara stores the host's account ID against rooms they create to verify the purchased license. Account email, login, and purchase data are managed under the site-wide HOLICEDE Privacy Policy.

PARTY SESSION DATA (HOSTS AND GUESTS)

  • Singer display name — the name a guest types when joining (e.g., "Alex").
  • Room session records — room PIN, 8-hour expiry, request-moderation mode, and participant session tokens (stored only as cryptographic hashes).
  • Queue and history records — each requested song stores the YouTube metadata listed above plus the singer display name.
  • Rate-limit records — to prevent abuse, YTKara keeps short-lived counters keyed by a cryptographic hash (HMAC) of your IP address; raw IP addresses are not stored in these records.
  • Search queries — normalized karaoke search text is stored alongside cached YouTube results (see Retention below).

4 // Cookies, Browser Storage & Similar Technologies

YTKara stores and accesses information on your device using cookies and browser storage, and allows third parties to do so when their embedded services run in your browser. The complete inventory:

FIRST-PARTY (SET BY YTKARA / HOLICEDE)

NameTypePurposeLifetime
PHPSESSID Cookie (HttpOnly, Secure, SameSite=Lax) PHP session used for CSRF security tokens on the karaoke API. Browser session
ytkara_v2_guest Cookie (HttpOnly, Secure, SameSite=Lax) Authenticates a joined guest to a party room; only a random token is stored, never credentials. Up to 8 hours (party lifetime)
ytkara_consent_v1 Cookie + localStorage entry Records your agreement to this Privacy Policy and the YTKara/YouTube Terms so the consent notice is not shown again. 1 year
ytkara_singer_name localStorage entry Remembers your singer display name on this device for faster joining. Until you clear site data
wordpress_logged_in_*, wp-settings-*, woocommerce_* Cookies (Secure) HOLICEDE account sign-in and cart/checkout session for hosts (site-wide WordPress/WooCommerce). Session / up to ~2 weeks

THIRD-PARTY STORAGE & REQUESTS

  • YouTube embedded player (Google) — on the TV Stage and Demo pages, the official YouTube IFrame player loads from youtube.com and may set or read Google/YouTube cookies and similar technologies (e.g., playback and preference cookies) subject to the Google Privacy Policy. YTKara loads this player only after you agree to this policy.
  • YouTube thumbnails (i.ytimg.com) — song thumbnails are served to your browser directly by Google's servers.
  • Google Fonts (fonts.googleapis.com / fonts.gstatic.com) — typeface delivery; Google may log the request.
  • Cloudflare CDN (cdnjs.cloudflare.com) — serves the QR-code library used to display room join codes.
  • Stripe / WooCommerce — only on holicede.com checkout and account pages, for license purchases and sign-in.

You can remove YTKara's first-party storage at any time via your browser's "clear site data" controls. Clearing storage signs out guests and resets your saved singer name and consent flag.

5 // How Information Is Used and Shared

  • Run the party room: search YouTube karaoke tracks, build the shared queue, and synchronize every participant's screen.
  • Render playback through the official YouTube embedded player (your browser talks directly to YouTube).
  • Enforce rate limits and security (CSRF tokens, room PINs, request moderation).
  • Process host license purchases via WooCommerce/Stripe on holicede.com.

We share information only with the providers named in this policy (Google/YouTube for search, metadata and playback; Stripe for payments). Party data is visible only inside your own party room to its participants. We do not share or sell data to advertisers or data brokers.

6 // Data Retention & Deletion

  • Party rooms are ephemeral: they end when the host closes them or automatically after 8 hours. Guest session tokens are revoked when the room ends.
  • Search-result cache — YouTube search metadata is cached server-side for a maximum freshness window of 7 days, then refreshed from the YouTube API on demand. Stale cache records are permanently deleted by an automated daily maintenance job, and never retained beyond 30 days.
  • Queue records — karaoke queue entries containing YouTube metadata are deleted no later than 14 days after creation by the same automated daily job.
  • Play history — YouTube-derived fields (video ID, title) in played-song history are erased no later than 14 days after the song was played; only the singer name and play timestamp remain.
  • Demo catalog validation — availability checks for the public demo catalog are re-fetched from the YouTube API every 24 hours.

No YouTube API metadata is stored longer than 30 calendar days without being refreshed — in practice, far less.

YOUR DELETION REQUESTS

Guests can remove their queued songs at any time from the remote (My Songs → Cancel) and can leave a party instantly, which revokes their session. To request deletion of any other data YTKara holds about you, email admin@holicede.com. Deleting data held by YTKara does not affect data held by YouTube or Google — for that, use your Google account controls or YouTube directly.

7 // Security

YTKara uses HTTPS transport, HttpOnly+Secure session cookies, CSRF tokens on all state-changing requests, per-scope rate limiting, and a server-side restricted API key that is never exposed to browsers. YouTube API credentials are held only on the server.

8 // Contact

Questions about this policy or YTKara's data practices: admin@holicede.com. See also the site-wide HOLICEDE Privacy Policy and the YTKara Terms of Use.

YTKARA  ·  Privacy Policy  ·  Terms of Use  ·  YouTube Terms  ·  Google Privacy
© 2026 HOLICEDE. Powered by YouTube API Services. YouTube™ is a trademark of Google LLC.