>_ViktorKav
Legal Documentation

Privacy Policy

Effective date: May 7, 2026 · Last updated: August 13, 2026

This Privacy Policy describes how the applications maintained by Victor Cavalcante (operating as "ViktorKav") ("we", "our", "us") collect, use, store, and share information when you authorize and use them. Most of our applications are personal content production tools that run locally on the operator's own machine, integrating with third-party APIs including Google APIs for YouTube data. One of them, the Members Area of this website, runs on a server and is used by visitors; wherever that difference matters, it is called out explicitly below.

By authorizing or using our applications, you acknowledge that you have read and understood this Privacy Policy.

1. Applications covered

This Privacy Policy applies to the following applications, and to any future applications by Victor Cavalcante that share this OAuth client configuration:

Note on the Members Area. Sections 2, 3, 5, 7 and 9 below describe it separately wherever its behaviour differs from the desktop applications. The most important difference: the desktop applications run entirely on the operator's own machine, while the Members Area runs on a server and therefore sets cookies in your browser and keeps a small amount of data about you. Both are described in full below.

2. Information we access

From the YouTube Data API

  • Members Area accesses, via channels.list with mine=true, exactly two fields about the visitor who signs in: the public channel ID of their YouTube channel (e.g. UCxxxxxxxxxxxxxxxxxxxxxx) and its public display name. Nothing else is read from the response.
  • We do not access or process: payment information, private messages, viewer location data, or any non-public personal information.

    The Members Area requests the openid and email scopes because Google requires them alongside any YouTube scope in order to show the consent screen. We never read your email address: the only API call the sign-in makes is channels.list, which does not return it.

    From the OAuth flow

    3. How we use the information

    4. Compliance with Google API Services User Data Policy

    Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    In particular, we confirm:

    5. Where the data is stored

    For the desktop applications, all data is stored locally on the operator's own infrastructure. We do not operate any cloud server that aggregates user data. Specifically:

    The only "output" that becomes public is the credit image at the end of YouTube videos (containing publicly visible member names), published as part of the video by the operator's choice.

    Members Area

    The Members Area is the one part of this policy that runs on a server: a single virtual private server rented by the operator in Brazil, not a third-party cloud platform that aggregates user data. What is kept there:

    6. Sharing with third parties

    We do not share Google user data with any third party. Specifically:

    7. Data retention and deletion

    The user controls all data, since everything is stored locally. To delete data collected by our applications:

    For the Members Area, where the data is about you rather than about the operator:

    To revoke our applications' access to your Google account at any time:

    8. Children's privacy

    Our applications are not directed to children under 13. We do not knowingly collect personal information from children under 13.

    9. Cookies and tracking on this website

    The website viktorkav.com.br uses no tracking cookies, analytics, fingerprinting, or advertising pixels anywhere, including this page. Nothing on this site tries to work out who you are or what else you do online.

    The Members Area does set two cookies, and neither of them tracks you: they are strictly necessary to sign you in and keep you signed in. Both are HttpOnly (unreadable by JavaScript), Secure (sent over HTTPS only), SameSite=Lax, and scoped to the /membros path, so they are never sent while you browse the rest of the site.

    CookiePurposeContentsLifetime
    membros_login Protects the sign-in itself, by tying the Google consent screen you were sent to back to this specific browser. A random one-time value and the PKCE verifier for that single sign-in. Nothing about you. 15 minutes
    membros_sessao Keeps you signed in, so the site does not send you back to Google on every page. Your channel ID, your display name, and the time it was issued, signed and nothing more. 7 days

    This Privacy Policy page loads its web fonts from Google Fonts, which means your browser makes a request to fonts.googleapis.com and fonts.gstatic.com when you open it (subject to Google's Privacy Policy). The Members Area does not: its fonts are served from viktorkav.com.br itself.

    10. Changes to this policy

    Material changes to this Privacy Policy will be reflected by updating the "Last updated" date at the top of this page. If the changes are significant, we will notify users through the operator's YouTube channel or via email when applicable.

    11. Compliance with related policies

    By using our applications, you also agree to comply with:

    12. Contact

    If you have questions about this Privacy Policy or want to exercise your privacy rights:

    This Privacy Policy is maintained by Victor Cavalcante (ViktorKav), an independent content creator based in Brazil.


    Versão em português: esta política está disponível em inglês como versão canônica para verificação Google. Para esclarecimentos em português, contate via email acima.