Privacy Policy: Monkeys in Space
Effective date: not filled in yet [PLACEHOLDER: date]
Version 2026-09-23.2
DRAFT for lawyer review. Not legal advice. Replace every [PLACEHOLDER] before publishing, and keep this policy in sync with what the app actually does.
Operator: Verlo Labs, LLC ("Verlo Labs", "we", "us")
Privacy contact: privacy@verlolabs.com · [PLACEHOLDER: mailing address]
This policy explains what Monkeys in Space (the website and app at monkeysinspace.app, bio pages and smart links) collects, how we use it, and your choices.
The short version:
- We use your data to show you your own stats and insights.
- We don't sell your data or use it for ads.
- You can disconnect a platform or delete your account anytime, and we'll delete the data.
1. What we collect
Account information
- Name, email address, password (stored hashed) or login-provider details, and when you created your account
- Your confirmation that you're 18 or older, and when you accepted our Terms and this Privacy Policy (and which versions)
- Plan status. Monkeys in Space is free during launch and there's no billing, so we collect no payment details. If we introduce paid plans, payments will be processed by Stripe, and we won't receive or store your full card number.
- A log of consent and deletion events: for example when you connected or disconnected a platform, accepted a new version of this policy, turned "Let Verlo Labs view my data" on or off, or when data was deleted. Each entry holds an internal account ID, the platform, the event, a version and a date, never your stats, email address or content.
Data from platforms you connect
When you connect an account, we receive the data that platform allows, based on the permissions you approve:
- YouTube (through YouTube API Services): Channel details (channel ID, name, subscriber count, total views, video count). Your videos' details (title, publish date, category, length and link) and statistics (views, likes, comments). Owner analytics from YouTube Analytics, per day: views, watch time, average view duration and average percentage viewed, subscribers gained and lost, likes, comments, shares, card impressions and clicks, and engaged views. We also collect:
- Your past daily figures: when you connect, we ask YouTube for your channel's past daily analytics and daily views by traffic source, going back up to 24 months while Monkeys in Space is free during launch.
- Views by traffic source: how many views came from each kind of source (for example YouTube search or related videos), per day. Only the kind of source, never search terms or which other videos sent the views.
- Thumbnail impressions: how often YouTube showed each video's thumbnail, and the share of those showings that led to a view (impressions click-through rate), per video per day. We also add up each day's impressions into a total for your channel. YouTube only provides these through a daily report, so we ask YouTube to set up a report job on your channel. It starts with the 30 days before it was set up, and we cancel it when you disconnect YouTube or delete your account (unless another Monkeys in Space account has the same channel connected, in which case it keeps running for them).
- Per-video figures for "why it popped": YouTube's average view duration, average percentage viewed and subscribers gained for your videos, so we can show what stood out on a post that did better than your normal.
- Audience breakdowns: the share of your viewers in each age group and gender, and your views by country (your top 25 countries), which we turn into shares. These are totals and percentages; they never identify a viewer.
- TikTok: Profile info (your TikTok account ID and display name). Follower, likes and video counts. For your public videos: title and description, publish time, duration, link, and view, like, comment and share counts.
We only request the permissions our features need.
Things you add
- Tags you create and apply to your posts, when tags are switched on (they're off for now)
- Notes you add to your timeline (a date and a short note you write)
- Links, labels and bio page content
- Notification settings, and your time zone as your browser reports it, so quiet hours follow your local time
Smart link and bio page visits
When someone clicks one of your smart links or visits your bio page, we add one to an hourly count for that link or page. Each count is broken down by:
- the hour
- the link clicked (or the bio page visited)
- the referring site's name, for example instagram.com (if the browser provides it), never the full address it came from
- the device type (mobile, tablet, desktop or other)
- an approximate country, from the location our hosting provider attaches to each request
We don't store raw IP addresses. We never read, store or hash a visitor's IP address, we don't set or read a cookie to count or recognize visitors, and we keep no record of any single click or visit in our database, only the counts. To leave out bots and link previews, we check the kind of browser a request says it comes from, once, and don't store it ourselves. We don't build profiles of the people who click your links.
Like any website, our hosting provider (Vercel) receives a visitor's IP address to deliver the page, and its server logs hold a line for each request, including the page asked for and the kind of browser, for up to 1 day (see "Server logs" below). If something breaks on a page, an error report goes to our error-tracking provider (Sentry), set up to remove personal data and not to store IP addresses.
Notifications
Alerts are worked out from your stats and shown in the app. If you turn on push notifications, we store a push subscription for each device you turn them on for (the address its browser's push service gives it and the keys that let only that device read our messages), and when a notification last got through, so we can send notifications. You can turn them off anytime.
Usage and technical data
- Basic logs (for example errors and when features are used) to keep the Service working and secure
- Server logs: Our hosting provider keeps basic server logs for up to 1 day for security and troubleshooting. IP addresses are not visible to us in these logs. The hosting provider itself (Vercel) still receives each visitor's IP address to deliver pages, and collects IP addresses for its own security, such as protecting against denial-of-service attacks.
- Error reports: when something breaks, a technical report of what went wrong and where in our code goes to Sentry, with personal data (such as email and IP addresses) and access tokens removed first
- Cookies: the sign-in cookies our sign-in provider, Clerk, sets to keep you logged in, and one short-lived security cookie of our own while you connect a platform, which checks that the connection was started by you and expires within 10 minutes. We don't use advertising or analytics cookies.
- If you turn on push notifications, your browser keeps a small script from us (a service worker) on that device so notifications can arrive
- [PLACEHOLDER: list any analytics tool, such as a privacy-friendly analytics provider, or remove this line]
2. How we use it
- To show you your stats, trends, tags, alerts and link analytics
- To send alerts and notifications you've turned on
- To run your plan (and billing, if we introduce paid plans)
- To keep the Service secure, prevent abuse and fix problems
- To follow the law and the rules of the platforms you connect
What we don't do:
- sell your data
- use platform data for advertising or ad targeting
- combine data across our customers to build benchmarks or rankings
- build profiles of the people who click your links
3. AI features
- AI features are switched off for now. While they're off, no data about you goes to an AI provider. The points below apply when they're on.
- To write summaries and suggestions, we send the minimum needed data about your own account to an AI provider acting as our service provider: Anthropic.
- The provider processes it only to generate your insights, under terms that don't allow training their models on it.
- We don't use your data to train our own AI models.
- AI-generated text in the app is labeled.
4. Who we share it with
We share data only with service providers that help us run the Service, under contracts that limit their use of it:
- hosting and infrastructure: Vercel (hosting) and Neon (database)
- sign-in: Clerk (holds your email address and sign-in details)
- error reports: Sentry (reports have personal data and access tokens removed)
- payments: Stripe, only if we introduce paid plans (not used while Monkeys in Space is free during launch)
- AI processing: Anthropic, only when AI features are on (they're off for now)
- notifications: browser push services, such as Apple, Google or Mozilla, deliver push notifications if you turn them on
We may also share data:
- if the law requires it, or to protect people's safety or our legal rights
- in a business transfer, such as a merger or sale, where the buyer must honor this policy
Your data stays private to your account. We don't show your connected platform data to other users. Verlo Labs staff see it only when you've turned on "Let Verlo Labs view my data" in Settings, or when the law requires it. The automated parts of the Service (collecting your numbers, working out your alerts) process it without anyone viewing it.
5. YouTube-specific information
- Monkeys in Space uses YouTube API Services.
- By connecting YouTube, you agree to the YouTube Terms of Service: https://www.youtube.com/t/terms (opens in a new tab).
- Google's Privacy Policy applies to YouTube data: http://www.google.com/policies/privacy (opens in a new tab).
- You can revoke our access to your YouTube data anytime through Google's security settings: https://security.google.com/settings/security/permissions (opens in a new tab). You can also disconnect YouTube in our app.
- We check at least every 30 days that our access is still authorized.
- YouTube video details other than statistics, such as titles, categories, lengths and links, are refreshed or deleted within 30 days. We don't store video descriptions or thumbnails.
- Every 7 days we ask YouTube whether each video we store still exists. When YouTube tells us a video is gone, we check again a day or more later, and if it's still gone we delete that video's numbers here. We never keep a video's numbers more than 30 days without YouTube confirming it still exists.
- We store YouTube data in our database (hosted by Neon) and use it only to show you your own stats, alerts and insights. We share it only with the service providers in section 4, never show it to other users, and never combine it with other creators' data.
- We don't show ads, and no third party serves ads or other content in Monkeys in Space, apart from the sign-in screens our sign-in provider (Clerk) provides.
- You can ask us to delete the YouTube data we store at any time: disconnect YouTube or delete your account in Settings, or email privacy@verlolabs.com. We delete it within 7 days. Deleting the data we store does not, in any way, affect data stored by YouTube. To delete data on YouTube itself, use YouTube or another app that YouTube allows to delete it.
6. How long we keep data, and deletion
- Connected platform data: Kept while the platform is connected and needed for your features. Some platforms only keep data for a limited time, and we save your stats so your history doesn't disappear. Daily figures older than 24 months are deleted.
- When you disconnect a platform: We revoke our access and delete that platform's data right away, including its alerts. If any part of that deletion fails, a daily cleanup job finishes it, within 7 days at the latest. Reconnecting later starts fresh: nothing is restored. Your tag names, notes and links stay, since they're your own content.
- When you revoke access through the platform instead (for example in Google's settings): We check our access every time we refresh your data. If we can't confirm it for 20 days (7 days once Google has verified our app), we delete that platform's data, and the app warns you before that happens.
- When you delete your account: Your bio page and smart links stop working right away, and we delete your account and associated data within 7 days. Backups are overwritten on our regular backup cycle.
- If you stop using Monkeys in Space: If 12 months pass without you opening the app, and you're not paying for a plan, we close your account and delete its data the same way.
- Smart link and bio page counts: Kept until you delete your account. Archiving a link stops it working and takes it off your bio page; its counts stay for you.
- Push subscriptions: Deleted when you turn notifications off on that device, when its push service tells us the subscription no longer works, or when you delete your account.
- Server logs: Kept by our hosting provider for up to 1 day.
- Error reports: Kept by Sentry for a limited period, then deleted.
- Consent and deletion log: Kept for 36 months, then deleted. It holds no stats, email address or content.
- Billing records (only if we introduce paid plans): We may keep these as long as tax and accounting laws require.
7. Your choices and rights
You can:
- see and update your account information in Settings
- disconnect any platform, turn notifications off, archive links, delete tags (when tags are switched on) and delete your account
- ask us for a copy of your data, or to correct or delete it, by emailing privacy@verlolabs.com
Depending on where you live (for example California or other U.S. states with privacy laws), you may have additional rights. We'll honor them as the law requires, and we won't treat you differently for using them.
8. Children
- Monkeys in Space is for people 18 and older.
- We don't knowingly collect personal information from anyone under 18.
- If we learn that we have, we'll delete it.
- If you think a minor is using the Service, contact privacy@verlolabs.com.
9. Security
- We use reasonable safeguards to protect your data, including encryption in transit, access controls and limited staff access.
- Connection tokens are stored securely.
- No system is perfectly secure. If a breach affects your data, we'll notify you as the law requires.
10. Changes to this policy
- We'll post any changes here and update the effective date.
- If a change is material, we'll let you know in the app or by email before it takes effect.
- If a new version covers a new kind of data or a new use of it, we won't start that for you until you accept the new version. Connecting a platform counts as accepting the version that's current at the time; the notice under every Connect button says so.
11. Contact
Questions or requests: privacy@verlolabs.com · Verlo Labs, LLC · [PLACEHOLDER: mailing address]