Canary Privacy Policy
Effective date: 1 September 2026
Canary is a private internal analytics tool operated by CANARY INSIGHTS (PTY) LTD (2026/197523/07) for use in its content-analysis, research, reporting and consulting work.
This Privacy Policy explains how Canary (“Canary”, “we”, “us” or “our”) collects, processes, stores, uses, shares, refreshes and deletes information.
Canary is not publicly accessible. Access to the application is restricted to authorised users. Access may also be provided temporarily to platform providers, auditors or reviewers where required for compliance, technical review or API-access purposes.
Consulting clients, members of the public and other third parties do not receive access to the Canary application as part of Canary’s current operating model.
Consulting clients may receive reports, analysis, findings and strategic insights prepared using Canary, but they do not receive access to the underlying application.
This Privacy Policy is publicly available for transparency and compliance purposes. Publication of this Privacy Policy does not make the Canary application publicly accessible.
1. Information Canary processes
Canary processes publicly available social-media information relating to selected brand accounts and their published content.
The collection method differs by platform.
For YouTube, Canary uses YouTube API Services, including the YouTube Data API v3.
For TikTok, Canary currently uses information manually collected from publicly accessible TikTok pages and interfaces.
Canary also creates and stores its own classifications, calculations, analytical outputs and consulting-related information.
Canary preserves the distinction between:
- information obtained through YouTube API Services;
- manually collected public TikTok information; and
- information independently created by Canary.
2. YouTube API Services
Canary uses YouTube API Services, including the YouTube Data API v3.
Canary uses the YouTube Data API to retrieve publicly available information relating to selected public YouTube channels and videos.
Canary currently accesses public, non-authorised YouTube data.
Canary does not require the owners of the public YouTube channels being analysed to:
- sign in to Canary using a Google Account;
- authorise Canary through Google OAuth;
- provide Google or YouTube usernames or passwords; or
- grant Canary access to private or authorised YouTube account information.
Canary does not currently use YouTube API Services to upload, edit or delete YouTube content, manage playlists, post comments, subscribe to channels or otherwise perform actions on behalf of YouTube users.
Canary’s use of information obtained through YouTube API Services is subject to Google’s privacy practices.
Google Privacy Policy: https://policies.google.com/privacy
3. YouTube information processed by Canary
Depending on what is publicly available through the YouTube Data API and required for Canary’s current functionality, Canary may process information including:
- YouTube channel identifiers;
- public channel names and handles;
- public channel subscriber counts;
- public channel video counts;
- YouTube video identifiers;
- public video titles;
- public video descriptions;
- publication dates and times;
- video duration;
- public language and publication metadata where supplied by the API;
- public tags or related metadata where supplied by the API;
- public video thumbnails;
- public video view counts;
- public video like counts; and
- public video comment counts.
Canary does not currently access private YouTube Analytics data or private channel information through Google user authorisation.
Canary preserves YouTube API provenance and does not represent manually collected information from another platform as YouTube API data.
4. TikTok information processed by Canary
Canary also analyses publicly available TikTok account and publication information.
TikTok information used by Canary is currently collected manually from publicly accessible TikTok pages and interfaces.
Canary does not currently use an official TikTok API integration for this information.
Canary does not require the owners of the public TikTok accounts being analysed to:
- sign in to Canary;
- provide TikTok usernames or passwords; or
- authorise Canary to access their TikTok accounts.
Depending on what is publicly visible at the time of collection, Canary may record information including:
- public TikTok account names and handles;
- public follower counts;
- public post URLs;
- public post identifiers where available;
- publication dates;
- publicly visible captions;
- publicly visible hashtags;
- publicly visible video duration or publication information;
- public video view counts;
- public like counts;
- public comment counts;
- public share counts where visible;
- public save or favourite counts where visible; and
- publicly visible thumbnails or media references.
TikTok observations may be stored as historical records for analysis of account and content performance over time.
Canary preserves the provenance of this information as manually collected public TikTok data.
Canary does not represent manually collected TikTok observations as information obtained through an official TikTok API and does not retrospectively change their recorded collection method.
Canary’s collection and use of TikTok information is subject to applicable TikTok terms and policies.
5. Platform data provenance
Canary records and maintains information about the source and collection method of platform data.
Where information is obtained through the YouTube Data API, its YouTube API provenance is preserved.
Where TikTok information is manually collected from publicly accessible sources, its manual collection provenance is preserved.
Canary does not knowingly:
- represent manually collected information as API-supplied information;
- misrepresent the source platform;
- misrepresent the collection method; or
- represent Canary-generated information as information supplied by a third-party platform.
6. Canary-generated classifications
Canary applies an independently developed content-classification framework to analysed social-media content.
Depending on the content being analysed, Canary classifications may describe characteristics such as:
- content theme;
- production style;
- talent type;
- occasion;
- product category;
- execution type;
- hook type;
- call-to-action type; and
- other defined fields within Canary’s content taxonomy.
These classifications are created independently by Canary.
They are not YouTube classifications, TikTok classifications or classifications supplied, approved or endorsed by Google, YouTube, TikTok or their respective operators.
Canary maintains the distinction between source-platform information and independently created Canary classification data.
7. Canary-generated analytics
Canary calculates analytical measures from available source-platform statistics using independently developed analytical methodologies.
Current calculations may include:
- Engagements;
- Engagement Rate;
- Like Rate;
- Comment Rate;
- Account-Relative View Performance;
- benchmark comparisons;
- benchmark differences;
- percentile-based performance comparisons;
- historical changes; and
- period-over-period comparisons.
Canary-generated calculations are independent analytical outputs.
They are not represented as official metrics, calculations or conclusions supplied, approved or endorsed by YouTube, TikTok, Google or their respective operators.
Raw source-platform metrics retain their original meaning and provenance.
Where a calculation requires a source value that is unavailable, Canary does not knowingly represent an invented or assumed value as though it had been supplied by the source platform.
Canary distinguishes between an unavailable source value and an observed value of zero.
8. How information is used
Canary uses the information described in this Privacy Policy for legitimate internal analytical, research, reporting and consulting purposes.
This may include:
- maintaining records of selected public social-media accounts and publications;
- analysing account and content performance;
- analysing changes in public statistics over time;
- comparing content performance within defined analytical groups;
- conducting benchmarking;
- applying Canary’s content-classification framework;
- calculating Canary-generated analytical measures;
- conducting historical and period-over-period analysis;
- identifying content-performance patterns;
- preparing internal research and analysis; and
- preparing consulting reports, findings and strategic insights.
Consulting clients receive resulting reports, analysis or insights rather than direct access to Canary.
9. YouTube statistical data and derived metrics
Canary may store timestamped observations of public YouTube statistics where permitted by the applicable YouTube API Services policies.
Unless and until Canary receives permission under YouTube’s additional policies for derived metrics and statistical-data storage, YouTube API data is refreshed or deleted in accordance with the standard storage and refresh requirements applicable to that data.
If Canary receives permission under YouTube’s additional policies for derived metrics and statistical-data storage, eligible public statistical data and permitted derived metrics may be retained for up to 36 calendar months, or for a shorter period where Canary no longer requires the information.
Any extended statistical-data retention permission applies only to data and derived metrics covered by that permission.
It does not alter the requirements applicable to other YouTube API data.
10. Other YouTube API data
YouTube API data that remains subject to YouTube’s standard data-storage requirements is refreshed or deleted within the period required by the applicable YouTube API Services policies.
This includes categories of information such as video titles, descriptions, channel or creator information and other non-statistical API metadata that do not qualify for extended statistical-data retention.
Canary uses reasonable efforts to keep stored YouTube API data consistent with current information available through YouTube API Services.
Where applicable YouTube policies require data to be refreshed or deleted, Canary follows those requirements.
11. TikTok data retention
Manually collected public TikTok observations may be retained where required for legitimate historical analysis, benchmarking, reporting and consulting purposes.
Historical TikTok observations retain their actual collection date and collection provenance.
Canary does not retrospectively represent manually collected TikTok observations as API-supplied information.
TikTok information may be deleted when it is no longer required for Canary’s legitimate analytical, reporting or consulting purposes or where deletion is otherwise required.
12. Canary-generated information
Canary may separately store information created independently of YouTube or TikTok.
This may include:
- Canary content classifications;
- calculated analytical measures;
- methodology information;
- benchmark results;
- findings;
- consulting analysis; and
- reports.
The retention of independently created Canary information is determined according to Canary’s legitimate business, analytical and reporting requirements, subject to applicable law and any platform requirements that apply to underlying source data.
13. Sharing and disclosure
Canary is a private application and is not publicly accessible.
Consulting clients and members of the public do not receive direct access to the Canary application.
Information may be processed by infrastructure, hosting, database, storage or other technical service providers used to operate, secure, maintain or back up Canary and its data.
Consulting clients may receive reports, findings, analysis and strategic insights prepared using Canary.
Those outputs may include or refer to publicly available social-media information together with Canary’s independent classifications, calculations and analysis.
Canary does not sell or license access to YouTube API Services.
Canary does not sell YouTube API data as a standalone dataset.
Canary does not provide consulting clients with access to Canary’s API credentials, databases, infrastructure or source code.
14. Google, YouTube and TikTok account credentials
Canary does not currently request Google OAuth authorisation from the owners of the public YouTube channels being analysed.
Canary does not collect or store Google or YouTube usernames or passwords belonging to those channel owners.
Because Canary does not currently access Authorised YouTube Data through a user’s Google Account, there is no Google Account authorisation granted to Canary that a channel owner needs to revoke.
Canary similarly does not request TikTok usernames or passwords from the owners of the public TikTok accounts being analysed and does not require those account owners to authorise Canary.
If Canary’s authorisation model changes materially in future, Canary will review and update its Privacy Policy, authorisation procedures, consent mechanisms and any applicable revocation procedures before that functionality is used.
15. Authentication, cookies and session technologies
Canary uses authentication, cookies or similar session-management technologies where necessary to secure access to the application.
These technologies may be used for purposes such as:
- authentication;
- maintaining an authenticated session;
- application security; and
- preventing unauthorised access.
They are not used to obtain access to third-party Google, YouTube or TikTok accounts.
Canary does not use its internal application authentication process as a substitute for platform authorisation where platform authorisation would otherwise be required.
16. Security
Canary uses reasonable administrative and technical safeguards designed to protect information against unauthorised access, disclosure, alteration, misuse or loss.
Access to Canary is restricted to authorised users and approved audit or review access where required.
Access to the Canary application does not automatically provide access to underlying technical resources.
17. Data deletion
YouTube API data is refreshed or deleted in accordance with the applicable YouTube API Services Developer Policies and any additional data-storage permissions granted to Canary.
If Canary:
- ceases using YouTube API Services;
- loses permission to retain particular YouTube API data;
- receives an applicable deletion requirement; or
- is otherwise required by the YouTube API Services policies to delete affected data,
the affected data will be deleted as required.
Manually collected public TikTok observations and Canary-generated information may be deleted when they are no longer required for legitimate analytical, reporting or consulting purposes or where deletion is otherwise required.
18. Third-party services
Canary depends in part on third-party platforms and technical service providers.
Third-party platforms operate independently of Canary and may change their services, interfaces, APIs, data availability, terms or policies.
Canary is not responsible for the privacy practices of third-party platforms.
Google’s handling of information is governed by the Google Privacy Policy:
https://policies.google.com/privacy
Use of YouTube is also subject to the YouTube Terms of Service:
https://www.youtube.com/t/terms
References to YouTube, Google, TikTok or other platforms do not imply sponsorship, approval or endorsement of Canary.
19. Children’s information
Canary is not directed to children and is not offered to members of the public as a consumer service.
Canary does not intentionally request account credentials or private account information from children through the application.
The social-media information analysed by Canary is limited to information obtained through the collection methods described in this Privacy Policy.
20. Changes to this Privacy Policy
This Privacy Policy may be updated when Canary’s:
- functionality changes;
- data practices change;
- collection methods change;
- third-party integrations change;
- operating model changes; or
- applicable legal or platform requirements change.
Any material change to the way Canary obtains, processes, stores, shares or deletes platform information will be reviewed against the applicable requirements before the changed functionality is used.
The effective date at the top of this Privacy Policy identifies the current version.
21. Contact
Questions about Canary’s privacy practices, use of platform information or this Privacy Policy may be directed to:
CANARY INSIGHTS (PTY) LTD (2026/197523/07)
NATASHA@CANARYINSIGHTS.CO.ZA
1 CENTURY BOULEVARD, CENTURY CITY, CAPE TOWN, 7441
