Data controls and present limitations
Audit preparation record - 6 September 2026. This document distinguishes verified behavior from required follow-up work.
Controls available now
- The Channels screen shows the exact selected YouTube channel, granted access and a local disconnect action.
- Local disconnect deletes the account's token record and its Windows-protected vault entry. It does not revoke other accounts through Google.
- The Google permissions link provides provider-side revocation. YouTube content remains on YouTube.
- Publishing packages bind a local master hash, target account and editable metadata to an explicit approval.
- An uncertain external write pauses without a blind duplicate attempt. Restored pending publications are held for reconciliation.
- Application backup exports exclude OAuth/client credentials and upload-session secrets.
Work that cannot be claimed complete
- A complete per-account erasure path covering provider metadata, publication receipts, related event payloads and historical backup copies.
- A verified refresh/delete lifecycle for each persisted YouTube API data class, including provider video/comment identifiers.
- A policy-acceptance control before access to YouTube features, bound to the final published policy version.
- A means to fulfill data-deletion/refresh deadlines during long offline periods; the current machine can be switched off indefinitely.
No real user data or account grants have been deleted as part of preparing this packet. Synthetic tests must be used to verify destructive data controls before applying a requested deletion to a real account.
Deletion request procedure to finalize
Contact highvaluedigitalproducts@gmail.com with the affected channel and request. Authenticate the requester using the existing account relationship; do not request passwords or identity documents in this application. Stop pending writes for that account, reconcile any in-flight provider operation, remove the related stored provider data and credentials, handle application-managed backups, and record only a non-identifying completion marker. Verify that a restore cannot resurrect the erased data. Confirm what was removed locally and that YouTube-hosted content was not deleted.
This procedure is specified for implementation and testing. It is not an assertion that the current disconnect button already performs every step.