M-4, operated by Mahnbach LLC · Last updated 23 July 2026
M-4 is a private, single-operator application operated by Mahnbach LLC. It is not open for public sign-up and has no external users. Exactly one Google Account is connected to it — the operator's own. This policy describes how M-4 handles data from that account.
M-4 requests read-only access to the operator's own YouTube channel, using these scopes:
youtube.readonly — the operator's own channel and video metadata: video IDs, titles,
publish dates, and public statistics such as views, likes and comment counts.yt-analytics.readonly — the operator's own channel analytics: views, impressions,
click-through rate, watch time and audience retention, captured at fixed video ages of 7, 30 and
90 days.M-4 requests no write, upload, publishing, scheduling, or deletion access, and cannot modify anything on the connected channel.
M-4 does not collect, through these scopes or otherwise: any other person's channel data · the identities of viewers or subscribers · personal contact information · the content of comments written by other people, beyond public counts · anything from any account other than the one the operator connects.
M-4 records what it expects a video to do before that video is published, and later reads the channel's own performance data to compare the actual result against that earlier prediction. Analytics access is what makes the comparison possible; without it the application has no function.
M-4 does not obtain revenue or earnings data from Google's APIs. Where the operator's past monetization figures appear in the application, they are figures the operator has entered themselves from YouTube Studio. They are stored, retained and deleted on exactly the same terms as the channel data described below, are never shared, and are shown as a record of what has already happened — never as a projection of future earnings.
Google user data is used solely to provide these functions to the operator whose account it came from.
M-4's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means: this data is used only to provide the measurement features described above, which are the application's primary user-facing purpose; it is not transferred to anyone; it is never sold, and never provided to advertisers, data brokers, or for any credit-related purpose; and no person other than the operator reads it.
Where it is held. Google user data is stored in M-4's own database, inside the deployment the operator controls. It is not sent to any third-party analytics service, data warehouse, or external processing service.
The operator's own channel data — analytics, channel statistics, and the derived prediction-versus-outcome record — is retained for as long as M-4 remains authorised to hold it. The application re-confirms at least every 30 days that the operator's authorisation is still in place. 🔴 If that authorisation is withdrawn or lapses and is not restored, the retained channel data is deleted — continued authorisation is the basis on which it is kept, not merely the means of obtaining it. The long-running record of predictions against outcomes is the application's entire purpose, which is why it is kept for as long as it is lawfully held.
Data about channels the operator does not own — public statistics gathered while researching what performs well in a subject area — has its raw statistical values expired or refreshed on a 30-day cycle. Values M-4 computes from them are M-4's own analysis and are retained.
How access is held. The credential that authorises M-4 to read the operator's channel is stored in the operating system's secure credential store on the machine running the application, encrypted at rest. It is never stored in the application's database, never written to the code repository, and never recorded in logs or error reports. It is read by a single component of the application, and by nothing else.
Access is held per channel: disconnecting a channel revokes that channel's access and deletes that channel's data. The operator may also revoke M-4's access entirely, at any time and without any action by M-4, at myaccount.google.com/permissions.
M-4 does not share the operator's channel data with anyone.
This includes M-4's own service providers. M-4 uses external services for keyword research and for language-model processing; those services receive only subject and topic terms — never the operator's channel analytics, channel identity, video performance, or revenue figures. The boundary is enforced in the application's architecture, not only by policy.
M-4 does not sell Google user data, does not transfer it for advertising, and does not use it to train any machine-learning model.
M-4's deployment runs on infrastructure the operator controls. Where that infrastructure is provided by a hosting or database provider, that provider stores data on the operator's behalf and has no independent right to use it. No other party receives Google user data.
The operator can revoke M-4's access to their Google Account at any time at myaccount.google.com/permissions. Revoking access stops all further data collection immediately.
Revocation is entirely the operator's — it requires no action by M-4, and M-4 cannot prevent or reverse it. Because continued authorisation is also the basis on which M-4 retains channel data, revoking access ends that basis (see How long, above).
The operator may request deletion of all stored Google user data at the contact address below. On disconnection or on request, the stored access credential is revoked first and the stored channel data is then deleted.
Deletion is completed within 7 days of a valid request. Because M-4 has exactly one operator, deletion in practice is immediate.
M-4 is a single-operator application. The person whose Google data it holds is the same person who operates it, so the controls that matter are direct rather than procedural:
If M-4 is ever opened to anyone other than its operator, this policy will be revised before that happens, and additional rights and disclosures will apply.
If this policy changes, the updated version is published at this address with a new "last updated" date.
If a change would broaden what M-4 collects or how it is used, that change takes effect only after fresh consent — a revised policy alone is not treated as agreement to a wider collection than the one originally authorised.
Questions about this policy, or requests relating to data, can be sent to clientservices@mahnbach.com.
M-4 is operated by Mahnbach LLC, 600 1st Ave. Suite 102, Seattle, WA 98104, United States.