Who we are
Thumbnail Vault is operated by Jamie Whiffen LTD. This policy explains what data we collect and how we use it when you use Thumbnail Vault.
Access and personal information
You can browse Thumbnail Vault and use its basic standalone tools without an account. A free account is required to save references, folders, notes, previews, comparisons and briefs across devices. We collect your email address for account confirmation and recovery, with email/password or Google sign-in. You may optionally say what best describes how you use YouTube and add a YouTube channel, as explained below. Images you choose in the Previewer are processed in your browser. If you explicitly save that work to your account, its images are uploaded to private Supabase storage so you can reopen them on another device.
Your profile answers
When you're signed in, the library may ask you two optional questions. The first asks what best describes how you use YouTube, such as Business owner or Thumbnail designer. We call that answer your creator type. The second asks for a YouTube channel, which can be your own or one you work on. If you add a channel, we may use it to suggest a niche, such as Gardening, which you can change. When you add a channel, we also ask whether to use its public YouTube picture for your account. If you say yes, we save a link to that picture with your answers and show it in your account menu, where only you see it. If you say no, we don't keep the picture. You can skip either question, and skipping never limits what you can use for free.
We use your answers to:
- Choose the examples in Picked for you, a section at the top of the library.
- Word Jamie's free channel review offer to suit your creator type. Thumbnail designers don't see this offer.
- Help Jamie see who might be a good fit for his one-to-one work, such as a coach who adds a channel. He compares these accounts by hand with his own records of booked calls and clients. If you're on his email list, he may email you about it, and you can tell him to stop at any time.
- See whether Picked for you is useful. We note when you first answered and which examples it first showed you. Jamie's weekly report then counts saves, folders, notes and briefs for each creator type.
Your channel link never goes to our analytics or into a cookie. We don't send your answers to Kit, our email provider.
You can see, change or remove your answers at any time in Account settings. Removing them also deletes your niche, the channel picture and the details we noted, and turns off Picked for you. We keep a note that you removed them, so we don't ask again. Your answers and those details are included when you ask for a copy of your data.
How we suggest a niche
To suggest a niche, our server asks YouTube for the titles of the channel's recent public uploads. We only do this when you add or change the channel in your profile and haven't chosen a niche yourself, or when you say yes to using the channel's picture.
We don't save the titles. Our server only holds them in memory, for up to a day, so it doesn't have to ask YouTube about the same channel again. Only the suggested niche is saved with your answers, along with a code made from the channel's link, so we can tell when you change it, and a link to the channel's picture if you said yes to using it. If the lookup can't run, such as when YouTube can't be reached, we save that code with a note to try again and look the channel up the next time you save your answers. If the channel has videos in the Vault, we also save a short code for it with your answers, which leaves them out of Picked for you. Picked for you says when a niche is only a suggestion, so you can change it if it's wrong. This lookup uses the YouTube API Services described under YouTube data.
Cookies and local storage
We use browser localStorage to maintain your secure account session, preserve an unfinished save, remember display preferences and keep standalone-tool drafts on this device. The remix prompt form remembers what you enter and your recent entries in this browser only, never on our servers, and its Clear saved answers button removes them. When you save to your account, Favorites, folders, notes and named tool documents are stored in your private account workspace. Clearing browser data signs this device out and removes device-only preferences, but does not delete account data.
If you've answered the profile questions, we also keep a small cookie in your browser while you're signed in. It holds your creator type, your channel niche and, if your channel has videos in the Vault, the short code that leaves them out of Picked for you. It never holds your channel link, handle or email address. The library uses it so Picked for you appears with the page. It lasts up to a year, and it's cleared sooner when you sign out, remove your answers or delete your account.
Network requests and service logs
With analytics permission, Thumbnail Vault records a small allowlisted set of first-party product events, such as account prompts, completed saves, folders and audit-link clicks. These events use a random browser identifier and, when signed in, your account identifier. They may also include campaign parameters, referring domain and page path. We do not accept free-form personal data in these events. Your browser requests public thumbnail images, and your channel's picture if you chose to use it, from YouTube. When you paste a YouTube link into Downloader or Brief Builder, the video ID is sent to noembed.com to retrieve the public title and channel. Standard hosting and security logs may process IP address, browser information and timestamps.
Optional usage analytics
With your permission, PostHog in the EU receives named usage events, a random browser identifier, page categories, campaign labels, device and browser categories, feature outcomes and safe counts. From your profile answers, it receives only your creator type and simple yes/no details, such as whether you added a channel. We use this to improve the tools and understand which visits lead to useful actions. We do not send your email, channel link or handle, channel niche, uploaded images, titles, briefs, raw searches, passwords or authentication links to PostHog, and we do not enable session recordings. With analytics permission, creating an account also saves campaign details with your account profile. These are the campaign source, medium and name from the link that brought you to the Vault and the domain of the site that sent you, and they're included when you ask for a copy of your data. Returning visits are measured on the same browser, not across all your devices. You can decline or withdraw measurement using Analytics settings in the footer. Do Not Track and Global Privacy Control also prevent optional usage measurement. Withdrawal stops future events. Your browser still makes a network connection to the provider when you allow analytics, although we disable IP-based enrichment.
YouTube data
Thumbnail Vault uses YouTube API Services. Video titles, channel names and pictures, publish dates, video lengths and view counts in the library, each channel's typical views on its recent uploads, and the recent uploads the Previewer shows for a channel you enter, come from YouTube through those services. By using Thumbnail Vault you agree to be bound by the YouTube Terms of Service. Google's Privacy Policy explains how Google handles data.
Third parties
Supabase provides authentication and private account storage. YouTube provides public thumbnail images, channel upload titles and channel pictures, and the other data described under YouTube data, noembed provides public video metadata, and Vercel serves the application. Creating a new Vault account includes joining Start Getting Views, Jamie's five-day course and ongoing YouTube newsletter. This is disclosed before you submit the signup form. After you verify your email, we record the signup request and send it to Kit. Existing course progress and unsubscribes are preserved. You can unsubscribe using the link in any newsletter email. Unsubscribing does not delete your saved Vault work. Course and booking links have their own privacy policies.
The Ideas + Bugs link opens our feedback board, a separate site run for us by Featurebase (CORDNET OÜ, Estonia), which stores data mainly in the EU. The Vault doesn't send it anything about you. Anyone can post or comment on the board without an account. Featurebase handles your posts, votes, comments and any images you add on our behalf, and your name and email too if you sign in to the board. Featurebase only emails people who sign in to the board. Posts and comments on the board are public, so please don't include private details. Featurebase's own site uses its own cookies and analytics, which its privacy policy covers.
Data retention
Account workspace and profile data remain until you remove items or request account deletion. Profile answers stay until you change or remove them, or delete your account. Removing your answers doesn't delete Jamie's own records of emails between you or calls you've booked. Device-only preferences remain until you clear site data. First-party product events and hosting logs are retained only as reasonably needed for product measurement, security and legal requirements. Newsletter data remains subject to your withdrawal of consent and Kit's retention controls. A limited record of a subscription request or unsubscribe may be retained to avoid re-enrolling you accidentally. Feedback posts stay on the board until you delete them, ask us to remove them or we close the board. Featurebase then removes the deleted data from its live systems within 90 days and from its backups within a year.
Your GDPR rights
Where we hold personal data about you, UK GDPR may give you the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure
- Request data portability
- Object to or restrict certain processing
You can ask for a copy of your data, including your saved work and profile answers, by emailing jamie@jamiewhiffen.co.uk, and we'll send it within a month.
Contact
You can delete your Vault account from Account settings. Deleting your Vault account does not unsubscribe you from email lessons, and unsubscribing does not delete your Vault account. Use the unsubscribe link in an email to stop those messages. For privacy requests, email jamie@jamiewhiffen.co.uk.