Security & data handling
CoyoteCast publishes on behalf of organizations that connect their own accounts to it. That makes the permissions it requests, and the data it touches, worth stating precisely.
Where it runs
CoyoteCast runs on servers operated by CoyoteCast LLC in the United States, not on a shared cloud platform. Content you submit is stored in your organization's own access-controlled folder and is sent only to the networks your organization has connected.
Keeping organizations and credentials separate
- Each organization authorizes its own accounts through each platform's official sign-in flow. CoyoteCast never asks for, receives or stores social media account passwords. Bluesky, which has no such flow, uses an app password you create for CoyoteCast and can revoke in Bluesky's settings at any time.
- Access tokens are stored on CoyoteCast's servers and only work for the account that granted them. No token is shared between organizations.
- You can revoke access at any time from the platform's own account settings, which immediately stops CoyoteCast from publishing to that account.
- Members sign in with individual accounts, and each member can only post for the organizations they belong to. Administrative pages are restricted to CoyoteCast staff.
- All traffic is encrypted with TLS.
Least-privilege permissions
CoyoteCast requests the narrowest set of permissions that still lets it publish and show you which account you connected. Permissions that would let it read audience data, manage existing content or read analytics are deliberately not requested, even where the underlying publishing software offers them.
Google / YouTube permissions
| Scope | Why it is required |
|---|---|
youtube.upload |
The core function: uploads your organization's video to its own channel. No narrower YouTube scope allows publishing a video. |
youtube.readonly |
Reads the connected channel's name and thumbnail so you can confirm you linked the right channel before publishing, and reads back a published video's status for the confirmation email. youtube.upload alone can't identify which channel it's uploading to. |
userinfo.profile, userinfo.email |
Identifies which Google account completed the authorization, so the connection can be labelled and attributed to the right organization. |
CoyoteCast does not request youtube, youtube.force-ssl, youtubepartner or yt-analytics.readonly. Those would grant broad channel management, content ownership and analytics access that no CoyoteCast feature needs. Its publishing path calls exactly two YouTube endpoints: a video insert and a channel list.
What is stored, and for how long
- Submitted content stays in your organization's folder, under your control, until your team deletes it.
- Connection tokens are kept while the account stays connected, and stop working when you disconnect or revoke access.
- Publishing records of what was posted where are kept so confirmations and support work.
CoyoteCast doesn't sell data, doesn't use your content or account data for advertising, and doesn't pass either to anyone beyond the networks you connect and the service providers named in the Privacy Policy.
Reporting a problem
Send security concerns to support@coyotecast.com. See the contact page for what to include.