About · Privacy · Terms · Data deletion
Last updated: 5 October 2026
This policy describes how APGO SDN. BHD. ("APGO", "we", "us") handles information through APGO MY Automation, an internal tool used by authorised APGO personnel. The tool uses YouTube API Services as well as Google Sheets and Google Drive APIs.
Information we access
- Google OAuth authorisation tokens and the identifier of the authorised APGO MY YouTube channel.
- APGO-owned video files selected from Google Drive, together with team-supplied titles, descriptions and publishing times.
- YouTube API data needed to upload and manage those videos, including video IDs, processing status, privacy status, scheduling status and publication URLs.
- Operational records such as upload progress, error codes and notification delivery state.
We do not request or store Google or YouTube passwords, viewing history, advertising profiles or unrelated channel data.
How we use information
We use this information only to operate APGO's internal content workflow: selecting team-approved content, uploading it privately, checking processing, optionally scheduling publication, preventing duplicate uploads, recording publication results and notifying authorised APGO staff.
Storage, sharing and security
OAuth credentials are stored as encrypted Cloudflare Worker secrets. Publication state is stored in Cloudflare D1, and APGO-owned source media may be cached in Cloudflare R2 for reliable upload processing. Operational notifications containing a video title, internal video ID, status or publication URL may be sent to APGO's private Telegram group.
We disclose data only to service providers needed for this workflow, including Google/YouTube, Cloudflare and Telegram, and to authorised APGO personnel. We do not sell API data or use it for advertising, surveillance or user profiling.
Retention and deletion
We retain OAuth credentials while the internal tool remains authorised. We retain operational records and APGO-owned media only for the business and reliability needs of the publishing workflow. When an authorised user revokes consent or submits a verified deletion request, we revoke or remove the associated credentials and delete related authorised Google/YouTube API data as soon as possible and no later than seven calendar days.
Deleting data from APGO MY Automation does not delete content stored by YouTube. YouTube content must be deleted separately through YouTube Studio or another authorised YouTube client.
Your controls
An authorised user may revoke this tool's Google access at Google Security — Third-party access. A user may also request access, correction or deletion by following our data deletion instructions.
Google and YouTube terms
Use of information received from Google APIs follows the Google Privacy Policy, the YouTube API Services Terms of Service and the YouTube API Services Developer Policies.
Contact
Questions or privacy requests may be sent to marketing@apgo.com.my.
Facebook and Instagram information
APGO MY Automation also uses Meta APIs for APGO's authorised Facebook Page and Instagram professional account. We access the Page and account identifiers, granted permissions and access tokens, APGO-owned media and captions, post and media identifiers, processing and publication status, and publication URLs. When authorised insights permissions are available, we access aggregate performance such as views, reach, watch time and engagement counts for APGO's internal reporting. We do not request Facebook or Instagram passwords or use this integration to collect private messages, personal browsing history or unrelated user profiles.
Purpose and protection of Meta data
Meta information is used to publish team-approved APGO content, verify processing and publication, prevent duplicates, maintain operational records, notify authorised staff and analyse APGO content performance. Access tokens are stored as encrypted Cloudflare Worker secrets; authorised operational and reporting data is stored in Cloudflare services. Media and captions are sent to Meta for publication, and publication status, titles or URLs may be sent to APGO's private Telegram group. Access is restricted to authorised APGO personnel and service providers required to operate this workflow, including Meta, Google, Cloudflare and Telegram.
We do not sell Meta API data or use it to build personal advertising profiles. We retain Meta credentials only while access is authorised and retain related API data only while needed for the stated internal purposes. On a verified deletion request or revocation of access, we remove or revoke the associated credentials and delete related stored Meta API data as soon as possible and no later than seven calendar days, except information we must retain by law. A lawful retention exception will be explained to the requester.
Meta access revocation and data deletion
Authorised users can remove APGO MY Automation in Facebook's Business Integrations settings, or ask the responsible APGO business administrator to remove the app or its assigned asset access. Users can also request access, correction or deletion at marketing@apgo.com.my following our data deletion instructions. Deleting data held by this tool does not automatically delete published Facebook or Instagram posts; those posts are managed separately in Meta Business Suite, Facebook or Instagram.