← Creator Intelligence

Privacy Policy

Last updated 3 October 2026.

1. Who this covers

Creator Intelligence ("we", "the service") is analytics and audience-management software for individual creators and the agencies that manage them, operating in India. This policy applies to anyone who creates an account, connects a platform, or is contacted through our WhatsApp messaging features on a creator's behalf.

2. What we collect, per platform

We only ever collect what a platform's own API returns under the permissions you explicitly grant during that platform's OAuth consent screen — never more, and never anything you have not authorized.

  • YouTube (Google): channel identity, video and comment content, subscriber/view/watch-time statistics, and — only if you turn on reply drafting — the ability to post a reply you have personally reviewed and approved. If you separately connect revenue data (offered for YouTube Partner Program channels), we also read each video's estimated revenue, CPM and ad-impression figures. Governed by YouTube's Terms of Service and the Google Privacy Policy. You can revoke our access at any time from Google account security settings as well as from Creator Intelligence itself.
    Creator Intelligence uses YouTube API Services to access this data. Creator Intelligence's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • Instagram & Facebook (Meta): Page/Business account identity, post and media content, permalinks, media assets, comments, granular reaction breakdowns, post/reel insights (reach, saves, views, interactions), and audience demographics (age, gender, country, city) — and, only if you enable the DM inbox, the direct messages for your connected Page and Instagram account — under whatever permission level (Standard or Advanced Access) your connection was granted. You can connect Instagram either through a linked Facebook Page or directly with Instagram login (no Page needed); we read the same kinds of data either way.
  • WhatsApp Business (Meta): message threads you or your team send and receive through your own connected WhatsApp Business number, used to power broadcasts, funnels, and AI-assisted replies you configure. We do not access WhatsApp messages outside a number you have explicitly connected.
  • Threads (Meta): post content, replies, and audience-demographic breakdowns Threads' API makes available.
  • TikTok, Spotify: content and statistics available under each platform's developer program, at whatever access tier your connection qualifies for (see §7 for the tiers we currently hold).
  • LinkedIn: sign-in identity only (name, photo, headline) via OpenID Connect. LinkedIn's free developer tier does not expose follower counts or post analytics, and we do not fabricate numbers to fill that gap — if you see no follower count on your LinkedIn page, that is why.
  • Snapchat: currently self-reported only (see below) — no API connection exists yet.
  • Moj, ShareChat: neither platform has a public developer API. Anything shown for these is a number you typed in yourself, labeled as self-reported everywhere it appears, on a schedule you control. Nothing here is fetched, scraped, or estimated.
  • Every platform, additionally: the OAuth access and refresh tokens needed to keep a connection working, encrypted (AES-256-GCM) before storage and never exposed to your browser.

3. Account & billing information

We collect the email address you sign up with (and, if you use Google sign-in, your Google account's basic profile). If you subscribe to a paid plan, Cashfree or Stripe handle your card or UPI details directly — we never receive or store them, only a subscription status and the plan you are billed at. If you are part of an agency workspace, we store the client roster you manage and each client's connected-platform data, scoped so only your agency can see it.

4. How we use it, and why

  • Analytics dashboards — showing you the statistics each connected platform already reports, in one place, without alteration.
  • Comment clustering and reply drafting — comment text is sent to TypeSafe's Jev model to group comments into topics (or to Anthropic's Claude API when Jev is unavailable), and to Claude to draft a suggested reply. Drafts are never posted automatically — you review and approve every one before anything reaches the platform.
  • Auto-replies you set up — if you create an auto-reply (a keyword, a public reply and, if you choose, a private message and files), we post that reply and send that private message automatically when a new comment on your Instagram or Facebook post contains the keyword. Only text and files you wrote and attached are sent; nothing AI-generated is posted this way. We keep a log of each auto-reply (who it went to and whether it was delivered), and you can turn any auto-reply off by deleting it.
  • Fan scores — an engagement score per commenter, computed with a fixed, disclosed formula (not a black-box model). You can see exactly what produced any given score.
  • Growth recommendations and weekly report emails — a scheduled job summarizes your week's activity using Claude, and — only if you have configured an email address — sends it to you via Resend. You can disable this without disconnecting anything else.
  • WhatsApp broadcasts and funnels — if you use these features, message templates and send logs are stored so you can see delivery status and manage opt-outs. You are responsible for having lawful consent to message the numbers you upload — see Terms of Service §7.
  • Billing — computing what your workspace owes, based on how many clients you actively manage (see the Pricing page for the exact formula), and passing that number to Cashfree/Stripe at checkout.

Purpose and lawful basis (DPDP Act, Section 6): we process this data on the basis of your consent, given when you connect each platform and again at signup, for the specific purposes listed above and no others. Withdrawing consent (disconnecting a platform, or deleting your account) stops that processing going forward — see §8.

5. Who else sees it

Data is stored with Supabase (database and authentication; our project is hosted in the ap-south-1 (Mumbai) region — your platform and account data is stored in India). Comment text and activity summaries are sent to Anthropic's Claude API (United States) for drafting and report generation, and for clustering when Jev is unavailable — this is a cross-border transfer of the specific text you are asking us to summarize, not of your account as a whole. Each comment's text and platform name are also sent to TypeSafe's Jev model, through OpenRouter (both outside India), to label the comment's type, group comments into topics and spot buying or collaboration enquiries; no account details go with it. A brand message you paste into the Deal Calculator is sent the same way to read what the brand is asking for, and is not stored. If you import your own customer list (a spreadsheet, store export or WhatsApp chat export), we process it on your behalf: the file is deleted as soon as it has been read, a summary per customer is kept (name, number, orders, spend, products), and only purchase history and message text, never names or numbers, go to Jev to judge who is likely to buy again. Report emails are sent via Resend. Payment is handled by Cashfree or Stripe directly. The app itself is hosted on Vercel. Error reports go to Sentry (Germany) so we can fix crashes; they carry technical details such as the page and error message, with access tokens and passwords removed before they are sent, and no session recordings. If you connect WhatsApp with the Facebook button, Meta's own login script loads on that page only. None of these sub-processors receive more than the specific data needed for the function above, and none are permitted to use it for their own purposes.

Agencies you link with: if you accept an invitation from an agency, the members of that agency's workspace can view your connected-platform data in Creator Intelligence for as long as the link is active. A link only becomes active when you accept the invitation yourself, and no other agency or creator can see your data.

6. Data retention

We keep platform data for as long as the connection is active, so your dashboards stay current. Disconnecting a platform (Accounts → that platform → Disconnect) deletes the posts, comments, and statistics history stored for it immediately — the connection cascades to everything derived from it at the database level, not just a status flag. Deleting your account (Settings → bottom of page) removes everything: every connected account, every synced item, your agency and client links, and your profile itself, in one irreversible action. What survives after account deletion is limited to billing and tax records we are legally required to retain, which contain no platform data.

While a connection is active, daily account-level statistics are kept for two years and then deleted automatically. If a YouTube connection stops working and needs you to sign in again (for example because you revoked our access in your Google account), and you do not reconnect it within 30 days, the YouTube data we synced for it — videos, comments, statistics and the scores derived from them — is deleted automatically. The account's name and handle stay listed so that you can reconnect. Comments you delete in the app can be restored for 7 days, after which they are permanently removed. If you unsubscribe from our emails, we keep only your email address on a suppression list, so that we can honour the request.

7. Where a platform limits what we can show you

LinkedIn's free tier does not expose analytics; Spotify's extended API access requires a 250,000 monthly-active-user threshold we do not currently meet; Snapchat has no live connection yet. We say so plainly on each affected page rather than estimating a number to fill the gap — nothing in this product is ever an invented figure presented as measured data.

8. Your rights and controls

  • Disconnect any platform at any time from the Accounts page — this stops future syncing and deletes what was stored for it. For an Instagram account connected directly with Instagram login, Instagram gives us no way to cancel its access token ourselves: disconnecting deletes the token we stored and ends the real-time updates we receive for the account, and the token then expires on its own within 60 days. You can also remove our access immediately in Instagram under Settings → Apps and websites.
  • Delete your account at any time from Settings — full, immediate, cascading erasure. See the data deletion status page for what this covers.
  • Meta users specifically: requesting deletion through Facebook's own "Apps and Websites" settings triggers our data-deletion callback automatically, which disconnects every Meta-connected account and deletes the data under it, and returns a confirmation code you can check at the link above.
  • Right to access and correction (DPDP Act, Section 11–12): you can request a copy of what we hold about you, or ask us to correct it, by emailing support@creatorintelligence.in.
  • Right to erasure (DPDP Act, Section 12): beyond deleting your own account yourself, you may request erasure of specific data by the same email above.
  • Grievance redressal (DPDP Act, Section 13): Grievance Officer — Darshan (Founder), darshan@creatorintelligence.in. We aim to acknowledge grievances within 7 days.
  • Email preferences: every digest, report and recommendation email has an unsubscribe link that takes effect immediately. Account and security emails (such as password resets and invites you asked for) are still sent.

9. Security

Platform access tokens are encrypted (AES-256-GCM) before being stored and are never exposed to your browser. Every account's data is isolated at the database level with Row-Level Security, so one creator — or one agency's client — cannot read another's data by default. Webhook endpoints verify a cryptographic signature before trusting any payload. See SECURITY.md in the project repository for the full technical detail.

10. Cookies

Every cookie we set is strictly necessary for the service to work, so there is no consent banner — there is nothing optional to consent to. We use no advertising, analytics or tracking cookies, first- or third-party.

  • Sign-in session (sb-…-auth-token) — keeps you signed in; cleared when you sign out.
  • Account type (ci_persona, 30 days) — remembers whether you chose Solo Creator or Agency while you sign up.
  • Active workspace (ci_workspace, 30 days) — for agency members, which client's workspace you are viewing.
  • Connection security (…_oauth_state, 10 minutes) — a one-time value that protects the step where you connect a platform account.

Your browser's local storage also remembers which pricing tab you last looked at. It never leaves your device.

11. Age requirement

This service is intended for creators and agency operators aged 18 or over. We do not knowingly collect data from anyone under 18.

12. Changes to this policy

We will update this policy as the product changes and post the new date at the top of this page.

13. Contact

Questions about this policy or your data: support@creatorintelligence.in.