Last updated 12 September 2026.
1. Who this covers
Creator Intelligence ("we", "the service") is analytics and audience-management software for individual creators and the agencies that manage them, operating in India. This policy applies to anyone who creates an account, connects a platform, or is contacted through our WhatsApp messaging features on a creator's behalf.
2. What we collect, per platform
We only ever collect what a platform's own API returns under the permissions you explicitly grant during that platform's OAuth consent screen — never more, and never anything you have not authorized.
- YouTube (Google): channel identity, video and comment content, subscriber/view/watch-time statistics, and — only if you turn on reply drafting — the ability to post a reply you have personally reviewed and approved. Governed by YouTube's Terms of Service and the Google Privacy Policy. You can revoke our access at any time from Google account security settings as well as from Creator Intelligence itself.
- Instagram & Facebook (Meta): Page/Business account identity, post and media content, permalinks, media assets, comments, direct message inboxes, granular reaction breakdowns, post/reel insights (reach, saves, views, interactions), audience demographics (age, gender, country, city), Meta Ad Account campaign performance (spend, impressions, clicks, CPC, ROAS), and shop product catalogs — under whatever permission level (Standard or Advanced Access) your connection was granted.
- WhatsApp Business (Meta): message threads you or your team send and receive through your own connected WhatsApp Business number, used to power broadcasts, funnels, and AI-assisted replies you configure. We do not access WhatsApp messages outside a number you have explicitly connected.
- Threads (Meta): post content, replies, and audience-demographic breakdowns Threads' API makes available.
- TikTok, Spotify: content and statistics available under each platform's developer program, at whatever access tier your connection qualifies for (see §7 for the tiers we currently hold).
- LinkedIn: sign-in identity only (name, photo, headline) via OpenID Connect. LinkedIn's free developer tier does not expose follower counts or post analytics, and we do not fabricate numbers to fill that gap — if you see no follower count on your LinkedIn page, that is why.
- Snapchat: currently self-reported only (see below) — no API connection exists yet.
- Moj, ShareChat: neither platform has a public developer API. Anything shown for these is a number you typed in yourself, labeled as self-reported everywhere it appears, on a schedule you control. Nothing here is fetched, scraped, or estimated.
- Every platform, additionally: the OAuth access and refresh tokens needed to keep a connection working, encrypted (AES-256-GCM) before storage and never exposed to your browser.
3. Account & billing information
We collect the email address you sign up with (and, if you use Google sign-in, your Google account's basic profile). If you subscribe to a paid plan, Cashfree or Stripe handle your card or UPI details directly — we never receive or store them, only a subscription status and the plan you are billed at. If you are part of an agency workspace, we store the client roster you manage and each client's connected-platform data, scoped so only your agency can see it.
4. How we use it, and why
- Analytics dashboards — showing you the statistics each connected platform already reports, in one place, without alteration.
- Comment clustering and reply drafting — comment text is sent to Anthropic's Claude API to group comments into topics and, only if you ask, draft a suggested reply. Drafts are never posted automatically — you review and approve every one before anything reaches the platform.
- Fan scores — an engagement score per commenter, computed with a fixed, disclosed formula (not a black-box model). You can see exactly what produced any given score.
- Growth recommendations and weekly report emails — a scheduled job summarizes your week's activity using Claude, and — only if you have configured an email address — sends it to you via Resend. You can disable this without disconnecting anything else.
- WhatsApp broadcasts and funnels — if you use these features, message templates and send logs are stored so you can see delivery status and manage opt-outs. You are responsible for having lawful consent to message the numbers you upload — see Terms of Service §7.
- Billing — computing what your workspace owes, based on how many clients you actively manage (see the Pricing page for the exact formula), and passing that number to Cashfree/Stripe at checkout.
Purpose and lawful basis (DPDP Act, Section 6): we process this data on the basis of your consent, given when you connect each platform and again at signup, for the specific purposes listed above and no others. Withdrawing consent (disconnecting a platform, or deleting your account) stops that processing going forward — see §8.
5. Who else sees it
Data is stored with Supabase (database and authentication; our project is hosted in the ap-south-1 (Mumbai) region — your platform and account data is stored in India). Comment text and activity summaries are sent to Anthropic's Claude API (United States) for clustering, drafting, and report generation — this is a cross-border transfer of the specific text you are asking us to summarize, not of your account as a whole. Report emails are sent via Resend. Payment is handled by Cashfree or Stripe directly. The app itself is hosted on Vercel. None of these sub-processors receive more than the specific data needed for the function above, and none are permitted to use it for their own purposes.
6. Data retention
We keep platform data for as long as the connection is active, so your dashboards stay current. Disconnecting a platform (Settings → that platform → Disconnect) deletes the posts, comments, and statistics history stored for it immediately — the connection cascades to everything derived from it at the database level, not just a status flag. Deleting your account (Settings → bottom of page) removes everything: every connected account, every synced item, your agency and client links, and your profile itself, in one irreversible action. What survives after account deletion is limited to billing and tax records we are legally required to retain, which contain no platform data.
7. Where a platform limits what we can show you
LinkedIn's free tier does not expose analytics; Spotify's extended API access requires a 250,000 monthly-active-user threshold we do not currently meet; Snapchat has no live connection yet. We say so plainly on each affected page rather than estimating a number to fill the gap — nothing in this product is ever an invented figure presented as measured data.
8. Your rights and controls
- Disconnect any platform at any time from Settings — this stops future syncing and deletes what was stored for it.
- Delete your account at any time from Settings — full, immediate, cascading erasure. See the data deletion status page for what this covers.
- Meta users specifically: requesting deletion through Facebook's own "Apps and Websites" settings triggers our data-deletion callback automatically, which disconnects every Meta-connected account and deletes the data under it, and returns a confirmation code you can check at the link above.
- Right to access and correction (DPDP Act, Section 11–12): you can request a copy of what we hold about you, or ask us to correct it, by emailing privacy@creatorintelligence.in.
- Right to erasure (DPDP Act, Section 12): beyond deleting your own account yourself, you may request erasure of specific data by the same email above.
- Grievance redressal (DPDP Act, Section 13): Grievance Officer — [founder,darshan.joc@gmail.com]. We aim to acknowledge grievances within 7 days.
9. Security
Platform access tokens are encrypted (AES-256-GCM) before being stored and are never exposed to your browser. Every account's data is isolated at the database level with Row-Level Security, so one creator — or one agency's client — cannot read another's data by default. Webhook endpoints verify a cryptographic signature before trusting any payload. See SECURITY.md in the project repository for the full technical detail.
10. Cookies
We use one strictly-necessary session cookie to keep you signed in. We do not use third-party advertising or tracking cookies.
11. Age requirement
This service is intended for creators and agency operators aged 18 or over. We do not knowingly collect data from anyone under 18.
12. Changes to this policy
This is a draft policy for a product in active development. It will be updated as features change, and materially reviewed by a lawyer before any public launch or platform submission.