Privacy Policy

Last updated 15 August 2026

This is a working draft describing what the platform actually does with data today. The highlighted fills need real answers, and it should be reviewed against the privacy law that applies where you operate.

1. Who handles your data

[LEGAL ENTITY NAME] at [REGISTERED ADDRESS] is the controller of the personal data described here. For privacy questions, write to [PRIVACY CONTACT EMAIL].

2. What we collect

From everyone who signs up:

  • Name, email address and password (stored hashed, never in plain text).
  • Which side of the platform you joined as, and when you signed up.

From creators:

  • Profile details you enter: headline, bio, city, country, niches, languages, social handles, portfolio link and your rate.
  • Course progress, which units you finished and when.
  • The videos you submit, plus the hook, caption and notes attached to them.
  • Payout status from Stripe. We store whether payouts are enabled and an account reference, and nothing more.

From brands:

  • Company name, website, what you sell and the revenue band you selected.
  • Briefs you post, invitations you send and review decisions you make.
  • Billing details, held by Stripe rather than by us.

When you give us a website address during signup, we fetch that page once to read its title, description and preview image so we can fill in your brand details for you. We do not crawl the rest of the site.

3. Why we hold it

  • To run your account and show you the right side of the product.
  • To match creators to briefs and let brands review submitted work.
  • To calculate and release payouts, and to keep a record of what was paid for what.
  • To send service messages: brief invitations, approvals, payout notices.
  • To keep the platform safe and to investigate misuse.

4. Who else sees it

Other users see what you would expect them to. A brand sees a creator's profile and submitted video. A creator sees the brand and the brief. Neither side sees the other's payment details.

We use these companies to run the service:

  • Supabase, for the database, sign in and video storage.
  • Netlify, for hosting the website.
  • Stripe, for payouts and payments. Stripe collects identity and bank details directly and holds them under its own privacy policy.

We do not sell personal data. We do not share it for advertising. We hand it over to authorities only where the law requires it.

5. Where it lives and how long

Data is stored on infrastructure operated by the companies above, in [DATA REGION]. Submitted video sits in a private bucket and is served only through short lived signed links to people entitled to see it.

We keep account data while your account is open. After you close it we delete or anonymise what we can within [RETENTION PERIOD], apart from records of payments, which tax and accounting rules require us to keep for longer.

6. Your rights

Depending on where you live you can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to some uses of it. Write to [PRIVACY CONTACT EMAIL] and we will answer within [RESPONSE WINDOW]. If you are unhappy with the answer you can complain to [SUPERVISORY AUTHORITY].

7. Cookies

We set a session cookie so you stay signed in. That one is required for the site to work at all. [ANALYTICS DISCLOSURE]

8. Age

The platform is for people aged 18 and over. We do not knowingly collect data from anyone younger, and we delete it if we find it.

9. Changes

If we change how we handle your data in a way that matters, we will tell you in the product or by email before it takes effect.