Privacy Policy
Effective and last updated: August 10, 2026
This policy explains how Influencely, a King of the Curve product ("Influencely," "we," "us," or "our"), collects, uses, shares, retains, and deletes information when you use the Influencely website, mobile apps, creator tools, campaigns, and support services.
Information we collect
Account and profile information
We may collect your name, email address, login-provider identifiers, profile photo or avatar, biography, creator handle, social profile links, Discord information, and app preferences.
Photos, videos, audio, and creator submissions
We collect only the photos, videos, audio, post links, drafts, and other media you choose to upload, select, or submit. This can include a profile photo, campaign source clips, completed posts, and media used in a slideshow or faceless-content workflow. We use this information to provide the feature you requested, store your draft, create or display your content, evaluate a campaign submission, prevent fraud, and let authorized campaign administrators review it.
Influencely does not request access to your full photo library when a system media picker can provide only the items you select. We do not sell private creator uploads or use them to train our own general-purpose AI models.
Social and campaign activity
If you connect or submit a social account, we may collect public profile information and public post metrics such as views, likes, comments, publication time, and platform identifiers. We also process campaign participation, progress, submissions, review decisions, referrals, clicks, signups, eligibility, and payout history.
Device, usage, and support information
We may collect app events, device and browser type, IP address, crash or diagnostic information, push-notification tokens, security logs, and messages you send to support. We use this information to operate, secure, troubleshoot, and improve the service.
We use first-party cookies and browser storage to operate Influencely. An HttpOnly session cookie keeps web users signed in, and short-lived HttpOnly authentication-flow cookies bind OAuth callbacks to the browser and help prevent forgery. Functional cookies and local storage may remember the selected Influencely brand or app, referral attribution, onboarding progress and completion, display preferences, push-prompt state, and, in the native-app web experience, a session token. We use these technologies for authentication, security, requested functionality, attribution, and preferences, not for cross-context behavioral advertising.
Embedded TikTok bounty examples
When an official TikTok example becomes the active card in the Bounties reel, Influencely automatically loads TikTok's official embedded player. That causes your browser or device to make a direct request to TikTok, so TikTok receives your IP address and browser or device information and may access or set TikTok cookies under the TikTok Privacy Policy. We configure the player to send no referrer, so TikTok does not receive the Influencely page URL, and Influencely session cookies are not sent to TikTok. The separate Watch on TikTok action is optional and opens the example's canonical TikTok post. Influencely does not load Pipiads media in these embeds.
Posting on your behalf (optional)
You can ask us to create and publish posts to a social account you control. This is off by default and is enabled separately for each platform in Account → Let us post for you. One exact provider account can be connected at a time for each platform. Turning it on records the date and exact authorization text you agreed to. Linking a profile, turning on Influencely consent, and authorizing the social platform are separate steps. None of those steps by itself causes a post.
When you connect a platform, it may issue access, refresh, or Page publishing tokens and the scopes and expiration information associated with them. We protect provider tokens with authenticated encryption at rest and decrypt them only inside the server process for an authorized provider request. Provider tokens are never sent to the browser. The Instagram chooser sends only the public account IDs, usernames, and Page labels needed for your selection. We do not use a credential you have not knowingly granted through the platform's own authorization screen.
TikTok and YouTube also require you to review and approve the exact account, media, caption or description, privacy, and platform-specific disclosures for each proposed post. Instagram posting is limited to the exact Professional account selected during its connection flow. Influencely's global posting worker must be enabled before any eligible work can dispatch. Public posts additionally require that platform in Influencely's public-platform allowlist. Application credentials, OAuth, or a queued label alone never mean a post was published.
Platform-specific data used for managed posting
TikTok. With your authorization, we access the connected account's provider ID, username or nickname, current posting limits, available privacy options, and interaction settings. We store the bound account identity, encrypted tokens, granted scopes and expiration, your exact per-post privacy, comment, commercial-disclosure, branded-content, export, and music confirmations, and the resulting publish status, post ID, and link. We send TikTok only the approved images, title or caption (including the campaign tracking link), privacy and interaction choice, and required commercial-content declarations needed for that post. We do not import unrelated TikTok posts or messages.
Instagram and Facebook. With your authorization, we access the Facebook Pages available to your login and the IDs, usernames, and Page names for linked Instagram Business or Creator accounts. When more than one account is eligible, we temporarily store an encrypted one-time chooser and do not select an account for you. We store the selected Instagram account identity, encrypted Page publishing token, granted scopes and expiration, the authorized frozen images and final caption, and resulting container or post IDs, status, and permalink. We send Meta the exact images and caption needed to publish that carousel. We do not read private messages or import unrelated Instagram feed posts.
YouTube and Google. We request youtube.upload to upload the
exact rendered MP4 you approve and youtube.readonly to call
channels.list(mine=true). That read-only call gives us the authenticated
channel ID and title so we can show, bind, and re-check the exact destination. We store
that channel identity, encrypted tokens, granted scopes and expiration, your exact upload
choices, and the resulting video ID, processing status, and link. We send YouTube the
approved MP4, title, description (including the campaign tracking link), privacy,
made-for-kids choice, and paid-promotion information. We do not enumerate or import your
unrelated videos.
Images prepared for TikTok or Instagram are frozen in content-addressed storage and made available to that provider through a tamper-evident HMAC-signed media URL. The URL authorizes access only to the exact recorded file and does not provide access to your Influencely account. YouTube receives the exact approved and verified MP4 bytes directly from our server.
Influencely's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide and secure the creator-facing YouTube connection and upload features described here, not for advertising, sale, credit decisions, or unrelated profiling.
Google processes information under the Google Privacy Policy. You can review or revoke Influencely's access remotely through Google Account third-party connections or Google security permissions. Remote revocation prevents future authorized YouTube API requests but may not be detected by Influencely immediately, and it does not delete videos held by YouTube. The seven-day authorization check described below removes stale local YouTube API data; use the local YouTube Disconnect control for immediate confirmed revocation and local deletion.
How we use information
- Provide accounts, creator profiles, campaigns, asset packs, drafts, submissions, rankings, and support.
- Authenticate users, preserve preferences, send requested notifications, and protect the service from abuse.
- Review campaign requirements, validate participation, calculate metrics, and administer approved rewards or payouts.
- Prepare, review, publish, and reconcile posts only for a platform where your Influencely consent is on and the exact provider account is connected, subject to all applicable approval controls.
- Analyze product performance using aggregated or de-identified information.
- Comply with law, enforce our terms, and protect users, Influencely, and others.
When we share information
We share information only as needed with service providers that help us host data, authenticate accounts, send notifications, process media, measure product performance, provide support, or administer payments. We may share a submitted campaign post and its metrics with the organization administering that campaign. We may also disclose information when required by law, to protect rights and safety, or as part of a merger, financing, acquisition, or sale after appropriate safeguards.
Third-party platforms such as Apple, Google, Firebase, Discord, TikTok, Instagram, and payment providers handle information under their own policies when you choose to use them. Influencely does not sell personal information or share it for cross-context behavioral advertising.
For managed posting, we share the exact media, metadata, account identifier, and choices described above with the selected social platform because that platform must receive them to perform the action you authorized. We may show the resulting post link, publication status, and campaign metrics to you and to the authorized organization administering that campaign. We do not share provider access or refresh tokens with campaign sponsors.
Retention and security
We keep account and creator information while your account is active and as needed to provide the service. Draft media and campaign records are retained while needed for the relevant workflow. We may retain limited transaction, fraud-prevention, security, dispute, or tax records when required by law or a legitimate business obligation. Backups expire under their normal retention schedule. Database deletion and storage or external-identity cleanup are separate operations. Cleanup retries automatically, and no manual retry is required. We use administrative, technical, and organizational safeguards designed to protect information, but no online system is perfectly secure.
Google and YouTube Authorized Data, including the connected channel identity, encrypted OAuth credentials, upload choices, and managed-post records, is retained only as needed to provide the connection and posting workflow, document its result, secure the service, resolve disputes, or meet applicable obligations. Influencely records the last successful authorized YouTube channel check. If no authorized check succeeds for seven days, Influencely disables YouTube managed posting and deletes the locally stored YouTube credential, queue, channel, upload, status, and provider-correlation data. This also removes stale local data after a permission is revoked directly in Google, although that remote change may not be detected immediately.
YouTube Disconnect stops remaining local posting work and asks Google to revoke Influencely's OAuth credential. After Google confirms revocation or that the credential is already invalid, Influencely deletes the matching local credential and YouTube API-derived managed-posting history. If Google cannot confirm revocation immediately, Influencely stores only a separately encrypted cleanup credential, retries automatically with bounded backoff, and hard-purges the matching local YouTube Authorized Data and cleanup credential within seven days. A provider operation accepted before Disconnect may still exist at YouTube; manage that content in YouTube directly.
Your choices and account deletion
You can choose what media and social profiles to submit, disable notifications in your device settings, disconnect supported social profiles, and sign out at any time. For managed posting, these controls have different effects:
- Switching Let us post for you off withdraws Influencely consent for that platform and stops items that have not crossed provider dispatch. It does not by itself revoke the provider's OAuth grant.
- Disconnecting YouTube programmatically revokes the Google credential before deleting Influencely's local credential and YouTube API-derived managed-posting data. TikTok and Instagram Disconnect remove Influencely's local credential and stop eligible undispatched work, but do not revoke the remote provider grant; remove Influencely in TikTok or Meta account settings to revoke those permissions remotely. You can also review or revoke Google access from Google's third-party connection or security-permissions controls linked above.
- A post already published remains in the provider account until you delete it there. An operation the provider already accepted may still complete while Influencely reconciles its truthful result, even if you disconnect or withdraw consent during processing.
You can permanently delete your Influencely account from Account → Delete account in the app. A successful database deletion immediately blocks new sign-ins, revokes your sessions, and removes or de-identifies your account, connected profiles, submissions, drafts, push tokens, managed-posting provider tokens, consent grants, queue and publication history, and temporary OAuth account-chooser state. We then run separate automatic cleanup of creator media and the external authentication identity. For at least 24 hours after database deletion, and until automatic cleanup succeeds, we retain only separately encrypted cleanup locators and one-way hashes of linked provider identities while we retry failed cleanup and repeatedly remove creator data written by requests already in progress. We scrub those cleanup records after cleanup completes. We retain domain-separated suppression hashes of the deleted account's internal creator aliases and converted anonymous onboarding session IDs so a stale request or database worker cannot recreate deleted creator data; these hashes contain no provider token, session ID, or plaintext profile data and are used only to reject stale writes. To prevent an already-issued provider token or callback from recreating the deleted account, registration with the same Google, Apple, Firebase, or Discord identity may be unavailable until that cleanup completes. When a YouTube credential is present, Influencely attempts Google revocation before completing local account deletion. If Google is temporarily unavailable, Influencely accepts the deletion request, stops publishing, retries automatically, and completes local deletion after confirmed revocation or the seven-day hard purge deadline; no manual retry is required. Deletion does not erase a post already held by a social platform or reverse an operation that platform already accepted; use the provider's controls for that content and remote authorization. Limited transaction, fraud, payment, tax, dispute, or security records may be retained where legally required or needed for a legitimate obligation.
If you cannot access the app, use our account deletion page to request deletion. We may need to verify that you control the account before processing an off-app request.
Children
Influencely is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Users who are not old enough to enter a binding agreement in their location must have permission from a parent or legal guardian. Paid campaign eligibility may require the age of majority.
International use and changes
Your information may be processed in the United States and other locations where our service providers operate, subject to applicable safeguards. We may update this policy as the product or law changes. We will post the new effective date here and provide additional notice when required.
Contact us
Questions, privacy requests, and appeals can be sent to heath@kingofthecurve.org.