CREATORVET · LEGAL

We read
public data.

no private analytics, no DMs, nothing behind a creator's login, on any platform

last updated August 2026

What we read

CreatorVet analyzes publicly available data only, with one exception you control: a creator can choose to connect their own YouTube account (described below), which shares specific read-only data with their explicit consent. We never access private analytics, direct messages, stories, or anything behind a creator’s login otherwise, on any platform.

YouTube

Channel statistics, recent uploads, video titles and descriptions, and engagement counts as exposed by the YouTube Data API. CreatorVet uses YouTube API Services. By using CreatorVet you agree to be bound by the YouTube Terms of Service. Google’s handling of data is described in the Google Privacy Policy.

Retention: YouTube data we hold is refreshed on a daily cycle and is stored no longer than 30 days without being refreshed or re-fetched; data that stops being refreshed is deleted or replaced. Aggregate figures that no longer identify a specific video or channel may be kept beyond that window.

We do not sell YouTube data, and we do not transfer it to third parties. It is used solely to show an advertiser the public reach and performance of creators and placements they are vetting or tracking, and it is removed on request via the deletion route below. You can also revoke any access you may have granted via Google’s own security settings at security.google.com/settings/security/permissions.

Optional: connecting your own YouTube account (creators)

A creator building a media kit can optionally sign in with the Google account that owns their channel. This uses Google OAuth with two read-only scopes, and it is the only case where CreatorVet accesses non-public data — always at the creator’s own request:

  • Channel identity (youtube.readonly): which channel the signed-in account owns — used solely to mark that creator’s own page “channel ownership verified”.
  • Audience statistics (yt-analytics.readonly): aggregate age and gender split, top viewer countries, and average watch time for the creator’s own channel — shown only on the creator’s own page, and only the parts the creator individually chooses to display. No individual viewer is ever identified.

These permissions can never edit, post, delete or change anything on a channel. We store the OAuth token Google issues (server-side, never exposed) and the audience summary above; both are deleted when the creator disconnects via myaccount.google.com/permissions and asks us to remove them (deletion route below), and the same 30-day retention rule applies to the audience summary as to other YouTube data. Signing in with Google as a login method shares only your name and email address, used to create and access your account.

How this data is protected

Data obtained through Google APIs — OAuth tokens, channel identity and audience statistics — is protected by the following mechanisms:

  • Encryption in transit: all communication between your browser, our servers and Google’s APIs uses HTTPS/TLS. Google user data is never transmitted over unencrypted connections.
  • Server-side token storage: OAuth access and refresh tokens are stored only in our server-side database. They are never sent to a browser, never included in any API response, never written to client-side storage, and never logged.
  • Access control: the production database is not exposed to the public internet; it is reachable only by the application server, which itself is accessible solely via key-based SSH authentication restricted to authorized personnel. Application access to Google user data follows least privilege — the two read-only scopes above are the only access ever requested.
  • No third-party transfer: Google user data is not sold, not used for advertising, and not transferred to any third party, except as necessary to provide the feature the creator requested, to comply with applicable law, or as part of a merger or acquisition with prior notice to users.
  • Deletion: tokens and audience data are deleted when a creator disconnects and requests removal (see the deletion route below), and audience summaries follow the 30-day retention rule above. In the event of a data breach affecting Google user data, we will notify affected users and relevant authorities without undue delay.

CreatorVet’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Instagram (Meta)

Where a creator operates a public Instagram Business or Creator account, we read that account’s public data through Meta’s Instagram Graph API, using the Business Discovery endpoint. Specifically:

  • Profile: username, name, biography, website, profile picture, follower count, following count and post count.
  • Recent posts: caption, permalink, timestamp, media type, like count, comment count and — for Reels — view count.

This is the same information any person can see by visiting that profile. We do not read private accounts, stories, direct messages, or any audience-level or demographic data. We do not post, comment, or take any action on a creator’s behalf.

We use it for one purpose: to show an advertiser the creator’s public reach and the performance of sponsored posts naming that advertiser’s brand, so they can verify a placement ran and how it performed. We do not sell this data, and we do not share it with third parties beyond the advertiser it concerns.

Instagram data is stored for as long as an advertiser is actively tracking that creator, and is removed on request (see below) or when tracking ends.

What we collect from you

Running a free check requires no account. If you use “Email this report”, we use the address you enter to send that one report — it is not added to a marketing list or shared with third parties. Brand and creator dashboard accounts store a username, a hashed password, and the brand or channel the account is scoped to. Standard server logs (IP, timestamp, requested URL) are kept briefly for abuse prevention and rate limiting.

Cookies & tracking

We set no advertising or cross-site tracking cookies.

Deleting your data

Email privacy@creatorvet.com from the address you used, or from an address associated with the channel or Instagram account in question, and tell us what you want removed. You can request:

  • removal of a YouTube channel or Instagram account from our cache and tracked roster;
  • disconnection of a connected Google/YouTube account, with deletion of its stored OAuth token and audience statistics;
  • deletion of any personal data you submitted, such as an email address;
  • deletion of a dashboard account and everything scoped to it;
  • a copy of the data we hold that relates to you.

We action requests within 30 days and confirm by email when the deletion is complete. No account or login is required to make a request.

GDPR

Scores and verdicts are probabilistic assessments derived from public data, provided as assistive screening for a human decision — never as an automated decision with legal or similarly significant effect. Our lawful basis for processing public creator data is legitimate interest in providing advertisers an independent verification service; you may object at any time via the deletion route above.

Contact

General: hello@creatorvet.com
Privacy, data access and deletion: privacy@creatorvet.com

CreatorVet is operated by TEKPROF INNOVATION LLP, B-4/97 Second Floor, Khanpur, Sangam Vihar, South Delhi 110080, India.