CreatorTrax

Privacy Policy

Last updated: September 2, 2026

Who we are

CreatorTrax (creatortrax.com) is a content planning and performance tracking tool for video creators. This policy describes what information we collect, how we use it, and the choices you have. Questions can be sent to support@creatortrax.com.

Information we collect

Account information. When you sign up we collect your email address and name through our authentication provider (Clerk) to create and secure your account.

Content you create. Ideas, titles, scripts, checklists, channel names, schedules, and performance notes you enter are stored so the product can function. This data belongs to you.

Usage data. We collect basic technical logs (such as IP address and browser type) needed to operate and secure the service.

Connected social accounts

If you choose to connect a social platform account (such as YouTube, TikTok, Instagram, or Facebook), we access only the data needed to provide the features you use: reading performance metrics for your videos and channels (such as views, likes, comments, and subscriber or follower counts) and, where you request it, uploading or scheduling content you created. We request the minimum scopes required, and you can disconnect a platform at any time, which stops all further access.

CreatorTrax's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use data obtained from connected platforms for advertising, we do not sell it, and no humans read it except as needed for security, compliance, or with your explicit consent for support.

Data protection for sensitive data

OAuth access and refresh tokens for connected platforms are the most sensitive data we hold, and we protect them accordingly:

  • Encryption. All traffic to and from CreatorTrax is encrypted in transit (HTTPS/TLS). Tokens are encrypted at rest in our database provider's storage.
  • Server-only access. Tokens are read and written exclusively by server-side code. They are never sent to, stored in, or readable from your browser, and never appear in a client-side API response.
  • Database access controls. The table holding connection tokens has row-level security enabled with no anonymous or user-role policies defined, so only our backend's service credential, never a public key, can read or write it.
  • Minimum scope. We request the narrowest OAuth scope that supports the feature (for YouTube, the read-only youtube.readonly scope only, covering video statistics and subscriber counts; for Instagram, the read-onlyinstagram_business_basic and instagram_business_manage_insights permissions, covering your own posts and their view, like, comment, and follower counts; we do not request any scope that can modify, upload, or delete content on your channel).
  • Limited human access. No one at CreatorTrax views connected-account data except as needed to investigate a security issue, meet a legal obligation, or with your explicit consent while helping you with a support request.

How we use information

We use your information solely to provide, maintain, secure, and improve CreatorTrax: showing your content pipeline, tracking per-channel performance, and sending service emails you request. We do not sell personal information and we do not share it with third parties for their marketing.

Storage and processors

Data is stored with Supabase (database hosting) and served through Vercel. Authentication is handled by Clerk. These processors handle data on our behalf under their own security and privacy commitments. Data is encrypted in transit.

Retention and deletion

We keep your data while your account is active. You may delete individual content at any time in the app. To delete your account and all associated data, including revoking any connected social accounts, email support@creatortrax.com and we will complete the deletion within 30 days. You can also revoke CreatorTrax's access directly in each platform's security settings (for Google, at myaccount.google.com/permissions).

Instagram data deletion. If you remove CreatorTrax from your Instagram account (Instagram Settings, Website permissions, Apps and websites), Meta notifies us and we delete the stored connection and access token for that account right away. Meta shows you a confirmation code for the request; if you have any question about it, email support@creatortrax.com with that code. Metric snapshots already recorded in your CreatorTrax workspace stay with the content item they belong to and are removed when you delete that content or your account.

Changes

If we make material changes to this policy we will update this page and note the new date above. Continued use of the service after a change means you accept the updated policy.

See also our Terms of Service.