Back home

Privacy Policy

Last updated: September 20, 2026

This Privacy Policy explains what data CreatorBase AI (“we”, “us”) collects, how we use it, who we share it with, and the rights you have over it. We try to keep this short and plain rather than drowning you in legalese. If something here is unclear, email support@creatorbaseapp.com.

1. Data We Collect

Account data. Your email address, your password (stored only as a bcrypt hash. We never store or can see your actual password), your chosen niche, content style, target audience, goals, and onboarding responses.

Payment data. New payments are processed by Polar. Historical transactions remain with their original payment provider. We do not see or store your card number. We receive transaction records such as customer and subscription IDs, plan, amount, currency, renewal dates, payment status and billing-country information needed for support, accounting and disputes.

Discord data. If you link a Discord account: your Discord user ID and username. We do not read your DMs or unrelated servers.

Usage data. Prompts and messages you send to the AI agent and chat, the videos/images/thumbnails you generate, feature-usage counters, timestamps, and technical logs (IP address, user agent, referring URL).

YouTube API data. CreatorBase uses YouTube API Services to retrieve public channel and video metadata, including channel and video IDs, titles, descriptions, thumbnails, publication dates, durations, view counts, subscriber counts, comments and other public statistics. We also store CreatorBase calculations derived from that public data, such as relevance, breakout ratio, velocity, estimated earnings and niche scores. Those calculations are ours, not YouTube metrics.

Other public-platform research. Where available, TikTok and Instagram research uses third-party data services to retrieve public profile and post information, such as handles, captions, thumbnails, publication dates and engagement counts. Search terms, public handles or post URLs you submit are sent to those services. This is separate from YouTube API Services and does not provide access to private accounts or private analytics. Results may be cached; coverage and refresh timing vary by platform and provider availability.

Google sign-in. If you choose Continue with Google, Google provides your basic account identity, such as your name and email address, so we can create or sign in to your CreatorBase account. CreatorBase does not request permission to manage your YouTube channel, upload videos or read private YouTube analytics.

Cookies & local storage. We use a JSON Web Token (JWT) stored in browser localStorage to keep you logged in, and strictly necessary cookies for session security and rate limiting. We do not use advertising or cross-site tracking cookies. We do not run session-replay recording by default.

2. How We Use Your Data

  • To create and authenticate your account.
  • To process your subscription and detect fraud.
  • To send transactional email: welcome, password reset, billing updates, login notifications, feedback replies.
  • To operate the AI agent — your prompts are forwarded to our model providers to generate a response.
  • To enforce rate limits, fight abuse, and keep the platform safe.
  • To improve the product (aggregated, non-identifying usage patterns only).
  • To provide YouTube research, channel discovery and CreatorBase-derived rankings from public YouTube API data.
  • To send the weekly newsletter (you can unsubscribe any time).
  • To comply with our legal obligations.

3. AI Processing

When you use the AI agent, chat, strategy generator, or coach, your prompt and the minimum necessary context (for example, your niche and recent outputs) are sent to the selected AI provider for inference. Video, image and voice prompts are sent to the provider selected for that generation. YouTube research queries are sent to YouTube API Services. Do not enter anything into the Service you would not want reviewed by a human for abuse-handling purposes.

4. Service Providers We Share Data With

We rely on reputable sub-processors, each with their own privacy commitments:

  • Polar — payment processing & subscription management
  • Supabase — database hosting (PostgreSQL)
  • Render — backend API hosting
  • Vercel — frontend hosting & edge network
  • Anthropic — large-language-model inference
  • Resend — transactional email delivery
  • Discord, Inc. — community chat platform
  • YouTube Data API (Google) — YouTube research
  • Public-platform data services — TikTok and Instagram research using the queries, handles or public URLs you submit
  • WaveSpeed — primary video & image generation
  • FAL.ai & Together.ai — video generation, used as fallback capacity
  • RunPod — self-hosted video generation infrastructure (Lifetime tier)

We do not sell your personal data to anyone. Ever.

5. Data Retention

  • Account & billing records: kept while your account is active and up to 24 months after cancellation (for tax and dispute purposes).
  • AI prompt/chat logs: kept up to 90 days for abuse investigation, then deleted or anonymized.
  • Server access logs: kept up to 30 days.
  • Stored YouTube API data is refreshed or deleted within 30 days. CreatorBase’s own historical calculations may be retained only where they no longer contain stale YouTube API data.
  • Marketing email list: until you unsubscribe.

6. Why We Can Process Your Data (Lawful Basis)

If you are in the EU, EEA or UK, the GDPR and UK GDPR apply to you regardless of where we are based, because they follow you rather than us. We rely on:

  • Performance of a contract — your account, subscription and the tools you asked us to run.
  • Legitimate interests — keeping the service secure, preventing abuse and fraud, and fixing faults. We only rely on this where it does not override your rights.
  • Legal obligation — tax and accounting records for payments.
  • Consent — optional emails, which you can withdraw at any time without affecting anything else.

We set no advertising or analytics cookies and use no third-party trackers, which you can verify in your browser's network tab. That is why you are not asked to accept cookies here: there is nothing non-essential to accept.

7. Your Rights, and How To Use Them

You do not need to explain why. To delete your account and its data, go to Profile → Delete account in your dashboard to submit a tracked deletion request. We retain only records we must keep for tax, fraud prevention or dispute obligations, then delete or anonymize the rest. For anything else, email support@creatorbaseapp.com and we will respond within 30 days, as the GDPR requires. Exercising any of these rights is free, and we will never restrict or degrade your account for asking.

Depending on your jurisdiction (including GDPR/UK-GDPR and CCPA/CPRA), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your account and associated data.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Complain to your local data-protection authority.

CreatorBase does not request OAuth permission to manage your YouTube channel, upload videos or read private YouTube analytics. YouTube research uses public data through YouTube API Services and our own service credentials. If you use Google sign-in, you can review or revoke that sign-in connection in your Google account permissions. Revoking Google sign-in does not itself delete your CreatorBase account; use the deletion request in Profile or email support for deletion. If you connected a Discord account for login or community access, you can review and revoke that connection anytime from your Discord Authorized Apps settings.

To exercise any right, email support@creatorbaseapp.com from the email on your account. We respond within 30 days.

8. YouTube API Services

CreatorBase is an independent service and is not affiliated with or endorsed by YouTube or Google. Pages that display YouTube data identify YouTube as the source and link to the original channel or video. Your use of those features is also governed by the YouTube Terms of Service. Google’s handling of information is described in the Google Privacy Policy.

CreatorBase does not offer YouTube downloads, private-channel access or third-party transcript extraction. We do not use public data to create fake engagement, manipulate YouTube metrics or automate publishing. If our access to YouTube API Services changes, we will update this policy and the controls available to you.

9. Security

We use HTTPS everywhere, hash passwords with bcrypt, enforce rate limits and account-level throttles, restrict database access by role, and rotate secrets. No system is perfectly secure — if we ever detect a breach that affects your data, we will notify you without undue delay.

10. Children

The Service is not directed to children under 16. If we learn that we have collected data from a child under 16 without verifiable parental consent, we will delete it. Signup requires an age confirmation, and accounts that appear to belong to someone under 16 may be suspended while we review them.

11. International Transfers

Our sub-processors are located in the United States and the European Union. By using the Service, you consent to the transfer of your data to these jurisdictions. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, new features, or legal requirements. Material changes will be announced by email or in-app notice at least 14 days before taking effect.

13. Contact

Privacy questions, data requests, or complaints: support@creatorbaseapp.com.