Legal

Privacy Policy

Last updated October 7, 2026

The short version: your account, your audience, and your content stay yours. We collect what the product needs to work, we do not sell any of it, and you can take it with you or have it deleted whenever you want.

1. Who we are

This policy covers Creator Platform, the web application at creator-platform-ten-sigma.vercel.app, which is registered with TikTok as the application "Content HQ". It is operated by Clay Bower, a sole proprietor based in Arizona, United States. In this policy, "Creator Platform", "we", and "us" mean that application and its operator, and "you" means the creator who holds the account.

Questions, requests, and complaints all go to clayjbower@gmail.com, and a real person reads them.

2. What we collect

Account information: your name, email address, password hash, and the settings you choose.

Content you create: the sites, pages, blocks, programs, products, email flows, broadcasts, and media you upload while using the service.

Data from accounts you connect: when you link a social or email account, we receive the data that platform grants for the permissions you approved. This is described in detail in the next section.

Audience data you bring: email subscribers, leads, and contacts you import or collect through your own pages.

Payment information: if you sell through the service, checkout runs on your own Stripe account. We receive order and payout metadata so your dashboard can show it. We never receive or store full card numbers.

Technical data: IP address, browser and device type, pages visited, and error logs, used to keep the service running and secure.

3. Data from the platforms you connect

Connecting an account is always your choice, always done through the platform's own official login screen, and always revocable. We never ask for or store your password to any third-party platform. We request the narrowest set of permissions each feature needs.

TikTok: Creator Platform is registered with TikTok as the application "Content HQ". With your authorization it uses TikTok's Login Kit and Content Posting API, holding three permissions and no others. user.info.basic returns your display name, username, and avatar, so you can see which TikTok account is linked. video.publish publishes the videos you compose and schedule in the content calendar. video.upload sends a video to your TikTok drafts instead, for you to finish in the TikTok app. Before each publish we ask TikTok which privacy levels your account allows and never exceed them. We do not request user.info.stats or video.list, so we do not read your follower counts, your video list, or their metrics. We use TikTok data only to run the posting you asked for, on your own account. We do not sell it, share it with other users, use it for advertising, or combine it with another creator's TikTok data. Our use of TikTok data follows the TikTok Developer Terms of Service and TikTok's own Privacy Policy.

Instagram and Facebook: with your authorization we use the Instagram and Facebook Graph APIs to read your profile and media, read account and post insights, publish posts you schedule, and, if you turn it on, send automated replies to people who message your account first. Our use of Meta platform data follows the Meta Platform Terms and Developer Policies.

YouTube and Google: we use the YouTube Data API for public video statistics and comments, and, if you authorize it, YouTube Analytics for your private channel stats. Our use of YouTube data follows the YouTube Terms of Service and the Google Privacy Policy. You can revoke our access at any time at myaccount.google.com/permissions.

Platform data is stored only as long as your connection is active. Disconnect an account inside the app and the stored tokens and cached platform data for it are deleted.

4. How we use what we collect

To run the service: render your sites, publish your posts, send your emails, process your orders, and show you your numbers.

To support you: answer your questions and investigate problems you report.

To keep the service safe: detect abuse, prevent fraud, and enforce our terms.

To tell you things that matter: service notices, security notices, and changes to pricing or terms. Product marketing email is separate and you can unsubscribe from it without affecting your account.

5. What we do not do

We do not sell your personal information, and we do not sell or rent your audience list.

We do not use your content or your audience to train our own machine learning models.

We do not use data from a platform you connected for advertising, and we do not combine one creator's platform data with another's.

We do not contact your subscribers on our own behalf. Your list is yours and is exportable to CSV whenever you want.

6. AI features

Some features draft copy, suggest content, or reply to direct messages on your behalf. When you use one, the relevant text is sent to Anthropic's API to generate the result. You control what an AI agent may say and when it must hand the conversation back to you, and every AI exchange is logged in your account where you can read it.

Anthropic does not train its models on data submitted through its API. If you prefer, you can supply your own Anthropic API key in Settings so those calls bill and run under your own account.

7. Who else touches your data

We use a small number of service providers to operate the product. Each one receives only what it needs to do its job:

Vercel (application hosting and file storage), Turso (database), Resend (sending your email), Klaviyo (email list management, when you connect it), Stripe (your checkout and payouts), Blotato (cross-platform post scheduling, when you connect it), Anthropic (AI features), and TikTok, Meta, and Google (the platform APIs described above).

Beyond these, we disclose data only when you ask us to, or when the law requires it. If the business is ever sold or transferred, your data moves with it under this same policy, and we will tell you before that happens.

8. How long we keep it

Account and content data: for as long as your account is open.

Platform tokens and cached platform data: until you disconnect that platform, or your account closes.

Technical and error logs: up to 90 days.

Records we are required to keep, such as tax and transaction records, for as long as the law requires.

9. Your rights and how to use them

Access and export: your subscriber list exports to CSV from inside the app at any time. For a copy of everything else we hold about you, email us.

Correction: edit your account and content directly in the app, or ask us.

Deletion: delete your account in Settings, or email clayjbower@gmail.com with the subject "Delete my account". We remove your personal data and content within 30 days, except for records the law requires us to keep.

Withdraw a connection: disconnect any platform in the app, which deletes the stored tokens and cached data for it. You can also revoke our access from inside TikTok, Instagram, Facebook, or Google directly.

Depending on where you live, you may also have the right to object to or restrict certain processing, to data portability, and to complain to your data protection authority. We honor these requests regardless of where you live, and we do not charge for them or treat you differently for making one.

10. Security

Connections run over HTTPS. Platform access tokens and API keys are stored encrypted and are never shown back to you in full or exposed to other users. Access to production data is limited to the operator.

No service can promise perfect security. If a breach ever affects your data, we will tell you promptly and tell you what happened.

11. Age

The service is for people 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us information, email us and we will delete it.

12. Where your data lives

The service is operated from the United States, and your data is processed and stored there. If you use it from elsewhere, you are sending your data to the United States, where privacy law differs from your own.

13. Changes to this policy

If we change this policy in a way that materially affects you, we will email the address on your account and update the date below before the change takes effect. Continuing to use the service after that means you accept the new version.

Questions about any of this?

clayjbower@gmail.com