Privacy Policy

Last updated: August 3, 2026

🔒 Our Privacy CommitmentCreatorFinder AI takes your privacy seriously. This policy explains what data we collect, how we use it, and how we protect it. We follow a minimal data principle and never sell user data.

1What We Collect

Data TypeHow CollectedPurpose
Email addressEntered on the payment or CreatorFinder login pageConnect purchases, subscriptions or Credits to an account and send login verification codes
Payment reference numberStripe or the enabled payment provider callbackOrder verification & refund processing
Activation codeSystem-generatedSubscription status verification
Fast Analyze request logWhen extension calls Fast Analyze (creator handle/URL + timestamp)Usage quota enforcement & abuse prevention; deleted after 90 days
Password hash and saltCreated after email-code verification during first-time setup or password resetAuthenticates the account; the plaintext password is never stored
Session credentialGenerated on our server after successful loginThe website stores it in a Secure, HttpOnly cookie that page scripts cannot read. The Chrome extension stores its separate session credential in chrome.storage.local. Both are invalidated on logout, password reset, or after 30 days.
CreatorFinder Search OAuth credentialIssued after you authorize CreatorFinder Search from ChatGPT or CodexA one-hour encrypted access token and a revocable refresh token authorize account-status and creator-search requests. Your password and email verification code are entered only on the CreatorFinder login page and are not placed in the AI conversation or sent as MCP tool arguments.
Anonymous device identifierFor guest searches, the extension creates a SHA-256 summary from limited browser and device environment characteristics, and the server issues a signed device cookieLimits the guest allowance per device; raw characteristics are not sent to the server
Extension and favorites dataWhen the user operates on supported creator and bio-link pagesCandidates, contacts, settings, favorite collections, saved creator snapshots, tags, and private notes remain in the current browser's local extension storage.
Auto-Discover and AI inputsWhen the user starts an AI-assisted or Auto-Discover taskRuns the requested campaign planning, search, recovery, and public creator enrichment
Website analytics dataGoogle Analytics after the visitor allows analyticsMeasures aggregate page visits, device/browser category, approximate region, and website interaction. We do not send email addresses, passwords, verification codes, full search briefs, or payment details to Google Analytics.
Optional AI-training interactionOnly after a signed-in user affirmatively consents in SettingsCreator matching and AI-model improvement; future collection can be disabled in Settings

We do not collect: your real name, ID number, bank card number, raw hardware serial numbers, general browsing history, or any personal information beyond the above.

2How CreatorFinder Clients Handle Data

The CreatorFinder AI extension runs locally in your browser. CreatorFinder Search connects ChatGPT or Codex to CreatorFinder through an HTTPS MCP service and OAuth. Below is a complete description of their data-touching behaviour:

  • Content script injection: The extension injects a content script into TikTok, Instagram, and YouTube pages, as well as certain bio-link pages (e.g. linktr.ee, beacons.ai, carrd.co and similar). On these pages the script reads publicly visible page text and link elements to extract creator handles, bios, follower counts, and contact links. No data is sent to our servers during this step.
  • Background tab — bio link email extraction: When a creator's profile contains an external bio-link (e.g. a link-in-bio page), the extension may open that URL in a hidden background browser tab to scan visible text for a contact email address. The tab is closed automatically within seconds. This behaviour is limited to a pre-approved allowlist of bio-link domains and never accesses arbitrary URLs.
  • Scroll trigger on TikTok profiles: To load video-grid metrics (views, likes, etc.), the extension may programmatically scroll a TikTok profile page. No data is transmitted during this action.
  • Local favorites: Favorite collection structure, saved creator snapshots, tags, and private notes are stored only in the current browser's chrome.storage.local. They do not automatically appear on another computer or browser. The web workspace can read or update them only through the connected extension in that same browser. Export JSON backups regularly if you need to move or restore them.
  • Guest device verification: For guest searches, the extension converts limited browser and device environment characteristics into an irreversible SHA-256 summary locally. The server also issues a signed, HTTP-only device cookie. These identifiers prevent reinstalling the extension from resetting the guest allowance; raw characteristics are not uploaded.
  • Subscription authentication: You normally log in with your email and password. First-time password setup and password resets require a one-time code sent to your email. Passwords are processed with scrypt and a random salt; only the resulting hash and salt are stored. Website sessions use a Secure, HttpOnly, SameSite cookie; page scripts cannot read this credential. Chrome extension sessions continue to use the extension's protected local storage. Sessions expire after 30 days, logout, or password reset.
  • CreatorFinder Search OAuth: On the first protected request, ChatGPT or Codex opens a CreatorFinder-hosted login and authorization page. You enter your email and verification code there; password login is also available. These login secrets are not entered into the conversation and are not exposed to MCP tools. After login, the OAuth service returns an encrypted one-hour access token and a revocable refresh token to the OAuth client. The access token authorizes only CreatorFinder account-status and creator-search scopes. CreatorFinder Search forwards the campaign goal, platform, country, follower range, keywords and requested result count needed for a confirmed search, then returns the relevant public creator results and billing status to the requesting ChatGPT or Codex client.
  • Fast Analyze: When triggered, the extension sends the creator's profile URL or handle and a timestamp to our server for enriched data parsing. Results are returned immediately; we do not persistently store creator profile content beyond the request log (deleted after 90 days).
  • AI analysis and Auto-Discover: User-entered campaign goals, product descriptions, budgets, selected creator types, search terms, and the public creator candidates required to complete the requested task are sent to CreatorFinder's backend. CreatorFinder may send the relevant request data to its server-managed DeepSeek or Gemini provider. The extension does not ask you to store provider API keys.
  • Optional AI-training interactions: Signed-in users may optionally consent in Settings to recording certain AI interactions with public creator profiles. A consented record may contain the account email, public creator identifier, interaction type, related cache key, and timestamp. Collection is off unless the user agrees. Turning collection off stops future records but does not automatically delete earlier consented records; deletion can be requested by email.
  • EnsembleData and Apify enrichment (optional): when cached, browser, or official API data is incomplete, CreatorFinder sends only public creator identifiers to EnsembleData first and Apify only as a fallback. Provider tokens remain server-managed.
  • Data export: CSV / Excel exports are generated locally and downloaded directly to your device, never passing through our servers.

3Data Sharing

We do not sell or rent user data. Data is transferred only as needed for the user-requested feature or another allowed purpose:

  • ChatGPT or Codex OAuth client: receives OAuth access and refresh credentials through the standard authorization flow, plus the account-status or public creator-search result requested by the user; it does not receive the CreatorFinder password or email verification code
  • CreatorFinder backend: receives account data, campaign inputs, Auto-Discover actions and public creator candidates needed to run and recover the requested feature
  • AI providers: DeepSeek or Gemini receives the relevant campaign and public discovery input for a user-triggered AI feature
  • Apify: receives selected public creator identifiers or URLs for optional enrichment
  • Google Analytics: after analytics consent, receives limited website measurement data for aggregate usage reporting; advertising storage and personalization remain disabled
  • Payment processing: Stripe or the currently enabled payment provider receives the information needed to complete the transaction, subject to that provider's privacy policy
  • Legal and security requirements: we may disclose necessary information when required by law or needed to protect against fraud, abuse, or security threats

4Data Storage & Security

  • Server data is stored on cloud servers in mainland China, transmitted via HTTPS encryption
  • Passwords are protected with scrypt and a unique random salt; plaintext passwords are never stored
  • Email verification codes are stored as keyed hashes, never in plaintext
  • Payment reference numbers are used only for order verification — full payment account numbers are never stored
  • Fast Analyze request logs (creator URL/handle + timestamp) are automatically deleted after 90 days

5Cookies & Tracking

The website includes Google Analytics property G-S2M7WJ4TFK for aggregate website measurement. Analytics storage is denied by default, and the website does not display an analytics-consent popup. Browsers without an earlier explicit analytics choice remain denied; a choice already saved in this browser continues to apply and can be revoked by clearing this site's stored data. Advertising storage, advertising user data, personalized advertising, and Google signals remain disabled. We do not send email addresses, passwords, verification codes, full creator-search briefs, or payment details to Google Analytics.

6Your Rights

You may exercise the following rights at any time by email:

  • Access: Ask what data we hold associated with your email
  • Deletion: Request deletion of your account data and consented AI-training interaction records, subject to legal retention requirements
  • Correction: Correct identifiable information such as your email address
  • Choice: Decline optional AI-training interaction collection or turn future collection off in extension Settings

Email: support@creatorfinder-sub.com — we will respond within 7 business days.

7Minors

This Service is not intended for users under 18. If you are a minor, please use it with a guardian or have a guardian make the purchase on your behalf.

8Governing Law

This Privacy Policy is governed by the laws of the People's Republic of China. For users located in the European Economic Area or the United Kingdom, we additionally commit to handling personal data in accordance with the principles of the General Data Protection Regulation (GDPR). For users located in California, we additionally comply with the California Consumer Privacy Act (CCPA).

9Policy Updates

This Privacy Policy may be updated as the service evolves. Major changes will be noted at the top of this page with an updated date and communicated to subscribers via in-extension notification or email.

10Chrome Web Store Limited Use

CreatorFinder's use of information received from Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension user data is used only to provide or improve the disclosed creator-research purpose and related security, reliability, and abuse-prevention operations. We do not sell user data, use it for personalized advertising or credit decisions, or transfer it to data brokers. Humans do not read extension user data except with the user's specific consent, when required for security or legal compliance, or in aggregated and anonymized form for internal operations.

11YouTube API Services

CreatorFinder uses YouTube API Services to retrieve YouTube channel and video information needed for creator discovery and collaboration-content reporting. By using CreatorFinder features that use YouTube API Services, you also acknowledge the YouTube Terms of Service. Google's handling of information is described in the Google Privacy Policy.

  • Data accessed: Depending on the feature, CreatorFinder may retrieve public channel or video identifiers, channel names, profile images, descriptions, thumbnails, publication dates, video titles, subscriber or video counts, and official statistics such as views, likes and comment counts. If a future feature requests Google authorization, it will access only the scopes the user expressly grants; CreatorFinder never asks for or stores a YouTube password.
  • Purpose and sharing: YouTube API Data is used to find relevant creators, display their public YouTube information, refresh collaboration-content performance and provide the user-requested report. It may be processed by CreatorFinder's backend and infrastructure providers solely to deliver and secure those functions. It is not sold, used for personalized advertising or disclosed to data brokers.
  • 30-day refresh or deletion: Stored YouTube API Data that is subject to the standard YouTube retention rule is refreshed from YouTube or deleted no later than 30 calendar days after it was retrieved. Deleted or unavailable YouTube resources are removed when detected. Data that cannot be refreshed is deleted rather than presented as current.
  • Authorization and deletion: If CreatorFinder uses Authorized Data, it rechecks authorization at least every 30 calendar days. A user may revoke Google access from Google security settings and may request deletion by emailing support@creatorfinder-sub.com. CreatorFinder deletes data covered by a direct deletion request or account deletion as soon as possible and within 7 calendar days; revocation-related YouTube API Data is deleted within the applicable YouTube policy deadline. Deleting CreatorFinder's copy does not delete information held by YouTube.
  • Statistical data retained for up to 36 months: Only if CreatorFinder's applicable analytics use case has passed the required YouTube API compliance review and received explicit permission, CreatorFinder may retain approved statistical metrics, such as dated views, likes, subscriber counts and comment counts, and approved derived metrics for up to 36 calendar months. Titles, creator names, descriptions, thumbnails, comment text and other non-statistical metadata remain subject to the 30-day refresh-or-delete rule. Unless that approval applies, the standard 30-day rule remains in force.
  • Derived metrics: A metric labelled as a CreatorFinder metric is not supplied or endorsed by YouTube. Subject to any required YouTube approval, examples may include an engagement rate calculated from official interaction and view counts, growth calculated from dated metric snapshots, or campaign performance combining user-entered campaign data with clearly identified YouTube statistics. CreatorFinder does not replace YouTube's official counts, and the interface distinguishes YouTube API Data from CreatorFinder calculations and from data supplied by other platforms.

CreatorFinder's access to and use of YouTube API Services is also governed by the YouTube API Services Terms of Service and the applicable YouTube developer policies.

12Contact

For privacy-related inquiries:

📧 support@creatorfinder-sub.com