Privacy
MuchCreator Privacy Policy
This policy explains what data we process, why we process it, how connected social accounts are used, and your data rights.
Last updated: October 1, 2026Data we collect
During account creation, sign-in, social account connection, campaign participation, and video link submission, MuchCreator may process your name, email address, user identifier, connected platform information, video URL, video ownership verification result, view metrics, and records required for payment operations.
Social media data
When a user authorizes a social account through OAuth, MuchCreator obtains only the limited data required for campaign verification and performance tracking from TikTok, YouTube, and Instagram. This data is used to verify video ownership, record the initial view count, collect periodic metric snapshots, and investigate security signals. Core metric verification is not presented as optional analytics or marketing consent.
Access to and use of Google and YouTube data
If you choose Google sign-in, your Google account identifier and the name, email address, and profile information supplied by Google are processed through Supabase to authenticate your MuchCreator account. Signing in with Google and connecting your YouTube channel for campaign verification are separate actions. If you separately connect your YouTube channel, the youtube.readonly permission is used to process your channel identifier and name, the identifier and channel/ownership information of a video you submit, its publication time, video metadata returned by the YouTube API, and view count. OAuth access and refresh tokens are used only to authorize and maintain this connection. This data is used to verify that the account and video belong to you, track the submitted video's performance, review campaign eligibility, and create reward-entitlement records. This connection does not access your Gmail, Google Drive, or calendar data, or publish, modify, or delete content in your YouTube account. Google/YouTube data is not used for advertising targeting, retargeting, data brokerage, credit assessment, or training general-purpose AI or machine-learning models.
Optional website analytics
Only after you accept analytics, we process visitor and session identifiers, the query-free path and category of visited pages, safe interaction labels, destination pages, and active time on a page. If you are signed in, these records may be linked to your MuchCreator user ID. Form fields, typed text, and raw IP addresses are not stored in analytics events; the source IP is transformed server-side into a keyed digest solely for rate limiting and reporting.
Metric notice evidence
Before a video link is submitted, the system records the version, language, content SHA-256 digest, and informed acknowledgement timestamp for the metric notice in the same transaction as the submission. This evidence is not a contract acceptance or an explicit consent record; those record types are kept separately when applicable.
Why we use data
We use data to manage user sessions, verify connected social accounts, check compliance with campaign requirements, calculate valid increases in views, manage pending payments, and protect the platform.
Retention and security
Social platform access and refresh tokens are processed only by authorized server-side components. Before database storage, OAuth tokens are encrypted at the application layer using AES-256-GCM; the encryption key and provider secrets are kept separately in server environment configuration. Raw tokens are not returned to the browser or shown in the user interface. Connections between users, MuchCreator, and provider APIs use HTTPS/TLS. Direct browser-role access to social connection and encrypted token records is disabled; access is limited to authorized server processes under least-privilege controls. Raw provider responses are designed to be retained for a limited period only for debugging, fraud investigation, and audit purposes. Detailed website analytics records are deleted after 90 days; daily totals that contain no personal event records may be retained longer for product performance comparisons. Users can disconnect social accounts and withdraw analytics permission from the footer preferences.
Sharing
MuchCreator does not sell Google user data or other personal data. The parties with whom Google/YouTube data is shared, transferred, or processed to deliver the service, and their purposes, are described below. Each recipient is limited to the data needed for its role. Supabase: Used to verify Google sign-in and manage accounts and sessions, and to store Google account/profile information, connected YouTube channel information, encrypted OAuth tokens, and video verification/performance records in the database. Vercel: Used to host MuchCreator and run server-side operations. Google/YouTube authorization operations, API requests, and their verification/performance responses are processed on this infrastructure; provider secrets and the token-encryption key remain in server configuration only. Google/YouTube: Authentication information and channel/video identifiers needed for Google sign-in, YouTube authorization, token renewal, and verification of your submitted video/channel are sent to the relevant Google APIs. Data obtained from the Google/YouTube connection is not sent to TikTok or Meta/Instagram APIs. Campaign brands and other users: They are not given direct access to your Google account, OAuth tokens, or raw Google/YouTube API responses. Before a creator-level Google/YouTube campaign report is transferred to a brand, the data and the campaign's recipient brand must be disclosed and the creator must expressly authorize that sharing. Such a report is limited to the relevant campaign's video link, channel/video identifiers, verification result, necessary performance data, and reward summary; tokens, sign-in credentials, and raw API responses are excluded. Human review of Google data by authorized MuchCreator personnel is limited to support where the user expressly authorizes review of specific data, necessary security/bug/abuse investigations, or legal obligations. Access is limited to the data needed for the role. Disclosure to competent authorities is limited to the data required by an applicable legal obligation or valid legal request. Google/YouTube data is not transferred to advertising platforms, data brokers, or for independent marketing or model-training purposes.
Google data-use limits and permission controls
MuchCreator's use and transfer to other applications of information obtained through Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. The YouTube connection is also subject to the YouTube API Services Developer Policies. Google's own data-handling practices are described in the Google Privacy Policy; use of YouTube is governed by the YouTube Terms of Service. This policy update does not authorize a new recipient or purpose; users are informed and the required authorization is obtained before a new use or transfer is enabled. You can disconnect YouTube in your creator panel. This removes the stored connection/token record and stops new metric collection associated with that connection. You can also revoke MuchCreator's access on Google's side through Google account permissions. To request deletion of previously stored video verification/performance data, use the verified request form in the Data Deletion Instructions or contact hello@muchcreator.com. Deleting data stored by MuchCreator does not delete videos you published on YouTube or data in your Google account.
Your rights and contact
For data access, correction, or deletion requests, contact hello@muchcreator.com. You can also use the Data Deletion Instructions page for the deletion process.

