Privacy Policy
Last updated: September 15, 2026
1. Controller and contact
Operator: Felix Hombauer
Support email: psiasupport@gmail.com
Privacy contact: psiasupport@gmail.com
Country / jurisdiction: Germany
Website: https://creator-video-portal.com
2. Service description
This Privacy Policy applies to Creator Video Portal, the creator portal used for creator registration, TikTok, Instagram, and YouTube connection, video submission, attribution, and campaign performance review.
Creator Video Portal is used to onboard creators, connect TikTok, professional Instagram, and YouTube accounts, receive video submissions, and support campaign attribution, review, and administration workflows.
3. Data categories
- Account and login data (for example email, authentication metadata, account status)
- Creator profile data (for example display name, creator code, internal profile IDs)
- TikTok account linkage data (TikTok user ID / open ID and basic profile metadata such as display name and avatar, provided by TikTok via the user.info.basic scope)
- Granted TikTok permission scopes recorded for the connected account (for example user.info.basic and video.list)
- TikTok OAuth-related technical tokens where required for account connection and verification workflows
- Submitted TikTok video URLs and normalized video IDs
- Public engagement metrics for submitted videos retrieved through the TikTok video.list scope: view count, like count, comment count, and share count
- Submission and review status (for example pending, approved, or rejected)
- Operational and security telemetry (for example request logs and anti-abuse traces)
- Instagram professional-account linkage data provided through Instagram Login, including username, account type, granted permissions, token-expiry status, and the profile Website or biography fields when the official API returns them
- Encrypted Instagram access credentials required to maintain an authorized connection; access tokens are not displayed in the portal
- Submitted Instagram Reel or post URLs, canonical Instagram media IDs, permitted media metadata, publication timestamps, and ownership/eligibility decisions
- Officially available Instagram media insights, which may include views or plays, reach, likes, comments, shares, saves, interactions, and applicable watch-time metrics; unavailable metrics are retained as unavailable rather than recorded as zero
- Redacted Instagram connection and batch audit entries, including stable failure categories but not raw provider errors, authorization codes, access tokens, or secrets
- Google/YouTube channel linkage data obtained through Google OAuth for your own YouTube channel: channel ID, channel title, and public channel handle/URL, together with the granted OAuth scope (youtube.readonly)
- Encrypted Google OAuth access and refresh tokens required to maintain the authorized YouTube connection; these tokens are not displayed in the portal and are never exposed to other users or browser code
- Submitted YouTube video/Short URLs, canonical video IDs, and the video's channel ID, used to verify that the submitted video belongs to your connected channel
- Public YouTube video metrics retrieved through the authorized YouTube Data API for videos on your connected channel: view count, like count, and comment count
- Redacted YouTube OAuth connection status and audit entries, including stable failure categories but not raw provider errors, authorization codes, access tokens, or secrets
4. Processing purposes
- Authenticate users and protect account access
- Support creator identity verification and profile management
- Enable TikTok, Instagram, and YouTube account connect/disconnect workflows
- Process and review video submissions
- Perform campaign and attribution checks
- Operate, secure, and improve portal reliability
- Verify ownership of submitted YouTube videos/Shorts through Google OAuth-authorized channel matching
5. TikTok data use and scopes
With your consent, Creator Video Portal requests the following TikTok permission scopes:
- user.info.basic — reads your basic TikTok profile (open ID, display name, and avatar) to confirm and display the connected account.
- video.list — reads your own TikTok videos and their public view, like, comment, and share counts to verify submitted videos and review campaign performance.
TikTok-linked data is used only for creator connection, submission verification, creator/video mapping, campaign performance review, and related administration tasks in this portal. TikTok-linked data is not sold, is not used for advertising, and is not shared with unrelated third parties.
TikTok is an independent third-party platform that is not operated by or affiliated with Creator Video Portal. The availability and accuracy of TikTok-linked data depend on the TikTok API and the permissions you grant, and may change if you revoke access. Where technically and legally possible, TikTok-linked data can be removed after disconnect, consent withdrawal, or a valid deletion request.
6. Instagram Login data use and permissions
With your consent, Creator Video Portal requests only the following Instagram Login permissions for your own professional account:
- instagram_business_basic — identifies the connected Instagram professional account and reads the official profile and the creator's own media needed to verify submitted Reels or posts.
- instagram_business_manage_insights — reads only officially available insights for the creator's own submitted media, such as views or plays, reach, engagement, and applicable watch-time metrics.
The portal does not request Instagram messaging, content-publishing, comment-management, Facebook Page-management, or advertising permissions for this workflow.
Instagram-linked data is used only to connect the creator's own professional account, verify ownership and publication timing of submitted media, maintain profile-link evidence when official fields are returned, and store official media insights for creator and protected admin review. Instagram metrics do not contribute to the separate TikTok reward campaign.
Instagram access credentials are encrypted at rest and are never exposed to browser code or portal users. Metrics are refreshed only by the fixed scheduled batch. Disconnecting removes the locally stored Instagram access credential; a valid deletion request can be made using the contact details above. Instagram is an independent third-party platform, and data availability depends on the Instagram API and permissions you grant.
7. Google OAuth and YouTube data use
With your consent, Creator Video Portal uses Google OAuth to connect your YouTube channel and requests only the following scope:
- youtube.readonly — identifies the YouTube channel connected to your Google account (channel ID, title, and public handle) and lets the portal read your own channel's videos to verify ownership of submitted YouTube videos/Shorts and retrieve their public view, like, and comment counts.
Creator Video Portal does not use this Google authorization to upload, edit, publish, or delete any YouTube video, Short, comment, playlist, or channel setting. The access is strictly read-only and is used only to identify your channel and verify ownership of videos you submit.
YouTube channel ownership is verified automatically: the channel returned by your Google OAuth authorization is matched against the channel ID of every submitted YouTube video or Short, and a video is accepted only when it belongs to your connected channel. Google/YouTube-linked data is used only for creator connection, ownership verification, submission review, campaign performance review, and related administration tasks in this portal. Google/YouTube-linked data is not sold and is not used for advertising.
Google OAuth access and refresh tokens are encrypted at rest on the server and are never exposed to other users, other creators, or browser-side code. You can disconnect your YouTube channel at any time from Dashboard → Account, which revokes the stored Google authorization and deletes the locally stored token; a valid deletion request can also be made using the contact details above. Google and YouTube are independent third-party platforms that are not operated by or affiliated with Creator Video Portal, and the availability and accuracy of YouTube-linked data depend on the YouTube Data API and the permissions you grant.
Creator Video Portal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Google/YouTube data sharing
Google/YouTube data described above is not sold and is not used for advertising, and it is not shared with unrelated third parties. It is shared only with the following categories of service providers (data processors), strictly to operate Creator Video Portal:
- Cloudflare, which hosts and delivers the application and may process data in transit while routing web requests.
- The managed database/hosting infrastructure that stores the data described above.
- Portal administrators, limited to those who need this data to review submissions, verify ownership, or provide support.
Google/YouTube data may also be disclosed where required by law or valid legal process. Outside of these service providers and legal exceptions, Google/YouTube data is not transferred to any other party.
Google/YouTube data is never sold or transferred to advertising platforms, data brokers, or information resellers, and it is never used for serving advertising of any kind, including targeted, personalized, retargeting, or interest-based advertising.
Google/YouTube data is never used to determine creditworthiness or for lending purposes.
Google/YouTube user data is not used to develop, improve, or train generalized or non-personalized artificial intelligence (AI) or machine-learning (ML) models.
9. Google/YouTube data retention, disconnection, and deletion
Disconnecting YouTube from Dashboard → Account immediately revokes the stored Google authorization with Google and deletes the locally stored OAuth access and refresh tokens; the channel connection is marked disconnected.
In addition to disconnecting inside Creator Video Portal, you can revoke this app's access at any time directly from your Google Account permissions at https://myaccount.google.com/permissions.
Previously stored channel identification and submitted-video ownership/metrics records are not deleted automatically on disconnect, because they remain part of the submission and audit history. They are retained under the same criteria described in Data retention below, and are deleted or anonymized when the related account or submission data is deleted.
You can request deletion of this data at any time using the privacy contact above or the Delete your data.
10. Data retention
Data is retained only as long as needed for account operation, submission review, compliance obligations, dispute handling, security, and auditability. Retention periods may differ by dataset and legal obligation.
11. Data subject requests
You may request access, correction, deletion, restriction, or objection where applicable under local law. Contact: psiasupport@gmail.com
12. Service providers
The portal relies on external service providers, including Cloudflare (hosting and runtime delivery), managed database infrastructure for storing the data described above, an authentication provider for account access, and the TikTok, Instagram, and Google/YouTube APIs for account connection and media data.
13. Security and cookies
Reasonable technical and organizational safeguards are used to protect data in transit and at rest, including encrypted (HTTPS/TLS) transport for all traffic and server-side encryption of OAuth access and refresh tokens, including the Google/YouTube tokens described above. These tokens are never exposed to browser-side code, are never visible to other users or other creators, and access to the systems that store them is restricted to the personnel and services necessary to operate and administer Creator Video Portal. Session and security cookies may be used for authentication, abuse prevention, and platform integrity.
14. Related documents
Please also review our Terms of Service · Delete your data.