Privacy Policy

Effective

DeepRed Connect and Creator Studio have not launched. This policy describes how they will handle personal data once they do. Every feature below is planned unless the policy says otherwise.

1. Who we are and what this policy covers

DeepRed Connect is run by DeepRed LLC ("we", "us"), a New Mexico limited liability company (NM Entity ID 0008059925), at 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States. Phone: +1 212-221-2221. For privacy questions, write to privacy@deepred.app.

On Instagram, YouTube, TikTok and the other platforms' permission screens, our app appears under the name "DeepRed".

This policy covers:

  • DeepRed Connect at connect.deepred.app: the sign-in and permission flow that links a platform account to us, this website and its legal pages.
  • My connections at connect.deepred.app/my-connections, where creators see which apps can read their data and revoke access in one click. It opens at launch.
  • Creator Studio at studio.deepred.app, where creators connect their social, video and income accounts, see their data and publish. It opens at launch.
  • The Connect API at connect-api.deepred.app and the developer console, once they open.

It does not cover the DeepRed marketplace app at deepred.app, which has its own privacy policy. If the marketplace ever reads data through DeepRed Connect, we will update this policy and ask you first (section 12).

We are the controller for Creator Studio, My connections, this website and our own products. One exception: for data from TikTok's business tools ("TikTok extra insights", section 6.3), we handle personal data solely for you, as your processor.

When another company's app uses Connect. We plan to let other companies build on DeepRed Connect, platform by platform, only where each platform's terms allow it. None do yet. If you connect an account through another company's app, that company decides how your data is used and its privacy policy applies to that use. We process the data for that company, on its instructions, under a data processing agreement. The Connect screen shows that company's name and links to its privacy policy and to this one. Sections 7, 8 and 10 still describe our own deletion, security and your rights with us.

2. The short version

  • You connect an account only through the platform's own sign-in and permission screen. We never ask for, see or store your platform password.
  • We read only what you allow, and only what the feature you use needs.
  • We don't sell personal data. We don't use platform data for advertising. We don't give it to data brokers. We don't use it to train AI models.
  • Only you see your connected-account data in our products.
  • You can disconnect at any time. We stop syncing at once and delete that account's data and tokens from our live systems within 24 hours. Deleted data is gone from our database backups within 7 days and from our encrypted disaster-recovery copies within 8 days. The key that encrypts your platform tokens is deleted within minutes, so no leftover copy of those tokens can be read.

3. What we collect

3.1 What you give us

DataExamplesWhy we need itRequired?
Account detailsName, email address, sign-in method, time zoneTo create and secure your Creator Studio accountYes. Without them we can't open an account
Your choices and consentsWhich platforms and data types you connected and when; each post you approved for publishing, with the time and what you previewedTo do what you asked and to prove you asked for itYes, for the feature you choose
MessagesEmails to support@, privacy@ or security@deepred.appTo answer youNo
Developer accounts (planned)Name, work email, company, team members. Billing details are collected by our payment providerTo run the developer console and bill API customersYes, to use the console

3.2 What the platforms send us

When you connect a platform, it gives us an access token and the data you allowed. We group that data into seven types. Before you leave for the platform's permission screen, Connect shows which types an app is asking for.

TypeWhat it means
IdentityYour account ID, username, display name, profile picture, bio, account type, verified status and public counts such as followers
ContentYour own posts, videos, stories and other content: captions, titles, media links, thumbnails, links, publish time and visibility
MetricsNumbers the platform reports for your account and content, such as views, reach, likes, comments, shares, saves and watch time
AudienceAggregated statistics the platform reports about your audience, such as shares by age range, gender, country and city. These are percentages. We never receive a list of individual followers through this type
CommentsComments and replies on your content: the text, the time, and the commenter's public username, ID and profile picture where the platform sends them with the comment. We don't look up commenters' profiles separately (on Facebook Pages we get only the name and ID that come with the comment)
PublishMedia, captions and settings you choose to post through us, and the platform's post ID and result
IncomeEarnings figures from sources that report them, such as YouTube estimated revenue. Amounts keep their original currency

We also store the access and refresh tokens the platform issues, and the list of permissions you actually granted. If you untick a permission on the platform's screen, we don't use the features that need it.

3.3 What we collect from each platform

What a platform can send depends on its API and on your account type. We ask only for the permissions a feature uses. "Planned" means the connection is not available yet.

PlatformIdentityContentMetricsAudienceCommentsPublishIncomeStatus
Instagram, connected with Instagram login (Business and Creator accounts)YesYesYesYes, once your account passes Instagram's follower thresholdYesYesNoPlanned
Instagram, connected through Facebook (professional account linked to a Page)Yes, plus your Facebook user ID and name so we can list the Pages you manageYesYesYesYesYesNoPlanned
Facebook PagesYes, plus your Facebook user ID and nameYesYesAge, gender, country and region of people who watched your videos, and the country and city of your Page's followers if Meta still returns them. Only where at least 100 people are countedYesYesNot collectedPlanned
ThreadsYesYesYesYes, for profiles with 100 or more followersRepliesYesNoPlanned
YouTubeYesYesYesAge group, gender and geographyOnly if we offer comment featuresYesEstimated revenue, only for channels in the YouTube Partner Program and only if you turn income onPlanned
TikTok (standard connection)YesYour public videosLifetime views, likes, comments and shares per videoNoNoYesNoPlanned
TikTok extra insights (optional second connection through TikTok's business tools; works with personal and business accounts)YesYour posts: videos, photos and textDaily account metrics for up to the last 60 days, and per-post metrics such as watch time, completion rate and traffic sources. Reach, engaged audience and new and lost followers only if your account is linked to TikTok for BusinessFollower age, gender, country and city once your account has at least 100 followers; viewers' gender, country and city for each postComments and replies on your posts, which you can answer, hide, like or deleteYes. Video posts are published publicly; you choose the visibility of photo postsNoPlanned
XYesYour postsPublic metrics for your posts, plus private metrics such as link and profile clicks for your own posts from the last 30 days. X gives private metrics only to the post's authorNoReplies to your posts from the last 7 daysYesNoPlanned
LinkedInName, profile picture, headline, profile URL and member ID. We don't request your LinkedIn email addressOnly posts you publish through usAnalytics for your posts and videos (impressions, members reached, reactions, comments, reposts, saves, sends, link clicks, followers and profile views gained, video plays, viewers and watch time) and your follower count over time. Fetched when you view them, not kept as historyNoNoYesNoPlanned
PinterestYesYour Pins and boardsYes, for business accountsOnly if you have a Pinterest ad account and grant the separate ad-account permission: age, gender, country, metro area, device and interests of your audience over the last 30 daysNoYesNoPlanned
TwitchYes. Your email only if a feature needs itVideos, clips and stream statusCounts only: follower total, subscriber total and subscriber points, Bits totals. We never store lists of followers or subscribers. If you allow Bits access, the Bits leaderboard also shows your top cheerers' Twitch names (section 3.4)NoNoNoNo. Subscriber and Bits figures are counts, not earningsPlanned
SnapchatDisplay name and Bitmoji, whichever you choose to shareOnly if Snap grants us partner accessOnly if Snap grants us partner accessOnly if Snap grants us partner accessNoNoNoPlanned
BlueskyYesYesPublic countsNoRepliesYesNoPlanned
RedditNot offeredNot offered
StripeBusiness name, country and default currencyAvailable and pending balance, charges, refunds and payouts. We discard your customers' names, emails, addresses and card details when a charge arrivesPlanned
ShopifyStore name, currency and countryShopify Payments payouts and balance transactions; orders, payments and refunds from the last 60 days, without customers' names, addresses, emails or phone numbersPlanned
PatreonYour Patreon profile and campaign: name, currency, patron count and billing typePending Patreon's consent: for each membership, the pledge amount, currency, charge dates and payment status, without patrons' names, emails, addresses, images or notes. Amounts are what patrons paid, before Patreon's feesPlanned

Section 6 adds rules that apply to particular platforms.

3.4 Information about other people

Some platform data is about people who don't use DeepRed Connect:

  • Commenters. If you connect comments, we receive the public username, display name, ID and profile picture of people who comment on your content, with their comment text. The source is the platform where they commented.
  • People who reply to you on X. We receive the author's X ID, @handle and reply text for replies to your posts. We keep nothing else about them, and we keep each reply for no more than 7 days.
  • Your top cheerers on Twitch. If you allow Bits access, Twitch's Bits leaderboard gives us the Twitch names of your top cheerers and how many Bits each cheered. Only you see them, and we keep them for no more than 24 hours. We never store lists of your Twitch followers or subscribers.
  • Your patrons on Patreon. If Patreon consents, for each membership we receive the pledge amount, currency, charge dates and payment status. We don't request patrons' names, emails, addresses, images or notes. We handle this data for you, as your sub-processor under Patreon's Creator Privacy Promise, and we pass any patron's privacy request to you.
  • Your store's customers on Shopify. We read orders, payments and refunds from the last 60 days without customers' names, addresses, emails or phone numbers. We never contact your customers. When Shopify passes on a customer's deletion request, we act on it.
  • Your customers on Stripe. Charges can carry your customers' names, emails, addresses and card details. We discard them when the charge arrives and keep only the amounts.
  • Your audience. Audience data is aggregated percentages and identifies no one.

We keep third-party data to the minimum the feature needs, and we delete it together with the rest of the connection. If you are one of these people and want your data removed from DeepRed Connect, write to privacy@deepred.app (section 10). Deleting it here doesn't remove your comment from the platform.

3.5 Information collected automatically

  • Logs. IP address, browser and device type, the pages and API endpoints requested, times and errors. We use them to run and secure the service. We never log tokens.
  • Cookies. Connect uses only strictly necessary cookies. One example is the cookie that ties a sign-in attempt to your browser so nobody can forge it. Creator Studio uses a session cookie to keep you signed in. Our cookies are secure, HTTP-only and same-site. We use session cookies where we can, and any cookie that outlives your session expires within 13 months. Connect pages carry no third-party trackers.
  • Embedded players. If Creator Studio plays your YouTube or Twitch videos, it uses the platform's own embedded player. The player collects data, may set cookies, and shares data with YouTube or Twitch under their own privacy policies, even before you press play if autoplay is on. We keep autoplay off.

4. How we use information, and why we're allowed to

PurposeData usedLegal basis (only where GDPR or UK GDPR applies)
Connect your accounts, keep the data fresh, show it to you, and publish what you approveSections 3.1 to 3.3Performing our contract with you
Show you comments on your content so you can read and answer themCommenters' public username, ID, picture and comment textOur legitimate interest, and yours, in managing conversations on your own content. We keep the minimum
Tell you when a connection needs attention, such as an expiring tokenAccount email, connection statusPerforming our contract
Keep the service secure, prevent abuse, investigate incidentsLogs, audit recordsLegitimate interests. Legal obligation where one applies
Fix bugs and improve features you can seeOur own service logs. Platform data only to provide or improve features shown to youLegitimate interests
Meet legal and platform obligations, such as deletion deadlinesRecords of consent and deletionLegal obligation where one applies. Otherwise legitimate interests

For TikTok extra-insights data we are your processor (section 6.3), so we use it only on your instructions, which are the purposes in this table that apply to features you use.

US state privacy laws don't use legal bases. Section 10.3 lists the rights they give you.

We do not:

  • sell personal data, or share it for cross-context behavioral advertising
  • use platform data for advertising, retargeting, credit or lending decisions
  • use platform data to decide anyone's eligibility for housing, jobs, insurance, education, credit or similar
  • use platform data for surveillance, or to build profiles of people without their consent
  • give platform data to data brokers or information resellers
  • use platform data to train generalized AI or machine-learning models
  • make decisions about you based solely on automated processing that have legal or similarly significant effects

If we want to use your data in a new way or for a new purpose, we will tell you and ask you to accept the updated policy first. We won't use data already collected for the new purpose until you do.

5. Who sees your data and who receives it

5.1 You

Your connected-account data is shown only to you, in Creator Studio. No other DeepRed Connect user and none of our customers can see it. Our staff can see it only in the cases in section 5.4.

5.2 The platforms

When you publish through us, we send your post, media and settings to the platform you chose. Its own terms and privacy policy then apply. When you connect, the platform learns that you authorized DeepRed, and each API request we make on your behalf tells the platform which account it concerns. We don't send platforms any other personal data about you. Section 6 says what each platform receives.

5.3 Service providers

Three service providers run DeepRed Connect for us:

  • Cloudflare, Inc. Hosting and compute for every part of DeepRed Connect, file storage, job queues, and the email we send and route.
  • PlanetScale, Inc. Our main database. PlanetScale runs it on Amazon Web Services in the us-east-1 region (Northern Virginia).
  • Google LLC (Google Cloud). Key management only. Google Cloud Key Management Service holds the master key that protects our encryption keys. It receives only those keys and our internal reference numbers, never your platform data or tokens.

They process data only on our instructions, under written contracts that require them to protect it and delete it when the work ends. Where a platform requires its own terms with service providers, our contracts include them. The current list, with what each provider does and where, is at connect.deepred.app/subprocessors. We update it before any new provider starts processing personal data.

5.4 Our staff

Our staff don't look at your connected-account data unless:

  • you ask us to, for example in a support request, and agree to us viewing specific data
  • it's needed for security, such as investigating a bug or abuse
  • the law requires it

Every staff view of creator data is logged with the reason.

5.5 Companies that build on Connect (planned)

If you connect through another company's app, we give that company the data you allowed, for that app only. Each company's data is kept separate from every other company's, even when the same creator connects to both. Platform rules travel with the data. Our customer terms require each company to follow the same deletion deadlines and sharing limits we follow. For Meta data, we act only on that company's behalf and at its direction.

We disclose data when the law requires it, for example under a valid court order, and we push back on requests that are overbroad. If DeepRed LLC is part of a merger, acquisition or sale of assets, we will ask for your explicit consent before transferring data we received from Google APIs. We will get Twitch's written permission before a new owner processes Twitch data, and we will follow every other platform's rules on such transfers.

6. Rules for particular platforms

6.1 YouTube and other Google services

  • DeepRed uses YouTube API Services.
  • By using the YouTube features of DeepRed Connect, you agree to be bound by the YouTube Terms of Service: https://www.youtube.com/t/terms
  • Google's Privacy Policy explains how Google handles your data: https://www.google.com/policies/privacy
  • Limited Use. DeepRed's use and transfer of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
  • What we access. The YouTube data in section 3.3, through these permissions: read your channel and videos; read YouTube Analytics; read YouTube revenue reports, only if you turn income on; upload videos, only when you first publish; manage comments, only if we offer comment features.
  • How we use it. Only to show you your channel, content, analytics and earnings, and to publish what you approve. We transfer it only to provide features you can see, and only with your consent. We never transfer it to advertising platforms, data brokers or information resellers, and never use it for advertising or credit decisions.
  • Only you see your YouTube data.
  • Publishing. We tell you every action we will take on your channel and the visibility a video will get, and we act only after you confirm. Until our app passes YouTube's audit, YouTube keeps videos uploaded through us private.
  • Accuracy and freshness. We show YouTube numbers as YouTube reports them, and we don't combine one creator's YouTube data with another's. We refresh or delete stored YouTube data other than analytics at least every 30 days, and we check every 30 days that you still authorize us.
  • Revoking access. You can disconnect in Creator Studio or at My connections. When you do, we revoke our token with Google right away. You can also revoke DeepRed's access to your Google data at any time at https://security.google.com/settings/security/permissions. Either way, we delete your YouTube data from our live systems within 24 hours.
  • Deleting data here doesn't delete anything on YouTube. To delete videos or comments on YouTube, use YouTube or another app that supports deleting them.
  • Questions or complaints about how we handle your YouTube or Google data: privacy@deepred.app.

6.2 Instagram, Facebook and Threads (Meta)

  • We access the Meta data in section 3.3 only for the accounts and Pages you select on Meta's permission screen.
  • We use Meta data only for the purposes in section 4. We don't sell or license it, and we don't use it for surveillance, eligibility decisions, discrimination or building profiles without consent.
  • When we process Meta data for a company that builds on Connect (planned), we do it only on that company's behalf and at its direction, and we keep each company's Meta data separate.
  • Threads data is shown only to you. Meta allows apps to show Threads posts only to the person who created them. We apply the same rule to your Threads insights and replies, whatever sharing choices you make elsewhere in DeepRed Connect.
  • How to ask us to delete your Meta data. Any one of these works:

    1. Disconnect the account in Creator Studio or at connect.deepred.app/my-connections.
    2. Remove DeepRed in your Facebook, Instagram or Threads settings. Where Meta offers it, send a deletion request from the list of removed apps. Meta passes it to us, and we give you a confirmation code and a link where you can check the status.
    3. Email privacy@deepred.app.

    Step-by-step instructions are at connect.deepred.app/data-deletion.

6.3 TikTok

TikTok offers two connections. Each has its own permission screen on TikTok, and you can use either or both.

  • Standard connection (TikTok Login Kit, Display API and Content Posting API). We receive your profile, your public videos, and lifetime views, likes, comments and shares for each video. This connection gives no audience data.
  • Extra insights (TikTok's API for Business). This is optional and works with personal and business accounts; you don't need to change your account type. We receive daily account metrics, per-post metrics, follower age, gender, country and city once you have at least 100 followers, and comments on your posts. Some metrics, such as reach and new and lost followers, appear only if your TikTok account is linked to TikTok for Business. The full list is in section 3.3.
  • Sharing. We make TikTok data available to you for your personal use. We don't share, sell, license or syndicate it unless TikTok agrees in writing.
  • Publishing. Through the standard connection you choose the privacy setting for each post; we don't preset one. Until our app passes TikTok's audit, TikTok keeps those posts private. Through the extra-insights connection, video posts are published publicly and you choose the visibility of photo posts; we show you which applies before you confirm.
  • Our role. For the standard connection, for people in the EEA, UK and Switzerland, we are an independent controller of the data TikTok sends us. For the extra-insights connection, we handle personal data solely for you, as your processor and service provider, following your instructions in our Terms (section 9.4) and your settings.
  • Revoking. If you disconnect or revoke either connection, we stop at once and delete the data within 24 hours. For the extra-insights connection TikTok's business terms ask for immediate deletion; we start the purge as soon as we learn of the revocation.

6.4 X

  • We collect the X data in section 3.3 and use it as section 4 describes. X gives private metrics, such as link clicks and profile clicks, only for your own posts and only for posts from the last 30 days. We receive replies to your posts as X reports them and through X's search, which reaches back only 7 days.
  • Replies written by other people: we keep only the author's X ID, @handle and the reply text, for no more than 7 days, and only you see them.
  • What X receives from us: the posts and media you publish through us, and our API requests, each of which identifies your account. We share nothing else with X.
  • Before anything is posted, we show you exactly what will be published and whether any location information is attached.
  • If a post is deleted, made private or changed on X, we delete or update our copy as soon as reasonably possible, and within 24 hours of a request from you or X.

6.5 LinkedIn

Before you connect LinkedIn, Connect tells you what we collect, when, how we use and disclose it, how to withdraw consent and how to ask for deletion. In short:

  • What and when. When you connect: your name, profile picture, headline, profile URL and LinkedIn member ID. We don't request your LinkedIn email address. While the connection is active: analytics for your posts and videos, and your follower count over time. Posts you publish through us. We refresh your profile details only while you are using DeepRed Connect, never on a schedule.
  • No analytics history. We fetch LinkedIn analytics when you view them and cache them for no more than 48 hours. We don't keep daily snapshots or a long-term history of LinkedIn data.
  • Use and disclosure. To show the data to you on a LinkedIn-only page and to publish what you approve. We don't export, email or share LinkedIn data, or combine it with other members' data or with data from other sources.
  • Withdrawing consent. Disconnect in Creator Studio, or remove DeepRed at https://www.linkedin.com/psettings/permitted-services
  • Deletion. Disconnect, or email privacy@deepred.app. LinkedIn requires deletion "immediately" on your request. We start at once and finish within 24 hours.
  • When your LinkedIn token expires, we ask for your consent again before we collect more data.

6.6 Pinterest

  • We access the Pinterest data in section 3.3.
  • Pinterest allows apps to store very little. Until Pinterest agrees in writing to more, we fetch Pinterest data when you view it, keep it only in a short-lived cache, and don't build a history of it. We keep your tokens, the IDs we need to run the connection, and any Pins you schedule until they are published.
  • Audience data comes only from a Pinterest ad account, and only if you grant that permission separately.
  • We don't share Pinterest data with anyone but you.
  • Disconnecting. Pinterest gives apps no way to revoke a user's access. When you disconnect Pinterest in Creator Studio or at My connections, we delete our tokens and data, but your authorization stays on Pinterest's side until you remove DeepRed in Pinterest's settings, in the Security section where Pinterest lists your connected apps.
  • If you revoke our access, ask for deletion or delete your Pinterest account, we delete your Pinterest data. Our live systems are cleared within 24 hours. Pinterest's own deadline is 30 days.

6.7 Twitch

  • We access the Twitch data in section 3.3. We ask for your Twitch email only if a feature needs it.
  • We never store lists of your followers or subscribers; we keep totals. Your top cheerers' names and Bits amounts are shown only to you and kept for no more than 24 hours.
  • Unless Twitch authorizes longer storage in writing, we keep copies of Twitch content for no more than 24 hours.
  • We don't share Twitch data with any third party or affiliate without Twitch's written permission.
  • If you revoke our access, or narrow the permissions you gave us, we delete the Twitch data that depended on them.

6.8 Snapchat

  • For Snapchat data, this policy incorporates by reference the Snap Privacy Policy: https://values.snap.com/privacy/privacy-policy
  • With Snapchat's Login Kit we receive only what you choose to share: your display name, your Bitmoji, or both. We use them to show which Snapchat account you connected.
  • We don't send Snap any personal data about you.
  • Snapchat removes app connections after 90 days of inactivity. When that happens, we treat it as a disconnect and delete the data.

6.9 Bluesky

  • Bluesky data is public on the AT Protocol network. We access your profile, posts, public counts and replies to your posts.
  • You can ask us to delete any of your Bluesky content we hold, and we will. When you delete a post or your account on Bluesky, we delete our copy within 24 hours of learning about it.

6.10 Reddit

We don't offer a Reddit connection. This section will describe one before we do.

6.11 Income sources

Stripe, Shopify and Patreon connections are planned. Each reads only your own account, through that service's official authorization, and only the fields in section 3.3.

  • Stripe. Read-only access to your balance, charges, refunds and payouts. We discard your customers' names, emails, addresses and card details when a charge arrives.
  • Shopify. Payouts, balance transactions, and orders, payments and refunds from the last 60 days, without customers' names, addresses, emails or phone numbers. We never contact your customers. When you uninstall the app, or a customer or Shopify asks us to delete data, we delete it from live systems within 24 hours, and every backup copy is gone within 8 days, inside Shopify's 30-day limit.
  • Patreon. Figures are what patrons paid, before Patreon's fees; Patreon doesn't report your payouts. We handle membership data as your sub-processor under Patreon's Creator Privacy Promise. We never show anyone outside your account information about an individual patron.
  • We don't use income data to decide anyone's eligibility for credit, insurance or any other product.

7. How long we keep data

DataHow long
Platform tokensUntil you disconnect, the platform revokes access or the token can't be refreshed. The key that encrypts them is deleted within minutes after that, and the tokens are purged from live systems within 24 hours
Data from a connected platformWhile the connection is active and the platform rules below allow. Deleted from live systems within 24 hours after you disconnect, revoke access at the platform, or delete your Creator Studio account
YouTube data other than analyticsRefreshed or deleted at least every 30 days
Content you delete or change on a platformDeleted or updated in our systems within 24 hours of learning about it
Twitch contentUp to 24 hours, unless Twitch authorizes longer
Twitch top-cheerer names and Bits amountsUp to 24 hours. Lists of followers or subscribers are never stored
Pinterest dataShort-lived cache only, unless Pinterest consents in writing to more. Tokens, operating IDs and scheduled Pins are kept while you stay connected
LinkedIn analyticsFetched when you view them and cached for no more than 48 hours. No history or daily snapshots
LinkedIn profile detailsKept while you stay connected; refreshed only while you are using DeepRed Connect
X replies written by other peopleAuthor ID, @handle and text only, for no more than 7 days
TikTok extra-insights data after you revokePurge starts as soon as we learn of the revocation and finishes within 24 hours
Media you upload to publishUp to 7 days after upload, then deleted automatically
Database backups (point-in-time recovery)Deleted data leaves them within 7 days
Disaster-recovery copies (encrypted daily copies of our database, kept in a second region)Deleted data leaves them within 8 days: each copy expires after 7 days, and expiry runs within about a day
Creator Studio account detailsUntil you delete your account
Records of deletion60 days. They hold IDs and times, not platform content
Security and audit logsService logs: 7 days. Audit records of token use and staff access: up to 400 days. They hold IDs and actions, no tokens and no platform content
Background job recordsUp to 7 days. They hold IDs only

"Live systems" means every place we keep data to run the service: databases, caches, file storage, event queues and logs.

8. How we protect data

  • Data is encrypted in transit with TLS and encrypted at rest.
  • Platform tokens are encrypted with a data key of their own. Those keys are in turn encrypted by a master key held in Google Cloud Key Management Service. Tokens are decrypted only in the services that call the platforms, and are never logged.
  • When we delete a connection, we delete its keys within minutes, and no copy of them is kept anywhere, so any leftover copy of the tokens can't be read.
  • Each customer's data is kept apart from every other customer's, in the database and in storage.
  • Staff access needs multi-factor authentication, follows least privilege, and is logged. We never copy production data into development systems.
  • We plan an independent penetration test before the public API launches.

More detail, and how to report a vulnerability, is at connect.deepred.app/security.

9. Where we process data

DeepRed LLC is a United States company, and we keep your data in the United States:

  • Our database runs on Amazon Web Services in the us-east-1 region (Northern Virginia), operated for us by PlanetScale.
  • Our files, queues and other stored state run in Cloudflare data centers. We ask Cloudflare to keep them in Eastern North America, and our disaster-recovery copies in Western North America. Cloudflare describes these location settings as best effort, not a guarantee.
  • Google keeps our master key in its us-east4 region (Northern Virginia).
  • Our code runs on Cloudflare's worldwide network. A request is received at a Cloudflare data center near the person making it, and background jobs can run in any Cloudflare data center, so data can be processed briefly outside the United States while that work runs. It is stored in the United States.

If you live outside the United States, your data is transferred to the United States, whose data-protection laws may differ from yours. For people in the EEA, the UK and Switzerland, where the law requires a transfer safeguard, we use one. Cloudflare's and PlanetScale's data processing terms include the Standard Contractual Clauses. Ask privacy@deepred.app for a copy.

10. Your rights and how to use them

10.1 What you can ask for

Depending on where you live, you can ask us to:

  • tell you whether we process your personal data, and give you a copy in a readable format
  • correct data that is wrong or incomplete
  • delete your data
  • give you your data in a portable format
  • restrict or object to some processing, including objecting to direct marketing
  • withdraw consent you gave, without affecting what we did before
  • not sell or share your data, or use it for targeted advertising or profiling. We don't do any of these
  • not subject you to decisions based solely on automated processing. We don't make any

You can also complain to us, and to a regulator (section 10.4).

10.2 How to ask

  • In the product. Creator Studio lets you disconnect accounts and delete your account. My connections at connect.deepred.app/my-connections lets you revoke any app's access in one click.
  • By email at privacy@deepred.app. Say what you want and which accounts it concerns.
  • By post to DeepRed LLC, Attn: Privacy, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States.

We confirm it's you before we act, usually by asking you to sign in or to reply from the email on your account. We never ask for your platform password. You can use an authorized agent; we'll ask the agent for proof of your permission and may ask you to confirm your identity.

We answer within the deadline set by the law that applies to you:

LawDeadline
California (CCPA)45 days, extendable once by 45 more days with notice
Other US state privacy laws45 days, extendable once by 45 more days with notice. If we refuse, you can appeal by replying to our decision, and we answer the appeal within 60 days
GDPR (EEA)One month, extendable by two more months for complex or numerous requests. We tell you within the first month if we extend
UK GDPROne month, extendable by two more months. The clock pauses while we wait for information we need from you

We don't charge for requests and we won't treat you differently for using your rights.

If you connected through another company's app (planned), we pass your request to that company, because it decides how that data is used. You can still revoke its access yourself at My connections.

10.3 State and regional information

  • California. If the California Consumer Privacy Act applies to us: we collect the categories in section 3, which are identifiers, internet or network activity, commercial information (income data) and audio or visual content (your posts). We collect them from you, from the platforms you connect, and automatically. We use and disclose them only as sections 4 and 5 describe. We have not sold or shared personal information as California law defines those terms, and we don't knowingly sell or share the data of anyone under 16. We operate online only, so you can make requests by email.
  • Other US states. Several states, including Virginia, Colorado, Connecticut and Texas, have consumer privacy laws that give residents rights to access, correct and delete their data, get a portable copy, and opt out of targeted advertising, sale of personal data and profiling with legal or similarly significant effects. We honor these requests from residents of any US state where such a law applies to us. If we deny your request, the decision tells you how to appeal and, if the appeal is denied, how to contact your state attorney general.
  • EEA and UK. If GDPR or UK GDPR applies to our processing of your data, DeepRed LLC is the controller for Creator Studio and our own products. In the UK you have a legal right to complain to us. We acknowledge complaints within 30 days and tell you the outcome.

10.4 Complaints

Please contact us first at privacy@deepred.app so we can try to fix the problem. You can also complain to a regulator, for example: your state attorney general; the California Privacy Protection Agency; your national data-protection authority in the EEA; or the Information Commission (ICO) in the UK.

11. Children

DeepRed Connect is not for children. You must be at least 18 years old, or the age of majority where you live if that is higher, to use Creator Studio or connect an account. If we learn we hold data from someone under that age, we delete it within 24 hours.

12. Changes to this policy

We post every change here, update the date at the top and record it in section 14. Before we use your data in a new way, or for a purpose this policy didn't cover when you connected, we tell you in the product and by email and ask you to accept the updated policy. Until you do, we don't use data we already hold for the new purpose. If California law applies to us, we review and update this policy at least once every 12 months.

13. Contact

14. Change log

DateChange
October 5, 2026First version