Legal documentation

Privacy Policy

Version 6.0 · Effective date: October 8, 2026

This Privacy Policy describes the data handling and privacy safeguards governing CollabBase accounts, connected platforms, campaign operations, and creator information.

Section 1.0

Who We Are and What This Policy Covers

CollabBase is operated by Impact Media LLC ('we', 'us', or 'our'). This Privacy Policy explains how we collect, use, store, and share personal information through our website, creator discovery, shared workspaces, campaign and messaging tools, connected-account features, and optional browser helper (the 'Service'). It covers customers, workspace members, connected creators, people whose public information appears in the creator catalog, and people who contact us or receive outreach. Where a feature requires separate permission or consent, this policy does not replace that permission.

Section 2.0

Information Collected

We process account and sign-in identifiers, profile details, billing and subscription records, search requests and settings, campaign records, creator lists, contact information, reviewed outgoing messages, conversation replies, sender identities, privacy preferences, and security and diagnostic records. Our creator catalog can include public profile information, public content and business contact pages, customer-supplied information and corrections, and information obtained from data providers. Available records may include topics, language, geography, account links, follower counts, content dates, views, and engagement; inferred or incomplete fields are not guarantees about a person or their audience. We use session and authentication cookies and browser storage for sign-in, connected-account handoffs, and other necessary product functions. When you connect an account, we receive the identifiers, profile fields, statistics, content, messages, or commerce information made available by the permissions you authorize. We store provider credentials in encrypted form. For teams, we store invitation email addresses, inviter and membership information, roles, invitation status, and timestamps. Owners and administrators manage workspace access. Authorized members can access shared creator lists, campaigns, settings, outreach, and inbox records according to their permissions. Removing a member ends that member's workspace access; it does not delete the workspace's shared records.

Section 3.0

Connected Google and YouTube Data

Google sign-in supplies the identity information needed to authenticate your account. Separately, a workspace may connect a Google sender account to send messages that a user has reviewed and authorized. For send-only outreach, CollabBase does not read the connected Google mailbox. Where private email reply tracking is enabled, new outreach conversations can use a private CollabBase Reply-To address. Replies sent to that address are processed into the workspace inbox so authorized members can read and answer them, stop follow-ups, and update campaign workflow. The inbound-mail provider may temporarily store the original email, which can contain HTML and attachments. The application imports bounded, sanitized plain text and necessary delivery headers. Attachments, raw HTML, unrelated mailbox threads, and general mailbox contents are not imported. Availability depends on the workspace configuration and enabled infrastructure. CollabBase uses YouTube API Services. A creator may separately authorize a YouTube connection for channel ownership verification, profile and channel statistics, recent content, and supported campaign analytics. Authorized profile and content information and available metrics can be stored in the searchable creator catalog, shown in relevant product features, and processed by the discovery AI features described below. Connecting an account is separate from granting permission for a brand to send messages. The information available depends on the permissions granted and provider restrictions; we do not promise access to every audience or analytics field. CollabBase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising, used to determine creditworthiness, or used to train a generalized artificial-intelligence model. You can revoke Google access through Google's account permissions page, linked below, in addition to using CollabBase's disconnect controls and privacy request process.

Section 4.0

Instagram and TikTok Connections

A creator may authorize an eligible Instagram professional account or a TikTok account to verify control and obtain the profile, statistics, insights, and recent content supported by that provider's granted permissions. TikTok creator login does not itself require an Instagram-style professional account. Authorized profile and content facts and available metrics can contribute to the searchable creator catalog and discovery processing described in this policy. Connections do not grant CollabBase permission to publish or edit the creator's social content. A brand's social inbox connection is separate from a creator's verification connection. Read-only import of replies is available only when the provider approves the relevant product and permissions, the account is eligible, and the feature is enabled. Where supported, official APIs and signed webhooks import matched outreach replies and update conversation and campaign workflow. An ordinary creator login does not automatically enable brand reply import. When that integration is unavailable, replies can be recorded manually. The browser helper described below verifies user-initiated sends; it does not infer or import social replies from inbox previews.

Section 5.0

Chrome Helper and Stripe Affiliate Data

The optional Chrome helper operates on the permitted CollabBase, Instagram, and TikTok pages for reviewed outreach tasks. It processes recipient handles and profile links, reviewed outgoing message text, a short-lived task authorization token, task URLs, and progress or send status. Current task state is stored in Chrome session storage; the helper requests reviewed tasks from CollabBase and reports progress back to the Service. It opens the intended profile or conversation, fills the reviewed message, and observes your own Send action and relevant composer or error state. It does not click Send and does not collect general browsing history. If you request verification of an uncertain send, the helper may compare a recipient handle and a bounded visible inbox message snippet with your reviewed outgoing text to help check whether the message was sent. This is not proof of recipient delivery or reading. It does not import social replies or retain unrelated inbox conversations. Its use and transfer of user data is limited to providing and securing these assisted-outreach and verification features, consistent with the Chrome Web Store User Data Policy, including its Limited Use requirements. A workspace may separately connect a read-only restricted Stripe key to measure creator-linked promotion codes and affiliate performance. The brand creates and controls its promotion codes in Stripe. CollabBase stores the connected account identifier, encrypted authorization material, promotion-code attribution, and bounded sales and revenue statistics required for reporting. This connection cannot move money or create charges, refunds, coupons, or promotion codes. Billing subscriptions and search top-up purchases are separate from this optional attribution connection.

Section 6.0

Purpose of Data Processing and Automated Assistance

We use information to provide discovery and campaign tools, facilitate user-authorized outreach and conversations, enforce search allowances and sender health, identify replies, opt-outs and delivery failures, verify connected creator profiles, measure supported campaign or affiliate performance, manage team access, secure and improve the Service, bill customers, and respond to privacy requests. A transactional message notification may identify the conversation and link to the private inbox; the notification does not contain the private message text. Users can turn these message notifications off in account settings without disabling verification emails or changing their inbox messages. Discovery uses AI service providers for query interpretation, search-progress assessment, relevance judgment, ranking, and match explanations. Inputs can include the search request and selected criteria, candidate identifiers and profile fields, bios, topics, geography and language, available metrics, and bounded recent-content or other search evidence. This can include information obtained through an authorized creator connection as well as public or provider-supplied information. Model responses and existing evidence can also inform later catalog attribute maintenance. Missing or inferred fields and AI explanations are not independent verification of a creator, their location, audience, or suitability. Where reply classification is enabled, an AI processor receives bounded, sanitized reply text and, where available, a subject and relevant previous outgoing text. Classification can suggest or apply conversation and campaign workflow states; authorized users can review and correct those states. CollabBase does not use this information to train a general-purpose AI model. Processing by an external provider is subject to the applicable provider terms and data-processing arrangements. An outreach message or batch requires deliberate user authorization before durable, paced delivery. AI processing does not authorize sending on your behalf, and the social browser helper still requires your own Send action.

Section 7.0

Data Security and Retention Safeguards

We use technical and administrative safeguards designed to protect information, including secure transport, application-layer encryption of provider credentials and imported message content, authenticated workspace and creator permissions, and restricted platform-administrator access. Where enabled, private reply routing uses opaque route tokens and signed, replay-bounded delivery events. These safeguards do not eliminate every security risk and are not a certification of the Service or its providers. Short-lived diagnostic records can include bounded AI request and response messages, search text, creator evidence, model decisions, and identifiers. Their content is scheduled for removal after seven days through periodic cleanup. Creator deletion and applicable connected-data revocation also remove associated diagnostic copies without deleting content-free model, token, rate, and cost records needed for accounting. Operational discovery logs retain content-free measurements rather than profile bios, private messages, or model prose. Historical investigation exports are separately controlled and must be included when fulfilling an applicable deletion request. The general AI-spend dashboard does not expose request or response text or decrypt private conversations. Authorized workspace members can access their conversations through the workspace inbox. Any exceptional administrative access to sensitive provider data must have the specific consent or security, privacy-request, or legal basis required by the applicable rules; role permissions alone do not establish that purpose or consent. Outreach and imported inbox message content has a configured deletion deadline; the application default is 180 days. Older records without an explicit deadline use their original creation time to determine expiry under that schedule, rather than restarting retention when cleanup is introduced. Catalog records, account and billing records, privacy-request evidence, and minimal suppression or pseudonymized commercial records have different retention needs. We review deletion and restriction requests in light of applicable law, provider obligations, and necessary security, accounting, and suppression records. Backup copies are rotated under the operational recovery-point schedule and may remain until that rotation occurs. Encryption of selected application fields does not mean that an entire database backup is encrypted. A restored backup may require privacy restrictions and deletions to be reapplied before affected information is returned to active use. We do not promise immediate erasure from every backup or a fixed restoration schedule.

Section 8.0

Third-Party Data Disclosures

We do not sell Google user data or customer workspace search history. Creator discovery makes public or licensed creator profile and contact information available to customers; depending on the jurisdiction, this may be treated as sale, sharing, licensing, or data brokering. Authorized workspace members receive shared workspace information as described above. Connected creator information may be shown in discovery and relevant campaign features, subject to the authorization and provider restrictions applicable to that information. We use service providers for hosting, database and storage, authentication, mail delivery and receipt, data acquisition, AI processing, payments, analytics, and security. They receive information needed for the relevant feature, under their applicable terms and our arrangements with them. We may also disclose information when legally required or necessary to investigate abuse, protect users, or enforce our terms. This description does not grant a provider permission to use Google or Chrome-helper user data outside the applicable Limited Use requirements.

Section 9.0

Your Choices and Privacy Rights

Depending on your location and applicable law, you may request access, correction, deletion, portability, restriction, or an opt-out from sale or sharing. Use the public Creator Privacy & Data Rights form or contact the privacy office listed on this page. We may verify identity and authority before disclosing or changing information. A verified request can result in catalog-wide restriction or deletion, with minimal request, suppression, and legally necessary records retained to honor the request and prevent inappropriate re-ingestion. You can disconnect a provider account in CollabBase and revoke access in the provider's account settings. Google access can also be revoked using the Google account permissions link below. Disconnecting removes stored connection credentials and stops future authorized access through that connection. For YouTube, disconnecting also removes data retained solely from that authorization and associated diagnostic copies; independently sourced facts and minimized business records may remain. YouTube authorizations are periodically revalidated, and unavailable or expired authorized data is removed under the applicable provider lifecycle rules. Disconnecting does not replace a separate catalog-wide deletion request. Contact us if you want other retained information reviewed for deletion. An ordinary reply asking one business not to contact you creates a non-expiring preference for that sending business; it does not by itself stop unrelated businesses from independently contacting you. A privacy request to CollabBase is a separate way to seek catalog-wide restriction or deletion. Team members can also ask their workspace administrator to remove their access, which does not delete shared workspace records.