Privacy Policy
Last updated 6 October 2026
This policy explains what Made Boring Campaigns collects, why we collect it, who we share it with, and how you can get it deleted. It covers both the campaign management application and any social accounts you choose to connect.
Who we are
Made Boring Campaigns is an influencer campaign management platform operated by Made Boring. Agencies, record labels, and brands use it to run creator campaigns — briefing creators, tracking published posts, and recording payouts. You can reach us at prathamsharma7711@gmail.com.
What we collect
- Account data— your name, email address, hashed password, and the organisation you belong to.
- Campaign data— campaigns, briefs, budgets, deliverables, creator records, client records, and payout amounts that you or your team enter.
- Connected platform data— when a creator connects a social account, the profile, posts and post insights described in the next section.
- Public profile data— for creators an organisation adds to its roster or tracker, the numbers their public profile shows to anyone. See Creators who have not connected an account.
- Technical data— server logs containing IP address, browser user agent, and timestamps, kept for security and debugging.
We do not collect payment card details. We do not buy personal data from third parties, and we do not use your data to train machine learning models.
Connected social accounts
Connecting a social account is always optional and always initiated by the account holder through that platform’s own consent screen. We request the narrowest permissions that make the feature work, we never post on your behalf, and we never read direct messages.
- TikTok — with the
user.info.basicpermission we read the account’s open ID, display name, and avatar. Withuser.info.profilewe read the profile link, bio description, and verification status. Withuser.info.statswe read the follower, following, and likes counts, which is how campaign fees are agreed against audience size. Withvideo.listwe read the account’s public videos and their view, like, comment, and share counts. This is shown only to the campaign manager in the organisation that added that creator, on that organisation’s campaign dashboard, and to the creator in their own creator portal. We do not access private or unpublished videos, we do not read direct messages, and we do not post, edit, or delete content. - Instagram— a professional (Business or Creator) account can be connected in either of two ways.
- Through Facebook Login, via the Facebook Page the Instagram account is linked to. With
pages_show_listandpages_read_engagementwe find the Page and the Instagram account linked to it. Withinstagram_basicwe read the username, name, bio, profile picture, follower, following and post counts, and recent posts (caption, link, image, date, likes and comments). Withinstagram_manage_insightswe read views and shares on recent posts, and reach, views, shares and saves on the posts the creator submits to a campaign. - Through Instagram Login, with no Facebook Page needed. With
instagram_business_basicwe read the same profile fields and recent posts, and withinstagram_business_manage_insightsthe views, reach and shares on recent posts.
- Through Facebook Login, via the Facebook Page the Instagram account is linked to. With
- Facebook Pages — with
pages_show_listwe list the Pages you manage so you can choose one. Withpages_read_engagementwe read that Page’s name, username, link, about text, picture, follower count and verified status, and its recent posts with their text, date, link, picture, and like, comment and share counts. Withpages_read_user_contentwe read the comments left on those posts: the comment, its date, its likes and the commenter’s name. Withread_insightswe read how many views each post got. - Threads — with
threads_basicwe read the username, name, profile picture and bio, and recent posts (text, link, media and date). Withthreads_manage_insightswe read views, likes, replies, reposts and quotes on those posts, and the follower count. - YouTube — with
youtube.readonlywe read the connected channel’s name, handle, picture and description, its subscriber, view and video counts, and its recent videos with their title, date, views, likes and comments.
We do not read audience demographics from any platform. The creator portal’s My accounts screen lists the same reads, permission by permission, beside each Connect button.
Access tokens are encrypted at rest with AES-256-GCM and are never exposed to other organisations. Revoking access in the platform’s own settings, or disconnecting the account inside Made Boring Campaigns, stops all further collection immediately.
Creators who have not connected an account
An organisation using Made Boring Campaigns can add a creator to its roster or tracker without that creator connecting anything. For those creators we read only what their profile shows to anyone, and only on the platforms below:
- Instagram— through Meta’s Business Discovery API, which answers for Business and Creator accounts only: the username, follower and post counts, profile picture, and recent public posts with their public view, like and comment counts. Personal and private accounts return nothing.
- YouTube— through the YouTube Data API: the channel’s public name, picture and subscriber count, and the public statistics of its recent videos.
- TikTok— from the public profile page: the follower count and the public counts on recent videos.
We also read the public numbers on individual post links that a creator or an organisation submits to a campaign. These readings are shown only to the organisation that added the creator, and to the creator if they sign up to the creator portal. A creator who wants them removed can email prathamsharma7711@gmail.com; see Data deletion.
TikTok data handling
Data obtained through TikTok is used solely to display and report on campaign performance to the organisation that the connected creator is working with. We do not sell it, we do not share it with advertising networks, and we do not combine it with data from other creators to build profiles.
You can disconnect a TikTok account at any time from the My accounts screen inside Made Boring Campaigns, or by revoking access in your TikTok account settings. On disconnection we revoke the token with TikTok, delete the stored access and refresh tokens immediately, and stop all further collection. Previously collected post metrics can be deleted on request to prathamsharma7711@gmail.com.
TikTok’s own handling of your information is described in the TikTok Privacy Policy.
YouTube API Services
Made Boring Campaigns uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service. Google’s handling of your information is described in the Google Privacy Policy. You can revoke Made Boring Campaigns’s access to your Google account at any time via Google security settings.
Made Boring Campaigns’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use data from a connected YouTube channel only to show its numbers to the creator and to the organisations running their campaigns. We do not sell it, and we do not use it for advertising.
How we use your data
We use it to operate the product you asked for: authenticating you, showing your campaigns, pulling the post metrics that populate campaign reporting, recording payouts, and sending service email about your account. We do not use it for advertising.
Who we share it with
We share data only with the infrastructure providers needed to run the service — our hosting provider and our managed database provider — with the social platforms you explicitly connect, and, for a creator who connects an account, with the organisations running a campaign that creator joined, as shown on the connect screen. We do not sell personal data. We disclose data to authorities only where legally compelled.
Cookies and storage on your device
Made Boring Campaigns stores a small amount of information in your browser. Cookies keep you signed in to the agency app and to the creator portal. Short-lived cookies protect the connection flow while you connect a social account, and expire when it finishes. Your browser’s local storage remembers display preferences, such as the colour theme, the sidebar state and when you last opened notifications.
We do not use advertising or analytics cookies, and we do not allow third parties to place cookies on, or collect information from, your device through Made Boring Campaigns. Our server logs record your IP address and browser type for security, and are kept for up to 90 days.
How long we keep it
Account and campaign data is kept while your organisation has an active account. Connected platform tokens are deleted on disconnection. For a connected YouTube channel, we refresh its statistics at least every 30 days, delete its tokens on disconnection, and delete its YouTube data within 7 days of a deletion request. Server logs are retained for up to 90 days. On account closure we delete your data within 30 days, except where we are required to retain records for legal or accounting reasons.
Your rights
You can request a copy of your data, correction of inaccurate data, or deletion of your data by emailing prathamsharma7711@gmail.com. We respond within 30 days. We delete YouTube data within 7 days of your request. Deleting data here does not affect anything stored on YouTube; to delete videos or your channel, use YouTube. If a creator wants their connected-account data removed, they can email us directly and do not need to go through the agency.
A creator with a portal login can also do it themselves: Disconnect on the My accounts screen deletes that account’s stored access straight away, and Delete my account and data on the Account screen deletes the login and every connected account. Removing Made Boring Campaigns from Facebook, Instagram or Threads settings sends us a deletion request that deletes the linked account the moment it arrives. All three routes are described on the Data deletion page.
Security
Traffic is served over TLS. Passwords are hashed. Platform access tokens are encrypted at rest with AES-256-GCM. Access is scoped per organisation, and every query is filtered by organisation so one customer cannot read another’s data.
Children
Made Boring Campaigns is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.
Changes
If we change this policy we will update the date at the top of this page and, for material changes, notify account owners by email.