Privacy
How CreatorOS handles personal data, for creators whose profiles we hold and for the brands using the platform.
Last updated Sep 19, 2026
Who we are
CreatorOS operates CreatorOS, a platform where brands find and work with creators. For creator data, we act as the controller when we source profiles and as a processor when a brand uploads their own contacts.
What we hold about creators
- What you give us — name, email, phone, city, category, social handles, portfolio links, and anything you write in an application or message.
- What we read from your public profiles — follower counts, engagement, recent posts and their view counts, from Instagram, TikTok and YouTube.
- What happens on the platform — applications, agreements, deliverables, content you upload, and payouts.
- Sign-in details — a hashed password, or your Google account identifier if you use Google sign-in. We never see your Google password.
Why we're allowed to hold it
If you signed up
Consent, and then contract: you asked to be here, and once you take on campaign work we need your data to run it.
If a brand sourced you
Legitimate interest. Your profile is public and professional, and brands use it to decide whether to approach you about paid work — which is the reason such profiles are public. We only read what is already visible, never anything private, and you can object at any time using the contacts below. If you object, we delete your record and add a one-way hash of your details to a suppression list so you are not sourced again.
Who sees it
- Brands you apply to, or who source you, see your profile, metrics and public work.
- Brands you actually work with also see your agreements, deliverables and payouts with them — never your work with anyone else.
- Our processors: the database and hosting provider, the email provider that sends notifications, and the scraping provider that reads public profiles.
- We never sell personal data, and never share it for advertising.
How long we keep it
Sourced profiles are deleted if nobody contacts you within 24 months. Accounts are kept while they're in use and for 12 months after that. Records tied to money — agreements, invoices, payouts — are kept for as long as tax law requires, usually six years. Suppression hashes are kept indefinitely, because their whole purpose is to keep you off the platform.
Your rights
You can ask for a copy of your data, correct it, delete it, object to our using it, or ask us to stop processing it while a complaint is resolved. Write to privacy@creator-os.com and we'll answer within 30 days. If you're in the UK or EU and unhappy with the answer, you can complain to your data protection authority.
Security and location
Passwords are stored hashed, never in plain text. Sessions use opaque tokens, and we store only their hash, so a copy of our database cannot be used to sign in as you. Data is processed in the EU and the United States under standard contractual clauses.
Cookies
We set one cookie to keep you signed in, and one to remember whether you chose light or dark mode. There is no advertising or cross-site tracking, so there is no consent banner to click through.
Questions about this page? privacy@creator-os.com