Privacy Policy

CreatorTrack ("CreatorTrack", "we", "us") is operated by Wiebelhaus Enterprises LLC, doing business as CreatorTrack.ai. This policy explains what information we collect when you use creatortrack.ai and app.creatortrack.ai (the "Service"), how we use it, and the choices you have.

1. Information we collect

Information you provide

Information from services you connect

CreatorTrack only accesses a connected service after you explicitly authorize it through that provider's consent screen. Depending on what you connect, this can include Google Calendar events, Google Tasks, Google Contacts, Gmail messages, YouTube channel and video data and analytics, and audience or performance data from social platforms such as Instagram, TikTok, or Facebook. You can disconnect any service at any time in Settings.

Information collected automatically

Visitor analytics on public creator pages

When someone visits a creator's public CreatorTrack page (on a creatortrack.ai URL or a connected custom domain), we collect first-party analytics about that visit on the creator's behalf: page views, clicks, funnel and link interactions, coarse approximate location (country/region, and city only in aggregate), parsed device and browser type, and referrer information limited to origin and path. This is a separate system from the in-app product analytics above and from a creator's captured leads described below; the two are never merged.

We do not store raw IP addresses or raw user-agent strings in this analytics system; only derived, coarser values are kept. We honor the browser Global Privacy Control (GPC) signal: if GPC is on, or a visitor otherwise declines tracking, or in strict-consent regions before a choice is made, we still count the visit but drop any identifiers, so it cannot be tied to a returning visitor or a session.

Where a visitor is not opted out, we set a first-party analytics cookie scoped to that creator's page to recognize repeat visits and sessions; it lasts up to 400 days (sessions refresh after 30 minutes of inactivity), and it is not used for advertising or shared across unrelated sites.

This analytics data belongs to the creator's workspace; creators can see aggregated visit and engagement metrics for their own pages, and platform-level detail like precise coordinates or network information is restricted to CreatorTrack administrators.

Lead capture and gated content

If a creator's page asks visitors to submit an email address or other information to unlock gated content or a media kit, that submission is stored with the creator's workspace as a lead, separately from the analytics data above; it never crosses into the analytics system. The creator controls how that information is used, consistent with our Terms of Service, Email Sending Policy, the disclosure shown when the information is collected, and applicable law.

2. How we use information

We do not sell your personal information, and we do not use your content or connected service data for advertising.

For creator-directed audience email, the creator decides the audience and message purpose, while CreatorTrack processes the message on the creator's instructions and independently enforces platform consent, suppression, security, and anti-abuse requirements.

3. Google user data

When you connect a Google account, CreatorTrack requests only the scopes needed for the features you are enabling: Calendar data to display and sync your calendar, Google Tasks to sync tasks, Google Contacts to sync contacts, Gmail access to read and send email you manage inside the Service, and YouTube read-only data and analytics to show channel research and performance metrics. We access this data solely to provide those user-facing features to you.

CreatorTrack's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke CreatorTrack's access to your Google account at any time in Settings inside the Service or at myaccount.google.com/permissions. When you disconnect, we delete the stored tokens for that connection.

4. AI features

Some features use third-party large language model providers to generate suggestions, summaries, or drafts from content you choose to run through them. Content sent to these providers is used only to return the result to you; we do not permit providers to use it to train their models under the API terms we operate on, and we never send connected Google user data to AI providers except when you explicitly invoke an AI feature on that data.

5. How we share information

We share personal information only with:

6. Storage and security

Data is stored on infrastructure operated by us in the United States. All traffic is encrypted in transit with TLS. OAuth refresh tokens for connected services are encrypted at rest with AES-256-GCM and are never exposed to your browser. Access to production systems is restricted and authenticated. No method of transmission or storage is 100% secure, but we work to protect your information with industry-standard safeguards.

7. Retention and deletion

We keep your information while your account is active. Disconnecting a service deletes its stored tokens. You can delete your account yourself from Settings, Account, or ask us to at [email protected]. Deletion takes effect once you confirm it by email: your account is deactivated, you are signed out everywhere, and tokens for connected services are revoked and removed. Your remaining personal information and workspace content, including analytics data tied to your workspaces, are then permanently deleted within 90 days, except where a longer period is required by law or for legitimate security records. During those 90 days you can ask [email protected] to restore your account; after that, deletion is irreversible.

While your account and workspaces are active, visitor analytics event data (described above) is retained for the life of the workspace rather than on a fixed schedule; how much historical detail you can see in your dashboard depends on your plan, but that plan limit controls visibility only, not whether the underlying record still exists. We do not keep this data indefinitely after your account or workspace is deleted: it is removed as part of the deletion process described above.

We may retain a minimal suppression record after an unsubscribe, hard bounce, complaint, or account deletion when needed to prevent an address from being emailed again, protect recipients and sending reputation, or meet a legal obligation. We do not use suppression records to send marketing.

8. Your rights

Depending on where you live, including under Texas and other US state privacy laws and the GDPR, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Exercise any of these by emailing [email protected]. We respond to verified requests within the time required by applicable law and will not discriminate against you for exercising them.

9. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.

10. Changes to this policy

We may update this policy as the Service evolves. If we make material changes, we will notify you by email or an in-app notice before the changes take effect. The effective date above always reflects the current version.

11. Contact

Questions or requests: [email protected], or write to Wiebelhaus Enterprises LLC dba CreatorTrack.ai, 5900 Balcones Dr Ste 100, Austin, TX 78731, USA.

Track your content business.

Bring your tasks, your calendar, your content pipeline, and your deals into one system, connected by AI from day one.