Legal

Privacy Policy

What we collect, why we collect it, who processes it, and the control you have over it.

Last updated

1. Who we are

Distinct is a platform for running creator marketing: brands manage a creator roster, campaigns, budgets, and results, and creators manage their media kit, links, and brand partnerships.

This policy explains what we collect when you use Distinct, why we collect it, who else processes it, and what control you have over it. It covers our website and the Distinct application.

For anything in this policy, contact us at hello@trydistinct.app.

2. Information we collect

Account information. We use Google sign-in. When you sign in, Google gives us your name, email address, and profile picture. We never see or store your Google password.

Workspace content. Everything you create in the product, including your profile, media kit, link in bio page, brand profile, roster entries, campaigns, deliverables, budgets and rates, tasks, notes, messages, and files you upload.

Public social metrics. If you add a public Instagram or X handle, we retrieve publicly available profile and post metrics for that account, such as follower counts, post counts, and engagement figures. We do not request access to private accounts, direct messages, or your social account credentials.

Connected Instagram account. If you connect an Instagram professional (Business or Creator) account through Instagram Login, Meta gives us an access token and, with your permission, your profile (username, name, profile picture, follower and media counts), your recent posts, reels and stories, and their insights, such as reach, views, likes, comments, shares, and saves. See "Connected Instagram accounts" below.

Waitlist and referral information. If you join the waitlist, we store your email address and, if you were referred, the referral code that brought you.

Technical information. Standard server and security logs generated when you use the site, including IP address, browser and device type, pages requested, and timestamps.

We do not knowingly collect special categories of personal data (such as health, biometric, or precise location data), and you should not put such information into the product.

3. How we use your information

We use the information above to:

  • Provide the product: authenticate you, render your workspace, and save your work.
  • Publish the pages you choose to publish, such as a media kit, link in bio page, brand profile, or campaign recap.
  • Show analytics and campaign results built from the metrics you or your connected accounts supply.
  • Power AI features you invoke, such as drafting messages or matching creators and brands.
  • Operate the waitlist and referral queue.
  • Keep the service secure, debug problems, prevent abuse, and enforce our terms.
  • Reply to you when you contact us.

We do not sell your personal information, and we do not share it with advertisers or data brokers. We do not use your workspace content to train our own models.

5. Pages you choose to make public

Parts of the product are public by design. When you publish a media kit, a link in bio page, a brand profile, or a campaign recap, the content on that page becomes accessible to anyone with the link and can be indexed by search engines and read by AI answer engines. Published profiles also appear in our public creator and brand directories.

Only publish information you are comfortable making public. You can unpublish a page at any time from your dashboard, which removes it from the directories and returns a not-found response at its URL. Search engines and other caches may retain a copy for some time after that, which is outside our control.

A campaign recap is shared through an unguessable link rather than listed publicly, and these pages are marked so that search engines do not index them. Anyone who has the link can still open it, so treat the link itself as the secret.

6. Cookies and local storage

We use a small number of strictly necessary items and nothing else:

  • Authentication. Your signed-in session, set by our authentication provider, so you stay signed in between visits.
  • Account connection. A short-lived security cookie, set only while you connect Instagram, that confirms the connection finishes in the same browser that started it. It expires after 10 minutes.
  • Preferences. Your light or dark theme choice and your sound on or off choice, stored in your browser's local storage and never sent to us.

We do not use advertising cookies, cross-site tracking pixels, or third-party analytics SDKs. Because we set no non-essential cookies, we do not show a cookie consent banner.

7. Service providers we use

We rely on a small set of providers to run the service. Each processes data only to provide their service to us:

  • Supabase: database, authentication, and file storage. Stores your account and workspace content.
  • Vercel: application hosting and content delivery. Processes request and log data.
  • Google: sign-in provider. Confirms your identity and supplies your name, email, and profile picture.
  • Apify: retrieves publicly available metrics from Instagram and X for handles you add.
  • Meta Platforms: provides Instagram Login and the Instagram API, which we call to read the account you connect.
  • DeepSeek: the AI model provider behind our AI features. When you invoke an AI feature, the specific content needed for that request is sent to the model provider server-side and used to return a result to you.

AI requests are made from our servers, never directly from your browser, and only when you invoke a feature that uses them. If you would rather no content be sent to a model provider, do not use the AI features.

8. Connected Instagram accounts

Connecting Instagram is optional and read-only. We request only the permissions needed to read your profile, media, and insights. We never post, comment, or send messages on your behalf, and we never see your Instagram password.

Your Instagram access token is encrypted before it is stored, is readable only by our servers, and is never sent to your browser or included in logs. Imported metrics are visible to you. They appear to others only where you choose to show them, for example in a published media kit with audience stats switched on, or on campaign deliverables you share with a brand.

While connected, we refresh your data about once a day and renew the access token before it expires. If access is revoked or expires, syncing stops until you reconnect.

You can disconnect at any time from Settings. Disconnecting stops syncing and deletes the stored token and the profile, post, and insights data we imported through Instagram Login. Numbers already copied onto campaign deliverables you shared with a brand stay on those deliverables. To also remove our access on Meta's side, open Instagram, go to Settings, then Apps and websites, and remove Distinct.

Removing Distinct from Instagram's Apps and websites settings, or sending a data deletion request through Meta, triggers the same deletion automatically. Meta shows you a confirmation code, and you can check its status on our data deletion page.

9. When we share information

Beyond the providers listed above, we share information only in these situations:

  • With other users, where the product's purpose requires it. For example, a brand you accept a connection with can see your profile and the campaign details you share with them, and a creator you invite can see the campaign you invited them to.
  • Publicly, for pages you have chosen to publish.
  • For legal reasons, where we reasonably believe disclosure is required by law or necessary to protect our rights, our users, or the public.
  • In a business transfer, such as a merger or acquisition, in which case we will give you notice before your information becomes subject to a different policy.

10. How long we keep information

We keep your account and workspace content for as long as your account is active. If you delete your account, we delete or anonymize your personal information within 30 days, except where we must keep it longer to comply with a legal obligation, resolve a dispute, or enforce our agreements.

Backups are retained on a rolling basis and are overwritten in the normal course of operation. Server logs are kept for a limited period for security and debugging.

Waitlist entries are kept until we launch generally or until you ask us to remove yours.

Data imported through Instagram Login is kept while the account stays connected and deleted when you disconnect, remove Distinct from Instagram, or request deletion through Meta.

11. Your rights and choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you and receive a copy of it.
  • Correct information that is inaccurate or incomplete.
  • Delete your account and the personal information associated with it.
  • Export your data in a portable format.
  • Object to or restrict certain processing, and withdraw consent you previously gave.
  • Complain to your local data protection authority.

Much of this is available directly in the product: you can edit your profile and content at any time, unpublish public pages, and delete your account from settings.

For anything else, email hello@trydistinct.app and we will respond within the period required by applicable law, normally within 30 days. We will not discriminate against you for exercising any of these rights.

12. Security

We protect your data with encryption in transit, encryption at rest for stored data, row level access rules that scope every database read to the account that owns the row, and access controls limiting which of our systems and people can reach production data.

No service can promise perfect security. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator as required by law.

13. International transfers

Our providers operate infrastructure in several countries, so your information may be processed outside the country where you live, including in the United States. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses for those transfers.

14. Children

Distinct is a business tool and is not directed at children. You must be at least 18 years old, or the age of majority where you live, to use it. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

15. Changes to this policy

We may update this policy as the product changes. When we do, we will revise the date at the top of this page. If a change materially affects how we handle your personal information, we will give you notice in the product or by email before it takes effect.

16. Contact us

Questions, requests, or complaints about privacy: hello@trydistinct.app.

Terms of Service

This policy covers how we handle your data. The terms cover the rest of the agreement: your account, your content, and what you may do with the service.

Read the Terms of Service