← Back to Settings

Privacy Policy

Last updated: July 2026

CreatorBase is operated by Nikolaos Giannakopoulos, a sole proprietor based in Greece (“CreatorBase”, “we”, “our”, “us”). We are the data controller for personal data processed through the CreatorBase application at creatorbase.cc (the “Service”). This Privacy Policy explains what we collect, why, who we share it with, how long we keep it, and your rights. It also describes, in dedicated sections below, exactly how CreatorBase handles Google user data obtained through YouTube OAuth.

Categories of personal data and purposes

  • Account data (name, email, avatar, login credentials via Google) — to create and secure your account. Legal basis: performance of contract.
  • Workspace content (projects, notes, link hubs, finance entries, livestream configuration) — to provide the Service. Legal basis: performance of contract.
  • Connected-channel data (YouTube channel metadata, videos, analytics, live chat and gift events) — to power the features you enable. Legal basis: performance of contract and your explicit consent at the OAuth screen.
  • Usage and device data (IP address, browser, basic telemetry, error logs) — for security, fraud prevention, and improving the Service. Legal basis: legitimate interests.
  • Support messages — to answer your questions. Legal basis: legitimate interests.
  • Billing metadata (subscription status, plan, renewal dates) — to provide paid features. Payment card details are collected and processed directly by Paddle, not by us.

Legal basis

We rely on performance of contract to provide the Service, your consent for optional integrations and scopes (such as YouTube monetary analytics), legitimate interests for security and product improvement, and legal obligation where the law requires us to retain records (for example, tax records via our Merchant of Record).

1. Information we collect

When you create an account we collect your name, email address, and basic profile information. When you connect a third-party account (for example a YouTube channel via Google OAuth) we receive OAuth tokens and channel data limited to the scopes you authorize. We also store application data you create inside CreatorBase (workspaces, notes, link hubs, livestream sessions, etc.).

2. How we use your information

We use your data to provide the CreatorBase workspace — displaying analytics, syncing content, powering livestream tooling, and enabling collaboration with your team. We do not sell your personal data and we do not use it for advertising.

3. Google User Data — Access and Use

CreatorBase accesses Google/YouTube data only after you explicitly grant consent through Google’s OAuth screen. The OAuth scopes CreatorBase currently requests are:

  • https://www.googleapis.com/auth/youtube.readonly — read-only access to your YouTube account: channel metadata, uploaded videos, playlists, live broadcasts, and live chat messages during your streams.
  • https://www.googleapis.com/auth/yt-analytics.readonly — read-only access to your YouTube Analytics reports (views, watch time, subscribers, traffic sources, audience metrics).
  • https://www.googleapis.com/auth/yt-analytics-monetary.readonly — read-only access to your YouTube monetary analytics (estimated revenue, RPM, CPM). This scope is optional and only used when you enable revenue analytics.

CreatorBase uses Google user data exclusively to power features you have asked for inside your workspace: displaying your channel analytics, listing your videos and live broadcasts, ingesting live chat and gift events during your livestreams, calculating creator scores and leaderboards, and letting you feature YouTube content in your Link Hub. CreatorBase does not use Google user data to train generalized AI/ML models, and does not use it for advertising or resale.

CreatorBase’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Sharing, Transfer and Disclosure of Google User Data

CreatorBase does not sell Google user data. CreatorBase does not share Google user data with advertisers, data brokers, or third parties for advertising or marketing purposes. CreatorBase does not use Google user data to train generalized machine-learning models.

Google user data is processed by CreatorBase on your behalf and is only disclosed to the following categories of service providers, strictly as infrastructure processors required to operate the Service:

  • Lovable Cloud (Supabase) — hosts our application database and authentication. Your account data, workspace content, and cached YouTube metadata are stored here under row-level security.
  • Nango — OAuth token vault. Google OAuth refresh and access tokens are stored and refreshed by Nango on our behalf so that raw tokens do not sit in our application database.
  • Cloudflare — serves the CreatorBase web application and edge/serverless functions that make API calls to Google on your behalf.
  • Fly.io — runs the livestream ingestion worker that polls YouTube Live Chat while your broadcasts are active.
  • Paddle — our payment provider and Merchant of Record for all CreatorBase subscriptions. Paddle receives billing, contact, device, and transaction data needed to sell the subscription, process payment, manage renewals, calculate and remit sales tax, issue invoices, and handle refunds. See Paddle’s Privacy Notice.
  • Professional advisers and authorities — legal, accounting, and regulatory recipients where required by law.

We may also disclose data (a) when you explicitly direct us to (for example, inviting a teammate into your workspace, in which case that teammate can see the channel data shared into the workspace), (b) to comply with a valid legal obligation, or (c) to protect the rights, safety, or property of CreatorBase, our users, or the public.

5. Data Security and Protection

CreatorBase implements the following technical and organizational measures to protect your data, including Google user data and OAuth credentials:

  • Encryption in transit. All traffic between your browser, CreatorBase, Google APIs, and our infrastructure providers is encrypted with TLS (HTTPS).
  • Encryption at rest. Data stored in our database and token vault is encrypted at rest by the underlying managed infrastructure providers (Supabase/Lovable Cloud and Nango).
  • OAuth token isolation. Google OAuth refresh tokens are stored in Nango’s token vault, not in our application database. Access tokens are fetched on demand server-side and are never sent to the browser.
  • Server-only credential handling. All Google API calls are executed by server-side functions and the ingestion worker. Google user data is never exposed to third-party client-side scripts.
  • Row-level security. Database access is enforced by per-row authorization policies so that each account can only read and write its own workspace data.
  • Least-privilege scopes. CreatorBase requests only the YouTube scopes required for the features you use, and the monetary revenue scope is optional.
  • Signed internal requests. Communication between our ingestion worker and our API is authenticated with HMAC-signed requests.
  • Restricted operator access. Only a limited number of CreatorBase operators can access production systems, and secrets (including provider credentials) are stored in a managed secrets store, not in source code.

6. Data Retention and Deletion

We retain Google user data only for as long as it is needed to provide the Service:

  • OAuth tokens are retained while the YouTube channel is connected to your CreatorBase workspace. When you disconnect the channel, we revoke the connection with our OAuth provider and delete the associated tokens.
  • Cached channel data (videos, analytics snapshots, livestream events) is retained while your account and connection are active and is deleted when you disconnect the channel or delete your account.
  • Account deletion. You can delete your CreatorBase account at any time from Settings, or by emailing support@creatorbase.cc. Upon deletion we remove your account, workspace content, and stored Google user data within 30 days, except where we are legally required to retain limited records.

7. Revoking CreatorBase’s access to your Google Account

You can disconnect a YouTube channel from CreatorBase at any time from Settings → Connections; this removes CreatorBase’s stored tokens for that channel.

You can also revoke CreatorBase’s access directly from your Google Account at any time by visiting https://myaccount.google.com/permissions and removing “CreatorBase” from the list of apps with account access. Revoking access through Google immediately invalidates the tokens CreatorBase holds for that connection.

8. International transfers

CreatorBase and its infrastructure providers may process data in countries other than your own. Where required, we rely on appropriate safeguards offered by our providers (such as standard contractual clauses) for international data transfers.

9. Your rights

Under the EU/UK GDPR and Greek data-protection law you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time. You can exercise most of these rights directly in Settings or by emailing support@creatorbase.cc. We aim to respond within one month. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) or your local supervisory authority.

10. Cookies

CreatorBase uses strictly necessary cookies and local storage for authentication, session management, and preferences (such as your selected currency and theme). We do not use advertising or cross-site tracking cookies. Paddle may set cookies on its own checkout pages as described in its privacy notice.

9. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you inside the application.

10. Contact

Questions or data requests? Email support@creatorbase.cc.