Creator Analytics
Privacy Policy
Last updated: 11 October 2026
What this service is
The Creator Analytics Dashboard reports on how content performs on Facebook, Instagram, YouTube and TikTok for the independent content creators that Creator Analytics works with. Those creators own and run their accounts. The reports are used by the Creator Analytics team and shared with the creators they describe; sign-in is by invitation from Creator Analytics, and there is no public sign-up.
Creator Analytics is a CBLabs Technologies service, operated by CBSoft Company Limited (“we”, “us”), which is responsible for the data described here. You can reach us at bryancastroco@gmail.com.
What we collect
Facebook Pages. When a Page admin connects their Page — by signing in with Facebook and approving the request on Facebook’s own consent screen — we read the following through the Meta Graph API:
- the Page’s name, and whether it is live;
- its posts, videos and livestreams, with their captions, likes, reactions, shares and comment text;
- Page insights, which otherwise only the Page’s admins can see: reach, views, watch time and followers.
We do not read the admin’s personal profile, friends or messages.
Instagram accounts. When a creator connects an Instagram Creator or Business account — by signing in with Instagram and approving the request on Instagram’s own consent screen — we read the following through the Instagram API:
- the account’s username, name, account type and profile picture;
- its follower, following and post counts, and its daily reach and views;
- its posts, reels and carousels, with their captions, likes and comment counts, and their insights: views, reach, saves, shares and total interactions;
- comment text.
Instagram grants comment access only as permission to manage comments; we use it to read comments and never reply to, hide or delete one. We do not read stories or messages.
YouTube channels. A channel’s public data needs no sign-in. Using YouTube API Services, we read:
- the channel’s title, handle, picture and subscriber count, and whether it is live;
- its videos and livestreams, with their view, like and comment counts;
- public comment text.
Granted analytics. If you own a channel and explicitly approve it through Google’s consent screen, we also read your YouTube Analytics reports: watch time, view duration, shares, subscribers gained and lost, and how often your thumbnails are shown and clicked. This access is read-only: we cannot post, edit or manage anything, and we do not request revenue data.
TikTok accounts. When a creator connects their TikTok account — by signing in with TikTok and approving the request on TikTok’s own consent screen — we read the following through the TikTok Display API:
- the account’s display name, username and avatar;
- its follower, following, like and video counts;
- its public videos, with their view, like, comment and share counts.
We read no comment text or messages. This access is read-only: we cannot upload, post, edit or delete anything on the account.
What we deliberately do not keep. Commenter identities — names, profile links, avatars — are discarded before comments are stored. The dashboard shows what was said, never who said it.
How we use and store it
The data produces performance reports for the Creator Analytics team and the creators concerned. Nothing read from TikTok is published on a public website; it appears only in the signed-in dashboard and in our private reporting spreadsheets. Access credentials (Facebook Page tokens, Instagram access tokens, Google refresh tokens and TikTok refresh tokens) are stored encrypted with AES-256-GCM and are never exposed to browsers, spreadsheets or third-party automation.
Data is hosted on Supabase (PostgreSQL) and Vercel. Reports are exported to Google Sheets through our reporting automation (n8n). Comment text is shown only inside the signed-in dashboard; it is not exported and is not sent to any AI model provider.
We do not sell any data, and we do not share it with third parties beyond the processors named above. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Because the dashboard uses YouTube API Services, the YouTube Terms of Service and the Google Privacy Policy also apply.
Your control
A creator can withdraw access at any time from the platform itself: in Facebook or Instagram by removing Creator Analytics from their settings, in TikTok by removing the app, and for YouTube Analytics at myaccount.google.com/permissions. Collection that relied on that access stops at the next attempt. When Instagram tells us an account has removed the app, we destroy its stored credential at once. A YouTube channel’s public data needs no permission, so it is read until the channel is disconnected from the dashboard.
Disconnecting a Page, channel or account from the dashboard stops all further collection for it. To ask about or request deletion of stored data, email bryancastroco@gmail.com. The steps for each platform are set out on our Data Deletion page.
Dashboard accounts
For members of the Creator Analytics team who sign in to the dashboard, we keep an email address, name, position, role and which countries the account may see, together with a record of administrative actions taken. Sign-in itself is handled by Supabase Auth, which keeps its own sign-in records. To have such an account removed, ask a Creator Analytics administrator.