Last updated October 5, 2026
Privacy Policy
This page describes what CreatorGrowth stores, including public channel information from YouTube API Services, what the connected mailbox is used for, and how to export or delete a workspace.
Contact us
Questions about this policy or your information can be sent to support@creatorgrowth.app.
Who we are
CreatorGrowth is a workspace for businesses that want to find partners and send outreach from their own mailbox. Each workspace is kept separate. One customer’s records are not shown to another.
Children
CreatorGrowth is not for anyone under 18. We do not knowingly collect information from children.
YouTube
When a campaign includes YouTube, CreatorGrowth uses YouTube API Services to look up public channel information. That lookup uses CreatorGrowth’s access to YouTube. It does not ask you to sign in with a YouTube account, and it does not read watch history, private analytics, or private videos.
The public fields that may be saved are the channel id, title, handle, description, subscriber count, average view count of recent public videos, country, topics or keywords taken from the public text, and an email address only when that address is written in the channel description or on a public page the channel links to. An address that is not written there is not guessed. A count YouTube did not return is left blank. Notes about a campaign, outreach status, and which campaign a channel belongs to stay in that business’s workspace. They are not stored in the shared copy of those public fields.
Saved YouTube API data is refreshed when that channel is looked up again. If it is not refreshed, it is deleted within 30 days. Results of a repeated public search are kept for a shorter time and are also deleted within 30 days.
YouTube discovery does not connect your YouTube account, so there is no YouTube permission to revoke for that lookup. If you connected a Gmail mailbox, you can disconnect it in Settings. You can also remove CreatorGrowth from your Google Account permissions. Deleting a workspace removes that business’s creator records, campaigns, and messages. It does not remove public channel facts kept in the shared lookup cache. You can ask for that cached public channel data to be deleted by email. The workspace owner can download or delete the workspace from Settings.
YouTube API data is not sold. How Google handles information is described in the Google Privacy Policy. Use of YouTube is also subject to the YouTube Terms of Service.
The mailbox you connect
A business connects its own Gmail or Microsoft mailbox. CreatorGrowth does not ask for the mailbox password. Google access is used to send mail and to read replies. Microsoft access is used to read and send mail.
Sending uses the connected mailbox, so outreach comes from that account. Reading is used to collect replies in the thread, including the message body, so the product can recognize opt-outs, declines, and quotes. The mailbox connection is encrypted and stays on our systems. It is not shown in the workspace and is left out of the data download.
Gmail data is not used for ads or to train AI models.
Stripe
Stripe is connected for each workspace, for revenue attribution only. CreatorGrowth checks the secret key with Stripe when you connect and does not keep that key. A separate encrypted secret is used only to confirm that payment notices came from Stripe. Disconnecting Stripe clears that secret and changes the address Stripe uses to reach us. Payments, refunds, and payouts stay in Stripe.
AI message generation
AI message generation uses a message service chosen for this installation. That service receives the business context and the draft or reply text needed for that task. It does not receive mailbox connections or Stripe secrets. CreatorGrowth does not use customer mail to train its own models. In practice mode, sample plans are labeled as samples and are not presented as a live result.
What we store
A workspace can hold a business profile, partner and creator records, campaigns, outreach messages, replies, a do-not-email list, deals, attribution events, recommendations, automation rules, and a record of actions taken in the product. Passwords are stored in a form that cannot be turned back into the password. Sign-in cookies are random values; we store only a scrambled form of the cookie.
Unsubscribe and other reasons not to email an address are stored for that workspace so the address is not emailed again. There is no button that removes someone from that list and restarts outreach.
How long data is kept
Expired sign-in sessions, expired mailbox connection attempts, and expired request counters are deleted. Short-lived records used to ignore duplicate public tracking clicks are deleted after two days.
Stripe event details are kept for 30 days, then reduced to the minimum needed for attribution. Payment references already saved for those results stay so they can still be reconciled.
Mailbox connections and the rest of the workspace stay until you disconnect the mailbox or delete the workspace.
Unsubscribe
Outreach mail includes a plain-language line that tells the recipient they can reply “unsubscribe” and we will stop. Live mail also includes an unsubscribe link. Opening that link, or using the one-click unsubscribe action, adds the address to the do-not-email list, blocks the contact, and cancels queued follow-ups for that address.
Replying with a request to stop is handled the same way. An address on that list is not added to a new send.
Security
Mailbox connections and payment secrets are encrypted. Access to customer information is limited to what the product needs to run the workspace.
Your rights
You can ask for access, a correction, or deletion by email. The workspace owner can also download a copy of the workspace, or delete it, from Settings.
Download your data
The workspace owner can download a copy of the workspace from Settings. The file includes that workspace only. Mailbox connections, passwords, sign-in secrets, and Stripe secrets are left out. Downloads are limited so the file cannot be requested too often.
Delete an account
The workspace owner can delete the workspace from Settings. The confirmation step asks for the account password or the exact workspace name. Deletion stops queued and in-progress work for that workspace, turns sending off, and disconnects the Google mailbox when the product is sending real email. Stored mailbox connections are then deleted. The rest of the workspace is deleted. Sign-in sessions for that workspace are ended. A short record is kept of when a workspace was deleted. That record does not include a name, email address, or message content.
A person who is not the owner can delete only their own sign-in, after entering their password, when another member remains. That does not delete the workspace.
Addresses that opted out, or that hard-bounced, on live mail are not kept as readable text after the workspace is deleted. Each address is stored only as a one-way hash of the email, together with the reason it was blocked and the time it was kept, plus a one-way hash of that business’s login email or sending mailbox. CreatorGrowth cannot turn the hash back into the address. The hash exists so that business cannot import the address again and email it. It does not apply to a different business. It is not used for advertising.
Cookies and sharing
The product sets a sign-in cookie so you stay signed in. It is not used as an advertising identifier.
We share data with the providers you connect: Google or Microsoft, for the mailbox you authorize; Stripe, for attribution events you connect; and the message service used for drafting and classification. Public YouTube channel lookups use YouTube API Services, described above. We do not sell personal information.
Changes to this policy
If this policy changes, the date at the top of this page changes with it. This policy was last updated on October 5, 2026.
See also the Terms of Service.