Privacy Policy

Last updated: July 15, 2026

1. Introduction

Candly ("Candly", "we", "us", or "our") is a platform for creating and managing user-generated content, operated by Pixel Creative LLC. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. It applies to our website and application (the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Information we collect

We collect the following categories of information:

  • Account information. When you sign up we collect your name and email address, and authentication identifiers, through our authentication provider (Clerk).
  • Content you create. Brands, projects, briefs, creator details, notes, media you upload, and other data you enter into the Service.
  • Connected Gmail data. If you connect a Gmail account, we access message metadata (headers and snippets) to let you search your inbox and import brand deals. We store only message headers, snippets, and the specific details you choose to import — never full email bodies. See Section 6.
  • Connected social platform data. If you connect a YouTube, TikTok, Instagram, or Facebook account, we access read-only profile and content data — such as your video or post list and its performance statistics — so you can import and track your deliverables. On YouTube this includes videos you have set to private or unlisted, so an unreleased deliverable can still be matched to a project; on the other platforms we see only public posts. We store only the items and metrics you choose to import. See Sections 68.
  • Payment information. Subscription and billing is handled by Stripe. We do not store your full card number; we retain subscription status and identifiers needed to manage your plan.
  • Usage and device data. Log data such as IP address, browser type, pages viewed, and timestamps, collected automatically to operate and secure the Service.

3. How we use your information

  • Provide, maintain, and improve the Service.
  • Authenticate you and secure your account.
  • Process payments and manage your subscription through Stripe.
  • Search your connected inbox and suggest brand-deal imports at your request.
  • Import and track deliverables from social platforms you connect, at your request.
  • Communicate with you about the Service, including transactional and support messages.
  • Detect, prevent, and address fraud, abuse, and security issues.
  • Comply with legal obligations.

4. How your information is processed by AI

When you use the email import feature, message content from your connected inbox is processed by Google's Gemini API solely to suggest brand-deal imports. When you use the optional portfolio writing assistant, the profile and project details you have already entered are processed by the same API solely to draft the text you asked for. Both happen only at your request, on the specific item you act on — we do not process your data in the background.

We do not use your content to train AI models, and our AI providers are contractually bound not to train their models on your data. In particular, information obtained through Google Workspace APIs is not used to develop, improve, or train generalized AI and/or ML models.

5. How we share information

We do not sell your personal information. We share it only with:

  • Service providers (sub-processors) who process data on our behalf: Clerk (authentication), Stripe (payments), Cloudflare (hosting, database, and object storage), and Google (AI processing via the Gemini API).
  • Connected platforms (at your election). When you choose to connect an account, we exchange data with that platform to provide the integration: Google (Gmail and YouTube), TikTok, and Meta (Instagram and Facebook). We access these platforms only after you authorize them and only to the extent needed to provide the features you use.
  • Legal and safety. When required by law, or to protect the rights, property, or safety of Candly, our users, or the public.
  • Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this policy.

6. Google services (Gmail and YouTube)

Candly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This applies to every Google scope we request, including Gmail and YouTube. We do not use Google data for advertising, do not sell it, do not use it to train AI models, and do not transfer it to others except as needed to provide the feature you enabled (see Section 5) or as required by law.

You can revoke Candly's access to your Google account at any time from your Google Account permissions page, or by disconnecting the integration in your Candly settings.

Gmail. The Gmail integration is not currently available to creators, so no Candly account can connect a Gmail account today. The terms below describe how we would handle Gmail data, and bind us if and when the integration is switched on.

  • We request read-only access to your Gmail (the gmail.readonly scope) only to let you search your inbox and import brand deals.
  • We store only message headers, snippets, and the details you choose to import — never full email bodies.
  • Disconnecting Gmail revokes our access at Google and deletes non-imported data associated with the connection.

YouTube. Our use of YouTube data is additionally governed by the YouTube API Services Terms of Service and the Google Privacy Policy.

  • If you connect a YouTube channel, we request read-only access to your channel profile and your video list, including videos you have set to private or unlisted, so that deliverables you have posted can be matched to a project automatically instead of typed by hand. We never upload, edit, or delete anything on your channel.
  • We do not request access to YouTube Analytics, and we do not read private analytics such as watch time, revenue, or audience demographics. The views, likes, and comments shown next to a deliverable are the public counts YouTube publishes for that video, read with our own API key — the same figures any viewer of the video can see.
  • We store only the videos you choose to import. Public counts are read on demand when you view a project and are shown only to you and to the brand you choose to share a deliverable with.
  • Disconnecting YouTube revokes our access and deletes non-imported YouTube data associated with the connection. You can also revoke access from your Google Account permissions page.

7. TikTok data

If you connect a TikTok account, we access a limited, read-only set of data through TikTok's Login Kit and Display API so you can import and track your deliverables. Our use of TikTok data follows the TikTok Developer terms and platform policies.

  • We access your basic profile information (such as display name, avatar, and profile link) and your public video list with its performance statistics (such as view, like, comment, and share counts).
  • We store only the videos and metrics you choose to import, and we refresh imported statistics only while the connection is active.
  • We do not use TikTok data for advertising, do not sell it, and do not use it to train AI models.
  • You can disconnect TikTok at any time from your Candly integration settings, which revokes our access and deletes non-imported TikTok data associated with the connection. You can also revoke access from your TikTok settings under Security & permissions → Manage app permissions.

8. Meta data (Instagram and Facebook)

If you connect an Instagram or Facebook account, we access a limited, read-only set of data through the Meta (Instagram and Facebook) APIs so you can import and track your deliverables. Connecting these accounts requires an Instagram or Facebook Professional (Business or Creator) account. Our use of Meta data follows the Meta Platform Terms and Developer Policies.

  • We access your professional profile, your media (such as posts and reels), their insights (such as reach, impressions, and engagement), and connected Facebook Page data, so you can import and track your deliverables.
  • We store only the items and metrics you choose to import, and we refresh imported insights only while the connection is active.
  • We do not use Meta data for advertising, do not sell it, and do not use it to train AI models.
  • You can disconnect Meta at any time from your Candly integration settings, which revokes our access and deletes non-imported Meta data associated with the connection. You can also remove Candly from your Facebook Business Integrations settings or your Instagram Apps and Websites settings. Removing Candly this way triggers our data-deletion process automatically; you can also request it directly on our data-deletion page.

9. Data retention and deletion

We retain your information for as long as your account is active or as needed to provide the Service. You may delete content within the app, disconnect integrations, or delete your account entirely (see Section 10). When you disconnect an integration, pending suggestions and non-imported data from that connection are deleted while brands, projects, and deliverables you have already imported are kept. We may retain limited information as required for legal, tax, or security purposes.

10. How to delete your data

You can permanently delete your account and all associated data at any time, directly from the app:

  • Sign in, open the account menu (top right), go to Account → Danger zone, then choose Delete account and confirm.
  • This permanently removes your brands, projects, deliverables, your portfolio and any media you uploaded, your connected integrations, and imported emails and platform content.
  • As part of deletion we revoke access to any connected platforms (including your Google, TikTok, and Meta authorizations) and cancel your subscription.
  • Your authentication identity is removed, so you will be signed out and the account can no longer be used.

Deletion is immediate and cannot be undone. If you are unable to access your account, contact us at privacy@pixelcreative.io and we will delete your data on your behalf. We may retain limited information as required for legal, tax, or security purposes.

11. Data security

We use technical and organizational measures to protect your information, including encryption in transit, encryption of stored OAuth tokens, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise these rights, contact us using the details below. We will respond consistent with applicable law.

13. Cookies

We use cookies and similar technologies that are necessary to operate the Service, such as keeping you signed in. We do not use non-essential advertising cookies.

14. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, please contact us and we will delete it.

15. International users

We operate the Service from the United States and may process your information there and in other countries where our service providers operate. By using the Service, you consent to such transfers.

16. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice. Your continued use of the Service after an update constitutes acceptance of the revised policy.

17. Contact us

If you have questions about this Privacy Policy or our data practices, contact Pixel Creative LLC at privacy@pixelcreative.io.