1. Who this policy applies to
This policy applies when you use the Sponso website, create a Brand or Creator account, participate in campaigns, or connect an external social-media account. Sponso is currently an early-stage service. Privacy questions and data requests can be sent to mtstudio@sponso-app.com.
2. Information Sponso may collect
Depending on how you use Sponso, we may process account details such as your name, email address, selected account role, authentication identifiers and session information; creator or brand profile information; campaign, offer, message, content-review and collaboration records; and technical security information needed to operate the service.
When you voluntarily connect a supported social platform, Sponso may receive provider account identifiers, usernames or handles, display names, profile images, profile links, audience or account statistics, media metadata and performance metrics to the extent that the provider API and permissions you approve make those fields available.
Sponso does not scrape social platforms or infer unavailable audience demographics. If an official provider API does not supply a field, Sponso treats that information as unavailable rather than estimating it.
3. Google and YouTube user data
When a Creator chooses Connect YouTube, Sponso uses Google OAuth to request read-only scopes including https://www.googleapis.com/auth/youtube.readonly and https://www.googleapis.com/auth/yt-analytics.readonly. Sponso may then access the YouTube channel associated with the signed-in Google account, including the immutable channel ID, channel title, handle or custom URL where available, channel image, subscriber/view/video counts where available, uploads-playlist information, metadata or statistics for videos, and aggregate YouTube Analytics reports authorized by the creator.
Aggregate analytics may include recent views, likes, comments, shares, watch time, average view duration, top viewer countries and provider-reported audience age/gender distributions when Google makes those reports available. Sponso stores and displays aggregate report data, not individual viewer identities. Google may suppress demographic or geographic rows when privacy or minimum-data thresholds are not met.
Sponso uses this Google/YouTube data only to provide or improve user-facing Sponso features, including proving control of the connected channel, showing verified creator identity, importing eligible creator-owned media, displaying portfolio evidence and presenting creator-facing or campaign-relevant audience and performance information.
Sponso does not use Google user data for advertising profiles, does not sell Google user data, and does not use Google user data to train generalized AI or machine-learning models. Sponso does not request YouTube permissions to upload, modify or delete videos.
4. OAuth credentials and security
OAuth access and refresh credentials are treated as sensitive server-side credentials. In the current Sponso architecture, supported provider credentials are encrypted before they are persisted. Browser users do not receive direct access to the token-storage table. Sponso also uses role-based access controls and database row-level security for application data.
No internet service can guarantee absolute security. We use reasonable technical and organizational safeguards and continue to harden the platform as it moves toward public launch.
5. Why we process information
We use information to create and secure accounts; provide Brand and Creator workspaces; match, negotiate and manage campaigns; verify social-account ownership; import provider-authorized creator information; prevent duplicate or fraudulent verification; maintain campaign records; provide support; monitor reliability and security; comply with legal obligations; and improve user-facing Sponso functionality.
6. Sharing and service providers
Sponso does not sell personal information. Data may be processed by infrastructure and service providers that help operate Sponso, such as hosting, authentication, database, security and API providers. Today, the Sponso stack includes services such as Vercel and Supabase. A connected platform such as Google/YouTube, TikTok or Instagram also processes information according to its own terms when you use its authorization flow.
Information may also be disclosed where required by law, to protect users or the service, or as part of a future business transaction subject to appropriate safeguards and notice where required.
7. Data retention and deletion
We keep account and campaign information for as long as reasonably necessary to provide Sponso, maintain legitimate business or security records, and meet legal obligations. Connected-platform data is retained only while reasonably needed for the features for which it was collected.
You can revoke Sponso's Google access from your Google Account's connected-app or third-party access settings at any time. Revoking provider access prevents new API access. You can also request deletion of your Sponso account, stored social connection data or other personal information by emailing mtstudio@sponso-app.com. We may retain limited records where legally required or necessary for fraud, security or dispute purposes.
8. Cookies and sessions
Sponso uses essential cookies or equivalent browser storage for authentication, secure sessions, OAuth state validation and core service functionality. These are used to keep users signed in and protect authorization flows. We do not currently describe non-essential advertising cookies as part of the Sponso product.
9. Your rights
Depending on where you live, including in the European Economic Area, you may have rights to access, correct, delete or restrict certain personal data, object to certain processing, receive a portable copy of eligible data, and lodge a complaint with a competent supervisory authority. To exercise a right, contact us at the email above. We may need to verify your identity before completing a request.
10. Google API Services User Data Policy
Sponso's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We request only permissions that are needed for the user-facing connection and verification features described in this policy.
11. Changes to this policy
We may update this policy as Sponso adds features, providers, payments or new legal requirements. Material changes will be reflected by updating the date above and, where appropriate, by additional in-product notice.