Legal

Privacy policy

Last updated July 18, 2026

The short version

Kora (“Kora,” “we,” “us”) is a dashboard for UGC (user-generated content) creators, with a free tier, an optional paid subscription, and an introduction layer between creators and brands. We collect the minimum we need to run that service. If you connect a social account (TikTok, Instagram, or YouTube), we use it only to show you your own content analytics and to show brands the performance of content you explicitly tag to their campaign. We never post, message, or comment on your behalf, we never access anyone else's data, and we never sell your data or use it for advertising. You can disconnect any platform at any time, and we delete your data on request.

1. Information we collect

  • Identity & account. If you create a creator account, your name, email address, phone number, a securely hashed password, and the profile you enter during onboarding (photo, gender, birth year, location, niches, earnings and goals, portfolio links, and any sample videos or portfolio files you upload). If you sign in with Discord instead, your Discord user ID, username, display name, and avatar URL. If you create a brand account, your email address, phone number, a securely hashed password, and the brand profile you enter (company name, logo, social links, website).
  • Subscription & billing. If you subscribe to a paid plan (creator Pro, or a brand listing subscription), our payment processor Stripe handles the payment; we receive your Stripe customer and subscription identifiers, subscription status, and payment events (succeeded or failed). A small number of legacy creator subscriptions are processed by Whop the same way. We never see or store your card details.
  • Connected social accounts (TikTok, Instagram, YouTube): only if you connect them.
    • OAuth access / refresh tokens for the connected account.
    • Your public profile on that platform (handle, display name, avatar, follower/following counts, bio, verification status).
    • Your own posts/videos and their public metrics (views, likes, comments, shares, saves, reach), including periodic snapshots so we can chart growth over time.
  • Brand & campaign data: for brands, the campaigns you create (brief, pay, requirements, optional logo and cover image); for creators, the campaigns you apply to, the deals and payments you track in your own dashboard (including contracts you upload), and the messages exchanged on an application.
  • Usage analytics (first-party only): pages visited on our site, session length, device type, referrer, and a coarsened IP address (last octet removed), linked to your account when you're signed in. We use no third-party analytics or advertising trackers. We also derive an approximate city and region from your IP address at the moment of your visit, using a local database, and store only that approximate location. Your full IP address is never stored. This product includes GeoLite2 data created by MaxMind, available from maxmind.com.
  • Server logs: request timestamps, IP address, path, and user-agent, used for debugging and abuse prevention.

2. How we use it

  • Identify you on the dashboard and provision the features your plan includes.
  • Show you analytics for your own connected content, and power your deal tracker, payments ledger, and tools.
  • Show a brand the performance of the specific content a creator tags to that brand's campaign.
  • Match open brand campaigns with interested creators.
  • Detect abuse, debug, and keep the service secure.

3. Meta / Instagram and TikTok platform data

When you connect Instagram (via the Instagram Graph API / Meta) or TikTok (via TikTok's Login Kit and Display API), we request only the read scopes needed to display analytics: your basic profile and your media together with their insights/metrics. Specifically:

  • We use this data for two purposes only: (a) to show you your own content analytics inside your creator dashboard, and (b) to show a brand the aggregate reach and engagement of content you choose to tag to that brand's campaign.
  • We never publish posts, send or read messages, or manage comments on your behalf. We only read your own public account and media.
  • We never sell this data, share it with data brokers, or use it for advertising or to build profiles about anyone.
  • Connecting one platform does not give us access to any other platform, nor to any other person's account.
  • Our use of Instagram/Meta data complies with the Meta Platform Terms and Developer Policies. Our use of TikTok data complies with TikTok's Developer Terms.

YouTube works the same way: we read only your channel's public statistics and your own videos' public metrics via the YouTube Data API, subject to the Google API Services User Data Policy.

You can disconnect a platform at any time from your dashboard. Disconnecting immediately stops further syncing and revokes the token where the platform supports it; see “Your choices and data deletion” below for what happens to stored data.

4. Who we share with

We do not sell your data and we do not share it with advertisers. We share it only with the service providers below, who process it on our behalf to operate the service:

  • Railway: cloud hosting for our web service and Postgres database, in the United States. This is where all Platform Data is stored.
  • Stripe: payment processing for creator Pro and brand listing subscriptions. Stripe processes payments under its own terms and privacy policy; we exchange only your email and the customer/subscription identifiers and payment status needed to provision your access.
  • Whop: legacy subscription billing for a small number of existing subscribers, under the same minimal exchange.
  • Discord: optional authentication, and, if you link Discord to join our community server, your Discord user ID and the assignment of member roles that reflect your account status.
  • Slack: only for brands that opt into a shared Slack channel with our team — Slack receives the brand's company name and the email addresses invited to the channel.
  • Cloudflare: hosts the tutorial videos in our Learn library. Watching a video loads it from Cloudflare's player, subject to standard access logs on their side; none of your account data is sent to Cloudflare.
  • Anthropic: only if you upload a contract for AI extraction or review, that file is sent to Anthropic's Claude API for that single request. Anthropic does not retain API content for model training under its commercial terms. No social-platform data is sent to Anthropic.
  • Resend: sends transactional email (for example, sign-up verification codes). Receives only an email address and the message content.

Authorized Kora staff can see account and campaign data as needed to operate the service (for example, reviewing brand campaigns and verification requests).

5. Brand campaigns

When a creator applies to a brand campaign, the brand sees the creator's display name and the pitch she provides. After the brand accepts, the two can message inside the portal. A brand sees performance numbers (views, engagement) only for the specific posts or videos the creator chooses to tag to that campaign, or for an account the creator chooses to dedicate to it: never the creator's contact details or her other accounts and content.

6. How long we keep it

  • Creator account + profile data: kept while your account exists; removed when you delete your account (from your profile settings or by request).
  • TikTok / Instagram / YouTube data: kept while the account is connected so your analytics and any campaign performance you tagged stay accurate. When you disconnect, we stop syncing and revoke the token; the stored history is removed on request (and we delete it automatically if you ask us to remove your account). See below.
  • Brand account + campaign data: kept while the account is active; deleted on request.
  • Server logs: retained for 30 days.

7. Your choices and data deletion

You can, at any time:

  • Disconnect a social account (TikTok, Instagram, YouTube, or Whop) from your dashboard. This stops further syncing and revokes the access token where the platform supports it.
  • Delete your account yourself from your profile or brand settings (email confirmation required). This permanently removes your account and its data.
  • Request full deletion of your data or account by emailing hello@koraugc.com with the subject “Data deletion.” We will delete the personal data we hold about you, including any Instagram or TikTok data, within 30 days and confirm when it's done.
  • Request a copy of the data we hold about you at the same address.

If you are in the EU or UK, you also have rights under the GDPR (access, correction, deletion, restriction, portability, and objection). Email us to exercise them.

8. Cookies

We use a single first-party session cookie (set by our authentication library) to keep you signed in. Our first-party usage analytics use browser storage, not cookies, and never leave our infrastructure. No third-party tracking or advertising cookies.

9. Security

Data in transit is encrypted via HTTPS. Data at rest is encrypted on Railway's managed infrastructure. Passwords are stored only as salted hashes. We follow least-privilege access controls. Report any security concern to hello@koraugc.com.

10. International transfers

Our infrastructure runs in the United States. If you access the service from outside the US, your data will be transferred to and processed in the US.

11. Children

The service is not directed to children under 13, and we do not knowingly collect personal information from them. If we learn we have, we will delete it.

12. Changes to this policy

We may update this policy occasionally. Material changes will be reflected by an updated “Last updated” date at the top of this page.

13. Contact

Questions, concerns, or data requests? Email hello@koraugc.com.

See also our Terms of Service.