Privacy Policy
Last updated: 2026-10-07
Foliocrew is a platform for content creators to publish their portfolio and manage their work with brands. This policy explains what data we process, why, and how you can control it. The data controller is Victor Ruiz (viruizbc@gmail.com).
1. Data we process
- Portfolio visitors: if you use the contact form or request a package, we store your name, brand, email, collaboration type or package, dates and approximate budget (if you add them) and your message.
- Creators using the dashboard: login email and the content they upload (texts, photos, videos, brands, deal notes).
- Connected social media accounts (Instagram, Facebook, TikTok, YouTube), only if the creator chooses to connect them: account ID, username, profile picture, follower count, posts and their metrics (views, likes, comments) and the access tokens issued by each network.
- Agreements with brands: when a brand accepts an agreement online, we store its name, email, date, time and IP address as proof of acceptance, and show it to the creator and the brand.
- Community (only inside the dashboard): the community profile each person chooses to show, their posts, replies, connections and private messages. Private messages are only visible to the two people in the conversation; the team only reviews a message if someone reports it.
- Essential cookies: chosen language and dashboard session. If you arrive through a Foliocrew ambassador's link, we store their invitation code in a cookie for 30 days, only so you can create your account and we know who invited you.
- Waitlist: your email and, if you add them, your name, Instagram handle, niche and audience size, plus the campaign you came from. We use them to let you know when your invitation is ready. Every email includes an unsubscribe link.
- Ad measurement: on the Foliocrew sales page we may use the Meta pixel to learn whether our ads work, only if you accept it in the notice shown there. If you don't accept, or your browser sends the Global Privacy Control signal, the pixel isn't loaded. To change your answer, clear this site's data in your browser. Beyond that we do not use advertising or tracking cookies, and we do not record your session.
2. How we use it
- To display each creator's public portfolio.
- To reply to brands that write through the contact form.
- To show creators, inside their private dashboard, their own metrics and posts, and to help them manage comments, messages and posts on their accounts when they request it.
- To generate AI text suggestions when the creator asks for them.
- Niche intelligence (only if the creator opts in from their dashboard): we use their post metrics, aggregated and anonymized, to work out what performs best in each niche (best times, formats and hook types). Only results from groups of at least 3 accounts are shown, never names, usernames or brands, and creators can opt out at any time. YouTube data is not used for this.
- Ambassador program: if you're an ambassador and turn the option on, your public name, photo, niche and the link to your site (what's already public) appear in the "Ambassadors" section of the Foliocrew page; you can remove yourself any time. For the program we store which accounts signed up with your link, only to count them and give the reward; you see counts, never their names or emails.
- Circles and sessions: your messages in a circle are seen by its members and moderators (who can hide them) and are tied to your community profile. If you book a session, we store your booking and only you receive the call link.
- Phone notices (when active): if you turn them on for a device, we store the address your browser gives us to send you notices and the keys to encrypt them, the notice topics you chose and the browser you turned them on from. Notices go through your browser's notification service (Google, Mozilla, Apple or Microsoft), are short and contain no sensitive data. You can turn them off any time and we delete them if the device stops existing.
- Recycle with AI: the text you paste (or the post you choose) is sent to Claude (Anthropic) only to generate the versions you asked for; we don't keep it in Foliocrew, only the result you choose to save to your content bank.
- Wellbeing: we store your content bank ideas, your rest periods (dates, note and what was moved, so it can be undone) and your workload limit. If you decide to let a brand know about your break, the email is only sent when you send it, with the text you reviewed.
- Automatic publishing (when active): if you turn it on for a post, Foliocrew uses the publishing permission of your Instagram account or Facebook page to publish the text and file you scheduled, at the chosen time, and stores the result (link or error reason). It doesn't publish anything you haven't scheduled.
- Brand reviews: if you write a review, we store your payment outcome, the days, your rating and your comment together with your account identifier, only so there aren't two reviews from you for the same brand and to moderate. Other accounts never see who wrote it, and a brand is only shown with reviews from at least 3 different people. You can delete your review any time.
- Comment → DM (when active): if you create a rule, we store the word and the message, plus the commenter's account id and the comment id only so we don't reply to the same person twice. Only the person who commented gets a reply, and it isn't used for anything else.
- Your business finances: the invoices, income and expenses you record (with the receipt photo if you upload one) are stored in your account so you can view and download them; we don't ask for tax ID numbers or bank details.
- Support and operations: platform administrators may view an account's data to provide support, troubleshoot, prevent abuse and measure use of the service.
We do not sell data or share it with third parties beyond the service providers we need to operate (see section 4). Your account and social media data is not used for advertising.
3. Social media data
We only access accounts the creator connects through each network's official login, and only with the permissions she approves on that screen. We never see her password.
Access tokens are stored encrypted (AES-256) and are never shown on the public site. Retrieved metrics and posts are only visible in the creator's private dashboard, unless she chooses to show them in her portfolio.
YouTube data: Foliocrew uses YouTube API Services. By connecting YouTube you agree to the YouTube Terms of Service (https://www.youtube.com/t/terms), and the Google Privacy Policy (https://policies.google.com/privacy) also applies. Foliocrew's use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. You can revoke access at any time at https://myaccount.google.com/permissions.
4. Service providers
- Vercel (site hosting and file storage).
- Neon (PostgreSQL database).
- Resend (contact form emails, when enabled).
- Anthropic (AI text suggestions; receives the text the creator asks to process and, for niche intelligence, caption excerpts stripped of usernames, links and emails along with their metrics). Anthropic does not use this data to train its models.
- Meta, TikTok and Google (only for the accounts the creator connects).
- Meta (ad measurement pixel on the sales page, only if you accept it).
5. Retention
Data is kept while the creator uses the platform. When a network is disconnected, its tokens are deleted immediately. Contact form messages are kept until the creator deletes them or deletion is requested.
6. Your rights
You can request access to, correction or deletion of your data by writing to viruizbc@gmail.com. We reply within 30 days. Instructions for deleting social media data are on the "Data Deletion" page.
7. Security
We use encrypted connections (HTTPS), encrypted tokens in the database and password-protected dashboard access, with optional two-step verification and a temporary lock after several failed attempts. No system is 100% secure, but we apply reasonable measures to protect your information.
8. Children
Accounts are for people aged 18 or older. The platform is not directed to children under 13 and we do not knowingly collect their data; if we learn that an account belongs to a child under 13, we delete it. If you believe this has happened, write to viruizbc@gmail.com.
9. Changes
If we change this policy, we will update the date on this page.