Draft for review. This page is placeholder copy and is not yet final.
Privacy policy
Last updated 8 October 2026
This policy explains what Creator Kitchen ("we") collects, why, how long we keep it and how you can delete it. Creator Kitchen is run by Creator Kitchen. Contact us at hello@creator.kitchen.
The short version
- We read your Instagram content and numbers so our AI coach can give you advice about your own account.
- We never post for you, never read or send DMs, and never sell your data.
- You can disconnect Instagram and delete everything at any time.
What we collect
When you sign in
Your name, email address and profile picture from Google, used to create and secure your account.
When you connect Instagram
Using Instagram's official API, and only with your permission, we read:
- Account basics: username, name, profile picture, follower count, number of posts and account type.
- Your posts: captions, media type, links, dates, thumbnails, and like and comment counts.
- Comments on your posts: the text, date and like count.
- Insights for your posts and account, such as reach, views, saves and shares, and audience information where Instagram makes it available.
- Video files for your own voice-led videos, where Instagram makes the file available, so we can transcribe what you say.
What you add
Ideas, scripts, captions, notes, links you save, videos you upload, and your answers to your coach's questions.
How you use the product
We use product analytics (PostHog) to see which features are used, and error tracking (Sentry) to fix bugs. Session recordings mask everything you type and all of your content.
Why we use it
- To build your creator profile and give you coaching based on your own content and numbers.
- To show you analytics and patterns about your posts.
- To run your account, billing and support.
- To improve the product.
AI model providers
To generate coaching, transcripts and summaries, we send the parts of your data that a task needs to AI model providers. We only use providers that do not train their models on data sent through their API.
TODO before publishing: list each provider by name with a link to its data policy.
Who else processes your data
- Supabase (database and file storage, United States)
- Vercel (hosting)
- Stripe (payments; we never see your full card number)
- PostHog (product analytics)
- Sentry (error tracking)
- An email provider for trial and billing emails
- Airtable (beta access requests only: name, email, Instagram handle, follower range, niche)
How long we keep it
- While your account is open, we keep your data so your coach can keep learning about your content.
- If you disconnect Instagram, we stop collecting new Instagram data straight away.
- If you delete your account, we permanently delete your data within 30 days.
- Billing records are kept as long as the law requires.
Your choices and rights
- Correct anything your coach has inferred about you, from your Profile page.
- Export your data as a file from Settings.
- Delete your account and data from Settings. See data deletion.
- Email us to ask what we hold about you.
Security
Instagram access tokens are encrypted and only ever used on our servers. Every table in our database is locked so each person can only reach their own data.
Changes
If we change this policy in a way that matters, we'll tell you in the app before it takes effect.