Platform Data Use Policy

Last updated: August 5, 2026

This page is maintained by MarketPilot AI to explain how insights, analytics and creator data obtained through official platform APIs are used inside MarketPilot. It describes our own practices; it is not an independent audit or certification.

1. Scope

This policy covers data MarketPilot accesses through official provider APIs on behalf of an authenticated business user, including Meta (Facebook Pages, Instagram Professional accounts, Instagram Creator/Business Discovery, Ads and Insights), Google, LinkedIn, TikTok, Pinterest, X, Threads, WhatsApp and Reddit. It supplements our Privacy Policy and Terms & Conditions.

2. Permitted purposes

Insights and creator data are used solely to deliver features the connected business user has explicitly requested inside their own workspace:

  • Displaying performance analytics for accounts the user owns or administers.
  • Creator discovery and evaluation: showing public profile information (name, username, profile picture, biography, follower count, media and aggregate engagement) so a brand can decide whether to contact a creator for a partnership.
  • Outreach, briefs, contracts and campaign tracking for creator collaborations.
  • Publishing, scheduling, moderation and inbox management for connected accounts.
  • Generating reports and recommendations for the connected business user.

3. Prohibited uses

MarketPilot does not, and will not:

  • Sell, license, rent or broker platform data, or share it with data brokers or ad networks.
  • Train, fine-tune or evaluate AI/ML models on platform content, insights or metadata.
  • Build cross-platform profiles of individuals for surveillance or re-identification.
  • Use platform data for eligibility decisions (credit, employment, insurance, housing, education) or for law-enforcement purposes.
  • Enable vote manipulation, artificial engagement, scraping outside official APIs, or spam.
  • Show one customer's connected-account data to another customer.

4. Creator discovery on Meta (how it works in MarketPilot)

Creator discovery runs entirely through Meta's official endpoints, using the connected business's own Page/Instagram Professional token with least-privilege scopes. We do not scrape, and we do not present invented statistics.

  1. A user opens Collaborate → Discover influencers and searches by handle, niche, platform or location.
  2. MarketPilot calls Meta server-side (Business Discovery for Instagram Professional accounts, Page lookups for Facebook) and returns only fields Meta exposes for that account: name, username, profile picture, biography, follower count, media count and recent public media with their aggregate like/comment counts.
  3. Derived figures (for example “estimated reach per post”) are computed from those returned metrics and are labelled as estimates in the interface.
  4. The user opens the creator profile, reviews the insights, and — if they want to work with the creator — saves them to the workspace CRM and sends outreach. Consent for the partnership itself is obtained from the creator directly; paid partnership tagging and partnership-ad permissions are granted by the creator inside Meta.
  5. Creator data stays inside the workspace that fetched it. It is used only to evaluate and manage that collaboration, never resold or pooled into a public directory.

Users can delete any creator record from the CRM at any time; deletion removes the cached profile, media references and metrics for that workspace.

5. Access, storage and security

  • All provider API calls are made server-side; access tokens never reach the browser.
  • Tokens are stored encrypted, scoped per connection, and revoked on disconnect.
  • Only the minimum scopes required for enabled features are requested.
  • Access is restricted by workspace membership and role, with row-level security in the database.
  • Administrative access is limited and audit-logged.

6. Retention and deletion

  • Cached insights and creator records are kept only while the feature is in use by the workspace.
  • Disconnecting a provider revokes the token and purges cached content for that connection.
  • When content is edited or removed on the source platform, our cached copy is updated or deleted; for Reddit this happens within the required 48-hour window.
  • Account or workspace deletion removes associated platform data. Requests can be made via Data Deletion.

7. Compliance

We operate in accordance with the terms of each provider we integrate with, including the Meta Platform Terms and Developer Policies, Google API Services User Data Policy (including Limited Use), TikTok, LinkedIn, Pinterest, X and Reddit developer terms, and applicable data-protection law such as GDPR and CCPA where relevant. Where a provider's terms are stricter than this policy, the provider's terms apply.

8. Shared responsibility

MarketPilot provides the controls described above. Customers are responsible for connecting only accounts they are authorised to manage, for obtaining any consent their own campaigns require, and for complying with each platform's rules when publishing or contacting creators.

9. Contact

Questions or data requests: privacy@marketpilot.ai.