Skip to main content
h@ndle
Log InGet Started
h@ndle

Last updated: October 7, 2026

h@ndle Privacy Policy

Handle App, LLC ("Handle", "we", "us", or "our") operates the h@ndle app and website at myhandle.app (the "Service"), a marketplace connecting content creators ("Creators") with brands and businesses ("Brands"). This Privacy Policy explains what information we collect, how we use it, and the rights you have over it.

The Service is offered to residents of the United States only. By using the Service, you confirm you are a US resident and you agree to the practices described here.

1. Information We Collect

1.1 Information you provide

When you sign up and use the Service, you provide:

  • Account details: name, email address, an optional phone number, password (stored only as a hash, a scrambled version that cannot be turned back into your password), user type (Creator or Brand), and for Brands, company name, a contact first and last name, and verification information. If you sign up as a Brand with a company email address (not a free mail service such as Gmail), we also save the domain of that address, and if another Brand account already uses the same domain, we privately note that the two accounts share it. No one in the app sees that note, and it gives no one access to your account.
  • Profile information: bio, profile photo, content categories, languages spoken, country, social media links and follower counts you choose to display, rate cards, portfolio items, and past collaborations (including any campaign details you add).
  • Payment information: Brands enter payment-card details directly with our payment processor, Stripe; Handle never sees or stores full card numbers (Section 1.3 lists the few card details Stripe sends us). Creators connect their payout account through Stripe Connect; we receive a Stripe account identifier but not bank account details (Stripe holds those).
  • Tax information: Creators submit a tax form directly to Handle: Form W-9 for US taxpayers, or Form W-8BEN for non-US persons. A W-9 includes your legal name, business name (if different), address, taxpayer type (for example individual or LLC), the type of ID number (Social Security number, employer identification number, or individual taxpayer identification number), and the ID number itself. A W-8BEN includes your legal name, address, country of citizenship, an optional date of birth, an optional foreign tax ID, and an optional tax treaty country.
  • Tax form signing and storage: You sign the form by typing your legal name, and we record the date, time, and IP address of that signature. The ID number (and any foreign tax ID) is stored encrypted, and our systems return and display only its last four digits. The full ID number is never shown to or shared with Brands. Once you and a Brand have both signed a contract, or a payment between you has been funded, that Brand can see the last four digits and the other form details listed in Section 3.1.
  • Content you create: profile content, posts, messages, contracts, briefs, reports you file about other users or content, the list of people you block, and any other content you submit through the Service.
  • Communications: the contents of messages you send through the Service's messaging feature.

1.2 Information we collect automatically

When you use the Service we automatically collect:

  • Usage data: the actions you take in the Service and when you take them (for example, signing a contract, sending a message, or submitting a deliverable), kept as part of the related record. We do not use third-party analytics tools, and we do not follow which pages you view or how you move around the site. The only page-level records we keep are the signup-step, profile-view, booking-page, and tracking-link records described below, plus a simple count of how many times a shared campaign report link has been opened (we do not record who opened it).
  • Where you came from (signup source): if you reach our site through a link we published, such as one of our ads, posts, or emails, the link can carry campaign tags (for example utm_source=meta or utm_campaign=fall-launch). Your browser keeps those tags for 30 days, and if you create an account in that time we save them with your account, along with the page that link opened. If you arrive through more than one tagged link, the most recent one counts. We use them only to see which of our own links bring people to Handle. We do not send them to ad platforms or anyone else.
  • Signup steps (visitors who are not signed in): to see where people stop on the way to creating an account, when you visit while not signed in we record a few anonymous steps: that a visit arrived (with the first page it opened and any campaign tags from the link), that the signup form was shown, that you started typing an email, that you pressed Create Account, any error that stopped you (such as a field left empty), and whether an account was created. Each record carries a random visit code that your browser keeps only until you close the tab, whether you used a phone or a computer, and the name of the app if you opened our site inside one (for example Instagram). It does not include what you typed, your name, your IP address, or your browser details, and it is not linked to your account. We delete these records after 90 days.
  • Profile-view data: when you view another user’s profile while signed in, we record that view and show your name, photo, and profile link to the profile owner as part of the “who viewed your profile” feature. You can turn this off at any time in Settings (“Browse profiles privately”), in which case we stop recording your profile views for this feature. If you are a Brand, opening a Creator’s profile is still counted in the booking-page opens described below.
  • Tracking-link clicks: when anyone, including someone without a Handle account, clicks a Handle tracking link, we record the time and an approximate country when our network provider supplies one. We also record a shortened one-way hash of their IP address (a scrambled code that cannot be turned back into the address; we do not store the raw IP address).
  • What else we record about a click: the browser and device details the clicker’s browser sends (the user agent text, which we also sort into mobile, tablet, desktop, or other) and the name of the website the click came from. We keep the site only, not the full page address, though clicks recorded before October 1, 2026 may still hold the full address their browser sent. Reports show only the site. We flag clicks that look like bots instead of deleting them. We do not set cookies on people who click.
  • How we use click data: we use it to measure campaign performance, count unique visitors, and filter bot traffic. The parties to the relevant deal see it only in aggregated form (for example, click and unique-visitor counts, top referring sites, device split, and countries), and a campaign report shared through a public link includes those same totals. The custom links a Creator adds in the Links section of their own profile are tracked the same way, and only that Creator sees the totals and device split. Other links on a profile, such as social media and portfolio links, are not tracked.
  • Click records and deletion: click records stay with the deal or profile link they belong to. Deleting a deal's tracking link, or deleting your account, stops new clicks from being recorded, but clicks already counted remain (for a deal, so the other party's report stays accurate).
  • Links you remove from your profile: a link you remove from your own profile is only hidden. Its tracking address keeps working and keeps counting clicks until you delete your account, so addresses you already shared still work.
  • Booking-page opens: when a Brand or a signed-out visitor opens a Creator's public profile, we record a one-way hash of their IP address and the date, one record per visitor per day, so the Creator can see how many people opened their booking page. We do not store the raw IP address. Only the profile owner sees the totals, and no one sees the individual records.
  • Signing and certification records: when you sign a contract, we record the IP address you signed from next to your typed signature and the time, and the contract shows that IP address to both parties. When you certify a tax form, we record the IP address you certified from and keep it with the form; it is never shown to Brands, and it is erased if you delete your account. These are full IP addresses, not hashed. Signing records are kept with the contract they belong to (see Section 8).
  • Download records: when a Brand downloads an original deliverable file, we record the Brand's account, the time, and the IP address in that file's download log; Creators see only a download count. This is a full IP address, not hashed. The log is kept with the file (see Section 8).
  • Notification settings: if you turn on browser notifications, we store the web address your browser's push service gives us for sending you alerts, its encryption keys, and your browser's user agent text (a line of browser and device details). See Section 7.
  • Server logs: our servers keep operational logs. Entries identify you by account number rather than name and can include the request method and address, the time, and the error that occurred. If an email to you fails to send, the log includes your email address and the email's subject line. If something fills in a hidden bot-trap field on our early-access sign-up form or our emailed rate report form, the log records that IP address. We do not keep a log of every page you view.
  • Rate limits and provider logs: to limit how many sign-in attempts and other requests can be made, our servers keep short-lived counters in memory. They are tied to things such as an IP address, an account number, a campaign, a collaboration confirmation link, or an email address typed into a sign-in, password-reset, or other form that sends an email (including an outside contact's address), and one counter is shared by all users. We do not save these counters. Our hosting and network providers process requests to deliver the Service and may keep their own logs, which can include IP addresses.
  • Code guess counts: unlike the counters above, a count of guesses at an emailed sign-in or verification code is saved, with your account or with that code, until the code is used, replaced, or removed.
  • Send-once records: so that a deal reminder, a draft email, a signature reminder, a retainer renewal notice, a milestone target email or a payout notice is sent only once (as is each card dispute notice), we save a small record with the deal: which deal and piece, which email, and when. It holds no message text and no email address, and it is kept with the deal (see Section 8). The one-time setup reminder keeps a timestamp on your account for the same reason; it holds no message text and no email address. The failed payout email keeps a similar record of the Stripe event and the day it was sent to your account (see Section 8).
  • Failed retainer charge records: so that the notice about a failed retainer charge is sent only once, we save a small record with the retainer: which month and which attempt. It holds no message text and no email address, and it is kept with the deal (see Section 8).
  • Device and connection information: like any website, our servers and our hosting and network providers receive your IP address, browser and device details, and the address of the page you asked for each time your browser contacts us. We do not store these in your account record. We keep them only in the specific records described in this section and in Section 3.3: tracking-link clicks, booking-page opens, signing, certification, and download records, notification settings, early-access list entries, and server logs.
  • Cookies and similar technologies: see Section 5.

1.3 Information from other sources

We receive information about you from these sources:

  • Connected social accounts: if you choose to connect a YouTube, Instagram, TikTok, Twitch, or Kick account, we receive limited information from that platform through its own sign-in and permission screen (OAuth). See Section 6 for exactly what. X (Twitter) and Snapchat cannot be connected: if you add either to your profile, you type the handle yourself, we do not check it with the platform, and it does not count toward your verified audience.
  • Sign in with Google: if you sign up or log in with Google, Google sends us your verified email address, your name, and your Google profile picture. We use the email address to find or create your account and the name as your account name. For Creators, the name and picture also become the starting name and photo on your public profile, which you can change. We do not receive your Google password, and we do not use Google sign-in to contact Google about you again after you sign in. Connecting a YouTube channel is separate and is described in Section 6.
  • Google sign-in and an existing password: if you sign in with Google to an account that has a password you did not set through an emailed reset link, we remove that password and sign you out of your other devices. If the account's email address was confirmed, we email you about it. You can keep using Google, or choose a new password with Forgot Password.
  • Stripe: the status of payments, refunds, disputes, and payout accounts, so we can run the Service. When you open your billing or instant-payout settings, Stripe also tells us the last four digits of the card on file (and, for a Brand's saved card, its brand and expiry date) so we can show them to you. Up to three days before a retainer month renews, we also ask Stripe for the expiry month and year of the Brand's saved card, so the renewal notice can say if it will have expired. We do not store these.
  • Other users: reviews, recommendations, and reports that other users write about you, the offers, contracts, and messages they send you, and lists a Brand keeps, such as saved Creators. If a Brand contact confirms a past collaboration for you, we receive their confirmation too (see Section 3.3).
  • Web pages you point us to: when you add a link to a portfolio item, our servers fetch that page to read its title and preview image. When a Brand verifies its website, our servers read its homepage, or the domain's public DNS settings, to find the code we gave it. Those sites see a request from Handle's servers.
  • Public lookups: when you use Legit Check (our tool for checking a brand's outreach message), we look up when up to three of the domains in the message you paste and the sender address you enter were registered. These are the domains of website links and email addresses, and we skip free mail services such as Gmail. For the email addresses among them, we also check whether the domain has a mail server. The registration lookup goes through the public lookup service rdap.org and the domain registry; we send only the domain names, not your message.

2. How We Use Your Information

We use the information described above to:

  • Operate, maintain, and improve the Service.
  • Create and manage your account, profile, and verifications.
  • Facilitate matching and communication between Creators and Brands.
  • Provide AI-assisted features, such as campaign brief suggestions, Creator matching and search, pitch coaching, deal import, Legit Check, and campaign report summaries (see Section 3.2).
  • Measure the posts and tracked links tied to a deal and report the results to the people on that deal (see Sections 1.2 and 6.2).
  • Process payments, payouts, fees, and refunds, and provide accounting and tax records related to those transactions.
  • Compute Handle Score and other reputation signals. This is automated and uses your profile setup, your connected platforms, the reviews you receive, and how your deals on Handle finish.
  • Produce rate estimates from signed paid deals on Handle (including deals still in progress) and, if you opt in to the Green Room, include the amounts of your completed paid deals in its pay statistics. See Section 3.1.
  • Send account and deal emails, such as contract and deal updates, offers and applications, messages, connection requests, payment and payout notices, password resets, and sign-in and verification codes. You can turn off message (including connection request and acceptance), offer, and deal-update emails in Settings.
  • Send the emails that are necessary to operate the Service, which are always sent while you have an active account: most payment, cancellation, dispute, retainer, verification, and security emails (including a receipt when a Brand's payment goes through, and a notice to a Creator that released money is waiting for payout setup), notices when your password or two-factor setting changes, a notice that we removed one of your posts, and notices that we had to disconnect a connected platform. When you delete your account in Settings, we also send one final confirmation. Section 7 has the full list.
  • Send a weekly summary of activity on your account and, in your first week, one reminder to finish setting up if you have not. Both are on by default and you can turn them off at any time. See Section 7.
  • Detect, investigate, and prevent fraud, abuse, security incidents, or violations of our Terms of Service.
  • Comply with legal obligations, enforce our Terms, and respond to lawful requests from authorities.

3. How We Share Your Information

We do not sell your personal information. We share information only in the following ways:

3.1 With other users of the Service

Your public Creator or Brand profile (name, photo or logo, bio, categories, follower counts, Handle Score, verified status, public collaborations, public reviews, and the other details listed in Section 4) is visible to other users and may be visible to non-users via search engines, on our public creator directory pages (which list Creators who have connected at least one social account, by content category), and through our public, read-only API, which AI assistants and other software can use to search Creator profiles. That API returns public profile information only and never includes your email, phone number, or rate amounts. When a public profile changes, we send its web address (and nothing else) to search engines through the IndexNow protocol so they can refresh their copy.

Among users, information you share inside a contract or message thread is visible only to the other party in that interaction. Our administrators and some of our service providers can also see parts of a contract, as described in Sections 3.2 and 10.

Some information reaches more users than the other party. For example, when a deal completes on Handle, we automatically publish a collaboration record naming the Creator and the Brand. It appears on the Creator's public profile, on a public collaboration summary page, and as a post in the feed that any signed-in user can see.

The summary page also shows the campaign title, the deal type, the date, the deliverable titles, and the Brand's review of the Creator (its star ratings and whether it would work with the Creator again). It never shows a payment amount or a budget, and search engines can index it. Deals completed with payment protection are labeled "Verified on Handle"; completed deals where no payment ran through Handle are published without that label.

Campaign performance reports are private to the parties unless one of them creates a share link. Anyone with the link can open the report without signing in. It shows the campaign, the Brand's name and logo, the Creator's name and photo, the post, click, and promo-code numbers, a written summary of them, and whether the deal's payment has been funded or paid out. We leave out the payment amount and any sales revenue the Brand entered. Either party can revoke the link at any time, and it stops working 30 days after the report was made.

Profile views: if you view another user’s profile while signed in and have not turned on “Browse profiles privately” in Settings, the profile owner can see your name, photo, and profile link, as described in Section 1.2.

When you sign a contract, the name you typed, the date and time, and the IP address you signed from are stored with the contract and shown to the other party on the contract page.

Tax details shared with Brands: once you and a Brand have both signed a contract (whether or not it has been funded yet), or a payment for a deal between you has been funded, that Brand can open and download a "vendor packet" about you. The packet shows the tax form you filed with Handle: the form type, your legal name, business name, taxpayer type, address, ID type, and the last four digits of your ID. For a W-8BEN it also shows your country of citizenship and tax treaty country.

The packet also shows the date you certified the form, your public name, whether your payout account is connected and enabled, and the contracts you have with that Brand and the amounts paid on them. It never shows your full ID number, date of birth, or the IP address you certified from. After you delete your account, a packet no longer shows any tax form details.

A Brand can also download a spreadsheet file (CSV) of its payments. For each payment it lists your public name, your tax form type, legal name, business name, taxpayer type, ID type and last four digits, your country, and whether your payout account is ready, alongside the amount, dates, and status of the payment. It does not include your account email address or your Stripe payout account ID.

Rate estimates: when you ask for a price estimate while signed in, the result can blend industry benchmarks with the amounts of signed paid deals on Handle, including deals still in progress. We show only a price range, never a list of deals or the name of the Creator behind one, and we use other Creators' deal amounts only when at least five other Creators are in the sample.

Green Room: if you are a Creator and opt in to the Green Room, the amounts of your completed paid deals are pooled with those of other opted-in Creators to produce pay statistics. Opted-in Creators see only rounded dollar figures and ranges, and only when at least five other Creators are in the group, never a list of deals or the name of the Creator behind any amount. The Green Room also shows opted-in Creators a card for each Brand that has at least five other opted-in Creators behind it: the Brand's name, its number of deals, a rounded total paid and median deal, and review scores (would work again, rating, and payment speed).

You can leave the Green Room at any time, and your deals are no longer counted. Deleting your account does not remove your deal amounts from rate estimates or, if you were opted in, from Green Room statistics, because the amounts stay in the contract records described in Section 8. Leave the Green Room first if you do not want them counted there.

3.2 With service providers (subprocessors)

We share data with third-party vendors that help us operate the Service. Each vendor may use the data only to provide its service to us, under its contract or terms with us. There are three exceptions. Stripe also uses some data as an independent company for payment, fraud, and identity checks, under its own privacy policy. Google (for our email inbox) and your browser's push service handle data under their own privacy policies. Current subprocessors:

  • Stripe, Inc.: payment processing, payouts, identity verification. We send Stripe your email address, a Brand's company name, your Handle account ID number, and, with each payment, the campaign name and contract number (stripe.com/privacy).
  • Railway Corporation, Inc.: application hosting, our production database, and server logs (US data centers).
  • Sentry (Functional Software, Inc.): error monitoring (sentry.io/privacy). When something on our servers fails, Sentry receives:
    • The error message, a technical record of where in our code it failed, the request method and path, and your account ID number if you were signed in.
    • Some reports also carry details such as a platform name, a deal ID, a payment ID, or a Stripe payout account ID, and some payment-failure reports carry refund or fee amounts.
    • If an email fails to send, the recipient's email domain (the part after the @). We do not add the full address or the subject line.
    We configure it not to send request bodies, headers, cookies, or your email address. We cut off anything after a question mark in the web address it receives, and replace ID numbers and code-like parts of the path (such as the secret code in an invite or report link) with a placeholder.
  • Resend, Inc.: email delivery for the account, deal, notification, weekly summary, and sign-up emails described in Sections 3.3 and 7 (resend.com/legal/privacy-policy).
  • Cloudflare, Inc.: domain name (DNS) service, inbound email routing, and file storage (Cloudflare R2) for the deliverable and draft files uploaded on deals, including watermarked preview copies. Browsers upload these files to Cloudflare, and load previews and downloads from it, directly through temporary links, so Cloudflare also receives the IP address and browser details of the person doing it.
  • Google LLC (Gmail): hosts the inbox that receives the email you send to our hello@, legal@, and privacy@ addresses and the replies to our emails, which Cloudflare forwards to it (policies.google.com/privacy).
  • Anthropic, PBC: AI-assisted features. When you use one of these features, or when we run one for you automatically as described below, we send the inputs listed here to Anthropic and show you what it returns.
    • Brand tools. Campaign brief suggestions: your company name, industry, and about text, the campaign name, deal type, compensation, deliverables, and deadline you enter, and the chosen Creator's name, bio, categories, follower counts, and past brand collaborations. Creator matching runs automatically each time you post a campaign. For matching, and for natural-language search (searching in everyday words), we send your campaign details or search text, plus a short summary of up to 200 of the newest Creators listed in brand discovery. The summary has each Creator's name, Handle Score, categories, tags, follower counts, past brand collaborations, the first 200 characters of their bio, and the rate-card prices they chose to show Brands. Only Creators with at least one connected platform are included.
    • Creator tools. Brief review: the brief text. Counter-offer drafting: the brief text, the review findings, your name, and the Brand's name. Pitch coach: the campaign details, your name, bio, categories, and follower counts, and any draft pitch you write. Deal import: the text of the email thread you paste in, up to 16,000 characters, which may include information about your outside contacts.
    • Legit Check. The first 6,000 characters of the message you paste and the sender address you enter. Handle does not save them.
    • Campaign report narratives. When you generate a report, and automatically after a campaign's measurement window ends: the campaign, Brand, and Creator names, the measurement window dates, each deliverable's label, platform, and numbers, and the report's totals (views, likes, comments, clicks, top referring site, and promo-code redemptions). Raw click records are not sent.
    Under Anthropic's commercial terms, inputs sent through our account are not used to train its models. Anthropic may keep them for a limited time for safety and abuse prevention (anthropic.com/legal/privacy).
  • Your browser's push service (run by Google, Apple, Mozilla, or Microsoft, depending on your browser): only if you turn on browser notifications. We send each notification through your browser maker's push service. The notification text is encrypted, so the push service cannot read it, but it can see that a notification was sent to your browser.

Connected social platforms (Google/YouTube, Instagram, TikTok, Twitch, and Kick) are not our service providers. We exchange data with them when you connect an account (and then each day to keep your counts current), sign in with Google, attach a post to a deal, add a post link to a past collaboration on your profile, or post a video link, as described in Sections 1.3 and 6 and in the next paragraph. What each platform does with your data is governed by its own privacy policy.

When you post a video link to your feed or in a Deal Room message, we send only that public link to YouTube or TikTok to get the video's title. For feed posts we also load a YouTube video's thumbnail from YouTube. Some other third parties, such as Stripe, Google Fonts, and Unsplash, also receive your IP address and browser details directly when your browser loads their content on our pages; see Section 5.

3.3 Information about non-users

Some features process information about people who do not have Handle accounts. If you import a deal by pasting an email thread, the text you paste (which may include your outside contact's name, email address, and deal terms) is sent to our AI provider (Section 3.2) to extract the deal details. If you then send that contact a deal invite, we store their email address, company name, and the deal details you entered, and we send them one email with the invitation. The email names you, the campaign, and the amount, and it includes a link to opt out of deal emails. We do not send reminders.

The invitation email also links to a page that anyone who has the link can open without signing in. The page shows your name and photo, the campaign, the amount, the deliverables, the timeline, your message, and the company name you entered, and it keeps working after the invite expires or you cancel it.

If you ask a brand contact to confirm a past collaboration, the contact enters their name, work email address, and optionally a company, and we email them one verification link. We store those details, and when the contact confirms, the domain of their email address (for example, brand.com) is shown on your profile. The full address is not published.

The confirmation link opens a page that anyone who has the link can see without signing in. It shows your name and photo and the collaboration's title, brand name, month, year, and platforms, and it keeps showing them after the link expires.

If a Brand verifies its business by email, we send a one-time code to the company email address it enters. That address can belong to a colleague who has no Handle account. We keep the confirmed address with the Brand's verification record until the Brand's account is deleted. If the Brand asks for a manual review instead, the code can go to any address the Brand enters, including a free mail address. We then email that address, the Brand's company name (or its account email address if it has none), and the LinkedIn or social profile link the Brand entered to our administrators.

If an address opts out of deal emails, we add it to a suppression list and do not email it again about deal invites, collaboration confirmations, rate reports, or our early-access list. Non-users can ask us to delete information about them, or to add their address to the suppression list, at any time via privacy@myhandle.app. We do not delete this information on a schedule, and it stays until someone asks us to delete it, even if the Creator who entered it has deleted their account.

If you ask for Brand access through our access request form without an account, we store your email address, company name, website, and the explanation you write, and we email you our decision. If you add a pipeline lead or a calendar entry about someone outside Handle, we store what you type, such as their name, email address, and notes. We do not delete access requests on a schedule, and pipeline and calendar entries are kept as described in Section 8.

If you give us your email address without creating an account, by joining our early-access list or by asking for an emailed rate report from our free rate calculator, we store your email address, the role and source recorded with your sign-up, a referral code of your own, the referral code of the person whose link you used (if any), a one-way hash of your IP address, and your browser's user agent text.

We email you a confirmation or the report you asked for. Asking for a rate report also adds your address to the early-access list. Each of those emails comes with an unsubscribe option, and when you unsubscribe we keep a record of that and do not email you about the list again.

Legit Check also handles information about people without Handle accounts: the message you paste, and the sender address you enter, may name or come from one of them. We send them to our AI provider for analysis (Section 3.2), look up the registration of up to three of the domains in them in public records (through rdap.org, which receives only the domain names), and we do not save them. We also compare the addresses and domains in them with verified Brands on Handle. If an address is a verified Brand's login email, or a domain is one that a Brand has proved it controls, the person running the check is shown that Brand's name and website.

3.4 For legal reasons or to protect rights

We may disclose information if we believe in good faith that disclosure is necessary to comply with a law, regulation, legal process, or governmental request; to enforce our Terms; to detect or prevent fraud or security issues; or to protect the rights, property, or safety of Handle, our users, or others.

3.5 In a business transfer

If Handle is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you (e.g., via email or in-Service notice) before your information becomes subject to a different privacy policy.

3.6 With your consent

We share information with other parties when you direct us to do so (for example, by posting it publicly on your profile or sending it through a message).

If you generate a verified income statement, it shows your name (your legal name from your tax form, or your profile name if you have no tax form, or your account email address if you have neither), the period you chose, the number of payments and the total you received, together with a verification link and code.

Anyone who has that link can open the verification page without signing in and see your name, the period, and the total. A link does not expire and you cannot revoke it, so share it only with people you trust, such as a landlord or lender. If you later delete your account, the link still works, but it shows "Deleted user" instead of your name.

4. Public Profile and User-Generated Content

Your Creator or Brand profile is public. There is no setting to hide it: you choose what goes on it, and deleting your account takes it offline. It includes your name, photo or logo, bio, categories, profile web address (for example myhandle.app/u/yourhandle), connected platform handles, profile pictures, follower counts (plus a chart of those counts over time), your Handle Score and verified status, and any case studies or portfolio items you publish. If you are a Creator, it also includes your headline, tags, languages, country, whether you are open to collaborations, the links in your Links section, and your channel descriptions. If you are a Brand, it also includes your website, industry, and social links.

A Creator's rate card is visible to signed-in Brands, and not to other Creators or to visitors who are not signed in. Posts you share to the feed as a Creator are public: any signed-in user can view, like, and comment on them, they appear on your public profile's Activity section, and they may be recommended to users outside your network whose interests match (labeled "Suggested"). Posts by Brands are shown to the Creators who follow them and to the Brand's accepted connections. They are also visible to any new signed-in account that has fewer than three connections.

A signed-in user who can see a post can reshare it in a post of their own. A reshare copies the author's name, photo, and the post's text, first image, and any video link into the resharer's post. If you delete the original post, the copied image is removed, but the text, your name, and your photo can stay in the reshare (see Section 8).

Campaigns a Brand posts to the marketplace are public too. Anyone can open them, including visitors who are not signed in. They show the Brand's name and logo, the campaign description, budget, deliverables, platforms, target audience, deadline, and the brief and any links the Brand adds. A new campaign also appears as a post in signed-in users' feeds. A Brand's sixth and later campaigns within 24 hours are posted to the marketplace without a feed post.

Any signed-in user can also see who follows you, who you follow, and your accepted connections (name, photo, and profile link), and the Brands a Creator follows are listed on that Creator's profile under Interests.

Signed-in users can also read the recommendations other users have written about you, shown with the author's name and photo. Reviews are public and show who wrote them (a Brand's name, or a Creator's name and photo) and the campaign they were for.

You can change what appears on your profile at any time from the Edit Profile page. Information that has already been viewed, cached, or copied by other users or third parties may persist outside of our control.

5. Cookies and Similar Technologies

We use cookies and similar technologies, such as your browser's local storage, to keep you signed in, remember a few preferences, and keep account connections secure. The categories we use:

  • Strictly necessary: your sign-in token (it expires after 7 days) and a saved copy of your account details, including your email address and profile information, are kept in your browser's local storage so you stay signed in. We remove them when you sign out. The Service will not function without these.
  • Strictly necessary, for security: when you connect a social account, we set a security cookie (handle_oauth_nonce) that lasts 15 minutes. It makes sure the connection finishes in the browser that started it. The sign-in and sign-up pages also save a random one-time value in local storage for Sign in with Google. It stays there until a Google sign-in on that browser uses it, even if you sign in another way, and signing out does not remove it.
  • Functional: small convenience settings kept in your browser's local or session storage, such as whether you dismissed a getting-started card, the tax set-aside percentage you chose, which Deal Room messages you have already seen, and which account turned on notifications on this device. These values stay in your browser and are not sent to us.
  • Signup source: if you arrive through a link of ours that carries campaign tags, your browser's local storage keeps those tags (handle_signup_attribution) for 30 days so your signup can record them (see Section 1). It is not a cookie and is never sent to anyone but us.
  • Signup steps: while you are not signed in, your browser's session storage keeps a random visit code (handle_funnel_visit), the campaign tags of the link you arrived on, and which signup steps were already recorded (see Section 1). It is deleted when you close the tab, is not a cookie, and is never sent to anyone but us.
  • Service worker: our app installs a small service worker in your browser. It only displays the notifications you turned on; it does not cache pages or track activity.
  • Third-party fonts and scripts: our pages load typefaces from Google Fonts, so your browser requests them from Google and Google receives your IP address and browser details (policies.google.com/privacy). Deal Room pages, and pages where you pay or add a card, load Stripe's script, which can set its own cookies or identifiers and collects device information to detect fraud (stripe.com/privacy). We do not load other third-party scripts.
  • Images and files hosted elsewhere: our Creator landing page shows sample photos hosted by Unsplash. Some other images can also be hosted by other sites, such as the profile pictures of connected accounts and thumbnails for videos you link to (YouTube previews, for example). Your browser may contact those sites directly to load them. When you upload, preview, or download a deal file, your browser also contacts Cloudflare's file storage directly (see Section 3.2).
  • Analytics: we do not load analytics or advertising scripts in your browser, and we do not use third-party advertising or behavioral-tracking tools. Error monitoring (Sentry) runs on our servers, not in your browser, and stores nothing on your device. See Section 3.2.

Most browsers let you block cookies and clear site data in their settings. Blocking or clearing the storage described above will sign you out and may break parts of the Service. We do not currently respond to "Do Not Track" browser signals because there is no industry standard for them. Global Privacy Control (GPC) is a browser setting that asks websites not to sell or share your data. We do not sell personal information or share it for cross-context behavioral advertising (ads aimed at you based on your activity on other companies' sites and apps), so there is nothing for GPC to opt you out of, and we do not currently read that signal.

6. Third-Party Platform Connections

The Service lets you connect external accounts (Google/YouTube, Instagram (Meta), TikTok, Twitch, Kick) so that follower counts, channel verification, and engagement metrics can be displayed on your profile, and so that your connected platforms can count toward your Handle Score. Connection happens through each platform's own sign-in and permission screen (OAuth). X (Twitter) and Snapchat cannot be connected: if you add either one, you type your handle, we do not contact the platform or verify it, and it does not count toward your verified audience.

6.1 What we receive

From each connected platform, we request only the permissions we need (the platforms call them scopes) to verify your account, show it on your profile, and measure the posts attached to your deals. Typical permissions per platform:

  • Google / YouTube: youtube.readonly. We call only the part of the YouTube API that returns your own channel, and we keep your channel ID, channel handle or name, profile picture, and public subscriber count. We do not read your playlists, subscriptions, or private videos. For YouTube videos you attach to a collaboration or deal, we also read the video's public view, like, and comment counts, publish date, title, and channel, using a YouTube API key that does not need your account access.
  • Instagram: via the Instagram API with Instagram Login (instagram_business_basic). We receive and store your Instagram account ID (and the separate app-specific ID Instagram gives us for you), username, name, account type, profile picture, and follower, following, and post counts. For posts attached to a collaboration or deal, by you or by the Brand on the deal, we look through your recent posts to find them and keep only the likes, comments, link, and timestamp of the posts attached. If you additionally grant insights access (instagram_business_manage_insights), we read the view count of those specific posts so it can be verified rather than self-reported. Read-only: we never publish, comment, or message on your behalf.
  • TikTok: user.info.basic, user.info.profile, and user.info.stats. We receive your TikTok ID, username and display name, profile picture and profile link, bio, and follower, following, like, and video counts. We keep your ID, username, profile link, picture, and follower count, and discard the rest. With the video.list permission, we also read views, likes, comments, shares, title, and publish date for the specific videos attached to a collaboration or deal.
  • Twitch: moderator:read:followers. We receive your Twitch user ID, username, profile picture, and follower count. For Twitch clips or videos you attach to a collaboration or deal, we read their public view counts, creation date, title, and the channel they belong to, using our own Twitch API access, which does not need your account.
  • Kick: user:read and channel:read. We receive your Kick user ID, username, profile picture, channel name and category, and your number of paid subscribers. Kick does not share follower counts with us, so the number shown for Kick is paid subscribers and is labeled that way. We do not store or use your Kick email address.

6.2 How we use this data

Data received from connected platforms is used to:

  • Verify that the platform handle you claim is actually controlled by you.
  • Show your connected handle, profile picture, follower count, and a chart of your follower counts over time on your public profile.
  • Make you eligible to appear in brand discovery and AI matching. Only Creators with at least one connected platform are listed.
  • Compute your Handle Score and other reputation signals.
  • Refresh the displayed counts about once a day and whenever you press Refresh. If we cannot refresh a connection for 14 days in a row (for example because you removed Handle's access at the platform), we disconnect it and email you.
  • Measure the posts attached to a deal, and report on them to the people on the deal in campaign reports. Either you or the Brand on the deal can attach a post link. For Instagram and TikTok posts, we check the link through the Creator's connection, even if the Brand attached it.
  • Keep those post numbers current. We refresh a post's numbers hourly for the first 2 days after it is submitted, daily for the next 12 days, and weekly until 90 days after it is submitted. For campaigns that use a measurement window, we also take a daily reading while the window is open, which can run longer than 90 days, and then one reading about 7 days after the window closes and one about 30 days after. We stop when the last of these schedules ends.
  • Re-check the post links you add to your past collaborations, once a day, for as long as that platform stays connected, and show the checked counts on that collaboration on your profile. We stop when you disconnect the platform or remove the link (see Section 6.4 for what happens to counts already shown).
  • Post a milestone card to your feed when a connected channel crosses a follower threshold (for example 10,000). You can turn this off on your Edit Profile page. Turning it off, or disconnecting the platform, does not remove a card that was already posted. To have one removed, email privacy@myhandle.app.

6.3 Google API Services User Data Policy: Limited Use

Handle's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Data received from Google APIs is used only to provide and improve the user-facing features described above (profile verification, follower display, Handle Score, brand discovery, campaign reporting, and the AI-assisted matching described in Section 3.2).
  • We do not transfer Google user data to third parties except as necessary to provide and improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets (with appropriate notice).
  • We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Google user data unless we have your affirmative agreement, doing so is necessary for security purposes (such as investigating abuse), or to comply with applicable law, or the data is aggregated and anonymized.

The same Limited Use principles apply to data we receive from any other connected platform.

6.4 Disconnecting and revocation

You can disconnect any connected platform at any time from your Edit Profile page. When you disconnect, we delete the stored access and refresh tokens right away, stop refreshing your profile, handle, and follower data from that platform, and remove the platform's displayed link, handle, picture, and follower count from your profile. A milestone card already posted to your feed stays there (see Section 6.2).

Posts already attached to a deal can still be measured as described in Section 6.2. For YouTube and Twitch we read their public numbers with our own API access, so those posts can keep refreshing after you disconnect, within the time limits in Section 6.2. For Instagram and TikTok, measurement stops because it needs your connection.

Links on your past collaborations are only re-checked while their platform is connected. After you disconnect, the next daily check removes the checked counts for that platform from your collaborations if you still have a YouTube, Twitch, Instagram, or TikTok account connected. If you have none of those connected, the counts stay on your profile, no longer updated, until you remove the link or the collaboration. Numbers already recorded for your deals stay with those deals and their reports.

We do not send a revocation request to the platform, so Handle may still be listed as a connected app in your platform account until you remove it there. You can also revoke Handle's access directly from each platform's account settings: for Google, this is at myaccount.google.com/permissions; for Instagram, remove Handle under Instagram → Settings → Apps and websites, which notifies us, and we disconnect the account the same way. If you also ask Instagram to delete your data, we permanently delete the Instagram connection record and your Instagram follower history.

After you disconnect, we keep a record of the connection for security, audit, and anti-abuse purposes (for example, to prevent a different account from immediately claiming the same platform handle). The record holds the platform, your account identifier and username there (for Instagram, also the app-specific ID Instagram gives us for you), your last follower count, the permissions you granted, and the dates you connected, last synced, and disconnected. We also keep the daily follower counts we recorded, but they are no longer shown on your profile. The profile picture and profile link we stored for the connection are deleted when you disconnect.

When you delete your Handle account, we also delete the username, follower count, and follower history. What stays is the platform, your account identifier there (for Instagram, also the app-specific ID Instagram gives us for you), the permissions you granted, and the dates. We keep this record until you ask us to delete it by emailing privacy@myhandle.app.

7. Email and Notifications

We send two kinds of email to account holders. Account and deal emails keep the Service running: contract and deal updates, offers and applications, messages, connection requests, payment and payout notices, password resets, and sign-in and verification codes. A weekly summary tells you what happened on your own account that week, and in your first week one setup reminder may ask you to finish setting up. We do not currently send marketing emails or a newsletter to account holders, and if we start, we will send them only to people who opt in. We also send one-time emails to people who do not have accounts, as described in Section 3.3.

The weekly summary is on by default for accounts with a confirmed email address. We send it at most once a week, once your account is a week old, and only when there is something to report. It is made of counts: profile views, unread conversations, what is waiting on you (contracts to sign, deliverables to review, applications or offers nobody has answered), and, for the week, how many people followed you, how many likes and comments your posts got, and how many people reshared, mentioned or recommended you. Creators also get new campaigns. It never names those people or repeats what they wrote. You can turn it off in Settings or with your email app's unsubscribe option.

Setup reminder email. In your first week we may email you one reminder to finish setting up, and never a second. A Creator with no deal gets it two to seven days after signing up, if the profile still lacks a name, photo, bio or category, or a connected platform. A Brand gets it three to seven days after signing up, if the company name or website is still empty and it has not posted a campaign, contacted a Creator or started a deal. It names what is missing in fixed words, never anything you wrote, and goes only to a confirmed address. It follows the weekly summary setting, and its unsubscribe link turns that off too.

Connection request emails. When someone sends you a connection request and your email address is confirmed, we email you their public name on Handle and whether they are a Creator or a Brand, and say whether they included a note. The email never contains the note itself or their email address. It follows your messages setting. We do not email you about a request from a person whose own email address is not confirmed, or from a Brand that has not yet verified its business. We also limit how many of these emails one person can trigger, or you can receive, in a day. In each of these cases the request still shows in your notifications in Handle.

Payment receipts and payout setup notices. When a Brand's payment for a deal goes through, we email the Brand a receipt. It shows the deal name, the Creator's public name, the agreed amount, our platform fee and the total charged in dollars, the date, and the contract number. When money is released to a Creator whose payout account is not set up, we email the Creator the deal name, the Brand's name, the amount released and, if other released payments are also waiting, the total waiting, with a button to set up payouts. Neither email contains a card number, bank details, or the other person's email address, and neither can be turned off in Settings.

Payout sent emails. When Handle sends released money to a Creator's payout account, we email the Creator one notice for everything sent at that time, for example after payout setup, a review hold ending, or a retry. It shows the amount in dollars and up to three deal names, and says Stripe pays it to the Creator's bank on their payout schedule. A first payout also says it takes about a week to reach the bank. It gives no arrival date, has no bank details, and cannot be turned off in Settings. We skip it for a payment released only moments earlier, unless that release email asked the Creator to set up payouts.

Payout waiting reminders. If released money is waiting because a Creator has not set up payouts, or because Stripe has payouts turned off on their account, we email the Creator a reminder when the oldest waiting payment is 7 days old and one more at 30 days, then none for that money. It shows the total in dollars, the number of deals, and the date the oldest was released, with a button to set up payouts. It names no deal or Brand, has no bank details, and cannot be turned off in Settings. When Stripe reports that payouts are off, we also mark the Creator's payout setup as not finished.

Failed payout emails. If Stripe tells us a Creator's bank rejected a payout, we email the Creator about that payout once, and never more than one such email a day. Stripe's news carries the amount, the date and a reason code, and we do not save them on your account. It shows the amount in dollars, the date Stripe tried, and a short reason, such as a closed account, in our own words rather than the bank's message. It says the money is back in the Creator's Stripe balance and has a button to the Payouts page, where the bank details are updated. It has no bank name or account number, and cannot be turned off in Settings.

Cancellation receipt emails. When a deal is cancelled in the Deal Room and the cancellation refunds a Brand's card or pays the Creator a kill fee, we email the Brand one itemized receipt. It shows, in dollars, any kill fee paid to the Creator, any card processing Stripe charged and kept, and the amount refunded to the card, plus the total paid when it covers every payment, with the deal name, the Creator's public name and the contract number. When the Brand asked to cancel, it replaces the shorter cancellation email. It never contains the reason either person gave, a card number or the other person's email address, and it cannot be turned off in Settings.

Card dispute emails. When a Brand's bank opens a dispute or review on a card payment for a deal, we email the Brand what it pauses while it is open (release, refund, cancel or retainer renewal). When the bank decides it, we email the result in neutral words. They show the deal name and a link to the Deal Room, and the dollar amount when a dispute opens or the bank returns the money, never the reason the bank gave, a card number or anything about the Creator, and they cannot be turned off in Settings. We also email our operations inbox the deal numbers, the amount and the evidence deadline. Creators are not emailed about card disputes.

Retainer renewal notice emails. Up to three days before a retainer month is charged to a Brand's saved card, we email the Brand one notice, as long as the charge is still going to be tried. It lists up to ten retainers and is normally sent once a day at most. It shows the Creator's public name, the deal name, the month, the date, the dollar amount and the card's expiry month and year, and how to end the retainer first. If the card will have expired by then, or there is none, it says so and links to card settings. It never shows a card number or the Creator's payout, and it cannot be turned off in Settings.

Funded deal emails. When a Brand pays for a deal, we email the Creator that it is funded. If the Creator's payout account is not ready, that email also asks them to set up payouts now and has a button to do it. It adds no amount and cannot be turned off in Settings.

Funding reminder emails. When both sides have signed a paid deal and the Brand has not paid for it, an automatic check every 15 minutes emails the Brand a reminder after one day and an urgent notice after three days. It also emails the Creator: first that the deal is signed but not yet funded, then that payment is still outstanding and not to start work yet. Each email names the deal and the other person's public name, never an amount or an email address, and is sent at most once per deal. None is sent while a cancellation request or dispute is open. The Brand's reminder and the three-day notices also show in your notifications in Handle.

Signature reminder emails. When a contract has waited three days for your signature, an automatic check that runs every 15 minutes emails you one reminder. If neither of you has signed, it goes to the Creator. An email about one contract names the deal and the other person's public name and says if they have already signed. If several contracts are waiting on you, we send one email with the number. These go only to a confirmed email address, follow your deal updates setting, never contain an amount, a message or an email address, and are sent once per contract, with a daily limit per person. A contract that has waited more than four days gets no reminder.

Milestone target emails. When a performance target on one of a Brand's milestones is reached, we email the Brand once for that milestone, if the Brand has paid for the deal, the payment is still held, and nothing is in dispute. The email names the deal, the Creator's public name, the target, and the milestone's amount in dollars. It asks the Brand to check where the numbers came from before releasing anything, and says a target never pays out by itself. The Creator is not emailed. It follows your deal updates setting, and we limit how many of these you can receive in a day. The target still shows in your notifications in Handle.

Review window emails. When a Creator submits the last deliverable on a paid deal and that starts the review window, the email we send the Brand about the submission also says when the window ends and that the payment is released to the Creator automatically if no one reviews the work by then. It follows your deal updates setting and never contains an amount.

Draft emails. When a Creator shares a draft before posting, we email the Brand that it is ready to review. The email names the Creator and the deal, says how many days an unanswered draft waits before it is approved automatically, and says that approving a draft does not pay anyone. We email the Creator when the Brand asks for changes (the round number, never the Brand's feedback) and when the draft is approved, including automatically after the Brand's review window passes. These follow your deal updates setting, never contain a file name or the other person's email address, and are limited to a few a day. The update still shows in your notifications in Handle.

Declined and withdrawn offer emails. When a Creator declines an offer you sent, we email you the Creator's public name and the deal name. When a Brand withdraws an offer before you have both signed, or removes you from it, we email you the Brand's name and the deal name, and if you had already signed, we say not to start any work for it. They never contain a reason the other person typed, an amount, or an email address. They go only to a confirmed email address and follow your offers and applications setting. We limit how many of them one person can trigger, or you can receive, in a day. The change still shows in your notifications.

Connection accepted emails. When someone accepts a connection request you sent, and both of your email addresses are confirmed, we email you their public name on Handle and whether they are a Creator or a Brand. The email never contains your note or anyone's email address. It follows your messages setting. We send at most one a day about the same person, and we limit how many of these emails one person can trigger, or you can receive, in a day. The acceptance still shows in your notifications in Handle.

Application emails. When a Creator applies to a Brand's campaign and the Brand's email address is confirmed, we email the Brand the Creator's public name and the campaign name and, when more than one application is waiting, how many. We send at most one of these a day for each campaign, so later applications show only in the Brand's notifications in Handle. The email never contains the Creator's pitch, rate or email address. It follows the offers and applications setting.

Confirmed collaboration emails. When a brand contact confirms a past collaboration you asked them to confirm, and your email address is confirmed, we email you the brand name you entered. The email never contains the contact's name, company or email address. It follows your deal updates setting, and we send at most three a day. The confirmation still shows in your notifications in Handle.

Emails that need a confirmed address. Emails about a direct message, a collaboration offer, a booking, a campaign brief, a reply to a brief, or a contract made from a brief go only to a confirmed email address. The item still shows in your notifications in Handle.

In Settings you can turn off four groups of email: messages (which also covers Deal Room posts, connection requests and accepted requests), offers and applications, deal updates, and the weekly summary (which also covers the setup reminder). These emails cannot be turned off while you have an active account:

  • Payment notices, such as a receipt to a Brand when its payment for a deal goes through, a deal being funded, a payment being released or failing, a notice to a Creator that released money is waiting for payout setup, and reminders that a deal is still unfunded (to the Brand, and to the Creator waiting on it).
  • A notice to a Creator that released money was sent to their payout account.
  • A reminder to a Creator that released money is still waiting for payout setup.
  • A notice to a Creator that their bank rejected a payout.
  • Cancellation, refund and card-dispute notices, including an itemized refund when a deal cancelled in the Deal Room returns money to a Brand's card and a notice when a bank dispute is opened or decided.
  • A notice that a deal invite you sent was accepted.
  • Retainer notices, such as a heads-up before a month renews, a month being delivered or renewed, a retainer being paused, or the other side ending the retainer.
  • Verification and security emails, including a notice when your password is changed, reset, or removed because you signed in with Google, when two-factor sign-in is turned on or off, and one final confirmation when you delete your account in Settings. Those three notices go only to a confirmed email address, and they never contain a password, a code, or a link that signs you in.
  • A notice that we removed one of your posts because we found, or were told, that it broke our Terms or infringed a copyright, with how to send a counter-notice.
  • Notices that we had to disconnect a connected platform.

Two other notices count as deal updates instead, so you can turn them off: a change order being funded (the notice to the Creator; the Brand's receipt for that payment is always sent), and a retainer wrapping up once its last paid month is released. After that one confirmation email, deleting your account stops email to your account address.

You can stop the weekly summary and setup reminder, early-access list emails, and deal-invite emails without logging in: use the unsubscribe option your email app shows, or the opt-out link inside the email (early-access list, deal-invite and setup reminder emails include one; the setup reminder's link asks you to press one button to confirm). Unsubscribe links take effect right away. You can also email privacy@myhandle.app, and we will honor the request within 10 business days, as the US anti-spam law (CAN-SPAM) requires.

Notifications in Handle and on your device. We also show notifications inside the Service, such as in the bell, and these cannot be turned off.

If you turn on browser notifications in Settings, we send push notifications to that browser or device about things like payments, deal activity, new campaigns that match your categories and platforms, likes, comments, and reshares on your posts, and when someone mentions you. Each notification is delivered through your browser's push service (for example Google, Apple, Mozilla, or Microsoft). You can turn push notifications off for a device in Settings or in your browser, and signing out of Handle on a browser turns them off there.

We also remove a device's push registration when you reset your password (every device), when you change your password in Settings (every device except the one you are using), when Google sign-in removes your password (every device), and when you delete your account. See Section 1.2 for what we store.

8. Data Retention

We retain your personal information for as long as your account is active and as needed to provide the Service. When your account is deleted, we apply the following defaults:

  • Account and profile data: if you delete your account in Settings, it takes effect immediately. If you email us the request instead, we run the same deletion for you. Either way, we replace the name and email address on your account with placeholders, sign you out everywhere, take your public profile offline, and release your profile link. For a Creator, we also erase the profile photo, bio, phone number, and social links. For a Brand, we erase the logo, company name, bio, website, verified domain, and badge; the contact name, phone number, industry, and social links stay unless you ask us to erase them (see “Asking us to erase them” below).
  • Connected platforms, devices, and tracking links: we delete your saved platform access tokens and push-notification registrations, blank the username, photo, and follower count stored on each platform connection record, delete your follower history, and stop the tracking links on your deals (as a Creator or a Brand), and a Creator's profile links, from redirecting. No new tracking link can be made on a deal once either person on it has deleted their account. The connection record itself stays: it keeps the platform, your account identifier there, the permissions you granted, and the dates (see Section 6.4).
  • Details we do not erase automatically: these stay in our database, attached to your anonymized account.
    • Profile details: your categories, languages, country, rate card, cover photo, headline, skills and tags, channel descriptions, next-available dates, availability, custom links, portfolio and case-study entries, and the follower counts stored on your profile.
    • Activity records: collaboration records, endorsements, follows and connections, saved lists, Brand cohorts (including the private note a Brand wrote about each Creator in one), reports you filed, people you blocked, the notifications you received, and the send-once records for deal reminders, draft emails, signature reminders, milestone target emails, payout notices and card dispute notices (which deal and piece, which email, and when; no message text or email address), failed payout notices (which Stripe event, and the day it was sent to the account; no message text or email address), failed retainer charge notices (which retainer, month and attempt), and retainer renewal notices (which retainer and month).
    • Notes and contacts: your pipeline and calendar notes, and the details of outside contacts you entered.
    • Links and account records: your tracking links (the web address each one points to, and its label), your Stripe payout account ID, and, for Brands, the private note that two accounts signed up with the same company email domain (it gives neither account access to the other).
  • Asking us to erase them: if you want any of these details, or the Brand contact details noted above, erased, email privacy@myhandle.app and we will handle the request as described in Section 9.4. If you can, email before you delete your account: after deletion your email address is no longer on the account, so we may not be able to match a request to it.
  • Your name in saved copies: some records keep a copy of your name from when something happened, and deleting your account does not change those copies. A contract keeps both parties' names (see Transaction records below). An application you sent to a campaign keeps your name, your pitch, and the rates you quoted. A campaign report keeps the Creator's and Brand's names, and if a share link was created for it, anyone with the link can still open the report until the link expires, 30 days after the report was made.
  • Notifications and reshares: a notification another person already received keeps your name if you caused it (for example, by liking or commenting on their post). A notification about a comment or a mention also keeps the first 80 characters of what you wrote, and a notification about a request for changes on a deliverable or draft keeps up to 500 characters of the reason a Brand wrote. A reshare of your post keeps a stored copy of your name and the profile handle you had when it was made, though the app shows it as “Deleted user”.
  • What stays when a Brand deletes its account: its company name stays on the collaboration entry and the feed post published on the Creator's profile when a deal completed. Campaigns the Brand posted are closed, not removed: their text stays and can still be opened by anyone who has their link, shown under “Deleted business”.
  • Deliverable and draft files: when your account is deleted, the video and image files you uploaded, including drafts and watermarked previews, are deleted for every deal that did not complete, and any older version you replaced is deleted even on a completed deal. If our file storage provider cannot carry out a deletion at that moment, that file can remain, and you can ask us to remove it at privacy@myhandle.app.
  • Files on a completed deal: we keep the rest of what you uploaded there: the final approved file, any draft that was not replaced, and their watermarked previews. We keep them as the record of what was delivered to the other party. Each time a Brand downloads an original file, we log which account downloaded it, when, and from which IP address, and keep that log with the file.
  • Messages and content: when you delete your account, your name is replaced with “Deleted user” (or “Deleted business”) on your posts, on your messages in the Messages inbox, and on your reviews. The photos on your posts are removed (including copies inside other people’s reshares), and your likes and comments on other people’s posts are removed. Your posts stop appearing in feeds, though the text of a post, and any video link attached to it, can still appear inside someone else’s reshare of it, shown under “Deleted user”. The public collaboration page for any deal you were part of is taken offline.
  • What stays in messages and content: the text of your posts and messages, and reviews you wrote or received, are retained so the other party’s records and conversations remain intact. You may email privacy@myhandle.app to request removal of specific content, subject to the transaction-record exceptions below.
  • Deal Room messages and attached files: messages you wrote inside a deal in the Deal Room keep the name saved with them. Files attached to messages or deals, such as brief files, Deal Room attachments, and screenshots saved as proof of results, also stay with the deal.
  • Transaction records (contracts, payments, fees, payouts): retained for at least 7 years to comply with US tax, financial-records, and audit requirements, and not erased when a party deletes their account. A contract keeps both parties' names as they were when it was created, the typed signatures, and the date, time, and IP address of each signature.
  • Moderation records: reports other people filed about you or your content, including what they wrote, stay in our database. If we remove a post for a policy or copyright reason, we also keep a record of the removal: our reason and a copy of the post's text. We use these records to count removals against an author, so we can enforce our repeat-infringer policy and answer a counter-notice. We do not delete them on a schedule, even after the account is deleted.
  • Tracking-link click records: we keep each click's one-way IP hash, approximate country, browser, and referring site with the link it came through, so a campaign report stays accurate. This includes clicks on the links on a Creator's profile and on links that were deleted or stopped working. We do not delete them on a schedule.
  • Tax forms: if you were never paid through Handle, we delete your tax form when you delete your account. If you were paid through Handle, we keep the tax form you filed for Handle's own tax reporting: your legal name, business name, address, form and taxpayer type, the encrypted ID number and its last four digits, and, for a W-8BEN, your citizenship, treaty country, and the encrypted foreign tax ID. We erase your date of birth and the IP address you certified from. A kept tax form is never shown to Brands once your account is deleted, and we keep it for at least 7 years.
  • Payment processor records: Stripe keeps its own records of payments, payouts, and identity checks under its own privacy policy and legal obligations. Deleting your Handle account does not close a Creator's Stripe payout account, so contact Stripe if you want it closed. When a Brand account is deleted, we remove its saved cards and the email address and name from its Stripe customer record; the customer record and the payments on it are kept as transaction records.
  • Activity and sign-up records: booking-page opens, profile views, early-access list and rate-report sign-ups, and the suppression list have no automatic deletion date. Email addresses on the suppression list stay there so we can honor an opt-out. You can ask us to delete other records about you at privacy@myhandle.app.
  • Server logs and error reports: these are not changed when you delete your account. Our server logs identify you by account number, and by email address if an email to you failed to send. Error reports sent to Sentry identify you by account number. Our hosting, error-monitoring, and email providers also keep their own logs on their own schedules.
  • Backups: our database host keeps routine backups, plus any one-off snapshot we take before a major change to the database. Information you delete can remain in a backup until that backup is deleted. We do not edit individual backups.
  • Aggregated and anonymized data: may be retained indefinitely.

9. Your Privacy Rights

9.1 Rights available to all US users

Regardless of your state, you may:

  • Access a copy of the personal information we hold about you.
  • Correct inaccurate personal information.
  • Delete your account and associated personal information yourself from Settings → Delete account (you confirm with your password, or with a code we email you if your account has no password because you only sign in with Google), or request deletion by email. We cannot delete an account while it has a contract waiting for signatures or in progress or, for Creators, earnings that have been released but not yet paid out, so finish or cancel those first. Some records are kept as described in Section 8.
  • Turn off most notification emails and the weekly summary (Section 7), and stop early-access list and deal-invite emails with the unsubscribe link in them.

9.2 California residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • Right to know: the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to delete: personal information we hold about you, subject to exceptions allowed by law.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing: Handle does not sell personal information and does not share personal information for cross-context behavioral advertising (ads aimed at you based on your activity on other companies' sites and apps). There is nothing to opt out of, and we do not currently read the Global Privacy Control signal.
  • Right to limit use of sensitive personal information: we use sensitive personal information (e.g., taxpayer identification numbers collected for tax documentation, stored encrypted) only as necessary to provide the Service and as permitted by the CCPA's limited-use exceptions; we do not use it for inferences about your characteristics.
  • Right to non-discrimination: we will not deny you the Service, charge you a different price, or provide a different level of service because you exercised your privacy rights.

9.3 Other US states

Residents of other US states with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Texas, Montana, Oregon, Delaware, New Jersey, New Hampshire, Kentucky, Maryland, Minnesota, and Rhode Island) have substantially similar rights to access, correct, delete, opt out of targeted advertising, opt out of sale, and opt out of certain profiling. Specific rights and verification procedures vary by state; we honor whichever framework applies to you.

9.4 How to submit a request

Email privacy@myhandle.app with the subject line "Privacy Rights Request" and a description of what you'd like to do. We will:

  • Acknowledge receipt within 10 business days.
  • Verify your identity by confirming you control the email address associated with your Handle account, and possibly by asking you to confirm one or two pieces of account information.
  • Respond substantively within 45 days, with a one-time extension of up to 45 additional days where necessary (we will let you know if an extension is needed).

You may designate an authorized agent to make a request on your behalf. We may require written authorization and identity verification from both you and the agent.

10. Security

We use industry-standard security practices to protect personal information, including:

  • Encrypted connections (HTTPS) that browsers are told to require.
  • Passwords stored only as bcrypt hashes, a standard method that scrambles them so they cannot be read back.
  • Taxpayer identification numbers and connected-platform access tokens encrypted before they are stored.
  • Sign-in sessions that expire after 7 days. Resetting your password ends all of them, and changing it in Settings ends all except the one you are using. Signing in with Google to an account that has a password you did not set through an emailed reset link ends all sessions except the one you just started.
  • An emailed one-time code before sensitive actions such as signing a contract or setting up payouts.
  • Rate limits on sign-in and other sensitive requests.
  • Card payments handled by Stripe, a PCI-compliant provider (it meets the card industry's security standard).
  • Administrative tools limited to a short list of authorized accounts. Those tools show account details (including email addresses), contracts, payments, and reports; they do not display messages or tax forms.

No system is fully secure. Choose a strong, unique password for your Handle account. You can also turn on two-factor sign-in in Edit Profile: after your password, we email you a one-time code. Two-factor sign-in requires a password on your account.

If we discover a security incident affecting your personal information, we will notify you and applicable authorities consistent with US state breach-notification laws.

11. Children's Privacy

The Service is not directed at children under 18 and we do not knowingly collect personal information from anyone under 18. To create an account, you must confirm that you are 18 or older and a US resident by ticking a box at sign-up, whether you sign up with email or with Google, and we record when you did. We do not check your age beyond that confirmation. If we discover that we have collected information from a minor, we will delete the account as described in Section 8, which also lists what we keep.

If the account has a contract waiting for signatures or in progress, or a Creator has earnings released but not yet paid out, we cannot delete it until those are finished, cancelled, or paid out (see Section 9.1). If you are a parent or guardian and believe a minor has used the Service, contact privacy@myhandle.app.

12. International Visitors

The Service is intended for residents of the United States only. We do not market to residents of the European Union, the United Kingdom, or other jurisdictions outside the US, and creating an account requires you to confirm that you are a US resident. We do not block visitors from other countries, so our public pages can be viewed from anywhere. If you access the Service from outside the US, you do so at your own initiative, your information may be transferred to and handled in the United States under this Policy, and you are responsible for complying with any local laws that apply to you.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. For material changes, we will notify you by email and/or by an in-Service notice at least 30 days before the changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

14. Contact Us

For questions about this Privacy Policy or to exercise your privacy rights:

Email: privacy@myhandle.app
Mail: Handle App, LLC
64 Piney Point Rd
Anaconda, MT 59711

Terms of Service·Back to Sign Up