Legal & Privacy.
Official legal terms for Brand and Creator users.
Table of Contents
Last Updated
May 06, 2026
1. Privacy Policy
This Privacy Policy applies only to Brand Users and Creator Users of TrueDian AI (the "Platform"). It describes how we collect, use, disclose, retain, and protect personal information when you access campaign collaboration, creator fulfillment, analytics, and settlement services.
By creating an account or using the Platform, you acknowledge this Privacy Policy. If local law requires additional notices, those notices form part of this policy.
1.1 Definitions
- - "Brand User" means an enterprise or authorized representative using the Platform to create or manage campaigns.
- - "Creator User" means an individual or team using the Platform to discover, accept, or deliver campaign tasks.
- - "Personal Data" means information that identifies, relates to, or can reasonably be linked to an identifiable person.
1.2 Information We Collect
- - Registration and account data: email, role, authentication credentials, and profile metadata.
- - Verification and compliance data: KYB or KYC records, document metadata, and verification outcomes.
- - Campaign operations data: campaign briefs, creator submissions, review decisions, and communications.
- - Financial and settlement data: transaction identifiers, payout requests, invoice details, and status logs.
- - Technical and security logs: device context, IP region, request diagnostics, and trace identifiers.
- - AI interaction data: user-provided prompts/inputs and generated outputs used to deliver AI features.
1.3 How We Use Information
- - Provide account access, identity checks, campaign workflows, and payout operations.
- - Deliver AI-assisted analysis, matching, and strategy generation features.
- - Detect abuse, fraud, unauthorized access, and policy violations.
- - Maintain product reliability, resolve incidents, and perform service analytics.
- - Improve service quality and model-assisted features, subject to applicable law and user controls where available.
- - Satisfy contractual, legal, tax, and regulatory obligations.
1.4 Social Media Data We Collect
- - Connected account identifiers: platform account ID, handle, profile URL, and account category where available.
- - Audience and growth metrics: follower ranges, audience geography, and trend indicators returned by connected platform APIs.
- - Performance and engagement metrics: impressions, views, likes, comments, shares, saves, click-through, and conversion indicators where available.
- - Content and campaign execution signals: published content metadata, posting cadence, campaign task status, and delivery evidence submitted in the Platform.
- - Risk and integrity indicators: anomaly flags, anti-fraud checks, and policy violation records used to protect marketplace trust.
1.5 Data Sources and Connected Account Authorization
We collect data from (a) information you provide directly, (b) connected third-party social media platforms through authorized APIs or OAuth flows, (c) campaign workflow interactions, and (d) security and operation logs generated by service use.
When you connect a social account, you authorize access within the permission scope shown at connection time. You can revoke authorization in your platform account settings and/or through available controls in TrueDian AI.
1.6 Cookies and Similar Technologies
We use essential cookies and similar technologies to support login sessions, fraud prevention, and core platform reliability.
Where permitted by law, we may use analytics or preference technologies to improve service quality. You can manage browser-level cookie settings, but disabling certain technologies may affect account access or feature availability.
1.7 Legal Grounds (Where Applicable)
Depending on your jurisdiction, we may process personal data based on contract performance, legitimate interests, legal obligations, and consent. Where consent is required by law, you may withdraw it subject to applicable limitations.
1.8 Sharing and Disclosure
We may share minimum-necessary data with service providers, including cloud hosting, payments, communications, security infrastructure, and AI processing vendors. These parties are subject to contractual confidentiality and security obligations.
For campaign execution, we may share relevant creator performance and delivery information with authorized Brand Users within the scope necessary for campaign collaboration, compliance, settlement, and dispute resolution.
We may also disclose information where required by law, lawful process, or to protect rights, safety, and platform integrity.
1.9 Brand Visibility and Data Minimization
- - Visible to authorized Brand Users: campaign-level performance aggregates, delivery status, approved creator profile signals necessary for campaign execution.
- - Visible in minimized or masked form: direct identifiers, contact details, and sensitive account-linked values unless disclosure is required for contract execution, settlement, or legal compliance.
- - Not visible by default: access credentials, refresh tokens, internal risk engine signals, and unrelated third-party account metadata.
1.10 International Transfers
If data is transferred across borders, we use legally recognized safeguards, including contractual protections, technical controls, and transfer minimization practices.
1.11 Retention by Data Category
- - Account registration and profile data are retained while your account remains active and for a reasonable period after closure for compliance and dispute handling.
- - Connected social platform tokens and refresh credentials are retained only as long as needed to maintain authorized integrations and are revoked or invalidated when connection is removed or authorization expires, subject to lawful retention obligations.
- - Transaction, settlement, and invoice records are retained according to legal and tax retention requirements in applicable jurisdictions.
- - Security, anti-fraud, and access logs may be retained for risk monitoring, investigations, and platform protection requirements.
- - Support and communications records are retained to resolve service disputes, quality reviews, and legal obligations.
- - Where local law does not mandate a specific period, operational records are typically retained for a limited business-necessity window and then deleted or de-identified under internal retention schedules.
1.12 Security and Incident Response
We retain personal information for as long as needed to deliver services, enforce agreements, satisfy legal obligations, and resolve disputes. Data is deleted or anonymized when retention is no longer required.
We implement appropriate technical and organizational security measures, including access controls, encryption where appropriate, auditing, and incident response procedures. No system is absolutely secure.
Where required by applicable law, we provide notice of qualifying personal data breaches to users and regulators within required timelines.
1.13 Your Rights, Requests, and Appeals
Subject to local law, you may request access, correction, deletion, restriction, portability, or objection.
Submit requests to [email protected] or [email protected]. We may require identity verification before processing requests. We provide an initial response within 30 days and aim to close requests within 45 days, unless local law permits or requires a different timeline.
Available controls may include account data access, export, correction requests, deletion requests, restriction requests, and revocation of connected social account authorization.
Where a request cannot be completed in the initial window due to complexity or legal review requirements, we provide delay notice and appeal instructions as required by local law.
1.14 Children and Minimum Age
The Platform is not intended for children below the minimum legal age in the relevant jurisdiction. If we learn that prohibited child data has been provided, we will take reasonable steps to delete or de-identify it as required by law.
1.15 Updates and Effective Date
We may update this policy due to legal, operational, or product changes. Material updates will be posted with a revised date and, where required, direct notice. Effective Date: May 06, 2026.
1.16 Regional Supplements and Priority
For specific jurisdictions, supplemental privacy notices may apply (including EEA/UK, US state-specific, and other regional requirements). Where a regional supplement conflicts with this global policy, the regional supplement controls for users in that jurisdiction.