1. Controller and contact
NETSKY GROUP LTD is a private company limited by shares registered in England and Wales under company number 10677601, with its registered office at 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX.
NETSKY GROUP LTD is the controller for the processing described in this Policy, except where we act on a business customer's documented instructions for customer workspace content. Privacy requests and complaints can be sent to influrscom@gmail.com or by post to the registered office. Mark postal requests “Data Protection”.
This Policy applies to influrs.com, the Influrs web application and related support, account, workspace and billing interactions. A separate Creator Data Notice gives Article 14 information for creators whose public profile data was not obtained directly from them.
2. Who this Policy covers
- Visitors and people who interact with public stories, creator profiles, external source links or an enabled third-party interface.
- Registered members, workspace owners, members and invitees.
- Customers and billing contacts.
- Creators, authorised representatives and people who submit a claim or privacy request.
- People who contact support, make a complaint or report content.
3. Data, purposes, legal bases and retention
The table summarises our main processing. “Contract” means processing needed to provide requested account or paid features; “legitimate interests” means operating a useful, secure and accountable creator-discovery service after balancing those interests against people's rights; “legal obligation” means record-keeping, consumer, tax, data-protection or other duties; and “consent” applies only where you have a real choice and can withdraw it.
| Data and purpose | Legal basis | Retention or criterion |
|---|---|---|
| Account and profile: name, email, avatar, locale, preferences, authentication provider and verification status; to create, secure and personalise an account. | Contract; legitimate interests in account security. | While active. A deletion request immediately closes access and revokes credentials; non-financial data is then erased. A durable retry record and only the minimum provider or billing locator needed for an unfinished purge/cancellation may remain until that step succeeds. The completed retry record is unlinked; records required by law follow their stated retention. |
| Sessions and security: session identifier, IP address, user agent, device/session records, timestamps and security events; to authenticate, prevent abuse and troubleshoot. | Contract; legitimate interests in security; legal obligation where applicable. | Browser session records normally expire after 120 minutes of inactivity. Rotating application logs are normally kept for 14 days; specific incident evidence may be retained while needed for investigation or claims. |
| Library and community: followed creators, saved stories, comments, replies, votes and reports; to provide member features and moderate content. | Contract; legitimate interests in community safety and enforcing rules. | Until removed or the account is deleted. On account deletion, comments may remain attributed to “Deleted user”; direct account and visitor links are removed. |
| Workspace data: organisation, members, roles, invitations, portfolio records, notes, tags, alert rules and delivery history; to provide collaboration and alerts. | Contract; legitimate interests of us and the customer. We may act as processor for customer-directed content. | For the workspace term and deletion cycle, subject to backups, disputes and records the customer or law requires. |
| Creator and platform data: profile, channel and video identifiers, names, handles, images, locations, languages, links, public content metadata and public counts; and existing free-text biography or claimed-profile contact/commercial fields. Broad automated discovery, public free-text biography output and public contact/commercial output remain disabled until the Article 14, sensitive-data and field-provenance controls are complete. Legacy identifying YouTube API records are retained only in restricted quarantine with a pending exact-channel consent record and are neither refreshed nor displayed; a current durable consent is required before any public-directory use. OAuth Authorized Data is not used as a public-directory source. | Legitimate interests for permitted non-YouTube indirectly obtained profile data. Contract, and consent where required, when a creator claims or requests a connection. Legitimate interests do not replace YouTube's consent requirements. | Legacy identifying YouTube API data without the required consent is kept only in restricted quarantine, is not refreshed or displayed, and is deleted when the pending retention deadline (no more than 30 days) expires. Where a permitted non-authorised YouTube API use exists, that data is refreshed or deleted within 30 days. Other profile data is retained only while relevant, attributed and subject to correction, objection and periodic review. |
| Creator claims and OAuth: requester identity, provider account identifier, approved scopes, encrypted access/refresh tokens, token expiry, connection state, checks and bounded compliance events; to verify control and run requested official platform features. | Contract; legitimate interests in preventing false claims and evidencing compliance. | While connected and for the deletion periods in section 6. A failed remote Google revocation retains the encrypted credential and exact channel locator only on a restricted revocation-pending record for hourly retry until a non-resetting deadline one hour before the seven-day maximum. Google confirmation starts the exact local purge sooner; otherwise the deadline irreversibly deletes credentials and scopes locally and attempts the purge even without confirmation. For connected services other than Google, a failed remote token-revocation request is retried hourly until the provider confirms it or a fixed, non-resetting conservative internal deadline is reached, no later than 6 days and 23 hours after the first request. At that deadline Influrs irreversibly deletes the local token and scopes and records that remote revocation was not confirmed; the user may still need to remove Influrs in the provider's own security settings. A physical-storage-only failure leaves the original application records detached or deleted; the physical object and a separate retry record with a random identifier, storage disk and encrypted path, without an account, creator, channel or connection identifier, may remain outside normal application surfaces solely until physical erasure succeeds. If the database transaction fails, affected linked data may remain restricted in a purge-pending state while exact local deletion is retried. No usable token remains in either case. Tokens are never included in a user export. |
| Terminal deletion of a connected non-Google platform graph: the exact provider-linked social account, content, metric snapshots and daily aggregates, collection records and provider data-source record; plus inferred topics, scores and provider-derived creator fields. | Contract; legitimate interests in honouring the disconnection and data-minimisation duties. | Deleted when remote revocation is confirmed or the fixed local deadline is enforced. If another active connection is independently authorised for the same exact provider account, the shared graph is preserved for that connection. Otherwise uncertain provider-derived creator identity fields are cleared and a profile with no remaining active account is archived and made private. A database failure leaves the graph non-public and non-syncable in a restricted purge-pending state until the durable retry succeeds. |
| Billing: Stripe customer, checkout, subscription, invoice, tax, payment-status and limited payment-method details; to take payment, manage access, prevent duplicate charges and keep accounts. | Contract; legal obligation; legitimate interests in fraud prevention and reconciliation. | Billing is currently disabled. The application is configured to prune redacted webhook payload detail after 30 days when the scheduled job is operating. Before billing is enabled, the production schedule, deletion evidence and a documented retention period for the remaining minimal event, invoice, transaction, tax and accounting records must be verified. Those core records are then kept only for the approved tax, accounting, claims and legal-obligation period, with a documented extension for a live dispute or other binding duty. |
| AI interactions: briefing prompts, conversation messages, output, usage counters and, for authorised editorial work, manually supplied, uploaded or separately licensed transcript text and instructions; to provide the requested feature, prevent misuse and preserve the user's conversation. | Contract; legitimate interests in safe and reliable operation. | Briefing conversations remain with the account until deletion. Raw temporary article transcript files from manual or separately licensed sources are encrypted and expire within 24 hours. |
| Analytics consent history: account identifier while linked, purpose, granted/denied status, policy version, source and timestamp; to record and enforce the user's choice and demonstrate compliance. | Legal obligation; legitimate interests in accountability and preventing optional tracking contrary to the recorded choice. | Linked to the account while it exists so we can record and enforce the user's choice and demonstrate compliance. The consent history is deleted when the account is deleted; Influrs does not retain an unlinked consent history after account deletion. |
| Optional product analytics: browser consent state; a pseudonymous HMAC visitor identifier and, for a consented signed-in event, the account user ID; client event ID, event type, path/feature context, referenced story or creator, bounded event metadata and daily aggregate; to understand and improve Influrs. The feed-experiment assignment and event runtime is disabled and creates no new records; legacy experiment records may remain only within the deletion period below. | Consent for optional product analytics. The feed-experiment runtime is disabled. Legal obligation and legitimate interests in respecting and evidencing a withdrawal and preventing stale requests from restarting tracking apply only to the minimal suppression marker. | No more than 365 days for raw events, anonymous daily aggregates and any legacy experiment records. Withdrawal immediately records a denied choice and stops new optional events. Once server cleanup succeeds, it removes the local analytics identifier and any legacy experiment visitor identifier and deletes raw analytics events and legacy experiment assignments/events linked to the signed-in user, HMAC visitor identifier or legacy experiment cookie. If cleanup fails, the original local analytics visitor identifier and a source-only pending-withdrawal marker remain solely to retry that deletion while tracking stays off; they are removed when cleanup succeeds. To respect the withdrawal and reject delayed requests carrying a stale grant, the server then retains a namespaced HMAC subject marker with denial and expiry times—but no raw account, visitor or experiment identifier—for no more than the same 365-day period and prunes it afterwards; a later valid grant clears the denial for that subject. Irreversible daily totals that no longer identify or link to a person remain only for the stated retention period. |
| Support, privacy and content reports: contact details, message, evidence, URLs, status and our response; to answer, investigate, protect rights and demonstrate handling. | Contract; legitimate interests; legal obligation. | Until the matter is closed and then only while reasonably needed for complaint, limitation, regulatory and accountability requirements. |
4. Where data comes from and what you must provide
We collect data from you when you register, configure preferences, comment, report, invite a member, enter workspace content, connect a platform, use an AI tool, buy a plan or contact us. Technical data comes from your browser, device and our security infrastructure. Payment status comes from Stripe. Authentication and connected-platform data comes from the provider you choose.
Creator data may come from the creator or an authorised representative, licensed data providers, attributable editorial research of publicly available sources, and documented official platform APIs only where the source rules and required consent permit the particular use. Legacy YouTube API records may be retained in restricted quarantine pending separate consent tied to the exact channel, but are not refreshed or used for an unclaimed public profile; OAuth Authorized Data is not a public-directory source. We do not use scraping or undocumented interfaces to obtain YouTube data or content.
Required fields are marked in the interface. Without account and authentication data we cannot create or secure an account; without billing data we cannot supply a paid plan; without an OAuth grant we cannot provide the connected feature. Optional profile, analytics and marketing choices are not conditions of unrelated core service.
6. YouTube API Services, OAuth and captions
Influrs uses YouTube API Services only through permitted, attributed functions. At present, new connection, import, refresh, scheduled synchronisation, embedded playback and captions-to-AI paths are unavailable; the remaining API-related processing is limited to validating, revoking and deleting legacy authorisations and data. Legacy records remain only in a restricted, non-public quarantine pending a durable exact-channel consent; they are not refreshed or disclosed, and a pending record expires within 30 days. Any future enabled channel or video function would require the controls described below before it could verify control or synchronise data for an approved purpose. YouTube data can include channel/video IDs, titles, descriptions, thumbnails, publication details and public statistics. Identifying data about an unclaimed creator is not shown without separate, durable consent tied to the exact channel. A UK GDPR legitimate-interests basis does not replace that platform consent. Our use is governed by the YouTube API Services Terms of Service and YouTube API Services Developer Policies.
New standard YouTube account connection is currently unavailable until Influrs stores a durable, versioned affirmative acceptance of the Influrs Terms, this Privacy Policy and the linked YouTube Terms of Service, together with separate consent for the exact channel, data, purpose and permitted recipients. OAuth may verify channel control and authorise a private connected feature, but Authorized Data obtained through OAuth is visible only to the authorising user or agents expressly approved by that user and is not a source for the public directory. If enabled after those controls are implemented, the connection will request only the configured read scope. A future captions workflow would require Google's broader `youtube.force-ssl` permission, whose Google consent description includes viewing, editing and permanently deleting videos, ratings, comments and captions. The current article-generation flow does not request that scope: its captions OAuth, API-download and AI-processing paths are blocked until a durable, versioned owner authorisation and AI disclosure record is implemented.
Public and non-authorised YouTube API Data is refreshed or deleted within 30 days. On an in-app disconnect, we attempt remote OAuth revocation immediately and must delete associated authorised data as soon as possible and no later than 7 calendar days; the same local-deletion maximum applies after account deletion or a user's deletion request. A transient remote failure is retried only until a fixed deadline before that maximum, when credentials are deleted locally and exact purge proceeds even without remote confirmation. A physical-storage-only failure detaches or deletes the original application records; the physical object and a separate encrypted-path retry record without account, creator, channel or connection identifiers may remain outside normal application surfaces solely while physical erasure is retried. A failed database transaction leaves affected linked data restricted while exact deletion is retried. No usable token remains after the deadline. If access is revoked in Google Security Settings or a token becomes invalid and cannot be refreshed, related API Data is deleted as soon as possible and no later than 30 days.
Deletion from Influrs does not delete a video, channel, caption or other content stored on YouTube. You can manage Google access in Google Security Settings. Google processes data under the Google Privacy Policy. Use of YouTube features is also subject to the YouTube Terms of Service.
While this path is blocked, no new authorised YouTube caption retrieval, staging or AI processing begins. Any pre-existing caption-derived draft, source metadata or associated media remains subject to the applicable deletion and purge rules. Manually supplied, uploaded or separately licensed article transcripts are encrypted in temporary storage and deleted within 24 hours. Any residual compliance record must be irreversible, unlinkable and contain no API Data or caption content.
YouTube embedded playback is also unavailable. Influrs provides only an external source link until it can look up and retain the current `status.madeForKids` value for each proposed video through the documented API and enforce the required no-tracking and applicable-law controls for every Made For Kids player.
8. International transfers
We are established in the United Kingdom. A provider or its support team may process data outside the UK. We make a restricted transfer only where the transfer is lawful: for example under an applicable UK adequacy regulation or an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum to approved standard clauses, together with a transfer risk assessment and supplementary measures where required.
The relevant provider entity, role, processing countries and safeguard depend on the production service actually used; we do not publish an unverified entity or country. You may request information about an applicable active transfer and its safeguard by contacting us. A new provider, country or material safeguard change requires assessment before the affected protected data is transferred.
9. Security
We use proportionate technical and organisational controls, including access restrictions, encrypted transport, encryption for stored OAuth tokens and temporary transcripts, secret separation, logging, backups, rate limits, deletion jobs and supplier controls. No internet service can guarantee absolute security.
If a personal-data breach creates a legal notification duty, we will notify the ICO and affected people within the applicable timescales. Please report suspected account or data compromise promptly.
10. Profiling and automated decisions
Influrs may personalise a feed, apply search and ordering rules, detect abuse, or generate AI drafts. These activities do not make a solely automated decision that produces legal or similarly significant effects about you. Creator verification and material moderation decisions use defined checks and, where needed, human review.
We do not enable YouTube-derived influence, suitability, brand-safety or similar scoring unless the required platform approval and a separate lawful product decision are documented. Public counts and editorial context are not eligibility or employment decisions.
11. Service messages and marketing
We send account, security, billing, workspace and alert messages needed for features you use. You can manage optional alerts in account or workspace settings, but cannot opt out of messages necessary to administer a live account or contract.
We send electronic marketing to individuals only with valid consent or where the complete UK soft opt-in conditions apply. Marketing consent is separate from these Terms and can be withdrawn in the message or by contacting us. We do not disguise the sender or make unsubscribe harder than signup.
12. Your data-protection rights
Depending on the circumstances, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. You may also complain and, where applicable, challenge an automated decision.
An objection to processing for direct marketing is absolute: we will stop that marketing. We may keep only the minimum suppression record needed to ensure that the address or account is not contacted again.
Use Account → Privacy for account export or deletion, follow the correction/removal instructions linked from a creator profile, or email influrscom@gmail.com. We may need proportionate identity verification. We normally respond within one month; for a complex or numerous request, the law may allow up to two additional months, and we will explain the extension within the first month.
Other rights are not absolute. For example, we may retain limited records to meet law, protect another person's rights or establish a legal claim. We will explain any refusal or restriction.
13. Privacy complaints and the ICO
Send a data-protection complaint to influrscom@gmail.com with enough detail to identify the issue and desired outcome. We will facilitate complaints, acknowledge receipt within 30 days, investigate without undue delay and keep you informed of progress and the outcome.
You may complain at any time to the UK Information Commissioner's Office (ICO). ICO telephone: 0303 123 1113. You may also have the right to complain to the supervisory authority where you live or work. We ask, but do not require, that you contact us first so we can try to resolve the issue.
14. Children and sensitive data
Influrs is for people aged 18 and over. We do not knowingly create accounts for children. If you believe a child has provided account data, contact us so we can investigate and delete it where appropriate.
Do not submit special-category data, criminal-offence data or another person's confidential information unless it is strictly necessary, lawful and you are authorised. We do not intentionally infer sensitive traits from public creator data for eligibility or significant decisions.
15. Changes to this Policy
We publish the effective and update dates above. We will give registered users reasonable advance notice of a material change where practicable and seek fresh consent if a new purpose requires it. Earlier versions and consent records may be retained where needed to show which notice applied.