Privacy Policy
Effective date: July 21, 2026
This Privacy Policy explains how Kolabl (“we”, “us”, “our”) collects, uses, stores, and shares information when you use our website, mobile experiences, and services (collectively, the “Service”). By using the Service, you agree to the practices described here.
1. Information we collect
Account information you provide
- Name, email address, profile photo
- Authentication identifier from your sign-in provider (Google)
- Profile fields you fill in: bio, tagline, location, niches, languages, content styles, rate card
Information from connected Instagram accounts
When you connect your Instagram Business or Creator account via Instagram Login, we receive only the data you authorise through the following permissions:
- instagram_business_basic — Your Instagram username, account ID, profile picture, biography, follower count, media count, and account type. Used to identify and display your connected account within Kolabl.
- instagram_business_manage_insights — Aggregate audience insights including impressions, reach, engagement metrics, audience demographics (age ranges, gender distribution, top countries and cities), story performance, and online-hours data. Used to populate your personal analytics dashboard (private to you) and, only if you choose to publish a Media Kit, the specific aggregate metrics you elect to display on it (see “Your public Media Kit” below).
We never receive your Instagram password. We do not collect data about your individual followers.
Information collected automatically
- Log data (IP address, browser type, request paths, timestamps)
- Cookies for authentication and session management
- Aggregate usage analytics (anonymised)
2. How we use your information
- To create and operate your Kolabl account
- To compute and display your analytics dashboard and audience metrics
- To send transactional communications (account, security, and service notifications)
- To match you with brand campaign briefs and include you in curated shortlists — only if you turn on Brand matching in Settings (it is off by default; see “Campaign matching” below)
- To detect, investigate, and prevent fraud and abuse
- To comply with legal obligations
3. How we share your information
We do not sell your personal data. We share data only in these cases:
Your public Media Kit (data you choose to publish)
Kolabl lets you create a Media Kit — a shareable page at a public URL (for example, app.kolabl.com/p/your-username) that you can send to brands. Publishing a Media Kit is entirely optional and under your control. If you choose to publish one, the specific information you select becomes visible to anyone with the link, which may include: your name, handle, profile photo and bio; selected aggregate metrics derived from your connected accounts (such as follower count, average reach, engagement rate, and aggregate audience demographics like age ranges, gender split, and top locations); your rate card / packages; and posts you specifically choose to feature.
You decide what to include, you can edit or remove items at any time, and you can unpublish the Media Kit entirely — which takes the public page offline. We never publish your individual followers' data, your private dashboard, or any metric you did not choose to display.
Campaign matching (optional, off by default)
If you enable Brand matching in Settings, our team may consider you when a brand submits a campaign brief and include you in a curated shortlist shared with that brand. A shortlist may contain: your name and handle, a link to your public Media Kit, aggregate account metrics (such as follower count, average reach, engagement rate, and top audience locations), your content niches, and your rate card. We never share your login credentials, private messages, or data about your individual followers.
This is opt-in: the toggle is off by default, and you can turn it off at any time in Settings, which excludes you from all future shortlists. Shortlists already delivered to a brand before you opted out are not retroactively withdrawn. We record when you change this setting so we can demonstrate your consent status.
Public showcase & creator directory (optional, off by default)
If you enable Feature me as a founding creator in Settings, we may display you on Kolabl's public pages — our landing page (the founding-creators showcase) and our public, filterable creator directory, where brands can browse and filter listed creators by niche and platform. In both places we show only: your name, handle, avatar, content niches, and total audience figure — derived from the figures shown on your published public Media Kit — with a link to that kit. Only creators with a published, publicly-visible Media Kit are shown. This consent is separate from Brand matching; enabling one never enables the other.
If you have set a city in Settings, enabling this option also counts you towards that city's total on our public creator map. We publish city-level counts only (for example “Mumbai · 3”), and only for cities on a fixed list we maintain — a city outside that list is not displayed at all. Your city is never shown next to your name or profile, and we never publish a more precise location. Setting a city on its own publishes nothing; it only counts once this option is on.
This is opt-in: the toggle is off by default, and you can turn it off at any time in Settings, which removes you from the showcase as our caches refresh — at most about 10 minutes. We record when you change this setting so we can demonstrate your consent status.
Deal records & scope-of-work acceptance
When a creator sends a scope of work through Kolabl, the brand contact reviews it at a private link. If the brand contact accepts, we record the acceptance as evidence of the agreement: the name they enter, their company's legal name, the date and time, the document's fingerprint (a cryptographic hash), and the IP address and browser signature of the accepting device. Before they click Accept, we show the accepting person a notice that their name, IP address and browser signature will be recorded; the date and time and the document's fingerprint are recorded automatically as part of the same acceptance record. This record exists so both parties can prove what was agreed; we retain it for as long as either party may need it as evidence of the contract. If the brand contact declines with a note, the note becomes part of the deal record and is shared with the creator.
As a deal progresses, further records are created and retained the same way: the deliverable links and note the creator submits; any change-request note the brand sends; and, if either party raises an issue, the issue description they write — which is shared with the other party and with Kolabl. If Kolabl mediates and records an outcome, the resolution note is shared with both parties.
Kolabl does not process, hold, or guarantee payment under any scope of work — payment is settled directly between the parties.
With service providers (data processors)
- Supabase Inc. — database hosting and authentication (United States, Singapore)
- Microsoft Corporation (Microsoft Azure) — backend application hosting (United States, East US region)
- Vercel Inc. — web hosting and CDN (United States, global edge network)
We maintain data-processing agreements with all processors that handle personal data on our behalf, limiting them to processing data only to provide the contracted service.
With Meta (Facebook / Instagram)
We access Instagram data via Meta's official Graph API. Our use of that data is governed by Meta's Platform Terms. We do not sell, license, or transfer Instagram or Facebook platform data to any third party. We do not use platform data to build advertising profiles or for any purpose beyond what is described in this policy.
For legal reasons
We may disclose information when legally required, when responding to a valid legal process, or to protect the rights, safety, or property of Kolabl, our users, or the public.
4. Your rights
You have the right to:
- Access a copy of your personal data
- Correct inaccurate information
- Delete your account and associated personal data
- Withdraw consent by disconnecting Instagram or closing your account at any time. Upon disconnection or account deletion, we delete your Instagram access token and all cached Instagram data within 24 hours.
- Object to or restrict certain processing
- Data portability — request a structured export of your data
To exercise any of these rights, see Data Deletion or email privacy@kolabl.com.
5. Data retention
- Account data — retained while your account is active.
- Instagram tokens and cached Instagram data — deleted within 24 hours of disconnecting Instagram or closing your account.
- Aggregated, fully de-identified peer benchmarks (e.g., median engagement for “Fashion / Nano-tier”) may persist after account deletion.
- Backup snapshots are retained on a 30-day rolling cycle and then permanently purged.
6. Security
We protect your data using industry-standard practices: encryption in transit (TLS) and at rest, role-based access control, principle of least privilege, and continuous monitoring. No system is perfectly secure; please notify us immediately of any suspected unauthorised access.
7. International transfers
Kolabl is operated from India, and our processors store and process data in the United States, the European Union, Singapore, and other regions. Where required, we rely on appropriate safeguards (e.g., Standard Contractual Clauses) for cross-border transfers.
8. Children's privacy
Kolabl is not intended for children under 13. We do not knowingly collect information from children. If you believe a child has provided us their information, contact privacy@kolabl.com and we will promptly delete it.
9. Changes to this policy
We will post material updates here and notify you via email when practical. Continued use of the Service after changes go into effect constitutes acceptance of the updated policy.
10. Contact
Questions about this policy?
Email: privacy@kolabl.com
Mail: Kolabl, Surat, Gujarat, India