← Back to Home
Privacy Policy
Effective Date: August 14, 2026 | Last Updated: August 14, 2026
At DraftCollab ("we", "our", "us"), protecting your privacy is foundational to how we operate. This Privacy Policy ("Notice") explains how we collect, use, store, disclose, and protect your personal data when you use our mobile applications, web platforms, and APIs (the "Services"). This Notice is drafted in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA"), the DPDP Rules, 2025, the Information Technology Act, 2000, and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
1. Scope
This Notice applies to all registered Creators, Business/Brand representatives, and visitors who access DraftCollab. By creating an account or using the Services, you acknowledge that your personal data will be processed as described here.
2. Our Role as Data Fiduciary
Under the DPDPA, DraftCollab acts as the Data Fiduciary, responsible for determining the purpose and means of processing your personal data. We follow the principles of data minimisation, purpose limitation, storage limitation, and lawfulness in everything we collect.
3. Personal Data We Collect
We collect only what is needed to connect local Creators with nearby Businesses:
•A. Creator Profile Data: Full name, display name, primary city, profile avatar, bio, niche categories, trust score, unique referral code.
•B. Business & Brand Data: Registered business name, representative name, business category, contact email/phone, city, and geolocation coordinates for local campaign discovery.
•C. Campaign & Collaboration Data: Paid and barter campaign details, applications, deliverable status, in-app workspace messages, completion records.
•D. Community Feed Activity: Public posts, replies, likes, poll votes, and your selected feed scope (local city vs. India-wide).
•E. Technical & Telemetry Data: Push notification tokens (FCM), IP address, device model, OS version, app version, crash reports, and security logs.
•F. Cookies & Similar Technologies (Web Platform): If you use our web platform, we use strictly necessary cookies for login sessions and security, and, where you consent, analytics cookies to understand feature usage. You can control cookies through your browser settings; disabling non-essential cookies will not affect core functionality.
🚫 Device Contacts Privacy Guarantee: We do not read, harvest, upload, or store your device address book or contacts. Your device contact list stays private to your device at all times.
4. Purpose and Legal Basis for Processing
The DPDPA recognises two lawful grounds for processing: (i) your consent, and (ii) a defined set of "certain legitimate uses" under Section 7 of the Act. We rely on these as follows:
•Account creation & OTP login (Name, phone number, role) — Consent (Section 6)
•Social verification & Creator metrics (OAuth tokens, follower/engagement data) — Consent (Section 6)
•Local campaign matching (Business geolocation, Creator city) — Voluntarily provided for the specified purpose you signed up for — Section 7(a)
•Security, fraud & abuse prevention (IP address, device data, system logs) — Certain legitimate uses — prevention/detection of fraudulent activity, Section 7
•Compliance with law enforcement or court orders (Relevant account/campaign data, as required) — Compliance with law — Section 7
Where we rely on consent, you may withdraw it at any time through Profile Settings, as easily as you gave it — this will not affect the lawfulness of processing carried out before withdrawal.
5. Contact Privacy & Data Security
•Contact Shielding: Your phone number and email remain hidden from public view and are shared only with a collaboration partner after mutual approval of a proposal.
•Zero Commercialisation: We do not sell, rent, trade, or lease your personal data or social statistics to advertisers or data brokers.
•Security Measures: Data in transit is protected with SSL/TLS (256-bit). Data at rest (Supabase & Firebase) is protected using Row-Level Security policies and AES-256 encryption. We conduct periodic access reviews on production systems.
•Breach Notification: If a personal data breach occurs that is likely to affect you, we will notify affected users without undue delay, in plain language, describing what happened, the likely impact, and the steps we're taking — consistent with DPDPA breach notification requirements.
6. Payments, Financial Transactions & Non-Liability
DraftCollab is strictly a technology discovery, matchmaking, and communication platform connecting local Creators and Businesses. We never collect, hold, escrow, process, or guarantee any monetary payment, sponsorship fee, or barter deliverable between users. All payments, barter products, and service redemptions are negotiated and executed directly between the Business and the Creator, off-platform. See Terms of Service Section 4 for the corresponding liability position.
7. Data Retention & Account Deletion
•Active account data is retained while your account remains active.
•On deletion (via Profile Settings): personal identifiers (name, email, phone, avatar, OAuth tokens) are permanently purged within 30 days. Historical collaboration records involving another user are anonymised (shown as "Deleted Creator" / "Deleted Business") rather than fully erased, since the other party retains a legitimate record of the collaboration.
8. Your Rights Under the DPDPA
As a Data Principal, you have the right to:
•Access — request a summary of the personal data we process about you.
•Correction & Completion — update inaccurate data directly in Profile Settings.
•Erasure / Withdrawal of Consent — delete your account or disconnect linked social accounts at any time.
•Grievance Redressal — raise concerns with our Grievance Officer (below), and escalate to the Data Protection Board of India if unresolved.
•Nomination — nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
9. Grievance Officer
In line with DPDPA Section 13 and Rule 3(2) of the IT Rules, 2021:
•Attn: Grievance Redressal Officer, DraftCollab
•Email: draftcollabsupport@gmail.com
•Subject Line: "Data Rights Request – DraftCollab"
•Acknowledgment: within 24 hours of receipt. Resolution: within 15 days of receipt (in line with IT Rules, 2021, Rule 3(2)).
10. Cross-Border Data Transfers
•We use cloud infrastructure hosted by Firebase (Google LLC) and Supabase, which may store and process data outside India. Transfers are made in accordance with DPDPA Section 16, which permits transfer outside India except to countries specifically restricted by the Central Government from time to time. Data remains protected in transit and at rest as described in Section 5 above regardless of storage location.
11. Children's Privacy (18+ Only)
•DraftCollab is intended solely for individuals 18 years or older. We do not knowingly collect data from minors. If we discover a minor has registered, the account and all associated data will be purged immediately upon discovery.
12. Updates to This Policy
•We may update this Privacy Policy to reflect product changes or legal requirements. We will notify you of material changes at least 30 days before they take effect, via in-app notice or email, matching the notice period in our Terms of Service.
13. Google API Services & YouTube User Data Disclosure
DraftCollab accesses YouTube user data through Google OAuth (specifically the https://www.googleapis.com/auth/youtube.readonly scope) to allow creators to authenticate and display their verified channel metrics.
•A. Data We Access and Collect: YouTube Channel Information (Channel ID, Channel Title, Description, Custom URL, Avatar thumbnail), and Channel Statistics (Subscriber count, view count, total video count, and public performance metrics).
•B. How We Use Google User Data: Exclusively to verify creator authenticity and ownership of the linked YouTube channel, and to display verified subscriber reach and channel metrics on the creator's DraftCollab profile for brand collaboration matching.
•C. Sharing, Transfer, and Disclosure of Google User Data: No Selling or Renting: DraftCollab DOES NOT sell, rent, lease, or trade Google user data to any third parties, data brokers, or advertising networks. We do not transfer or disclose Google user data to third parties, except: (1) Displaying public channel metrics (Channel Name, Subscriber count, avatar) to registered businesses within the platform for collaboration matching with creator consent; (2) As required by law, subpoena, or valid legal process. Google user data is never used for generalized AI/ML model training, and no human employees or contractors read or inspect your private Google user data.
•D. Google API Limited Use Compliance: DraftCollab's use and transfer to any other app of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
•E. Data Retention and Revocation: Users can disconnect their YouTube channel or delete their DraftCollab account at any time in App Settings, which permanently deletes all stored Google tokens and metrics from our servers. You may also revoke DraftCollab's access at any time via
Google Security Settings.
•F. Data Storage, Security & Infrastructure (Supabase): All creator YouTube data, OAuth authentication tokens, and channel metrics retrieved through Google APIs are securely stored on our backend infrastructure hosted on Supabase (PostgreSQL engine) with AES-256 encryption at rest, TLS 1.3 encryption in transit, and strict Row-Level Security (RLS) policies. Access is strictly restricted to authenticated user sessions.
14. Meta & Instagram Graph API User Data Disclosure
DraftCollab integrates official Meta & Instagram Graph APIs to verify creator profiles and provide authentic analytics for brand collaborations.
| Data / Scope |
Purpose & Use |
Storage & Security |
instagram_basic Profile & Handle |
Verify creator identity and display profile thumbnail on brand marketplace |
Supabase (AES-256 encryption, Row-Level Security) |
instagram_manage_insights Reach & Analytics |
Calculate reach metrics (followers, engagement rate, average views) for campaign matchmaking |
Supabase (Encrypted tokens; No passwords or direct messages ever accessed) |
•A. Zero Credentials Access Guarantee: We never request, access, or store your Instagram passwords, private direct messages (DMs), stories archives, or non-public personal posts.
•B. Storage on Supabase: All verified Instagram metrics and access tokens are securely stored on our backend infrastructure hosted on Supabase with AES-256 encryption.
•C. Meta Data Deletion, Revocation & 14-Day Grace Period: You can disconnect your Instagram account anytime in App Settings or revoke permissions externally via your Facebook/Meta Settings → Apps and Websites → Remove DraftCollab. Upon revocation, DraftCollab respects your choice immediately. To prevent accidental disruption to ongoing brand collaborations, DraftCollab provides a 14-day reconnection grace period during which you can re-authenticate. If not reconnected within 14 days, your verified creator status and access to verified campaign listings will be paused until you re-authenticate.