Sponlio Privacy
Sponlio stores the creator-platform data a creator authorizes. Instagram data can include profile metadata, media metadata, account insights and media-level insights. Connected YouTube/TikTok data can include profile identity, follower/subscriber counts and recent public-content performance returned by those official APIs. OAuth access and refresh tokens are encrypted at rest so creators can sync their accounts. Creators can also choose to store a public headline, location, collaboration email, category, public asking-rate overrides, and referral activity for their media kit and invite tools. Sponlio Pro creators can store private brand CRM details, deal terms, deliverables, deadlines, negotiation history, campaign-to-content links, campaign metric snapshots, invoice identity/payment instructions, invoices and payment-status records, creator-business expenses and follow-up reminders for their own workflow. Sponlio also stores daily Creator Intelligence snapshots such as follower count, Sponlio Score, recommended Reel rate and summarized performance so creators can see historical trends. Category benchmarks use aggregated connected-creator snapshot data and only expose cohort statistics after a minimum sample threshold; they do not expose another creator’s private account record. Brand-facing report and invoice pages are accessible to anyone who has their unguessable share URL, so creators should share those URLs only with intended recipients. Access tokens are encrypted at rest and are never exposed in public creator profiles.
Creators can disconnect Instagram or delete their Sponlio account from the app. Account deletion removes the creator account, stored Instagram, YouTube and TikTok connections, imported platform/media metadata, account/media insight snapshots, Creator Intelligence history snapshots, media-kit settings, rate overrides, private brand/deal CRM records, contract review text and findings, generated deal memos/agreements, saved AI-assistant outputs, campaigns, sponsored-content metric snapshots, invoices, invoice profile/payment instructions, deliverables, deal activity, referral records/codes, billing linkage records, and active sessions from Sponlio's database. If the account has a Stripe web subscription, Sponlio requests cancellation when the account is deleted. App Store subscriptions are managed by Apple and must be cancelled through Apple separately.
For subscription operation Sponlio stores the minimum billing linkage and entitlement state needed to determine Pro access, such as provider, product/price identifier, external subscription identifier, status, expiration/renewal state and Stripe customer mapping. Payment card details are not stored by Sponlio.
Sponlio's manual creator-outreach CRM can store public Instagram usernames, approximate follower counts, niche labels and outreach notes. It does not send automated Instagram messages. When a matching creator deletes their Sponlio account, the matching outreach record is removed as well.
Contact: privacy@boxtheorylabs.com