Impresshyn
Privacy Policy
Impresshyn is a creator-led UGC agency. This policy explains what information our tools handle, why, and the choices you have. It covers our website, our creator analytics dashboard, our creator connect pages (connect.impresshyn.com), and the reports we publish for clients (reports.impresshyn.com).
Information we collect
- Creators who work with us: your name, the social handles you give us during onboarding, and the public statistics of the campaign accounts you run for us (video views, likes, comments, follower counts).
- Connected accounts: when you choose to connect a TikTok, Instagram, or Google/YouTube account through our connect page, we receive an access token from that platform and the account data described below. Connecting is always your action — we never access an account you have not connected.
- Clients: campaign-level aggregated statistics only. Client reports never include creator contact details.
Use of YouTube API Services
Our tools use YouTube API Services. By connecting a YouTube account through Impresshyn, you are agreeing to be bound by the YouTube Terms of Service. Google's handling of your information is described in the Google Privacy Policy.
Through the YouTube API we access, with your consent: your channel's identity (handle and channel ID), your channel and video statistics, and aggregated, country-level audience geography from YouTube Analytics. We do not access private videos, comments you can read privately, or any information about individual viewers.
You can revoke Impresshyn's access to your Google account at any time from your Google security settings, or by asking us to disconnect the account, which deletes the stored token.
How we use this information
- To show creators their own performance in their personal dashboard.
- To compile campaign analytics and verified view counts for the brand a campaign is run for.
- To bill clients based on verified, aggregated view counts.
Google user data is used only to provide these user-facing features, in line with the Google API Services User Data Policy, including its Limited Use requirements. We do not use it for advertising, we do not sell it, and no human reads it except as needed to operate the service, with your consent, for security, or to comply with law.
How we protect your data
Access tokens for connected accounts — including Google/YouTube tokens — are treated as sensitive data and are protected by the following measures:
- Encrypted in transit. Every connection to our services runs over HTTPS with TLS. All calls to Google, YouTube, TikTok and Instagram APIs are made over TLS. We serve no part of the service over plain HTTP.
- Encrypted at rest. Tokens and cached statistics are stored in Cloudflare D1, which encrypts stored data at rest on Cloudflare's infrastructure. Off-site backups of our own tools are encrypted with AES before they are written.
- Tokens stay on the server. Access and refresh tokens are only ever held server-side in our Cloudflare Workers backend. They are never sent to a browser, never written into any page we publish, and never exposed by any public endpoint. Our publishing process automatically refuses to release a page if a credential is detected in it.
- Secrets are not in our source code. API keys and client secrets are stored as encrypted Cloudflare Worker secrets, injected at runtime, and are not present in our code or in any published file.
- Access control. Administrative access to campaign data is restricted to Impresshyn's owner and is protected behind a secret key and an authenticated session; internal API endpoints require a bearer token. Creators can only reach their own connection page and their own statistics. Clients receive only aggregated campaign statistics, never tokens or personal contact details.
- Least privilege. We request read-only scopes only (
youtube.readonly and yt-analytics.readonly). We hold no write access: we cannot upload, edit, delete or comment on a connected account, and we never request more than the connected channel's own data.
- Separate credentials per environment. Development and testing use separate credentials and separate data from the live service, so production tokens are not used outside production.
- Deletion and revocation. Disconnecting an account — from the "Disconnect" control on your own connect page, by asking us, or by revoking access in your Google Account settings — revokes our access with the provider and deletes the stored token and that account's cached statistics from our database. Deletion is immediate, not scheduled.
Where data lives and how long
Connected-account tokens and cached statistics are stored on Cloudflare's infrastructure (Workers and D1), and statistics refresh roughly hourly while an account is connected. A token is kept only while the account is connected and is deleted as soon as it is disconnected. Cached statistics for a campaign are retained for that campaign's reporting and billing records, and are deleted on request.
We do not use Google user data — or any data obtained through YouTube API Services — to develop, improve or train generalized artificial intelligence or machine learning models. We do not transfer this data to any third party for that purpose.
Sharing
We never sell personal information. Data is shared only with: the client whose campaign the statistics belong to (aggregated form), and the infrastructure providers that run our tools (Cloudflare; Google, TikTok, and Meta as the platforms you connect).
Your choices
- Disconnect any connected account at any time — from your Google, TikTok, or Instagram security settings, or by contacting us.
- Ask us what we hold about you, or ask us to delete it: joey@impresshyn.com.
Contact
Impresshyn · joey@impresshyn.com · impresshyn.com