Privacy Policy
Klymb Studio (“Klymb”, “we”, “us”) operates klymbstudio.com, a platform where brands and agencies run UGC (user-generated content) campaigns with independent creators. This policy explains what personal data we collect, why, and the rights you have over it. It applies to brands, agencies and creators using the platform, and to visitors of this site.
Klymb Studio is the data controller for the processing described here. You can reach us at privacy@klymbstudio.com.
1. Data we collect
Account & profile
- Name, email address and password (stored as a salted hash — we never see or store your plain-text password).
- Workspace and organization details you provide (company name, industry, team members you invite).
- For creators: handle, profile details, portfolio information and training progress.
Campaign content
- Briefs, scripts, messages and comments exchanged on the platform.
- Videos submitted by creators for review, hosted on Cloudflare Stream.
Payments
- Payments are processed by Stripe. We never see or store card numbers or full bank details. We store references Stripe gives us (customer, subscription and payout identifiers, amounts, statuses) to operate wallets, subscriptions and creator payouts. Creators are onboarded through Stripe Connect, which collects identity-verification (KYC) data directly under Stripe's privacy policy.
Social platform data
- When a creator connects a social account (TikTok, Instagram, YouTube), we collect — through the platforms' official APIs and with the creator's authorization — basic profile information and the performance metrics of campaign videos (views, likes, comments counts). We use this solely to show campaign performance to the creator and to the brand or agency the creator works with.
- We do not post on anyone's behalf, and we do not access private messages, contact lists or followers' personal data.
Technical data
- Standard server logs (IP address, browser type, timestamps) kept for security and debugging.
2. Why we process it (legal bases)
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the platform: accounts, campaigns, review flows, messaging | Performance of a contract (art. 6(1)(b)) |
| Subscriptions, campaign wallets and creator payouts | Performance of a contract; legal obligations (accounting, anti-fraud) |
| Displaying social performance metrics of campaign videos | Consent of the creator who connects the account (art. 6(1)(a)) — revocable at any time |
| Transactional email (password resets, invitations, payout confirmations, trial reminders) | Performance of a contract; legitimate interest |
| Security, abuse prevention, service integrity | Legitimate interest (art. 6(1)(f)) |
We do not sell personal data, we do not run third-party advertising, and we do not use your data to train AI models.
3. Where your data lives
Our database is hosted by Supabase in the European Union (AWS eu-west-3, Paris). Videos and the website are served by Cloudflare. Emails are sent by Resend from EU infrastructure. Where a processor transfers data outside the EU/EEA, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
4. Who we share data with
Only the processors needed to run the service:
| Processor | Role |
|---|---|
| Supabase | Database, authentication (EU — Paris) |
| Cloudflare | Hosting, CDN, video storage & streaming (Stream) |
| Stripe | Subscriptions, campaign wallets, creator payouts (Connect) |
| Resend | Transactional email |
Within the platform, data is shared on a need-to-know basis: a brand sees the creators working on its campaigns and their campaign-video metrics; an agency sees the workspaces it manages; a creator sees their own campaigns, briefs and earnings. Tenant isolation is enforced at the database level (row-level security).
5. Social platforms (TikTok, Instagram, YouTube)
Klymb uses the official developer APIs of TikTok, Meta (Instagram Graph API) and Google (YouTube Data API) to read the performance of campaign videos published by creators who have connected their accounts.
- Klymb's use of YouTube API Services is subject to the Google Privacy Policy. You can revoke Klymb's access at any time via Google security settings.
- You can revoke TikTok access in your TikTok app settings, and Instagram access in your Facebook/Instagram account settings — or simply disconnect the integration inside Klymb.
- When access is revoked, we stop collecting new data immediately; previously collected campaign metrics may be retained as part of the campaign's historical record.
6. Retention
- Account data: for as long as your account exists, then deleted within 90 days of account closure.
- Campaign content and metrics: for the life of the workspace, as it forms the shared business record of brands and creators.
- Payment records: as long as required by accounting and tax law (typically 10 years in France).
- Server logs: up to 12 months.
7. Your rights
Under the GDPR you can ask for access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Where processing relies on consent (social integrations), you can withdraw it at any time without affecting past processing.
Write to privacy@klymbstudio.com — we answer within 30 days. You can also lodge a complaint with your supervisory authority (in France, the CNIL).
8. Cookies & local storage
Klymb uses no advertising or cross-site tracking cookies. We use the browser's local storage strictly for the session that keeps you signed in and for interface preferences. Stripe sets its own cookies on its checkout pages, under its own policy.
9. Security
All traffic is encrypted in transit (TLS). Data access is scoped per tenant with database row-level security. Payments and identity verification are handled by Stripe, a PCI-DSS Level 1 provider. Passwords are hashed with bcrypt.
10. Age
Klymb is a professional tool intended for users aged 18 or over. We do not knowingly collect data from minors.
11. Changes
If we change this policy in a meaningful way, we will notify account holders by email or in-app before the change takes effect. The “last updated” date above always reflects the current version.
Contact
Klymb Studio — privacy@klymbstudio.com