influensar.ioBack to website
Privacy Policy

Privacy Policy

How influensar.io collects, uses, shares, and protects personal data across our website and services.

Effective: July 29, 2026

This notice applies to website visitors, waitlist contacts, customers, users, creators, and other professional contacts.

Overview

This Privacy Policy explains how influensar.io collects, uses, shares and protects personal data when people visit our website, join our waitlist, use our invited-user creator relationship management platform, interact with our AI Assistant or browser extension, or communicate with us. It also explains the choices and privacy rights available to individuals.

1. Scope

This Policy applies to the influensar.io website, waitlist, B2B CRM, AI Assistant, browser extension beta, support channels and related business operations (together, the Service).

It covers personal data about:

  • customer administrators and invited users;
  • creators, influencers, managers, agents and other professional contacts;
  • website visitors and waitlist contacts;
  • people who contact us for support or exercise a privacy right; and
  • suppliers, advisers and other business contacts.

In this Policy, personal data means information relating to an identified or identifiable person. Customer Content means information submitted to or generated in a customer's workspace, such as creator records, campaign data, notes, files, conversations and reports.

2. Who is responsible and how to contact us

For processing that influensar.io determines, the person responsible (responsable/controller) is Egor Monakhov.

Address: Sonora 49-301, 06700 Mexico City, Mexico

Email: info@influensar.io

You may use this email address to ask a privacy question, withdraw consent, request a limit on use or disclosure, or exercise a privacy right.

Our principal privacy framework is Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, or LFPDPPP). Other laws, including the GDPR, UK GDPR and US state privacy laws, apply only where their territorial and other legal requirements are met.

3. Our role and our customers' role

influensar.io acts as a responsable/controller for activities we determine, including account administration, authentication, security, operation of the website and waitlist, support, service communications, contracts, billing, limited product telemetry and compliance with our legal obligations.

Customers decide which creator, campaign and business-contact information to place in their private workspaces and why they use it. For that Customer Content, influensar.io generally acts as an encargado/processor and handles the data on the customer's instructions. Customers are responsible for having an appropriate purpose and legal basis, giving required notices, obtaining consent where necessary, keeping data accurate and assigning appropriate user access.

If a privacy request concerns Customer Content, we may refer the request to the relevant customer or help that customer respond. We remain responsible for processing whose purposes and means we determine, including the shared creator registry described in Section 7.

4. Personal data we collect

Depending on how the Service is used, we may process the following categories of personal data:

  • Account and organization data: name, work email, user ID, organization, role, membership, invitations, authentication events and access status.
  • Creator and professional data: name, handle, platform, public profile link, manager or agent, professional contact information, category, availability, exclusivity, public audience and performance metrics, and customer notes.
  • Campaign and CRM data: campaigns, shortlists, deliverables, content tasks, dates, communications, rates, budgets, status, results, linked records, custom fields and imports.
  • Registry and claim data: the limited creator fields made available in the shared registry, the agency submitting a claim, the requesting user, claim status, review information and audit evidence.
  • Assessment data: Brand Score inputs and results, prior-work indicators, workflow, creative and statistics assessments, and user-entered fraud or reputational checks.
  • AI and submitted content: prompts, AI outputs, recent conversation context, authorized CRM excerpts, report snapshots, statistics screenshots and file metadata.
  • Website and communications data: waitlist email, team-size range, form location, consent records, support messages and business correspondence.
  • Technical and security data: event time, service route, status, error information, request or trace identifiers, extension-session metadata, audit records, IP address, browser type and user agent.
  • Commercial and legal data: contract contacts, invoices, payment status, tax or accounting records and legal correspondence, where relevant to our business relationship.

The Service is not designed to require health, biometric, religious, political, sexual-life or similar sensitive data. Customers must not use the Service to infer sensitive traits without an appropriate legal basis and required safeguards. Users should not submit bank account details, government-issued identity documents or complete signed agreements to the AI Assistant.

5. Where personal data comes from

We receive personal data:

  • directly from the person concerned;
  • from customer administrators, invited users and customer imports;
  • from public profiles and public social-platform pages selected by a user;
  • through the browser extension when a user activates it on an open page;
  • through AI interactions, uploaded files and screenshots;
  • from service, authentication, security and audit events;
  • through support, email and other business communications; and
  • from service providers acting for us.

Professional information may be publicly available, but that does not remove a customer's responsibility to use it lawfully and provide any notice required by law.

6. How and why we use personal data

We use personal data to:

  • provide, authenticate, administer and secure the Service;
  • create and operate customer workspaces;
  • manage creator relationships, campaigns, imports and reports;
  • operate the shared creator registry and review ownership claims;
  • provide the user-operated Brand Score;
  • respond to prompts and provide requested AI assistance;
  • analyze user-submitted statistics screenshots;
  • send authentication, service and security communications;
  • respond to support, privacy and legal requests;
  • monitor reliability, prevent abuse and investigate incidents;
  • maintain audit evidence and restore the Service from backups; and
  • administer contracts, billing, tax records and legal claims.

Depending on the activity and applicable law, we rely on performance of a contract, steps requested before entering a contract, the customer's documented instructions, compliance with law, legitimate interests in operating and protecting a B2B service, establishment or defense of legal claims, or consent.

Joining the waitlist is optional. A person who submits the form and selects the consent option asks us to contact them about influensar.io access. They may withdraw that choice at any time by emailing info@influensar.io.

If we introduce a materially different purpose, we will provide any additional notice, consent or refusal mechanism required before using personal data for that purpose.

7. Customer workspaces, creator registry and ownership claims

Private customer workspaces are separated by organization and protected by role-based access. A customer does not receive unrestricted access to another customer's campaigns, communications, files, AI chats, audit logs or private workspace.

The Service also includes a limited shared creator registry. Active, authenticated users from different customer organizations may search registry entries containing selected professional information, such as a creator's handle, platform, manager, availability, exclusivity and record-creation information. Registry information may originate from public sources or from creator information previously entered into a customer workspace.

An authorized agency owner may submit an ownership claim for a registry entry. A service administrator reviews the claim. If it is approved, the associated creator record may be made available in the claiming agency's workspace. Approval does not give the agency access to the source customer's campaigns or continuing access to its workspace.

Customers must not place private communications, identity documents, bank details or unrelated sensitive information in registry fields. Claims may be submitted only by people authorized to represent or manage the creator. A creator, manager or customer may ask us to review, correct, restrict or cancel an entry or claim by contacting info@influensar.io.

8. Brand Score and profiling

The browser extension beta includes a Brand Score tool. A user enters criteria relating to prior work, workflow, creative quality, statistics and their own professional assessments. A fixed calculation converts those inputs into category results and a score. Users may keep a draft locally or save a final score to their customer workspace where their role permits it.

Brand Score is a customer-side professional assessment. It is not generated by Anthropic, Z.ai/GLM or another large language model, and influensar.io does not independently verify every input. Customers should use relevant, accurate and non-discriminatory criteria and should not use the score as the sole basis for a decision that produces legal or similarly significant effects on a person.

9. AI Assistant

9.1 What it does

The AI Assistant supports chat, analysis of permitted CRM context, recommendations, report preparation, drafting of reviewable CRM changes and recognition of statistics in screenshots. It assists users and does not replace professional, legal, tax, financial or business judgment.

Depending on configuration and availability, requests may be processed using Anthropic models or Z.ai/GLM models. A vision-capable model may process a statistics screenshot when a user asks for that analysis.

9.2 Information sent for AI processing

An AI provider may receive the user's prompt, limited recent conversation context, relevant organization context, CRM fields or search results authorized for the request, report instructions, and screenshots or other content submitted for analysis. The Service is designed to request relevant, bounded information rather than provide unrestricted database access.

Access to designated sensitive CRM fields requires a separate permission in the interface. AI may prepare a proposed create, update, archive or similar change, but the change is carried out only after it is presented for review and confirmed by an authorized person.

The AI Assistant is not used to make solely automated decisions that produce legal or similarly significant effects. Users remain responsible for checking AI output before relying on it.

9.3 Training, retention and processing location

influensar.io does not use Customer Content to train its own AI model. External AI providers process data under the agreement and account configuration applicable to influensar.io. Their retention, abuse-monitoring and model-improvement practices may differ by provider and service plan. We do not promise zero provider retention or no provider use unless the applicable written agreement expressly supports that statement.

AI processing may occur outside Mexico, including in the United States, Singapore or another location used by the applicable provider or its subprocessors. AI data should not be understood as stored or processed exclusively in Mexico.

10. Service providers, disclosures and international transfers

We disclose personal data only as needed for the purposes described in this Policy. Recipients may include:

  • customer-authorized users and the limited authenticated registry audience;
  • personnel who need access to operate, support or secure the Service;
  • infrastructure, database, storage, email and AI providers;
  • professional advisers subject to confidentiality obligations;
  • a potential investor, purchaser or successor in a properly structured business transaction; and
  • public authorities where disclosure is legally required.

Depending on deployment and configuration, providers include Cloudflare for the public website and waitlist database; Resend for waitlist notification email; AWS for infrastructure and transactional email; self-hosted Supabase/Postgres/Storage and NocoDB components; ImprovMX for inbound email forwarding; and Anthropic and Z.ai/GLM for requested AI processing.

These providers or their subprocessors may process data in Mexico, the United States, Singapore or other countries. Where required, we use an available legal transfer mechanism, such as an adequacy decision, contractual clauses, consent or another safeguard permitted by applicable law.

Providers acting for us are not authorized to use Customer Content for their own advertising. We do not disclose personal data to an independent third party for that party's unrelated purpose without identifying the recipient and purpose and providing any consent or refusal mechanism required by law.

11. Browser extension, website storage and telemetry

The browser extension beta helps an invited user capture selected public metrics from Instagram, TikTok and YouTube pages opened by that user and save them to the relevant customer workspace. It is not intended to collect private messages, passwords or information unrelated to the user-selected page.

The extension may store a service origin, access token, session metadata, Brand Score drafts and limited diagnostic entries in the browser's local extension storage. Disconnecting clears connection data. Drafts and diagnostic entries may remain until the user resets them, clears extension data or removes the extension.

The public website stores the person's cookie choice in browser local storage. At the effective date of this Policy, it does not load advertising cookies, advertising pixels or a cross-site analytics service. The CRM may use essential cookies or comparable browser storage for authentication, security and preferences.

Application telemetry records limited operational information such as event type, timing, status, error category and pseudonymous request identifiers. It is designed to exclude prompts, chat messages, CRM record content, emails, filenames, handles, URLs and tokens. Infrastructure and security providers may still process ordinary request metadata, including IP address and user agent, to deliver and protect the Service.

12. Data retention and deletion

We retain personal data for as long as reasonably necessary for the purposes described in this Policy, customer instructions, account and contract administration, security, dispute resolution and applicable legal obligations. We consider the type of data, the length of the relationship, security needs and mandatory limitation or record-keeping periods.

Some technical periods are fixed:

  • AI report snapshots are available for 24 hours and are removed through the report-cleanup process after expiry.
  • Browser-extension server tokens expire after no more than 30 days and may be revoked earlier.
  • Where the documented production backup lifecycle is active, encrypted backup objects are configured to expire after 30 days.

For customer workspaces and CRM records, AI conversation history, statistics screenshots, registry and claim records, audit records, waitlist submissions and operational telemetry, we do not currently apply one universal fixed automated deletion period. These categories are kept while the account, workspace, waitlist relationship or relevant purpose remains active and afterward only as reasonably necessary for closure, security, legal obligations, limitation periods and disputes.

A customer or individual may request deletion or cancellation by emailing info@influensar.io. We will assess the request against the customer's instructions, the rights of other people and any legal exception. Approved deletion is applied to active systems within a reasonable operational period. Protected backup copies are allowed to expire through their applicable lifecycle and deletion instructions are reapplied if a backup is restored.

13. Security and incidents

We use administrative, technical and organizational measures appropriate to the Service and the risks involved. These include authenticated access, role-based permissions, workspace separation, database access controls, private file storage, encrypted connections, protected service credentials, bounded AI tools, human confirmation for CRM changes, audit records and backup and restoration controls.

The shared registry described in Section 7 is intentionally accessible across authenticated organizations and should not be confused with private workspace data. No online service can guarantee absolute security.

If we learn of unauthorized access, loss or another security incident, we work to contain it, assess the affected information and risk, remediate the cause and notify affected customers, individuals or authorities when required by applicable law. Suspected incidents may be reported to info@influensar.io.

14. Privacy rights

14.1 Mexico: ARCO rights

For personal data for which influensar.io is responsible, a person in Mexico may request Access (Acceso), Rectification (Rectificación), Cancellation (Cancelación) or Objection (Oposición), known as the ARCO rights. A person may also withdraw consent or request a limit on use or disclosure where the LFPDPPP permits it.

Send a request to info@influensar.io and include:

  • your name and a safe method for receiving our response;
  • enough information to locate the relevant account, registry entry, claim, waitlist submission or customer workspace;
  • a clear description of the right and personal data concerned;
  • for rectification, the requested correction and available supporting information; and
  • if a representative acts for you, information showing their authority.

We may request proportionate information needed to verify identity and protect another person's data. Please do not email a full identity document unless we specifically provide a secure verification method.

Under the current LFPDPPP, the responsible party generally communicates its decision within 20 days after receiving a complete ARCO request. If the request is granted, it is generally implemented within the following 15 days. Each period may be extended once for an equal period where the circumstances justify it. Legal exceptions may apply.

14.2 EEA and United Kingdom

Where the EU GDPR or UK GDPR applies, a person may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. Legitimate-interest processing may be subject to objection and balancing requirements.

influensar.io does not use the AI Assistant for solely automated decisions that produce legal or similarly significant effects. International transfers of GDPR-protected data use an applicable lawful transfer mechanism where no adequacy decision applies.

14.3 United States

US state privacy rights apply only when the relevant territorial, business and other statutory thresholds are met. Where applicable, a person may have rights to know, access, correct or delete personal data, obtain a portable copy, appeal a denied request, and opt out of certain sale, sharing, targeted advertising or profiling practices.

We do not discriminate against a person for exercising an applicable privacy right. Requests under this Section may be sent to info@influensar.io.

15. Children and creators under 18

User accounts are intended for adults aged 18 or older. We do not knowingly invite children to create Service accounts.

A customer may manage professional information about a creator under 18 only where it has an appropriate legal basis, provides required notice, obtains any necessary parent or guardian involvement or consent, and applies safeguards appropriate to the creator's age.

Contact info@influensar.io if you believe a minor created an account or a child's information was added, assessed, placed in the registry or transferred without proper authority.

16. No sale or advertising profiling

influensar.io does not sell personal data, disclose it for cross-context behavioral advertising or use it for targeted advertising. We do not receive payment for providing customer CRM records to third parties.

The authenticated creator registry and ownership workflow are product collaboration features. Their cross-organization operation is described in Section 7 and is not used as an advertising-data marketplace.

If our practices change in a way that creates a notice, consent or opt-out obligation, we will provide the required method before relying on the changed practice.

17. Changes, language and contact

We may update this Policy when the Service, providers, data practices or legal requirements change. We will update the effective date and provide additional notice before a material change takes effect where required by law.

This English version is the governing version to the extent permitted by applicable law. A translation provided for convenience does not limit rights granted by mandatory law.

Questions and privacy requests may be sent to:

Egor Monakhov

Sonora 49-301, 06700 Mexico City, Mexico

info@influensar.io

© 2026 influensar.ioinfo@influensar.io