Privacy Policy · FindKol
Last updated: 2026-09-17
1. Overview
This Privacy Policy explains how DiffLab Co., Limited ("we", "us") collects, uses, shares and protects personal data when you use the FindKol website and applications (the "Service").
For account data and service operations, we act as a data controller. Where business customers use the Service to process personal data (for example, creator contact details in their lists and messages), the customer is the controller and we act as a processor following the customer's instructions; a data processing agreement is available on request.
2. Information We Collect
Account data: name, email address, password (stored only as a hash), role, organization and team membership.
Workspace content: creator lists, notes, relationships, collaborations, discount codes, email templates and messages, follow-up tasks — whatever you create in the Service.
Creator public data cache: publicly available profile information about social-media creators — display name, handle, avatar, bio, follower/engagement metrics, estimated audience composition and contact details that creators publish publicly (for example, an email address in a bio). This data is aggregated through third-party data providers and cached with its source.
Email channel data: when you connect Gmail or Outlook, we store the OAuth access token (encrypted with AES-256-GCM) and the metadata and content of conversations related to outreach sent through the Service. We do not import your general inbox.
Shopify data: shop domain and only the order fields needed for discount-code attribution (for example order id, total, currency, timestamp and applied discount codes).
Billing data: plan, credit balance and transaction records. Card numbers are handled by Stripe and never stored on our servers.
Usage data: log files, device and browser information, pages viewed and actions taken in the Service, used to secure and improve the product.
3. How We Use Information and Legal Bases
We use personal data to: provide and maintain the Service (accounts, search, reports, outreach, attribution); secure the Service and prevent abuse; provide support; process billing; send service communications and, with your consent, product updates; and comply with legal obligations.
Legal bases under the GDPR: performance of a contract (operating your account and the Service); legitimate interests (caching publicly available creator data to provide discovery features, and securing the Service — balancing assessments are available on request); consent (optional communications); and legal obligation (invoicing and record-keeping).
We do not use your workspace content or emails to train foundation models, and we do not sell personal data.
4. Creator Public Data
Creators are not required to have an account with us. We collect publicly available information about creators from public web sources, aggregated through third-party providers, and use it to provide discovery and analytics features to our business customers.
Audience characteristics such as country, language and age composition are statistical estimates with confidence labels, not verified facts.
Creators may request access to, correction of, or removal of their cached data by contacting us (see "Contact"). We will action verified requests within a reasonable timeframe and will also flag the request to the relevant data provider where the data originated there.
5. AI Processing
Some features send inputs — such as your search query, creator data or draft context — to a third-party large language model provider to generate outputs like parsed search filters, suggested outreach drafts or report summaries.
Under our agreements, the provider may process these inputs only to provide the service to us. We do not use your workspace content to train foundation models.
AI output can be inaccurate or incomplete. Review it before relying on it or sending it.
7. Your Email Channel
Connecting a Gmail or Outlook mailbox is optional. We request only the OAuth scopes needed to send the outreach you approve and to read replies to conversations sent through the Service.
Access tokens are stored encrypted (AES-256-GCM) and used only for the purposes above. Disconnecting the channel revokes our access and deletes the stored token.
9. Data Retention
Account and workspace data: kept while your account is active. After termination you may request an export for thirty (30) days; data is then deleted or anonymized within a reasonable period, except where longer retention is legally required.
Cached creator public data: kept until it becomes obsolete or a deletion request is honored.
Invoicing and transaction records: retained for up to seven (7) years where required by accounting and tax laws. Technical logs are kept for a limited period consistent with security and legal needs.
10. Your Rights
Depending on your location, you have some or all of the following rights: access to your personal data; correction; deletion; restriction of or objection to processing; data portability; and withdrawal of consent where processing is based on consent.
If you are a California resident, you have the right to know, delete and correct personal data, and to opt out of any "sale" or "sharing" of personal data. We do not sell or share personal data as those terms are defined by the CCPA/CPRA.
To exercise any right, contact us through the feedback page inside the Service or via the email below. We may need to verify your identity. You also have the right to lodge a complaint with your local data protection authority.
11. International Data Transfers
We and our service providers may process data in countries other than your own. Where personal data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms required by applicable law.
12. Security
We protect data in transit with TLS, encrypt stored integration tokens and sensitive fields with AES-256-GCM, hash passwords, and apply least-privilege access controls and audit logging.
No method of transmission or storage is completely secure. If a personal data breach affects your rights, we will notify you and the relevant authorities as required by law.
13. Children's Privacy
The Service is a business tool directed to adults (18+) and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child's data has been provided to us, contact us and we will delete it.
14. Changes and Contact
We may update this Privacy Policy as the Service evolves. Material changes will be announced in the Service or by email.
Privacy questions and requests can be raised through the feedback page inside the Service or sent to support@findkol.com.