Security & data handling
What we collect, where it lives, and who can see it — in the terms a procurement or security reviewer will ask about.
What we collect
Two distinct things. First, publicly available creator data from Instagram, YouTube, TikTok and Facebook — profile, post and audience-level metrics that any visitor to those profiles can see. Second, your own account data: the workspace you create, the campaigns and creator lists you build, and the team members you invite.
What we do not collect
We never ask for, store or transmit your social platform passwords. Where an integration needs access, it uses the platform's official OAuth flow, and you can revoke that access from the platform at any time without contacting us.
Access control
Workspace data is scoped to your workspace and the team members you invite. Access is role-based, and you can remove a team member's access yourself at any time from your workspace settings.
Data in transit
All traffic between your browser and Ylytic runs over HTTPS/TLS. The same applies to our API.
Retention and deletion
Campaign and creator-list data persists for as long as your workspace is active. You can ask us to export or permanently delete your workspace data — write to sales@ylytic.com and we will confirm once it is done.
Reporting a vulnerability
If you believe you have found a security issue, email sales@ylytic.com with the details. Please give us a reasonable window to investigate and fix before disclosing publicly.
Need something more specific?
If your security review needs a DPA, a sub-processor list or answers to a specific questionnaire, we will work through it with you directly.
Contact us →See also our Privacy Policy and Terms of Service.