← Krevo

Privacy Policy

Last updated: August 2026

Krevo represents creators towards advertising partners. To do that we process data about the creators who sign up, and about the companies we approach on their behalf. Here is what that means in detail.

Who is responsible

Paul Geiser, reachable at geiser.paul@gmail.com.

What we store about a creator

  • Account: username, email address, a password hash. We do not store the password itself and cannot read it.
  • Profile: a description of their content, previous advertising partners, preferred term, minimum price and target price.
  • Channels: the addresses of their social media profiles and, if the creator connects an account, the data the platform returns: profile picture, follower count, reach, the age, gender and country distribution of the audience, and per post the views, likes, comments and a thumbnail.
  • Uploads: screen recordings of their own insights and an introduction video, if provided.
  • History: which brands were suggested, approved or rejected, and which offers came out of it.

What we use it for

To find suitable advertising partners, approach them in the creator's name and negotiate up to an offer. The numbers are the argument in that conversation: a brand decides on reach and audience, and without them an enquiry is worthless.

The legal basis is performance of the contract with the creator (Art. 6(1)(b) GDPR). For approaching companies we rely on the legitimate interest in business contact (Art. 6(1)(f) GDPR).

What is public, and what is not

Every creator gets a sponsor page at its own address. That page is public: whoever has the link can see it, and the link is in every mail we send to a brand.

The creator decides on both: whether the page exists at all, and whether the numbers appear on it. Both can be switched off in the settings. The minimum price, the target price, the email address and the negotiation history are never on that page.

Who else is involved

  • Cloudflare runs the servers and the database. The data lives in Cloudflare's network.
  • Google (Gemini) reads uploaded screen recordings to extract the numbers from them. The file is transferred, not the creator's profile. We use the paid tier: Google does not use the data to improve its products and no human reads it.
  • Meta (Instagram) and TikTok, if the creator connects an account. We request read access only: profile, posts and their metrics. We have no access to messages and we publish nothing.
  • Anthropic (Claude) researches brands and drafts the mails.

How long we keep it

  • Account data for as long as the account exists.
  • Uploaded recordings until they have been read; after that only the resulting numbers remain.
  • Profile pictures and company logos are cached for up to 30 days so the page does not have to fetch them on every visit.
  • Instagram and TikTok access tokens until the connection is removed, at the latest until they expire.

Cookies

One cookie, named cos_session. It keeps a creator logged in and holds nothing but a session token. It is set on login and deleted on logout. There is no consent banner because there is nothing to consent to: without this cookie there is no login, and we set no others.

Your rights

Access, rectification, erasure, restriction, data portability and objection. An informal mail to geiser.paul@gmail.com is enough. How deletion works in practice is described under Data deletion.

You also have the right to lodge a complaint with a data protection supervisory authority.

What we do not do

No advertising trackers, no analytics services, no sale or sharing of data beyond the processors named above. The sponsor page loads no images from third-party servers: profile pictures and logos are served through us, so that a brand visiting the page does not show up in someone else's logs.