kumpr
Home
Legal Center

Privacy Policy

Last updated: October 2, 2026

This policy explains what data we collect when you use kumpr, why and how we use it, who we share it with, and the rights you have over it. kumpr is a panel that helps you schedule social media content, generate UGC-style ad scripts and videos with AI, and analyze public competitor/market data.

1. Data we collect

Account information: your email address, name, and the hashed value of your password.

Connected social accounts: when you connect a Facebook, Instagram, TikTok, YouTube, or Pinterest account, we store the access and refresh tokens issued by that platform, plus your account ID and display name. These tokens are stored encrypted with AES-256-GCM in our database, never as plain text.

Bluesky account: when you connect a Bluesky account, we store the AT Protocol OAuth session issued by your Bluesky server — a DPoP-bound token set, not a simple access/refresh token pair — together with your DID, handle, display name and avatar. This session data is stored encrypted with AES-256-GCM in our database, never as plain text.

Content data: media you create or upload (video, images), post copy you write or generate with AI, project analyses, and scripts.

Reference slideshows (Slideshow Remix): the slide images you upload, or — when you paste a link to a public TikTok photo post — that post's images, title and caption, which kumpr's server reads from the public TikTok page and stores so you can remix them. No TikTok account is used for this and nothing is posted.

Usage records: who did what and when (audit log) — for account security and accountability.

AI provider keys (BYOK): if you want to use AI features, you enter your own Anthropic/OpenAI/fal.ai API key; this key is also stored encrypted and is only ever used for AI calls made on your behalf, at your request.

2. How we use your data

We only use your data to provide the features you request: publishing content you scheduled to the social account you connected, at the time you specified; generating content (script, video, captions) you asked AI for; analyzing store/competitor data and showing it to you.

We do NOT use your data for advertising, profiling, or selling to third parties. kumpr has no advertising or analytics/tracking third parties at all.

3. Sharing with third parties

Meta, Google (YouTube), TikTok, Bluesky, and Pinterest: we use these platforms'/protocols' official APIs only to publish content you created/approved to the account you yourself connected and to read that account's data described in section 4. We never send them any data without your consent.

AI providers (Anthropic, OpenAI, fal.ai): when you use AI features, data relevant to the content you want generated (e.g. project analysis, script text, reference image) is sent to these providers through your own API key. Their own privacy policies apply.

Slideshow Remix: the reference slideshow's images and caption, your project's details, notes you add and — if you choose to research a feature — excerpts of your project's own store/web pages are sent to Anthropic (Claude reads the reference, writes the new slides and checks each generated slide), and each reference slide with its new text to the image model you choose — OpenAI (GPT-Image) or fal.ai (Nano Banana Pro). When a reference slide shows an app screen, your project's screenshots are shown to Claude to pick one; the screenshot itself is placed into the slide by kumpr and is not sent to the image model.

Feature research (Projects → Features, "Research in Sources with AI"): the feature's name, your project's name and value proposition, and excerpts of your project's own store/web pages are sent to Anthropic; Claude writes what the pages say about the feature as a suggested description. The suggestion isn't stored unless you save it.

Bunny.net (CDN): media files you upload are hosted on Bunny.net as our content delivery network.

Resend (email delivery): the emails kumpr sends you (account invitations, publishing failure notices, support ticket updates and — only if you turn it on in your profile — the weekly analytics email, which contains a summary of your accounts' results and the captions of your top posts) are delivered through Resend. Your email address and the content of that email are sent to Resend only to deliver it.

We do not share any of your data with any other third party except where legally required.

4. Platform data: Meta, TikTok, YouTube, Bluesky and Pinterest

When you connect a social account, to publish on your behalf we receive: the account identifier (e.g. Facebook Page ID, Instagram Business account ID, TikTok open_id, YouTube channel ID, Bluesky DID, Pinterest user ID), the display name and profile picture, an access credential (access/refresh tokens, or for Bluesky an OAuth session) and its expiry.

Posts you published outside kumpr: so that Analytics covers your whole account, kumpr also reads the posts you published directly on a connected Facebook Page, Instagram account, TikTok account, YouTube channel, Pinterest account or Bluesky account — their text (and title), publish time, link, media type and cover image — together with the counters listed below for each platform. They appear in kumpr read-only and marked "Direct"; kumpr never edits or deletes anything on the platform. Where the platform's own image link expires (Instagram and Facebook), we keep a small copy of the cover image; TikTok's cover image is not copied — kumpr asks TikTok for a fresh link before the old one expires. An imported post and its cover copy are deleted when the post is deleted on the platform, when you remove the account from kumpr, or when you remove kumpr in Meta's or TikTok's own settings.

Meta (Facebook/Instagram): we request pages_show_list, pages_read_engagement, pages_manage_posts, business_management, instagram_basic, instagram_content_publish, read_insights, instagram_manage_insights and pages_read_user_content. These are used to list the Pages you manage, find the linked Instagram Business account, read a connected Page's or Instagram account's name, username, picture and follower count (for Instagram also its following and post counts), list its posts and read their reaction, like, comment, share, view, reach and save counts — both the posts we published for you and the ones you published directly on Facebook or Instagram (to show performance in Analytics) — and publish the content you scheduled. Meta requires pages_read_engagement together with pages_manage_posts. read_insights and instagram_manage_insights are used to read the view count and reach (the number of unique accounts that saw it) of each Facebook post (plus its clicks, by type, and its reactions, by type) and the views, shares, reach and saves of each Instagram post, plus the watch time (average and total) of the videos among them and, for Facebook videos, how many views lasted 3 seconds and how many were completed; pages_read_user_content only to read the reaction and comment counts of those Facebook posts. read_insights is also used to read the daily activity of your Facebook Page (content views, reach, page visits, post engagements, new and lost followers) and aggregated statistics about its followers (the number of followers per country and per city), and instagram_manage_insights the same for your connected Instagram account: its daily activity (views, reach, accounts engaged, profile visits, taps on profile links, new followers) and the share of your followers by age group, gender and country, and the same breakdown for the accounts that engaged with your content in the last 30 days (likes, comments, shares, saves, replies). We read this data only to show it to you on your kumpr Analytics page. We never receive information about individual followers or accounts, and we do not read the content of comments or messages. Posts you published outside kumpr are imported as described above.

TikTok: we request user.info.basic and video.publish, and for Analytics user.info.profile, user.info.stats and video.list. The first two are used to show your account name and picture and to publish the video or photo content you prepared with the privacy setting you chose. user.info.profile reads your TikTok username and profile link; user.info.stats reads your account's follower, following, total like and public video counts; video.list reads your public videos — including the ones you posted directly on TikTok — with their caption, publish time, link, cover image and view, like, comment and share counts. TikTok does not give us impressions, reach, watch time or information about your followers, and we read this data only to show it to you on your kumpr Analytics page and post details. When you remove kumpr from your TikTok account (or the account is deleted), TikTok notifies us automatically and we delete the counters and the imported posts we read from TikTok.

YouTube (Google): we request youtube.upload, youtube.readonly and yt-analytics.readonly. The first uploads the video. The second reads your channel name and @handle, the list of your channel's uploads (including videos you uploaded outside kumpr) and the counters of your channel and its videos (subscribers, video count, views, likes, comments). The third reads YouTube Analytics reports for your own channel (daily views, watch time, subscriber changes, shares and the apps they were shared to, where your views came from (such as the Shorts feed, YouTube search or external sites), where your videos were played (on YouTube itself or on websites that embed them, with those websites' addresses), the device types and operating systems they were watched on, and how views split between Shorts and other videos and between subscribed and non-subscribed viewers), aggregated statistics about your audience (the share of your signed-in viewers by age group and gender, and views by country and by city) and, for each of your videos, its audience retention (the share of viewers still watching at each point of the video) and where its views came from (traffic sources and countries), so we can show them on your kumpr Analytics page and post details; it is optional and publishing works without it. We never receive information about individual viewers, we do not access your watch history, and we read this data only to show it to you.

Bluesky (AT Protocol): we request the atproto identity scope plus permission to create posts (repo:app.bsky.feed.post), upload the images attached to them (blob:*/*), and — only for video posts — the delegated-token calls video upload requires (rpc:com.atproto.server.getServiceAuth, rpc:com.atproto.repo.uploadBlob). We do not request read/write access to the rest of your repository or to your follows, likes or other posts. We also read your public profile (handle, display name, avatar, and follower, following and post counts) and your public posts with their like, reply, repost and quote counts (so Analytics also covers posts you shared outside kumpr) — this is public AT Protocol data anyone can already see, not a private permission grant.

Pinterest: we request pins:read, pins:write, boards:read, boards:write and user_accounts:read. These are used to create the Pin you scheduled, let you pick which board to publish it to, show your account name and avatar, and show how your account and your Pins (including those you created outside kumpr) perform on your kumpr Analytics page (your follower, following and Pin counts; for each Pin, its impressions, saves, reactions, comments and clicks and, for video Pins, their watch time and completed views; and the aggregated daily activity of your whole account: impressions, engagements, Pin clicks, link clicks and saves — totals only; we never receive information about the individual people who saw or saved your Pins, and we do not read Pins you saved from other accounts).

We never use data received from these platforms for advertising, profiling, model training or sale to third parties; we process it solely to carry out the publishing you requested and to show you the performance of your own accounts.

5. YouTube and Google API services

kumpr uses YouTube API Services. By using kumpr you agree to the YouTube Terms of Service (https://www.youtube.com/t/terms). Google's privacy policy is available at https://policies.google.com/privacy.

kumpr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke kumpr's access to your Google account at any time at https://myaccount.google.com/permissions; once revoked, the tokens we stored for that account become invalid and we delete the corresponding record.

6. Competitor/market analysis data

kumpr's competitor analysis feature shows PUBLICLY AVAILABLE profile and video statistics (follower count, views, likes — general, public metrics) for a username you enter. This is not access to a private account — it's a summary of information anyone could already see in a browser.

7. Data retention

We retain your data for as long as your account is active. When you disconnect a social account, its access token is deleted immediately. If you request full account deletion, see section 9 below.

8. Data security

All connections are encrypted over HTTPS. Social media access tokens and your AI API keys are stored encrypted with AES-256-GCM in our database. Session cookies are marked HttpOnly and SameSite. OAuth connection flows use CSRF protection (state, plus PKCE for TikTok).

9. Your rights and deleting your account

You can disconnect any connected social account at any time — this immediately and permanently deletes the associated token (for TikTok, kumpr also revokes its access on TikTok).

To have your account and personal data (login credentials, AI keys, notifications) deleted, contact us at [email protected]; your request is processed within 30 days at the latest. See /data-deletion for details.

You can also disconnect your Facebook/Instagram account by removing the kumpr app from your own Facebook settings, or your TikTok account by removing kumpr from TikTok's app permissions — in that case we automatically receive the platform's notification and remove the corresponding records from our systems.

10. Not directed at children

kumpr is not directed at individuals under 18 and does not knowingly collect data from them.

11. Changes to this policy

We may update this policy from time to time; the date at the top of this page reflects the latest revision.

12. Contact

For questions: [email protected].

Data controller: Ali Cenk Ergin.