Privacy Policy
UpNext uses creator data to run the service, not to sell a profile of you. This notice explains what is processed, why it is needed, and the choices you keep.
Our privacy commitment
UpNext follows the transparency, legitimate-purpose, and proportionality principles of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173). We collect only data reasonably needed to provide, secure, and improve the features you choose to use.
What UpNext processes
UpNext does not define its collection as all activity. Each category below has a specific product, security, or legal purpose:
- Account and access data: email, display name, one-way password hash, one-way recovery-code hashes, consent records, and protected session identifiers, used to create, authenticate, recover, and separate creator workspaces.
- Creator workspace data: only the ideas, plans, analytics, private opportunity records, rates, deadlines, templates, settings, media-kit details, and other fields you choose to enter, used to provide the features you request.
- Connected-platform data: the provider account identifier, account name and image, encrypted authorization token, granted scopes, available metrics, and sync status, used only to connect and refresh the account you authorize.
- Login-abuse records: a one-way hash derived from the attempted email, network address, and action, plus attempt counts and timestamps, used only to rate-limit repeated sign-in or signup attempts.
- Error references and essential request information: a short error reference and the minimum technical request data processed by the hosting infrastructure, used to deliver the site, prevent abuse, and diagnose a specific failure.
What UpNext does not log
UpNext does not keep its own page-view history, clickstream, advertising identifier, cross-site browsing history, keystroke log, or a general record of everything you do. Product records change only when you create, edit, connect, sync, export, disconnect, or delete something, and technical security records are limited to the stated purposes above.
Why it is processed
Data is processed to provide the service you request, keep each creator’s records separate, calculate or display creator-selected metrics, support exports and deletion, secure the site, and comply with applicable law. A social connection is processed only with your authorization and can be withdrawn by disconnecting it.
No selling, ad profiling, or brand access
UpNext does not sell, rent, trade, or broker personal data. It does not build advertising profiles, run targeted advertising, or give brands access to private creator records. Data is disclosed only to infrastructure providers that help operate the service, to a social platform you deliberately connect, when you intentionally create and share a media-kit link, or when disclosure is legally required.
Social connections and public media kits
Official social connections are read-only and never require you to give UpNext a social-media password. Provider access and refresh tokens are encrypted before storage, are never included in exports, and are used only for the connection you authorize. Disconnecting stops future syncing and removes the connection authorization used by UpNext; analytics already imported remain part of your private workspace under the retention schedule below until you delete them or your account. A media kit becomes accessible to anyone with its URL only when you save a public slug. UpNext does not list, recommend, distribute, or send that link to brands. You decide whether to share it, but recipients may forward it, so publish only fields you are comfortable making public.
Connected-platform data
When you choose to connect a provider, UpNext requests only the read-only permissions required for features currently shown in UpNext: Instagram professional profile, media, and available insights; Facebook Pages you select, Page content metadata, and available Page insights; TikTok basic profile, follower statistics, and public-video data; and YouTube channel information and read-only channel analytics. If a metric is unavailable through an approved permission, UpNext shows it as unavailable or offers manual entry; it does not request adjacent data just in case. UpNext does not request permission to publish, send messages, manage comments, run ads, or control your account.
Google API data and Limited Use
UpNext's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the user-facing YouTube analytics connection you request, is not used for advertising, and is not transferred except as needed to provide the feature, for security, to comply with law, or with your affirmative consent.
Retention and deletion
UpNext applies the following retention periods to records it controls. You can shorten any creator-record period by deleting the record, disconnecting the account, or deleting your UpNext account, as applicable.
- Account, profile, content, deal, template, media-kit, manual analytics, and content-level analytics records: retained while your account remains active or until you delete the record, then removed from the active database when you delete the account.
- Synced account-level analytics: UpNext keeps at most one detailed snapshot per connected platform and day for 90 days. After 90 days, it retains the latest synced snapshot for each platform and calendar month while the account remains active. Manual and content-level analytics are not compacted by this schedule.
- Connected-account authorization tokens and connection metadata: retained until you disconnect that platform, delete the account, or the authorization expires and cannot be refreshed, whichever comes first.
- Signed social-authorization state: valid for 10 minutes and not stored as a continuing activity log.
- UpNext login sessions: expire 30 days after creation, or sooner when you sign out, change access, or delete the account.
- Password recovery codes: only one-way code hashes are retained until a code is successfully used, you generate a replacement set, or you delete the account. Plain recovery codes are displayed in a protected browser session for no more than 5 minutes and are not stored in the active database.
- Login-abuse and rate-limit records: retained for 30 days after the latest recorded attempt, then deleted during routine authentication maintenance.
- Application-generated error references: kept only as long as needed to diagnose the reported failure and no longer than 30 days where UpNext controls the log.
- Active-database deletions take effect immediately in the application. Recoverable infrastructure backups, if created by the hosting provider, are isolated from normal use and allowed to roll off for no more than 30 days unless a longer period is required by law or needed for a documented legal claim.
Security
UpNext uses one-way password and recovery-code hashing, single-use recovery codes, protected and expiring sessions, sign-in and recovery rate limits, server-side record ownership checks, encrypted connections, application-level encryption for social authorization tokens, platform-provided storage protection, signed and time-limited authorization state, restricted browser permissions, input and request limits, anti-framing controls, non-public creator routes, and non-revealing server errors. No internet service can promise zero risk, so security controls are reviewed as the service changes.
Your rights and choices
Subject to the Data Privacy Act and its implementing rules, you may ask to be informed, access or correct your data, object to or withdraw consent from processing, request erasure or blocking, obtain portable data where applicable, and file a complaint with the National Privacy Commission. You may also seek damages where the law provides. Open Settings → Privacy & Data to view, download, correct, disconnect, or delete data, or contact support@upnextcreator.com for a privacy request.
Service providers, location, and changes
Hosting, authentication, database, security, and official social-platform providers may process data in the Philippines or other countries under their own safeguards and service terms. UpNext is not intended for children under 18. Material changes to this notice will be shown by a new effective date and, when appropriate, an in-product notice.
These pages describe UpNext's current behavior and safeguards. They do not replace advice from a qualified lawyer, accountant, or security professional for your specific situation.