Privacy

What we hold, why we hold it, and who else can see it. If something here is unclear or you want your data gone, write to hello@ugcjobs.io and a person will answer.

Last updated 30 August 2026.

Who is responsible

ugcjobs.io is operated by YR Labs LLC, [REGISTERED ADDRESS]. We are the controller of the personal data described here. Questions, requests and complaints go to hello@ugcjobs.io.

What your account holds

This is the whole list. It is the set of fields the database actually has, not a category list that leaves room for more.

WhatWhy
Name, email address and avatar from your Google accountTo have an account at all, and to write to you about it
Session records: a token, your IP address, your browser's user agent, and when the session started and expiresTo keep you signed in and to spot a stolen session
Google sign-in tokensTo verify the sign-in. We never receive your Google password
A Stripe customer id, your plan, and the dates your subscription starts, renews or endsTo know what you have access to and to bill it. Card numbers stay with Stripe
The Instagram handle you type inTo find the brands in your niche. Until you sign in it stays in your own browser — see the note on the handle field below
The brands you save and the filters you setSo the list is still yours the next time you open it

We do not hold your password. Signing in goes through Google, so what reaches us is a confirmation plus your name, email address and avatar.

The handle you type on the home page

Typing your Instagram handle into the field on the home page does not send it to us. It is kept in your own browser’s session storage and travels no further until you sign in — at which point we use it to look up your public Instagram profile and work out which niches you shoot in. Close the tab before signing in and it is gone.

The lookup reads what Instagram already shows the public: display name, bio, follower count, whether the account is a business one, and recent post thumbnails. We do not connect to your Instagram account, ask for its password, or post anything.

Brands and public profiles

The product is a list of brands, and building it means holding information about people who never signed up here: a marketing manager named on a company contact page, the bio and follower count on a brand’s Instagram account, the fact that a company is running video ads. All of it is collected from sources that are already public — company websites, public social profiles, and public ad libraries.

Our basis for this is legitimate interest: connecting creators with companies that buy creator video is the point of the service, and the data is business-contact data rather than private life. We do not collect special categories of data, and we do not buy consumer data.

If you are one of those people and you would rather not be listed, write to hello@ugcjobs.io from an address at that company, or from the account in question, and we will remove the record and keep the domain out of future crawls. No reason required.

Cookies

One cookie: the one that keeps you signed in. There is no analytics script on this site, no advertising pixel, and no third-party tracker — which is why you were not shown a consent banner. There is nothing to consent to.

Who else can see it

The services we run on. Each one sees only what its job needs, and each is bound by a data processing agreement.

ServiceWhat it does
VercelHosting and request logs. United States
NeonThe database — your account, subscription state and saved lists. United States (AWS us-east-1)
Cloudflare R2Stored images used by the brand list. United States
StripePayments, invoices and card data — which never reaches our servers. United States and Ireland
GoogleSign-in. We receive your name, email address and avatar, never your password. United States
Anthropic and Google (Gemini)Classifying brands and matching a profile to niches. Prompts are not used to train their models under their business terms. United States
Instagram data providers (HikerAPI, ScrapeCreators, Apify)Reading the public Instagram profile behind a handle you give us, and the public brand profiles in the list. United States and European Union

Several of these are in the United States, so your data is transferred there. Those transfers rely on the European Commission’s standard contractual clauses, or on the EU–US Data Privacy Framework where the provider is certified under it.

We do not sell personal data, and we do not share it with advertisers. The only circumstances in which we hand data to anyone else are a binding legal order, or a sale of the business — in which case you would be told before your data moved.

How long we keep it

  • Sessions expire on their own and are deleted when they do.
  • Account data lives as long as the account. Ask us to delete it and it is gone within 30 days.
  • Invoices and the records behind them are kept for as long as tax law where we are established requires, because we are not allowed to delete those on request.
  • Brand and public-profile records are refreshed continuously; a record we can no longer verify is dropped rather than kept as history.

Your rights

If you are in the UK, the EU or the EEA, you can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, take it elsewhere in a portable form, or object to processing we do on the basis of legitimate interest. We answer within 30 days, and we do not charge for it.

You can also complain to your data protection authority. We would rather you wrote to us first, but that right does not depend on it.

Security

Traffic is encrypted end to end. We store no passwords and no card numbers — sign-in goes through Google and payment through Stripe, so neither secret is ours to lose. Access to the production database is limited to the people who operate the service.

If a breach happens that puts you at risk, we will tell you and the relevant authority within 72 hours of finding out. Saying nothing is not an option we are keeping.

Age

The service is for people doing paid creator work and is not intended for anyone under 16. We do not knowingly hold data about children; if you believe we do, write to us and it will be removed.

Changes

When this policy changes, the date at the top changes with it. If a change affects what we do with data we already hold, we email account holders before it takes effect rather than quietly editing the page.