Privacy
Last revised 2026-09-13
Prscnt is a talent-management tool. Agencies use it to track brand deals for the creators they represent, and creators can connect their own social accounts so the agency can see their public performance numbers in one place. This page says what that connection actually collects, what it cannot do, and how to end it.
Two different relationships
Two kinds of people give us data and they are never mixed together.
- Agency users sign in to run their own workspace. We hold the email address and name their sign-in provider gives us, and the business records they enter: brands, contacts, deals, rates, drafts, invoices.
- Creators may connect a social account. That grant belongs to the creator, it is stored inside the one workspace that represents them, and it is not readable by any other workspace.
What a connected social account gives us
When a creator connects Instagram, TikTok, or YouTube, we ask the platform for the access listed below, and nothing else:
| We ask for | What that means |
|---|---|
| Account identity | The platform's own account id and the display handle, so the right numbers attach to the right creator. |
| A list of the account's own posts | Post ids, captions, timestamps, permalinks. |
| Public counters on those posts | Views, likes, comments. Counters are not analytics. |
| Account-level insight reports, where the platform offers them | Aggregate reach and audience breakdowns for the connecting account only. |
| Comments and messages on the connected account | Comments on the account's own posts, and message threads people have sent to it, shown so the account holder or the manager they authorised can answer. We never start a conversation. Bodies are held in memory for at most sixty seconds and never stored. |
| Permission to publish and reply | Used only when a person confirms a preview in the product. Nothing is scheduled, automated, or drafted by a model. |
What it does not give us
- No automatic publishing. The product can publish a post, reply to a comment or message, or hide a comment only when a person confirms that exact action on a preview. There is no scheduler and no automation.
- No downloading your videos or photos. Being able to see a media URL is not permission to keep the file behind it, and we treat it that way: media download is switched off for every platform. Where a creator wants video analysed, they supply the file.
- No access to anyone else's account. Only the account that went through the consent screen.
- No data about your followers as individuals. Audience figures are the aggregate breakdowns the platform itself publishes.
A platform may hand back fewer permissions than we asked for if the person unticks a box on the consent screen. We record what was actually granted, not what was requested, and features that need a missing permission refuse rather than guess.
How the access credential is stored
The token a platform issues is encrypted with AES-256-GCM before it is written, and the encryption key lives in the server environment, never in the database. A copy of the database without that key cannot open a single token. Tokens are opened only in the process that is making a request to the platform, and are never written to logs, error messages, or API responses.
Ending a connection, and deletion
You can disconnect at any time
An account holder can disconnect a connected platform from the connections page. Disconnecting revokes our credential, tells the platform to revoke it on their side, and records the retention obligation the platform's terms place on anything already derived.
Removing the app on the platform works too
If you remove Prscnt from your Instagram or Facebook settings, Meta notifies us and we revoke the credential on our side without you doing anything else.
Asking us to delete what we hold
If you ask Meta to delete your data for this app, Meta sends us that request and we return a confirmation code and a status page you can check. You can also write to chris@prscnt.com and ask directly.
How long we keep platform data
Retention follows the platform's own terms, per platform, and we do not average them into one number:
| Source | Obligation we record |
|---|---|
| YouTube (Data API) | Deletion action generally within 7 days of the grant ending. API-derived data is kept out of shared benchmarking and derived commercial scores. |
| Instagram (Meta) | Meta's terms apply to everything derived. We have not established an exact history window, so we do not claim one. |
| TikTok (Display API) | Display API terms apply to derived counters and listings. No deletion window is established, so the obligation is recorded without a deadline rather than with a guessed one. |
A record of the fact that access existed, and when it ended, is kept after a disconnect. That is the audit trail that lets us answer "what could this integration reach, on what date", and it holds no credential.
What we do not do with platform data
- We do not sell it.
- We do not use it to train a general-purpose model.
- We do not pool one creator's platform-derived numbers into a cross-customer benchmark. Benchmarks in the product are built from deal records contributed deliberately and de-identified first, not from connected accounts.
Who else processes it
Named because the product actually calls them, not as a general disclaimer: the social platform a creator connects (Instagram, TikTok, or YouTube); Google, when an agency connects a Gmail mailbox to send from it; Stripe, for payment; Clerk, for sign-in; and Render, which hosts the service. Each receives only what its job needs.
Email we send
Outbound email is sent from an agency's own connected mailbox, under a human's explicit approval of each message. Nothing in the product sends on a person's behalf without that approval.
Contact
Prscnt LLC — chris@prscnt.com. We answer data questions from agency users and from creators directly, whether or not the creator holds the account that signed up.