Privacy Policy
Last updated: July 20, 2026
mudy (“we”, “us”, the “Platform”, available at mudy.io) connects content creators (“clippers”) with brands. Clippers post short clips promoting brand campaigns and are paid based on the public view counts of those clips. This policy explains what data we collect, how we use it, and your choices.
Information we collect
- Account data — email, display name, language and niche preferences, and your USDT (TRC‑20) payout address.
- Social account data — when you connect a social account (TikTok, Instagram, Facebook, X, YouTube/Google), and only with your explicit authorization, we receive your platform user id, username/handle and basic public profile, and—where you grant it—public statistics of your own posts (such as view, like and comment counts).
- OAuth tokens — access/refresh tokens issued by the platform when you connect, stored encrypted and used only to act on your behalf as you authorized.
- Submission & campaign data — links to clips you submit and their public performance metrics.
- Payment data — deposit/payout records processed via our payment providers; we do not store full card numbers.
How we use platform data
We use data obtained through the TikTok, Meta (Instagram/Facebook), Google (YouTube) and X developer APIs solely to provide the Platform’s features:
- verify that a connected account belongs to you (ownership verification);
- match submitted clips to your verified account and measure their public view counts to calculate campaign earnings;
- detect fraud and fake engagement.
We do not sell platform data, do not use it for advertising, and handle it in accordance with each platform’s developer terms and policies. We request the minimum scopes needed for the above.
YouTube (Google) API Services
When you connect a YouTube channel, mudy uses YouTube API Services. We request only the youtube.readonly scope, and use it solely to read your own channel’s id and title (via channels.list?mine=true) to verify that the channel belongs to you. We do not read, post, modify or delete any other YouTube data. Public view counts of submitted videos are obtained separately through the public YouTube Data API and do not require this connection.
- By connecting YouTube you agree to the YouTube Terms of Service.
- Google’s handling of your data is described in the Google Privacy Policy.
- You can revoke mudy’s access to your Google account at any time via Google security settings (in addition to disconnecting inside mudy).
- We do not store your Google OAuth token: it is used once, in the moment you connect, to read your channel id and title, and is then discarded. We keep only the channel id and title, which are deleted when you disconnect the channel or delete your account. We do not use YouTube API data for advertising and do not share it with third parties except the infrastructure providers that host the Platform.
Third parties
We share data only as needed to operate the service: social platforms (TikTok, Meta, Google, X) for the connections you authorize; payment processors for deposits and USDT/TRON payouts; and infrastructure providers that host the Platform. We do not sell your personal data.
How we protect your data
We take the security of your data seriously and use encryption to protect your information. We treat OAuth tokens and the platform user data we obtain through the Google (YouTube), TikTok, Meta and X APIs as sensitive data, and take reasonable and appropriate measures — described below — to protect Google user data and other sensitive data against unauthorized or unlawful access, use, alteration, disclosure, loss or destruction:
- Encryption in transit — all traffic to and from the Platform is served exclusively over HTTPS/TLS.
- Encryption at rest — OAuth access and refresh tokens and other secrets are encrypted before they are written to storage, using a key that is held separately from the database.
- Access controls — access to production systems and stored user data is restricted to a small number of authorized personnel, protected by authentication and least‑privilege permissions, and is used only to operate, support and secure the service.
- Isolation & hardening — secrets and tokens are never exposed to the browser or third parties; databases and backups are not publicly accessible and are protected behind the Platform’s infrastructure.
- Data minimization — we request the minimum OAuth scopes required, and store only the platform data needed to provide the features described above.
- Monitoring & incident response — we monitor for unauthorized access and abuse, and will notify affected users and the relevant authorities of any breach involving personal data as required by applicable law.
Data retention & deletion
We keep your data only while your account is active. When you disconnect a social account, its stored OAuth tokens are deleted. When you delete your account, we delete your personal data and all stored platform tokens, subject to limited records we must retain for legal, accounting or anti‑fraud purposes. Google user data is retained only as long as needed for the purposes described above and is deleted on the same basis.
Your rights & data deletion
- Access or correct your data from your account settings.
- Disconnect a social account at any time in Settings → Socials; this removes the stored tokens for that account.
- Delete your account in Settings, which removes your personal data and all stored social tokens. You can also revoke mudy’s access from the connected platform’s own app settings.
- To request deletion or ask a question, contact us at support@mudy.io.
Children
The Platform is not directed to anyone under 18, and we do not knowingly collect their data.
Changes
We may update this policy and will revise the “Last updated” date above.
Contact
Questions about this policy: support@mudy.io.