This Privacy Policy explains what information Sentinel Relay collects, why, how long it is kept, who it is shared with, and what rights you have. It applies to the Sentinel Relay platform, its creator portal, and its notification bots.
The data controller is Sentinel Relay, a sole-trader business established in the United Arab Emirates, at Al Ain, Abu Dhabi, United Arab Emirates. For any privacy question or request, contact [email protected].
Sentinel Relay is a business-to-business service. Where an agency uses it to analyse creators it represents, that agency decides which creators to track and which sections a creator may see; in that respect the agency acts as controller of its own roster data and we process it on the agency's behalf.
We do not collect payment card details, government identifiers, or special category data such as health, biometric or political data, and you should not enter them into the Service.
Where TikTok features are enabled for an agency, Sentinel Relay obtains TikTok data from two sources, set out below. Both are limited to creators on that agency's roster. Neither involves a creator's TikTok password, which we never ask for, store, or have access to, and neither gives us the ability to act on a creator's account.
a. Connected accounts. When a creator connects their TikTok account through TikTok's own login and permission flow, we read data through TikTok's official APIs under the permissions that creator granted: basic profile information for the authorised account (display name, username, avatar, follower and following counts, total likes and video count) and metrics for that account's own videos (video identifier, title or description, publication time, and counts of views, likes, comments and shares). A creator can withdraw this permission at any time.
b. Publicly available information. For roster creators who have not connected an account, we also record information that TikTok publishes openly on public profile and video pages, which does not require a connected account: the account's display name, biography, avatar, follower and total-like counts, and, for each public video, its title or description, publication time, length, and public view, like, comment, share and save counts. This is the same information available to anyone viewing those pages. We record nothing private, draft, deleted, or restricted by this route, and no information about a creator's audience, messages, or viewing history.
In both cases we keep day-by-day snapshots of these figures so that growth can be charted over time.
What we do not do. By both routes, access is read-only. We cannot post, edit, delete, or schedule content, send messages, or take any action on a creator's TikTok account. We do not access private or draft content, direct messages, contact lists, or a creator's viewing history. We do not remove or alter watermarks or other creator attribution. We do not use TikTok data for advertising or ad targeting, we do not sell it, and we do not share it with data brokers.
Who can see it. TikTok data is visible only to the authorised creator and to the users of that creator's linked agency who need it to operate the creator program. It is never visible to other agencies or to other creators.
Withdrawing permission and deletion. A creator can disconnect at any time in the Service, or revoke access directly in their TikTok account settings. Disconnecting revokes our access and deletes the stored authorisation together with the TikTok analytics we hold for that account. We also delete TikTok data when an agency stops tracking a creator, when the account is closed, or on request to the contact address above. A creator can also ask us to stop recording their publicly available information and to delete what we hold, using the contact address above, whether or not they have an account with us. Our use of TikTok data obtained through TikTok's APIs is carried out under the TikTok Developer Terms of Service.
We use Google/YouTube APIs to provide functionality. This application uses YouTube API Services. Where a creator authorises a YouTube connection, we access their YouTube channel and video metadata (youtube.readonly) and their YouTube Analytics reports — views, watch time, retention, subscribers gained/lost, traffic sources, geography, and demographics (yt-analytics.readonly). All access is read-only; we never request or collect revenue or monetary data, and we cannot post, edit, or modify anything on the channel. OAuth refresh tokens for authorised connections are encrypted at rest, and connected analytics data is encrypted at rest. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. By connecting YouTube you also agree to the YouTube Terms of Service, and Google’s use of your data is governed by the Google Privacy Policy. You can revoke our access at any time via your connection settings or at Google security settings.
Google/YouTube data is available only to the connected creator and authorised users of their linked agency who need it to operate the creator program. It is not visible to other agencies, sold, used for advertising, or shared with data brokers. Infrastructure providers process it only as needed to operate and secure Sentinel Relay.
Disconnecting a YouTube channel revokes Sentinel Relay's access and deletes the stored OAuth connection and connected YouTube analytics from Sentinel Relay. The creator can also revoke access through Google security settings.
For Twitch we use the official Twitch API to read public channel information and the public record of a channel's past broadcasts, such as stream titles, start times, duration, viewer figures and saved-broadcast view counts. For Discord we use a bot to deliver the notifications an agency configures; it reads the identifiers needed to send a message to the channel or recipient you have chosen and does not read your server's message history.
We use information to provide and secure the Service, to authenticate users, to generate analytics, reports and payout calculations, to send notifications you configure, to support you, and to detect and prevent abuse. Where the law requires a legal basis, we rely on: performance of our contract with you, for operating the Service; your consent, for connecting a platform account, which you may withdraw at any time; our legitimate interests, for security, abuse prevention and product improvement; and compliance with legal obligations. We do not sell personal information, and we do not use it for advertising or to train machine-learning models for third parties.
We do not sell or rent personal data. We share it only with:
If the Service is ever transferred to another operator, we will give notice before your data is transferred, and the receiving operator will remain bound by a policy no less protective than this one.
Our servers are located in the European Union. Where a connected platform is based elsewhere, retrieving your data necessarily involves a transfer to that platform's own infrastructure under its own privacy policy. Where we transfer personal data out of the European Economic Area, we rely on an adequacy decision or on the European Commission's standard contractual clauses.
We protect data with encrypted transport (HTTPS), role-based access controls, tenant isolation so one agency cannot reach another's data, hashed passwords, optional two-factor authentication, rate limiting, automatic blocking after repeated failed logins, alerting on unusual sign-ins, and daily backups. OAuth refresh tokens and connected-platform analytics are additionally encrypted at rest. No system is perfectly secure, and we cannot guarantee absolute security.
We may keep records longer where the law requires it, or where needed to resolve a dispute.
Depending on where you live you may have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent you have given. If you are in the European Economic Area or the United Kingdom these rights arise under the GDPR; if you are a California resident you have comparable rights under the CCPA, including the right not to be discriminated against for exercising them. We do not sell personal information, so there is nothing to opt out of in that respect.
To exercise any right, email [email protected]. We will respond within 30 days. You may also disconnect any authorised platform connection yourself at any time in the Service. If you believe we have handled your data improperly you may complain to your local data protection authority.
The Service is intended for business users aged 18 or over and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
We use a session cookie (Secure, HttpOnly) to keep you signed in and a token to protect against cross-site request forgery. Both are strictly necessary to operate the Service. We do not use advertising cookies, third-party trackers, or cross-site analytics.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where required, and will inform affected users without undue delay.
We may update this policy. The "last updated" date above always reflects the current version, and we will give notice in the Service before a material change takes effect. Continued use after that date means you accept the updated policy.
Sentinel Relay, Al Ain, Abu Dhabi, United Arab Emirates. Questions about this policy, or requests to access, correct or delete your data: [email protected].