Privacy
Last updated 18 September 2026
1.What we collect
There is no account and no password here. Three things can happen, and each is your choice:
If you only read the page
Nothing is collected. There are no analytics, no advertising cookies and no third-party scripts - the page loads nothing from anyone but us.
If you connect a social account
We ask the platform for read-only access, which you approve on its own screen: instagram_business_basic and instagram_business_manage_insights for Instagram; user.info.basic, user.info.username, user.info.profile, user.info.stats, user.insights, video.list and video.insights for TikTok; youtube.readonly and yt-analytics.readonly for YouTube. From that read we keep, per account:
- the platform, its own id for the account, and your handle;
- your follower or subscriber count;
- up to 12 of your most recent Reels, TikToks or Shorts from the last 30 days, and for each: the post id, the format, the date, and its view, like and comment counts;
- the average of those views, and the rate we priced it at;
- your audience by age band, gender and country, as shares of the audience the platform disclosed - never individual viewers;
- if a platform refused to give demographics, the reason it gave.
The platforms send more than that in their standard responses - TikTok’s includes bios, profile links, verification status and each video’s title, description and thumbnail. We read what we need and never write the rest down.
We never receive your password, your messages, your follower list, your email address from the platform, your posts themselves, or any permission to post, comment or message as you.
If you join the list
- Your name and email address.
- The date and time you ticked the box - the moment rather than a yes, because when you agreed is the half a yes cannot answer.
What the site records by working
- A session cookie (
wl_session, 30 days) holding a random id that names your draft, so the tab coming back from Instagram is recognised as the tab that left. Signed, httpOnly, shared with nobody, and not an advertising identifier. - A cookie during a connection (
wl_flow, 10 minutes) holding a one-time value we check on the way back, so a response from a connection you did not start is rejected. Deleted as soon as the connection ends. - Your IP address, to rate-limit connections - each one spends around nineteen calls of an API budget shared by every visitor. Where you already have a session cookie we count against that instead.
- Server logs, recording requests and errors with IP addresses and timestamps, in the ordinary way.
2.Why do we need this?
Fair question. The honest answer is arithmetic plus curiosity.
The arithmetic is unavoidable: we cannot tell you what you would earn without knowing how many people actually watch what you post. A follower count would let us guess, and guessing is what every other calculator does. The average views on your last dozen posts is the real number, and it is the one that turns “you seem to be doing well” into a figure in dirhams.
The curiosity is the rest of it. We are building getUGC for creators in this region and we do not know nearly enough about them yet. How big is a typical creator here? Do Reels travel further than TikToks, or the other way round? Is a Dubai food account’s audience actually in Dubai? Every account that connects makes the next version of this less of a guess - which rates are realistic, which platform to build for first, what the app should be good at. That is why the figures stay with your waitlist entry for a year rather than being thrown away the moment you have seen your estimate.
What we are not doing: building a profile of you, selling anything to anybody, or reading your messages. The sections above and below are the long version of that promise, and they are the version that counts.
3.What we never keep: your access token
The authorisation you grant is used once, inside the single request that reads the figures above, and is then discarded. It is never written down - there is no column in our database for a token, so there is none to leak. The worst a breach here could expose is view counts and email addresses, not access to anyone’s social accounts.
Where a platform lets us hand the grant straight back we do, before the request ends; TikTok and Google both allow it. Instagram Login publishes no revocation endpoint, so that grant simply expires on Instagram’s schedule. You can remove our access yourself at any time - Instagram: Settings, then Apps and websites. TikTok: Settings, then Security and permissions, then Manage app permissions. Google and YouTube: myaccount.google.com/permissions. That stops future reads; to delete what we already hold, see section 6.
4.YouTube data specifically
The waitlist uses YouTube API Services. By connecting a YouTube channel you are also agreeing to the YouTube Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy.
What we do with YouTube data is exactly what section 1 describes and nothing else: we read your channel’s recent Shorts and their view, like and comment counts, and the age, gender and country breakdown of your viewers; we store the subset listed there for twelve months; we show it back to you; we do not share it with anyone; and we do not use it for advertising. You can revoke our access at the Google link above, and ask us to delete what we stored at any time.
5.How long we keep it
- What we read from your accounts - 12 months from the day you connected. It is kept for that period alongside your waitlist entry so we can improve the product and calibrate the estimates it quotes.
- Name and email - until we open in your market and for 12 months after, or until you unsubscribe or ask us to delete, whichever comes first.
- The consent timestamp - as long as we hold the entry it belongs to, since evidencing that entry is its only purpose.
- Cookies - 30 days for the session, 10 minutes for the connection.
- Rate-limit counters - hours; they die with their window.
- Server logs - 30 days.
When a period ends the record is deleted, not archived.
6.Deleting it, and your other rights
Email hello@getugc.com with the address you signed up with - or, if you only connected an account and never left an email, the handle you connected. That is enough to find you.
You can ask us to:
- delete everything - your entry, what we read from your accounts, the audience rows. A real delete, not a flag; removing your entry removes every connected account attached to it;
- show you what we hold, or send it in a machine-readable form;
- correct it, or withdraw your consent - which means we delete;
- stop using it while you query something.
We answer within 30 days, and if something will take longer we will say so before the 30 days are up rather than after. You can also unsubscribe from the foot of any email, which stops the email and leaves the rest. If you think we have handled your data badly, you can complain to your local data protection authority.
7.Who else sees it, and where it lives
The platform you connect knows you authorised us, and is an independent controller of its own side of that under its own policy. Beyond that, the only others who touch it are the services that run this site on our behalf: our database is Neon, hosted on AWS in Frankfurt, in the European Union, and our hosting and email providers process what they must to serve the page and send the one email this list exists to send. If you are in the UAE, that means your data is stored outside it.
We do not sell your data, do not share it for advertising, and do not pass it to brands.
8.Security, children, and changes
The cookies are signed, so a browser cannot edit one into somebody else’s, and httpOnly, so scripts cannot read them. Connections are rate-limited and verified with a one-time value. The protection that matters most is structural: there are no credentials in the database at all. No system is perfectly secure, and if something goes wrong we will tell you and the relevant authority as the law requires.
The waitlist is for people aged 18 and over. If you believe a child’s data is here, write to us and we will delete it.
If this page changes materially we will update the date at the top, and where a change affects data you have already given us, we will email you before it takes effect. The terms cover what joining does and does not get you.