1Who we are
Kolony is operated by KleePay Limited ("KleePay", "we", "us"). KleePay Limited is the data controller for the information described here. You can reach us at partnership@kleepay.ai.
2Who this policy covers
- Creators: people who publish on YouTube, X or Reddit and whose public profiles appear in Kolony, whether or not they ever talk to us.
- Affiliates: creators who join the KleePay affiliate programme and share a referral link.
- Referred users: KleePay customers who signed up through an affiliate link.
- Team members: KleePay staff who sign in to Kolony.
3Information we collect and where it comes from
Public creator information. Using the platforms' official APIs (the YouTube Data API, the X API and the Reddit API) and the public pages creators publish, we collect the profile information those creators have made public: channel or account name and handle, profile image, description, follower or subscriber counts, recent public posts with their view and engagement counts, country and language where available, and any business contact details the creator has published (for example an email address in a channel description or link-in-bio page).
Our own notes. Team members may add notes, tags, a pipeline status and an assessment of fit for the affiliate programme. Some assessments are drafted with the help of an AI model from the public information above.
Outreach records. When we email a creator we keep a copy of the message, the address it went to, delivery status, and any reply. Replies are matched to the creator they came from.
Referral and commission records. For affiliates we record the referral code and link we issued, clicks on that link (the visitor's IP address is hashed and not stored in the clear, together with browser type and referring page), and events KleePay's own systems report about referred users: signup, first spend and later spend amounts, and reversals. We record a pseudonymous user identifier for referred users, never their name, card details or account contents.
Team member information. The Google account email and name used to sign in, a record of security-relevant actions (changing settings, sending campaigns, exporting data) and standard server logs.
4How we use it
- To find creators whose audience overlaps with KleePay's and decide whom to invite to the affiliate programme.
- To contact creators about the programme, and to stop contacting them when they ask.
- To attribute referred customers to the right affiliate and calculate the commission we owe them.
- To keep the platform secure and auditable.
We do not sell this information, use it for advertising, or build profiles of creators for any purpose other than the partnership described here.
5YouTube API Services
Kolony uses YouTube API Services to retrieve public channel and video information. By using Kolony, team members agree to be bound by the YouTube Terms of Service. Google's handling of information is described in the Google Privacy Policy.
- Kolony only accesses public YouTube data. It does not request access to anyone's YouTube account and does not use OAuth scopes for YouTube.
- YouTube data stored in Kolony is refreshed from the API or deleted within 30 days. Channels that are no longer of interest are removed rather than kept.
- Kolony does not aggregate YouTube data across channels to derive metrics beyond the fit assessment for a single creator, and does not display YouTube data to anyone outside the KleePay team.
- Google may collect usage information about Kolony's API calls in accordance with its own policies.
6Sharing
We share information only with service providers that process it on our behalf under contract: our hosting provider (Vercel), our database provider (Supabase), our email delivery provider (Resend or an SMTP provider) for messages we send and receive, and an AI provider (Anthropic) that receives public creator information to draft assessments and outreach text. We do not share creator or referral information with other companies for their own use. We may disclose information if required by law.
7Retention
- Platform data (YouTube, X, Reddit): refreshed or deleted within 30 days, as described above.
- Outreach records and creator notes: kept while the creator is a prospect or partner and for up to 24 months afterwards.
- Referral and commission records: kept for the duration of the affiliate relationship and as long as required for accounting and tax purposes.
- Security audit logs and error logs: 90 days.
- Do-not-contact records: kept indefinitely so that a request to stop is honoured.
8Your choices
Creators can ask us at any time to stop contacting them, to see what we hold about them, to correct it, or to delete it. Replying "STOP" or "unsubscribe" to any of our emails does this automatically; you can also write to partnership@kleepay.ai. Deleting a record removes it from Kolony; it does not affect the public profile on the original platform.
Affiliates can request their referral and commission records and close their participation in the programme at any time.
You may also revoke any access Google has granted to third-party applications through the Google security settings page. Kolony does not hold such access, but the link is provided as required by YouTube's policies.
9Security
Kolony is available only to signed-in KleePay staff. Data is stored with row-level security enabled, credentials for third-party services are encrypted at rest, transport is encrypted with TLS, and sensitive actions are recorded in an audit log.
10International transfers
Kolony's servers and database are located in Japan (Tokyo). Service providers listed above may process data in other countries under their own safeguards.
11Changes
We will update this page when our practices change and revise the effective date above. Material changes affecting affiliates will also be communicated by email.