Effective Date: June 27, 2026 Last Updated: June 27, 2026 App Name: Promo Platform: Android · iOS · Web · Desktop
Welcome to Promo ("we", "our", or "us").
Promo is an influencer marketing marketplace that connects brands and content creators. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, how we store and protect it, and what rights you have over your data.
By downloading, installing, or using the Promo application, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree with the terms of this policy, please do not use our app.
Please read this policy carefully. If you have any questions, contact us at the details provided at the end of this document.
We collect information that you provide directly to us, information generated automatically when you use the app, and in some cases, information from third-party services you connect to Promo.
Account Registration:
Email address
Password (encrypted — never stored in plain text)
Display name
Role (Brand or Influencer)
Profile Information:
Company name (Brands)
Bio / About section
Profile photo / avatar
Website URL
Location (city, region, or country — text format)
Geographic coordinates (when you use auto-detect location)
Niche / industry category tags
Social Media Information (Influencers):
Social media platform handles / usernames (Instagram, YouTube, TikTok, Twitter/X, LinkedIn, Snapchat)
Follower counts (entered manually or synced via platform APIs)
Content You Create:
Campaign cards (Brands) — titles, descriptions, budgets, requirements, images
Portfolio items (Influencers) — images and descriptions of past work
Milestone records (Influencers)
Chat messages — text, images, files, voice notes
Application pitch messages and proposed rates
Notes added to applications (Brands)
Verification Information:
Government-issued ID or business registration documents (only when you submit a verification request)
Usage Data:
Screens and features you visit within the app
Actions you take (applying to cards, accepting applications, etc.)
Timestamps of key activities (application date, login time, last active time)
Profile view records (who viewed whose profile and when)
Device Information:
Device type and operating system (Android, iOS, Web, Desktop)
Firebase Cloud Messaging (FCM) push notification token
App version
Location Data:
GPS coordinates — only when you explicitly grant location permission and use the auto-detect location feature or the map screen
We do not track your location continuously or in the background
Error and Crash Data:
Crash reports and error logs collected via Sentry
Navigation traces (which screens were visited before a crash)
These are used solely for debugging and improving app stability
Google Sign-In: When you choose to sign in with Google, we receive from Google:
Your Google account email address
Your Google display name
Your Google profile photo (optional) We do not receive your Google password.
Social Platform APIs: When you connect a social media platform and enable follower sync, we may receive your current follower/subscriber count from that platform's public API. We do not access your private messages, posts, or account credentials on those platforms.
We use the information we collect for the following purposes:
Create and manage your account
Display your profile to other users on the platform
Enable brands to post campaign cards and influencers to discover and apply to them
Facilitate real-time messaging between brands and influencers
Display your location on the map discovery feature
Show portfolio items, milestones, and analytics to relevant users
Show influencers recommended cards matching their niche, platforms, and location
Show brands relevant influencer results based on their targeting preferences
Display the profile completeness score and suggestions
In-app notifications for new applications, application status changes, new messages, and profile views
Push notifications via Firebase Cloud Messaging (FCM) on mobile devices
Enforce the 7-day session inactivity timeout
Detect and prevent fraudulent or abusive behavior
Validate uploaded files (size, format, MIME type)
Apply Row-Level Security to ensure users only access data they are authorized to see
Analyze crash reports and error logs via Sentry to fix bugs
Understand how features are used to improve the product
Respond to valid legal requests from authorities where required
Enforce our Terms of Service
We do not sell your personal information. We do not share your data with advertisers or third-party marketing companies.
We share information only in the following limited circumstances:
Your public profile information is visible to other users on the platform. This includes:
Display name
Profile photo
Bio
Location (city/region)
Niche tags
Connected social platforms and follower counts (Influencers)
Portfolio items (Influencers)
Active campaign cards (Brands)
Verification badge status
Your private information (email address, password, exact GPS coordinates, device tokens, crash logs) is never shared with other users.
Chat messages are visible only to the participants of that conversation (1:1 or group members).
We use trusted third-party services to operate the app. These providers process your data only as necessary to provide their services to us:
Service Provider
Purpose
Data Shared
Supabase
Database, authentication, file storage, real-time
All app data stored here
Firebase (Google)
Push notifications (FCM)
Device push token, notification content
Sentry
Crash and error reporting
Error logs, navigation traces, device info
Google Sign-In
OAuth authentication
Email, name (from Google account)
OpenStreetMap Nominatim
Geocoding (text to coordinates)
Location search text you type
Carto
Map tile rendering
No personal data — map tile requests only
All service providers are required to handle your data securely and only for the specified purpose.
We may disclose your information if we believe in good faith that disclosure is necessary to:
Comply with a legal obligation or valid government request
Protect the rights, property, or safety of Promo, our users, or the public
Enforce our Terms of Service
Prevent fraud or abuse
In the event of a merger, acquisition, or sale of all or part of our assets, your information may be transferred to the new owner. We will notify you of any such change via in-app notice or email.
Your data is stored on Supabase cloud infrastructure:
Database: Supabase PostgreSQL (hosted on Supabase Cloud)
Files and Images: Supabase Object Storage
Authentication: Supabase Auth (JWT tokens with refresh token rotation)
A small amount of data is stored locally on your device:
Theme preference (Light/Dark/System)
Cached profile data for fast app restore
Session activity timestamp
Onboarding completion flag
We implement the following technical and organizational measures to protect your data:
Database Security:
Row-Level Security (RLS) — enforced at the database level. Users can only read and modify data they are explicitly authorized to access. This applies to all tables including profiles, messages, applications, and cards.
Authentication Security:
Passwords are hashed using bcrypt via Supabase Auth — never stored in plain text
JWT tokens with automatic refresh token rotation
PKCE (Proof Key for Code Exchange) flow used for Google OAuth on web
Global session invalidation when password is changed — all sessions on all devices are terminated
Session Security:
7-day inactivity timeout — sessions automatically expire after 7 days of no activity
Users must re-authenticate after session expiry
File Upload Security:
All uploaded files are stored with UUID-based filenames to prevent path traversal attacks
MIME type validation — only allowed file formats are accepted
Size limits enforced — avatars up to 10 MB, other files up to 25 MB
Input Security:
All user-submitted text is passed through an InputSanitizer that strips HTML tags, script injections, and other potentially malicious content before storage (XSS protection)
Transport Security:
All data is transmitted over HTTPS/TLS encrypted connections
We retain your data for as long as your account is active. If you request account deletion, we will permanently delete your data from our systems, including:
Your profile and all profile information
Your campaign cards (Brands)
Your portfolio items and files (Influencers)
Your chat messages and attachments
Your application history
Your notification history
Note: Crash logs in Sentry may be retained for a short period per Sentry's own retention policy, subject to anonymization.
We do not have an automated data expiry policy beyond account deletion.
Depending on your location, you may have the following rights regarding your personal data:
You can view all the personal information you've provided by visiting your Profile and Settings screens within the app.
You can update your profile information at any time by editing your profile within the app (Profile → Edit Profile).
You have the right to request deletion of your account and all associated data. Since self-service account deletion is not available in the current version of the app, please contact us via the Support screen (Settings → Help & Support) to submit a deletion request. We will process it promptly.
You can withdraw consent for optional data collection at any time:
Location access: Disable location permission in your device settings
Push notifications: Disable notification permission in your device settings or via Settings → Notification Preferences in the app
Camera/Microphone: Disable in your device settings
Google Sign-In: You may disconnect Google from your account by signing in with email/password instead
If you wish to receive a copy of your data, contact us through the Support screen and we will provide it in a readable format where technically feasible.
You may object to certain processing of your data. Contact us via the Support screen with your specific objection.
If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR), including the rights listed above. Our legal basis for processing your data is:
Contractual necessity — processing required to provide the app's services
Legitimate interests — security, fraud prevention, and app improvement
Consent — for optional features like location access and push notifications
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to delete, and the right to opt out of sale (we do not sell personal data).
Promo is not intended for use by anyone under the age of 13 years old. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately via the Support screen. We will take steps to delete such information promptly.
The following permissions may be requested by the app on your device:
Permission
Why We Need It
Optional?
Internet
Required for all app features — Promo is cloud-based
No
Camera
To take profile photos and portfolio images
Yes
Photo Library / Storage
To select images from your device for upload
Yes
Location
To auto-detect your location for profile setup and map centering
Yes
Notifications
To send push notifications for messages and application updates
Yes
Microphone
To record and send voice notes in chat
Yes
You can deny any optional permission. The core app will still function, but features that depend on denied permissions will not be available.
The app may display links to external websites (e.g., brand websites entered in profiles). These third-party sites have their own privacy policies and we are not responsible for their content or practices. We encourage you to review their privacy policies before providing any information.
We use Firebase Cloud Messaging (FCM) to send push notifications to your mobile device. These notifications include:
New application received (Brands)
Application status updates (Influencers)
New chat messages
Profile activity alerts
You can disable push notifications at any time:
Via Settings → Notification Preferences in the app
Via your device's notification settings for the Promo app
Note: Push notifications are not fully supported on all web browsers due to technical limitations of Flutter Web and FCM.
Promo stores a small amount of data locally on your device using SharedPreferences (a local key-value storage mechanism). This is used for:
Remembering your theme preference (Light / Dark / System)
Caching your profile data for fast app restore on relaunch
Storing your session activity timestamp
Recording your onboarding completion status
This local data is not shared with any third parties. It is cleared when you sign out or uninstall the app.
Promo does not use browser cookies for tracking or advertising.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons.
When we make significant changes, we will:
Update the "Last Updated" date at the top of this policy
Notify you via an in-app notice or push notification
We encourage you to review this policy periodically. Your continued use of Promo after changes are posted constitutes your acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us through:
In-App Support: Settings → Help & Support
This Privacy Policy applies to the Promo mobile and web application across all supported platforms including Android, iOS, Web, Windows, macOS, and Linux.
© 2026 Promo. All rights reserved.