Privacy policy

Your data, in plain language

Effective August 27, 2026. This is the policy — we've written it to be read, not skimmed past.

Privacy policy

What we collect

Account details (name, email, role), your public creator or brand profile, synced platform stats (followers, engagement) used for verification badges, order and dispute threads, and payout preferences. Payment card and bank details go directly to our regulated banking partners — we never store them.

Connected social accounts

When you link YouTube (Google), Facebook or Instagram (Meta), or LinkedIn from the studio, you approve access on that platform's own consent screen. We receive your profile basics (name, username, avatar), audience counts, your Pages or channels, and — only when you ask the studio to do it — the ability to publish a post, reply to a comment, or start a live stream on your behalf. Access tokens are held one of two ways. For Facebook, Instagram and LinkedIn they stay in secure, browser-only (httpOnly) cookies on your device and never reach our database. For YouTube — where one account can connect several channels, more than a cookie can carry — the tokens are stored on our servers instead, in a private area of the database that is walled off from our data API entirely; the safeguards on it are described under “How we protect Google user data” below. Everything else our servers keep is non-secret account metadata such as your handle and follower count. We use platform data solely to run the features you see, in line with the Meta Platform Terms and the Google API Services User Data Policy — never for advertising profiles, and never sold.

Google user data we receive

When you connect a YouTube channel, Google — not Shaheeno — shows you the consent screen, and you choose what to grant. With the scopes you approve there, we receive only:

  • Channel basics — channel name, handle, avatar, and subscriber, view and video counts.
  • Your uploads — video id, title, thumbnail URL, duration, category, privacy status, publish date, and the public counters (views, likes, comment count).
  • Your own channel analytics — day-by-day views, watch time and subscriber changes for your channel. We do not request revenue data.
  • Comment threads on your videos — so the Channel Inbox can show them and let you reply.
  • OAuth tokens — an access token and a refresh token, held as described under “How we protect Google user data” below.

Uploading a video, changing a thumbnail, posting a comment reply and starting a live stream happen only when you press the button that does them. Nothing is published on your behalf automatically.

How we share Google user data

Raw Google user data. We do not sell, rent or trade it. We never share it with advertisers, ad networks, data brokers, credit bureaus or lead-generation services, and we never use it to build advertising or credit profiles. Apart from you, raw Google user data reaches only these types of parties:

  • Service providers (sub-processors) acting on our instructions, under written contracts that restrict them to running Shaheeno and forbid any other use or disclosure:
    • Cloud hosting (Heroku, a Salesforce company) — runs the application servers that call Google's APIs on your behalf.
    • Database, authentication and file storage (Supabase, hosted on Amazon Web Services) — stores the channel, video and daily-stat rows your dashboard displays.
    • AI drafting (Anthropic's Claude API) — only when you press an AI button. Choosing “AI draft” on a comment, for example, sends that single comment, and where relevant the video's title, so a suggested reply can be written for you to edit and approve. Nothing is sent in bulk or in the background, and under Anthropic's commercial terms that text is not used to train models.
  • Google itself — when you publish a video, set a thumbnail, post a reply or start a live stream, that content goes back to YouTube.
  • Other Shaheeno users and the public — only what you choose to publish. Brands you work with and visitors to your public profile see the profile fields you put there (channel name, handle, avatar, and the follower figure behind your verification badge). Your channel analytics, comment threads and access tokens are never shown to them.
  • Law enforcement or regulators — only where a valid legal process requires it, or where disclosure is necessary to prevent fraud, abuse or harm, and then only the minimum needed.
  • A successor entity — if Shaheeno is ever merged or acquired, data may transfer to the buyer, who remains bound by this policy. We tell you before that happens so you can delete your data first.

Aggregated and anonymized Google user data. We also compute aggregate figures across many connected accounts at once — for example typical engagement rates or pricing benchmarks by category and audience size. These are stripped of channel and account identifiers and cannot be traced back to an individual channel or person. We display them only inside Shaheeno and on our own public pages; we do not sell them, and we do not share them with advertisers, data brokers or any other third party.

We do not use or transfer Google user data — raw, aggregated or anonymized — to develop, improve or train generalized or non-personalized AI or machine-learning models.

Shaheeno's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect Google user data

Google user data is protected in transit, at rest, and against access by anyone but you, with these specific safeguards:

  • Encrypted in transit — the site is served over HTTPS only, and every call we make to Google's APIs is made server-to-server over TLS.
  • Tokens are isolated — your Google access and refresh tokens are stored in a private database schema that is deliberately not published to our data API: every role is refused direct access to it, our own privileged server role included, and it carries row-level security with no policy that would let a request through. Three narrow, audited server functions are the only way to read or write a token, and only our server may call them. The tokens are never sent to a browser, so no script on the page can reach them, and never written to logs; only our server sends them, and only to Google.
  • Encrypted at rest — the channel, video and daily-stat rows we do keep, and the tokens described above, live in managed PostgreSQL (Supabase on AWS), encrypted at rest, with encrypted backups.
  • Enforced per-row access control — every studio table runs PostgreSQL Row-Level Security, so a row can only be read by the account that owns it. That check happens in the database itself, not just in application code, so an application bug cannot expose your channel to another user. Privileged service credentials stay on the server and are never sent to a browser.
  • Least privilege — we request only the Google scopes the features you can see actually need, and we revoke them with Google when you disconnect.
  • Limited human access — a small number of authorized staff can reach production data only when support or debugging requires it, under confidentiality obligations. We do not permit any human to read raw Google user data except with your consent, for security or abuse investigations, to comply with applicable law, or where the data has been aggregated and anonymized.
  • Auditing and secrets — every sync, token refresh and API error is recorded in a connection event log, so unusual activity is visible afterwards. API keys and OAuth client secrets live in environment configuration, never in source code, and are rotated if we suspect exposure.
  • If something goes wrong — if Google user data is ever exposed, we notify affected users and Google without undue delay, and in any case within 72 hours of confirming it.

How we use it

To run the marketplace and studio: matching, verification badges, escrow, payouts, FBR statements, scheduling and publishing your content where you tell us to, and support. Aggregated, anonymized numbers power features like rate benchmarks.

What we never do

Sell your personal data, show your earnings to other users, share your contact details with a counterparty before a funded order connects you, or post to a connected account without an action you took.

Cookies

We use cookies to keep you signed in and, for Facebook, Instagram and LinkedIn, to hold the access tokens for the accounts you connect — those are httpOnly, so scripts in the page can never read them. We don't run third-party advertising trackers.

Data retention & deletion

Disconnecting a linked social account, revoking access from the platform's side, deleting your whole account, or asking us by email — all are free and always available. The step-by-step instructions live on the Data deletion policy page. Deletion completes within 30 days, minus records the law requires us to keep.

For a connected Google account specifically: pressing Disconnect revokes our token with Google immediately, which ends all further access to your channel. You can do the same from your Google Account under Security → Third-party access. Stats already synced into your own dashboard stay there so your history is not lost; deleting your Shaheeno account removes them, along with every other row tied to you, within 30 days.

For a connected Facebook Page specifically: pressing Disconnect revokes every permission you granted Shaheeno with Meta immediately, which ends all further access to your Page. You can do the same from Facebook under Settings & privacy → Settings → Apps and websites → remove Shaheeno. For a connected Instagram account, Meta's Instagram API offers no revoke endpoint, so pressing Disconnect destroys the access token on our side — your account is unreachable to us from that moment — and you remove the app itself from Instagram under Settings → Website permissions → Apps and websites. Page or account details already mirrored into your own dashboard stay there so your history is not lost; deleting your Shaheeno account removes them within 30 days.

Who you must be

Shaheeno is for adults — you must be 18 or older to hold an account, so we do not knowingly collect data from children.

Changes & contact

If this policy changes materially we notify you by email and in-app before it takes effect. Questions or requests about your data: use the contact page — a human answers.

Looking for the rules of the marketplace instead? Terms of Service · Questions? Contact us

Ready to take flight?

Join the marketplace where Pakistani brands and creators work together — every order funded into local-bank escrow, every payout in rupees.

امید · پرواز · شاہین