How CreatorAPI and OF Monitor collect, use, and protect your information, including data from Google Drive.
01Overview
This Privacy Policy explains how AWE Tradegroup LLC (we, us, our) collects, uses, shares, and protects information when you use our products. It applies to:
- CreatorAPI, the unified API for creator platforms, including the website at creator-api.com, the API at api.creator-api.com, and the dashboard.
- OF Monitor, our CRM and content workspace for creators and agencies, available as a web app at app.creator-api.com and as a desktop app for macOS and Windows.
- The related websites, APIs, dashboards, integrations, and support channels that we operate.
Together these are the Service. CreatorAPI and OF Monitor are both products of AWE Tradegroup LLC. When you connect Google Drive to OF Monitor, the Google consent screen shows the app name CreatorAPI. We keep data collection to what we need to run the Service and to bill you. This policy works together with our Terms of Service.
02Who is responsible
The data controller for CreatorAPI and OF Monitor is AWE Tradegroup LLC, 30 N Gould St, STE 4000, Sheridan, Wyoming 82801, United States. For any privacy request, contact [email protected].
03Information we collect
- Account data: the email address you provide at signup, and the API keys we issue to you.
- Usage data: metadata about your API calls, such as endpoint, timestamp, credit cost, and success or error status. We use this to meter credits and show you your dashboard.
- Connected account credentials: the access tokens or session material you provide so we can operate the creator accounts you connect. These are stored to perform the calls you request.
- Billing data: handled by Stripe. We receive a customer reference, plan, and payment status. We do not receive or store full card numbers.
- Technical data: standard request logs and security signals provided by our network layer.
- Google user data: only if you connect Google Drive to OF Monitor. Section 09 describes this in full.
04How we use information
- To provide, operate, and secure the Service.
- To meter and bill credits and manage subscriptions.
- To communicate about your account, billing, and service changes.
- To detect, prevent, and address abuse, fraud, and security issues.
- To comply with legal obligations.
We do not sell your personal data, and we do not use the content you access through connected accounts, or any Google user data, to train any model of ours.
05Legal bases and consent
Where the GDPR or the UK GDPR applies, we rely on these legal bases:
- Contract: to provide the Service you signed up for, including the calls, imports, and posts you request.
- Consent: for access to your Google Drive. You give this consent on Google's own consent screen, separately for each Google account you connect. You can withdraw it at any time by disconnecting the account in OF Monitor or by revoking access in your Google Account settings. Withdrawing consent does not affect processing that happened before.
- Legitimate interests: to keep the Service secure, prevent abuse and fraud, and fix errors.
- Legal obligation: to keep billing and tax records and to respond to lawful requests.
06Payment processing
Payments are processed by Stripe, Inc. Your card details are handled directly by Stripe under its own privacy policy. We recommend you review Stripe's privacy terms for how it processes payment information.
07How we share information
We share information only as needed to run the Service:
- Stripe for payments and subscription management.
- Cloudflare for network delivery, TLS, and security.
- Connected platforms that you direct us to call on your behalf.
- Google, when you connect Google Drive to OF Monitor. We send requests to Google's APIs to list and download what you selected.
- Legal and safety: where required by law, or to protect rights, safety, and the integrity of the Service.
We do not share your data with advertisers. Section 09 lists exactly who receives Google user data.
08Connected account data
Credentials for accounts you connect are used only to carry out the API calls you request. You can remove a connected account, and you can ask us to delete its stored credentials, by contacting us or through the tools we provide. When you disconnect an account or close your account, we delete the associated credentials within a reasonable period.
09Google Drive and Google User Data
This section applies if you connect a Google Drive account to OF Monitor. CreatorAPI's public API does not access Google Drive. Connecting Google Drive is optional.
How you connect and which permissions we ask for
OF Monitor uses Google OAuth 2.0. You sign in on Google's own page, and we never see your Google password. You can connect one or more Google accounts that belong to you. We ask only for the permission that the feature you choose needs:
- Choose files (scope
https://www.googleapis.com/auth/drive.file): OF Monitor can access only the specific files you pick in the Google file picker. - Choose or sync a folder, and Drive folder sources in Feed Poster (scope
https://www.googleapis.com/auth/drive.readonly): read only access to your Drive, so OF Monitor can show your folder names and read the files inside the folders you select. Google describes this permission as the ability to see and download your Drive files. OF Monitor lists folder names only so you can pick one, and it reads only the files inside the folders you select.
We request offline access so that a folder you set up as a content source can keep syncing without you signing in each time.
Google data we access
- Google account details: when you connect an account for Feed Poster, we read your Google display name, your email address, and an account identifier from the Drive API. We store the name and email so we can show you which account is connected. We use the identifier only to compute an internal connection ID and do not store the identifier itself. For the file and folder import in the Vault, we do not read your name or email.
- Folder metadata: folder names, folder IDs, and parent folder IDs, so you can browse, search, and select folders.
- File metadata: file names, file IDs, MIME types, and whether a file is in the trash.
- File content: the files you pick, or the files inside the folders you select. The feature is built for images and videos. When a folder is used as a Feed Poster source, every file in that folder that Google allows us to download is imported, so please select folders that contain only media you want to use. Google Docs, Sheets, and similar files cannot be downloaded this way and are skipped.
- OAuth tokens: the access token and refresh token that Google issues, with their expiry time and the permission you granted.
How we use Google data
- To show you which Google accounts are connected.
- To list and search your Drive folders so you can select one.
- To use the folders you select as a content source, and to check them for new files every few minutes while the source is active.
- To show, import, and add the media from those files and folders to your Content Queue.
- To send the media you import to the creator platform you chose, for example into your OnlyFans vault or as a post on OnlyFans or Fansly.
- To provide other features you explicitly request.
What we do not do
- OF Monitor only reads from Google Drive. It never changes, moves, shares, or deletes anything in your Drive.
- We do not sell Google user data.
- We do not use Google user data for advertising, retargeting, or interest based profiling.
- We do not use Google user data to assess creditworthiness or for lending decisions.
- We do not transfer Google user data to data brokers or information resellers.
Where and how Google data is stored
- Tokens and account details: stored on our server in an encrypted file (AES based authenticated encryption) that only the service account can read. For Feed Poster connections, the same encrypted file holds your Google display name and email. Tokens are not stored in the application database. When you open the Google file picker, a short lived access token is passed to your own browser, because Google's picker requires it.
- Selected folders: for a Feed Poster source we store the folder ID, the label you gave it, and the internal connection ID in our database.
- Folder and file lists: fetched live from Google while you browse and not saved. The exceptions are the Drive file IDs of imported files, which we keep to avoid importing the same file twice, and the status of a running import, which is held in memory only.
- Media imported into a Vault: downloaded to a temporary folder on our server, uploaded to your creator platform vault, and deleted from the temporary folder automatically when the import finishes or fails.
- Media imported into the Content Queue: a copy of each file is stored on our server's disk in a folder for that creator. HEIC images are converted to JPEG. The queue record holds the Drive file ID, the path of the stored copy (which includes a cleaned up version of the file name), the file type, your caption, the status, and the post IDs after publishing.
- Previews: we do not create separate thumbnails of Drive files. Previews in the queue show the stored copy, only to signed in users who are authorized for that creator. Your browser may cache a preview privately for a few minutes.
We run OF Monitor on servers that we operate ourselves. We do not place Google user data with a third party cloud storage provider.
How long we keep Google data
- Tokens, display name, and email: until you disconnect that Google account in OF Monitor, or until we delete your workspace. If you revoke access at Google, the stored tokens stop working, and we delete them when you disconnect the account or ask us to.
- Temporary files from a Vault import: deleted automatically at the end of the import, normally within minutes.
- Content Queue copies and queue records: kept so that your queue and posting history keep working, until you ask us to delete them or your workspace is deleted. They are not deleted automatically when you skip an item, remove a source, or disconnect Google. OF Monitor does not yet offer a button that erases stored copies yourself, so please email us and we will delete them within a reasonable period.
Disconnecting, removing a source, and deletion
- Disconnect a Google account in OF Monitor: we delete that account's tokens, display name, and email from our encrypted store right away. Folder sources that used the account stop syncing. OF Monitor does not currently send a revocation request to Google, so we recommend that you also remove the app in your Google Account.
- Revoke access at Google: you can remove the permission at any time at myaccount.google.com/connections. This works even if you no longer have access to OF Monitor.
- Remove a source: we delete the source record and stop reading from that folder. Items that were already imported stay in your queue and history.
- Delete your account or send a deletion request: email [email protected]. We delete your Google tokens, connection details, sources, queue records, and stored copies within a reasonable period, except for records we must keep by law, such as billing records. Content that was already published to a creator platform stays on that platform, where you control it.
Who receives Google user data
- Cloudflare: carries the encrypted traffic between your browser or desktop app and our servers, including previews of imported media.
- The creator platform you choose: when you import into a vault or publish a post, the media file and your caption are uploaded to that platform, for example OnlyFans or Fansly. Network and proxy providers carry this upload in TLS encrypted form and cannot read it.
- Legal requirements: if a law or a binding legal order requires disclosure.
Nobody else receives Google user data. We do not send it to AI providers, advertisers, or analytics companies.
AI features and Google data
OF Monitor has an optional AI caption drafting feature. It runs only when you click to draft a caption, or when you switch on automatic captions in your posting plan. It sends text only to Anthropic (Claude): a style profile learned from your past post captions, your tone notes and selected tone, and examples of your own past messages that led to purchases, with the purchase amounts. It does not send your Google Drive files, file names, folder names, or any other Google user data, and the AI does not look at the imported image or video. If this ever changes, we will update this policy first.
We do not use Google Workspace API data to develop, improve, or train generalized or non personalized AI or machine learning models.
Human access
Our staff do not read Google user data, unless you gave us explicit permission for specific files or messages (for example while we help you with a support request), it is necessary to investigate a bug, abuse, or a security incident, or the law requires it.
Limited Use
CreatorAPI and OF Monitor's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10Data retention
We keep account and usage data for as long as your account is active and as needed to provide the Service, resolve disputes, and meet legal and accounting obligations. When data is no longer needed, we delete or anonymize it.
The retention rules for Google user data are listed in section 09. To delete your account or specific data, including Google user data, email [email protected] from the address linked to your account.
11Security
We use technical and organizational measures to protect data, including access controls, encryption in transit, and restricted storage of sensitive credentials. Google OAuth tokens are encrypted at rest. Connections to the Service and to Google use TLS. Imported media is stored on servers we operate and is only served to signed in users who are authorized for that creator. No method of transmission or storage is perfectly secure, and you use the Service at your own risk.
12International transfers
We operate internationally, and your information, including Google user data, may be processed in the United States and other countries where we or our service providers operate. Where required, we rely on appropriate safeguards for cross border transfers.
13Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. This includes rights under the GDPR, the UK GDPR, and the California consumer privacy laws. These rights also cover any Google user data we hold about you. Where we rely on your consent, you can withdraw it at any time. To exercise any right, contact [email protected]. You may also complain to your local data protection authority.
14Children
The Service is for adults and is not directed to anyone under 18. We do not knowingly collect data from children.
15Changes
We may update this policy. We will update the effective date above and, for material changes, take reasonable steps to notify you.
16Contact
For privacy questions and requests about CreatorAPI or OF Monitor, including Google user data: [email protected]
AWE Tradegroup LLC
30 N Gould St, STE 4000, Sheridan, Wyoming 82801, United States