CreateThrough

Privacy Policy

Last updated: September 16, 2026

Ethan Nerone (“CreateThrough”, “we”, “us”) operates CreateThrough, a service that helps people track and publish content across their social platforms. This policy explains what we collect, why, how long we keep it, and how to get rid of it.

What we collect

Account information. Your name, email address and, if you sign in with Google, your Google account identifier and profile picture. If you sign up with a password we store a bcrypt hash of it, never the password itself.

Connected platform data. When you connect LinkedIn, YouTube or Instagram, we store the access and refresh tokens that authorize the connection, your account identifier and display name on that platform, and metadata about content you have published there — titles, text, publication dates, links, thumbnails and engagement counts such as views, likes and comments.

Content you create here. Topics you define, content ideas, drafts and scheduled posts, and your publishing cadence goal.

Billing information. If you subscribe, Stripe processes your payment and we store only the Stripe customer and subscription identifiers. We never see or store your card number.

Operational data. Server logs and error reports, which may include IP addresses, for security, abuse prevention and debugging.

How we use it

We use your data to show you analytics about your own publishing, to generate content suggestions, to publish posts you schedule, to operate billing, and to send you transactional email such as address verification and password resets. We do not sell your data, we do not share it with advertisers, and we do not use it to build profiles of you for anyone else's benefit.

Google user data

CreateThrough's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we request read-only access to your YouTube account in order to import your own videos and their public engagement metrics into your dashboard. We do not transfer this data to third parties except as necessary to provide the service, we do not use it for advertising, and no human reads it except where required for security or to comply with law. You can revoke our access at any time from your Google account permissions page, or by disconnecting YouTube inside CreateThrough.

Meta and LinkedIn data

Instagram data is accessed under the permissions you grant during connection and is used solely to display your own content and metrics back to you, and to publish posts you schedule. If you remove CreateThrough from your Instagram settings, we revoke the stored tokens automatically. You may also request deletion of Instagram-derived data through Meta, which we honour by deleting the connection and every post we synced from it.

LinkedIn data consists of what you import yourself (via LinkedIn's data export) or publish through us. We request only the permissions needed to identify your account and post on your behalf.

Who we share it with

We use a small number of processors, each of which sees only what it needs: Amazon Web Services (hosting and databases, United States), Stripe (payments), Resend (transactional email), Anthropic (generating your content suggestions), and Sentry (error monitoring). Content you schedule is transmitted to the platform you are posting to. We disclose data to law enforcement only where legally compelled.

Text from your posts and topic names is sent to Anthropic to generate suggestions. Anthropic does not train models on data submitted through its API.

Security

Platform access tokens are encrypted at rest with authenticated encryption before being written to the database. Databases and backups are encrypted, traffic is served over TLS, and the application runs in a private network with no direct public access to data stores. No system is perfectly secure, but we treat your connected-account credentials as the most sensitive thing we hold and design around that.

How long we keep it

We keep your data while your account is open. When you delete your account we remove your profile, posts, topics, ideas, scheduled posts, suggestions and platform connections immediately and irreversibly. Encrypted database backups roll off within 7 days. We retain billing records where tax and accounting law requires it.

Your rights

You can access and correct your information in the app, export nothing-you-did-not-give us by disconnecting a platform, and delete your entire account from Settings at any time. Depending on where you live you may also have rights to portability, restriction of processing, or to object — including under the GDPR and the CCPA. Email privacy@createthrough.com and we will respond within 30 days. You may also complain to your local data protection authority.

Children

CreateThrough is intended for adults. You must be 18 or older to hold an account, and we do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will delete it and the data associated with it.

Changes

If we change this policy materially we will email account holders before the change takes effect. The date at the top always reflects the current version.

Who operates this service

CreateThrough is operated by Ethan Nerone. For the purposes of the GDPR, Ethan Nerone is the data controller for the information described above.

Contact

Questions about this policy or your data: privacy@createthrough.com.