Privacy policy

Privacy policy

Last updated 2 September 2026

DT OS is Double Tap's internal tool for managing inbound brand partnership deals with the creators we work with. This page explains, in plain language, what personal data DT OS holds, why, how long it's kept, who inside Double Tap can see it, and how to ask us to change or delete it. It covers creators we work with, and the people at brands who email us — not visitors to this page itself, which sets no cookies and tracks nothing.

What we collect, and why

Five kinds of data pass through DT OS. Each is collected for a specific, narrow reason — nothing here is collected speculatively.

Creator profile and platform statistics

What
Name, handle, category, nationality, city, languages, and follower/engagement statistics per platform (Instagram, TikTok, YouTube), plus audience demographics for creators who've connected an account for that.
Why
To evaluate whether a creator is a fit for a brand offer, to support rate negotiation, and to report real campaign performance back to brands.
How long we keep it
Kept while the creator is on Double Tap's active roster. If an admin permanently deletes a creator's profile, their platform stats, audience data, and platform handles are deleted with it. A creator's name may still appear on a campaign report already delivered to a brand — that's the record of work already done, not a live profile.

Inbound email content

What
The full text of brand outreach emails arriving in inboxes a Double Tap staff member has connected — sender, subject, and body.
Why
To detect brand partnership offers automatically and score them. The original text is kept specifically so scoring can be re-run later, as the process improves, without needing to re-fetch it.
How long we keep it
Kept indefinitely alongside the offer it produced, unless deleted on request. DT OS only ever reads email — it has no ability to send, reply, or delete anything in the connected inbox itself.

Commercial data read from HubSpot

What
Deal values, pipeline stage, contract terms, and revenue figures for brand relationships, read from Double Tap's separate HubSpot CRM.
Why
HubSpot, not DT OS, is the team's system of record for this — DT OS's assistant answers commercial questions by reading it live rather than keeping its own copy.
How long we keep it
Not stored. Read live from HubSpot at the moment a question is asked, held in memory for at most five minutes to avoid repeat lookups within the same conversation, then discarded.

OAuth tokens for connected Google and Meta accounts

What
The access and refresh tokens issued when a Double Tap staff member connects a Gmail inbox, or a creator connects their Instagram account for insights.
Why
To read brand emails and read Instagram performance data on an ongoing basis without asking for sign-in again each time.
How long we keep it
Stored encrypted, never in plain text, for as long as the connection stays active. Never shown to any user — used only by the server to make the relevant API call.

Creator personal details, including contract and identity information

What
Nationality, city, languages, and commercial rate terms entered by Double Tap staff, plus contract summaries and flagged clauses where a contract exists for a specific deal.
Why
To run and track partnership negotiations and commercial agreements.
How long we keep it
Kept while the creator relationship is active, or as needed for an ongoing or completed deal's own records. Deletable on request, subject to the caveat under Your rights below.

Who inside Double Tap can see what

Access follows role, and is enforced by the database itself, not just by what the app's screens show.

  • Admin — full access to everything on this page.
  • Partnerships — deal, contract, and payment detail; creator profiles; and brand emails and offers, but only from the inboxes they themselves connected. One partnerships account cannot see another's connected inbox unless an admin reassigns it to them.
  • Viewer — campaign reports and creator/campaign lists only, read-only. No access to deal value, contracts, payments, brand emails, or account settings.

Where your data lives

DT OS's database runs on Supabase, hosted in the EU (Frankfurt). A small number of specialist services process specific data on our behalf, each scoped to one job:

  • Anthropic — reads offer and email text to parse and score brand offers, and powers the in-app assistant that answers staff questions.
  • Apify — fetches public social media statistics for creators from Instagram, TikTok, and YouTube.
  • Phyllo — provides audience demographic data for creators who've connected an account for it.
  • HubSpot — Double Tap's separate commercial CRM; DT OS reads deal and revenue data from it live, as described above.
  • Google — provides read-only Gmail access to inboxes a staff member connects.
  • Meta — provides Instagram Insights data for creators who connect their account.
  • Sentry — receives error reports if something in DT OS breaks, so we can fix it. Email content, commercial figures, tokens, and anything from our secrets store are stripped out before a report is ever sent.

Your rights

If DT OS holds data about you — as a creator we work with, or as someone at a brand who's emailed us — you can ask what we hold about you, ask us to correct it, or ask us to delete it.

Write to info@doubletapcontent.com. We'll get back to you and handle the request directly — there's no automated self-service flow for this yet.

One honest caveat: some records tied to a completed commercial agreement — a paid invoice, an outstanding balance — may need to be kept for our own accounting and legal obligations even after a deletion request, in which case we'll tell you plainly what we kept and why rather than silently keeping it.

Double Tap — this policy covers DT OS specifically, not doubletapcontent.com or any other Double Tap product.