Privacy Policy

Last updated: 9 September 2026

Statcard is operated by Archer Nagle LLC, a California limited liability company. This policy explains what we collect when you make a media-kit card, what we do with it, and how you take it back.

1. What we collect

Account data: your handle, name, and email address when you sign up.

Date of birth: we do not ask for one when you create a Statcard account. If you arrive from a partner service that runs its own age check, that step collects a date of birth and we store it privately. It is never shown on your public page, never included in an export, and it is deleted with your account.

Connected-account statistics: when you connect a social account (YouTube, TikTok, Instagram, Threads, Bluesky or X), we retrieve aggregate statistics about it from the platform's official API, such as follower count, engagement rate, and view averages, via read-only access. We also retrieve your recent posts with their thumbnail, caption, link and view, like and comment counts, which appear in the content row of your card. On Instagram we also read your stories while they are live and keep their views, reach and replies, and their Facebook views if you shared them there. Instagram's own picture link expires with the story, so we keep a copy of each story's image or video for your media kit. Delete one from your card, or turn copies off in Settings to delete them all. Where a platform provides them, we retrieve aggregate audience demographics (country, age range and gender shares). We do not retrieve your private messages, your contacts, or the content of your audience's accounts.

Embedded content: your card can display your public Instagram and Threads posts in the platform's own embed format, the post as it appears on the platform, linking back to it. That uses Meta's oEmbed interface, which reads only public posts by their public URL and returns nothing private. We embed only posts from your own connected account.

Access credentials: when you connect TikTok, Instagram, Threads, YouTube or X, the platform gives Statcard an access token. It is a key to the read-only parts of your account, and we store it. It is encrypted (AES-256-GCM) before it goes into the database, with the encryption key kept outside the database. It is never shown in the app and never included in an export, and we do not log it. Error messages coming back from the platforms are stripped of anything token-shaped first. We never receive or store your password. Connecting Bluesky creates no token: every figure it shows is public on the network, and you prove ownership with a one-time code in your bio instead.

Usage data: standard server logs (IP address, browser type, pages visited) used for security and to operate the service.

2. How we use it

To display and keep current the media-kit page you created, to operate and secure the service, and to contact you about your account. We don't use platform data for anything beyond what this section describes. We do not sell it, we do not use it for advertising or ad targeting, and we do not use it to train machine learning or AI models.

Your access token. TikTok, Instagram, Threads, YouTube and X give apps ongoing access rather than a one-time read. Instagram says as much on its own consent screen. That is how the integration works, and it is what keeps your card showing real numbers instead of a snapshot from the day you set it up.

The token renews itself, so the connection does not lapse. When someone opens your card and its numbers are more than about half a day old, it re-reads your own profile figures, your recent posts and, where you granted it, your audience breakdown. On Instagram it also reads your live stories and their counts, when the card is opened and once a day. When you disconnect, it is what we use to ask the platform to drop the grant.

If we add a use, this page says so first, and it stays inside the read-only permissions you already granted and reads only your own account. We never post, message, follow, or change anything, and your token is never used to reach anyone else's account.

3. What we share

Your media-kit page is visible to anyone you share the link with. If you use the export feature, you choose who receives your exported statistics. We do not sell personal data and we do not share platform-derived data with third parties except at your direction (your public page, your exports) or as required by law. Infrastructure providers (hosting, analytics) process data on our behalf under their own safeguards.

4. Data from platforms

When you connect an account you grant Statcard read-only, creator-authorized access via the platform's official OAuth flow. We only request the minimum scopes needed to read your own profile, your own posts and aggregate follower/engagement statistics. The permissions we request are:

  • Instagram: instagram_business_basic, instagram_business_manage_insights and Meta oEmbed Read.
  • Threads: threads_basic, threads_manage_insights and Threads oEmbed Read.
  • TikTok: user.info.basic, user.info.profile, user.info.stats and video.list.
  • YouTube: youtube.readonly and yt-analytics.readonly.
  • X: users.read, tweet.read and offline.access. Read-only: your own profile counts and your own recent posts with their public counts. X publishes no audience demographics, so none are retrieved.
  • Bluesky: none. Figures are read from the public network API with no credential.

Data retrieved from connected platforms is handled according to each platform's developer terms, including Meta's Platform Terms and Developer Policies for Instagram and Threads data.

That access is ongoing, not a single visit at connect time. Tokens expire, so a job runs once a day and renews them before they do, without asking you again. Instagram and Threads tokens last about 60 days and renewal starts ten days out. A TikTok access token lasts about a day and is renewed from a refresh token that lasts about a year. A YouTube access token lasts about an hour and is renewed on demand, when your card is opened. An X access token lasts about two hours and is renewed the same way, from a refresh token that X replaces on every renewal; because X charges for every read, an X card re-reads its numbers about once a week rather than every half day. If a renewal fails for good we delete the credential, and Settings asks you to reconnect.

You can take that access back at any time. Disconnect the account inside Statcard and we ask the platform to drop the grant, then delete our copy. The delete happens either way: if the platform does not answer, or if there was never a stored credential to ask with, our copy still goes. You can also remove Statcard from the platform's own settings (Instagram → Settings → Apps and Websites; Threads → Settings → Account → Apps and websites; TikTok → Manage app permissions; Google Account → Third-party apps for YouTube; X → Settings → Security and account access → Apps and sessions → Connected apps). For Instagram and Threads, Meta tells us and we delete that connection's data here automatically. Either way, all further retrieval stops and the statistics from that connection are deleted. Bluesky has nothing to revoke; removing it in Settings deletes what we hold.

5. Retention and deletion

Access credentials are treated as urgent, because a live one is a key to your account. Disconnect a platform or delete your account and we ask the platform to drop the grant and destroy our copy in the same request. It never sits in a 30-day queue.

Everything else we keep while your account exists. Delete your account and we delete your page and stored statistics within 30 days, except minimal records we must keep for legal or security reasons. Your sign-in is deleted in the same step, so there is no login left behind. To delete your account or exercise any data right (access, correction, portability, erasure), use the delete button in Settings or email us.

Our data deletion page has step-by-step instructions: disconnecting a single platform, removing Statcard from a platform's own app settings (which deletes the associated data here automatically), and full account deletion.

6. Cookies

We use only the cookies needed to keep you signed in. No advertising cookies, no cross-site tracking.

7. Children

Statcard is not intended for anyone under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us their information, write to us and we will delete the account and its data.

8. Contact

Data controller: Archer Nagle LLC, operating as Statcard. Requests and questions: andrew@archernagle.com.