1. Who we are
Gridcore AI Social Auditor is a subscription service that connects to a customer's YouTube channel, Facebook Page and Instagram professional account with read-only access and produces a daily AI-written performance audit. It is operated by Gridcore Inc.. You can reach us at support@gridcoreinc.online.
2. Information we collect
2.1 Information you give us
When you subscribe and complete onboarding we collect:
- your name and email address;
- the links to your YouTube channel, Instagram profile and Facebook Page (optional);
- your Telegram/WhatsApp number (optional). Telegram and WhatsApp notifications are not active; we do not message this number unless you later switch such notifications on.
2.2 Payment information
Payments are processed by Razorpay. Your card, UPI, bank or wallet details are entered on Razorpay's secure checkout and are never sent to or stored by us. We store only the Razorpay order ID, payment ID, amount, currency, status and payment date.
2.3 Data from accounts you connect
When you choose to connect an account, you sign in on Google's or Facebook's own pages and grant us read-only permissions:
- Google / YouTube — your basic Google profile (account ID, name and email address, used to identify you and let you sign in) and, through the YouTube Data API v3 and YouTube Analytics API with read-only scopes (for example
youtube.readonlyandyt-analytics.readonly): your channel ID and name, public channel and video information (titles, publish dates, durations, thumbnails), and channel/video analytics such as views, watch time, average view duration, audience retention, subscriber changes, traffic sources and subscribed vs. non-subscribed viewer breakdowns. - Meta / Facebook & Instagram — your app-scoped Facebook user ID and name, the list of Facebook Pages you manage and choose to connect, and read-only Page and Instagram professional-account insights (for example via
pages_show_list,pages_read_engagement,read_insights,instagram_basicandinstagram_manage_insights): Page and Instagram account IDs, names/usernames, posts, Reels and their captions and publish times, and metrics such as reach, impressions, plays, likes, comments counts, shares, saves and follower vs. non-follower reach.
We do not read your private messages, we do not post, comment, like or edit anything, and we do not access your contacts or friends lists.
2.4 Credentials you enter manually
If you choose to connect an account by pasting credentials (such as an API key or access token) instead of signing in, we store them encrypted and use them only to read the same analytics described above.
2.5 Technical information
Our servers keep standard technical logs (IP address, browser user-agent, requested page, time) for security and troubleshooting. We use only essential cookies (see Cookies). We do not use advertising or cross-site tracking cookies.
3. How we use information
We use your information only to provide the service you subscribed to:
- to create and secure your account and let you sign in (private link, Google or Facebook sign-in);
- to fetch the analytics of the accounts you connected, typically once a day;
- to generate your AI audit and show it — with your report history — on your private dashboard;
- to process and verify payments and keep required financial records;
- to provide support you request, keep the service secure, and comply with the law.
We do not sell your data, we do not use it for advertising, and we do not use it to build profiles for anyone else.
4. AI analysis (Anthropic Claude)
To write your report, we send the relevant metrics and content details from your connected accounts (for example video titles, captions and performance figures) to the Claude API provided by Anthropic. Anthropic processes this data as our service provider solely to return the analysis to us, under its commercial terms, which do not allow Anthropic to train its models on this API data. We send only what is needed for your audit and never send your access tokens or passwords.
5. Google API Services & Limited Use
In particular, for data we receive from Google (including YouTube data):
- we use it only to provide and improve the user-facing features of Gridcore AI Social Auditor — your daily audit and dashboard;
- we transfer it to others only as necessary to provide those features (the AI analysis described in section 4), for security purposes, to comply with applicable law, or as part of a merger or acquisition with your notice;
- we do not use or transfer it for serving advertisements, including retargeting or personalised ads;
- we do not sell it and do not use it to determine credit-worthiness or for lending purposes;
- we do not use it to develop, improve or train generalised AI and/or machine-learning models;
- no human at our company reads it unless you give us permission (for example when you ask for support), it is needed for security purposes (such as investigating abuse), it is needed to comply with applicable law, or it has been aggregated and anonymised for internal operations.
6. YouTube API Services
Gridcore AI Social Auditor uses YouTube API Services to read your channel analytics. By connecting YouTube you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
You can revoke our access to your Google account at any time from your Google Account's third-party access page (Security → Third-party apps & services). You can also disconnect YouTube from your Gridcore AI Social Auditor dashboard.
7. Facebook & Instagram data
Data received from Meta Platforms is used only to produce your audit, in line with the Meta Platform Terms. Meta's own practices are described in the Meta Privacy Policy.
To revoke access, go to Facebook Settings & privacy → Settings → Business integrations (direct link), select Gridcore AI Social Auditor and choose Remove. You can also disconnect Facebook and Instagram from your dashboard. See our Data Deletion Instructions for deleting data we already hold.
9. Storage & security
- OAuth access and refresh tokens and any credentials you paste are encrypted at rest with AES-256-GCM, using a key kept outside the database.
- All traffic to our site is encrypted in transit with HTTPS.
- Sign-in sessions use signed, HTTP-only cookies; your private dashboard link is stored only as a one-way hash, so it cannot be recovered from our database.
- Administrative access is restricted and password protected.
No method of storage or transmission is 100% secure, but we work hard to protect your data and will notify you and the relevant authorities of a breach where the law requires.
10. Data retention
- Account details and reports — kept while you have an account, so you can still open your report history after a paid month ends. Each report stores a snapshot of the metrics used to create it. Ask us to delete the account when you no longer want it kept.
- Access tokens — kept only while the connection is active. When you disconnect an account in your dashboard, we stop accessing it and delete its stored tokens. When your paid month ends we stop reading your accounts; disconnect them (or ask for deletion) if you also want the tokens removed.
- Deletion requests — when you ask us to delete your account, we delete your profile, connections, tokens and reports within 30 days.
- Payment records — kept for as long as tax and accounting laws require (they contain no card or bank details).
- Server logs — kept for a limited period for security and troubleshooting.
11. Your choices & rights
- Disconnect any account at any time from your dashboard.
- Revoke access at the source: Google third-party access or Facebook Business integrations.
- Access, correct or delete your personal data by emailing support@gridcoreinc.online — see also our Data Deletion Instructions.
- Withdraw consent at any time; this does not affect processing already carried out.
We will respond within the time required by applicable data-protection law, including India's Digital Personal Data Protection Act, 2023 and, where it applies, the GDPR. We may need to verify your identity before acting on a request.
13. Children
Gridcore AI Social Auditor is intended for businesses and creators aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
14. International processing
Our service providers may process data in countries other than your own (for example, AI analysis may be performed in the United States). Where this happens we rely on the providers' contractual commitments to protect your data.
15. Changes to this policy
We may update this policy as the service evolves (for example when email reports launch). We will change the “Last updated” date above and, for material changes, notify active clients by email or on the dashboard before the change takes effect.
16. Contact & grievances
Questions, requests or complaints about privacy can be sent to our grievance contact at support@gridcoreinc.online. We aim to acknowledge requests within 72 hours and resolve them within 30 days.